CVE-2018-7837: Schneider Electric Iiot Monior
High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.
An Improper Restriction of XML External Entity Reference ('XXE') vulnerability exists on numerous methods of the IIoT Monitor 3.1.38 software that could allow the software to resolve documents outside of the intended sphere of control, causing the software to embed incorrect documents into its output and expose restricted information.
Affected products
- Schneider Electric Iiot Monior: version 3.1.38 only
Published 2018-12-24. Last modified 2026-06-17.