CVE-2018-7822

MEDIUM

SoMachine Basic and Modicon M221 < 1.10.0.0 - Unauthorized Access via Incorrect Default Permissions

Title source: llm
STIX 2.1

Description

An Incorrect Default Permissions (CWE-276) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references, all versions prior to firmware V1.10.0.0) which could cause unauthorized access to SoMachine Basic resource files when logged on the system hosting SoMachine Basic.

References (1)

Core 1
Core References

Scores

CVSS v3 5.5
EPSS 0.0005
EPSS Percentile 14.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-276
Status published
Products (2)
schneider-electric/modicon_m221_firmware < 1.10.0.0
schneider-electric/somachine_basic
Published May 22, 2019
Tracked Since Feb 18, 2026