CVE-2018-7841
KEV PoC ×2—SQL Injection in Schneider Electric U.motion Builder 1.3.4
CISA: Schneider Electric U.motion Builder SQL Injection Vulnerability
CVE-2018-7841 is a SQL injection flaw (CWE-89) in Schneider Electric's U.motion Builder software, specifically version 1.3.4. The flaw is scored with a network attack vector, no privileges required and no user interaction (CVSS 9.8), so an attacker can trigger it remotely without authentication by submitting an improper set of characters to the application. Successful exploitation could cause unwanted code execution, with high impact to confidentiality, integrity and availability — effectively unauthenticated remote code execution. Anyone still running the end-of-life U.motion Builder 1.3.4 is affected. Exploitation is actively tracked: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-04-15, carries a 72.7% EPSS probability of exploitation within 30 days (99th percentile), and two public PoC/exploit references are available.
What to do: Per CISA's required action, the impacted product is end-of-life and should be disconnected from the network if still in use; no fixed version is provided in the available data. Inventory for U.motion Builder 1.3.4 deployments — prioritizing any that are internet-facing — and retire, replace, or isolate them. Monitor Schneider Electric advisories for any updated guidance.
| Schneider Electric U.motion Builder | 1.3.4 (version specified in the CVE; CISA lists the product as affected) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution when an improper set of characters is entered.
- Affected
- Schneider Electric U.motion Builder
- Required action
- The impacted product is end-of-life and should be disconnected if still in use.
- Due date
- Ransomware use
- Unknown
- Vendors
- schneider-electric
- Products
- u.motion builder
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.