CVE-2018-7836

CRITICAL

IIoT Monitor 3.1.38 - Code Injection

Title source: llm
STIX 2.1

Description

An unrestricted Upload of File with Dangerous Type vulnerability exists on numerous methods of the IIoT Monitor 3.1.38 software that could allow upload and execution of malicious files.

References (2)

Core 2
Core References
Third Party Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/106484

Scores

CVSS v3 9.8
EPSS 0.0232
EPSS Percentile 84.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
schneider-electric/iiot_monitor 3.1.38
Published Dec 24, 2018
Tracked Since Feb 18, 2026