Skip to content
COOEY

EXPOSURES › CVE-2018-7841

CVE-2018-7841

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-04-15 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2018-7841 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 65/100 rceexploited-in-wildunpatched

Schneider Electric U.motion Builder suffered a SQL injection vulnerability that allowed unwanted code execution when improper characters were entered.

A SQL injection flaw in Schneider Electric U.motion Builder enabled unwanted code execution upon input of specific characters, exposing systems to potential data manipulation or unauthorized access. DIB organizations must ensure all industrial control and building management software is patched against known vulnerabilities, especially those listed in CISA's KEV catalog, to prevent similar exploits. This failure highlights the risk of relying on unpatched or poorly secured third-party software in critical infrastructure environments.

Shame score — The vulnerability was actively exploited (KEV) and allowed code execution, indicating a significant lapse in securing industrial software despite known risks.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

A SQL Injection vulnerability exists in U.motion Builder software which could cause unwanted code execution when an improper set of characters is entered.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.