CVE-2018-7822: Schneider Electric Modicon m221 Firmware
Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.
An Incorrect Default Permissions (CWE-276) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references, all versions prior to firmware V1.10.0.0) which could cause unauthorized access to SoMachine Basic resource files when logged on the system hosting SoMachine Basic.
Affected products
- Schneider Electric Modicon m221 Firmware: before 1.10.0.0 (fixed in 1.10.0.0)
- Schneider Electric Somachine Basic: any version
Published 2019-05-22. Last modified 2026-06-17.