CVE-2017-7574
Last modified
CVE-2017-7574 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Schneider Electric SoMachine Basic 1.4 SP1 and Schneider Electric Modicon TM221CE16R 1.3.3.3 devices have a hardcoded-key vulnerability. The Project Protection feature is used to prevent unauthorized users from opening an XML protected project file, by prompting the user for a password. EPSS estimates a 1.24% chance of exploitation in the next 30 days.
Description
Schneider Electric SoMachine Basic 1.4 SP1 and Schneider Electric Modicon TM221CE16R 1.3.3.3 devices have a hardcoded-key vulnerability. The Project Protection feature is used to prevent unauthorized users from opening an XML protected project file, by prompting the user for a password. This XML file is AES-CBC encrypted; however, the key used for encryption (SoMachineBasicSoMachineBasicSoMa) cannot be changed. After decrypting the XML file with this key, the user password can be found in the decrypted data. After reading the user password, the project can be opened and modified with the Schneider product.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Schneider-Electric | Modicon Tm221ce16r Firmware | 1.3.3.3 | — |
| Schneider-Electric | Somachine | 1.4 | Sp1 |
References
- http://www.securityfocus.com/bid/97518Third Party Advisory, VDB Entry
- https://os-s.net/advisories/OSS-2017-02.pdfBroken Link
- http://www.securityfocus.com/bid/97518Third Party Advisory, VDB Entry
- https://os-s.net/advisories/OSS-2017-02.pdfBroken Link
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-7574?
How severe is CVE-2017-7574?
How do I fix CVE-2017-7574?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-7566MyBB before 1.8.11 allows remote attackers to bypass an SSRF…
- CVE-2017-7568NetApp OnCommand Unified Manager for 7-Mode (core package) v…
- CVE-2017-7569In vBulletin before 5.3.0, remote attackers can bypass the C…
- CVE-2017-7570PivotX 2.3.11 allows remote authenticated Advanced users to …
- CVE-2017-7571public/rolechangeadmin in Faveo 1.9.3 allows CSRF. The impac…8
- CVE-2017-7572The _checkPolkitPrivilege function in serviceHelper.py in Ba…
- CVE-2017-7575Schneider Electric Modicon TM221CE16R 1.3.3.3 devices allow …9.8
- CVE-2017-7576DragonWave Horizon 1.01.03 wireless radios have hardcoded lo…9.8
- CVE-2017-7577XiongMai uc-httpd has directory traversal allowing the readi…
- CVE-2017-7578Multiple heap-based buffer overflows in parser.c in libming …
- CVE-2017-7579inc/PMF/Faq.php in phpMyFAQ before 2.9.7 has XSS in the ques…
- CVE-2017-7581SQL injection vulnerability in NewsController.php in the New…
Are you affected by CVE-2017-7574?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
