CVE-2018-7798: Schneider Electric Somachine Basic

High severity, CVSS 8.2. EPSS: 0.7% chance of exploitation in the next 30 days.

A Insufficient Verification of Data Authenticity (CWE-345) vulnerability exists in the Modicon M221, all versions, which could cause a change of IPv4 configuration (IP address, mask and gateway) when remotely connected to the device.

Affected products

Published 2018-11-02. Last modified 2026-06-17.