CVE-2017-7574
published 2017-04-06CVE-2017-7574: Schneider Electric SoMachine Basic 1.4 SP1 and Schneider Electric Modicon TM221CE16R 1.3.3.3 devices have a hardcoded-key vulnerability. The Project Protection…
PriorityP347critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.24%
65.8th percentile
Schneider Electric SoMachine Basic 1.4 SP1 and Schneider Electric Modicon TM221CE16R 1.3.3.3 devices have a hardcoded-key vulnerability. The Project Protection feature is used to prevent unauthorized users from opening an XML protected project file, by prompting the user for a password. This XML file is AES-CBC encrypted; however, the key used for encryption (SoMachineBasicSoMachineBasicSoMa) cannot be changed. After decrypting the XML file with this key, the user password can be found in the decrypted data. After reading the user password, the project can be opened and modified with the Schneider product.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | modicon_tm221ce16r_firmware | — | — |
| schneider-electric | somachine | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Schneider Electric Modicon M221 PLCs and SoMachine Basic (Update A)
cisa_ics·2017-04-13
Schneider Electric Modicon M221 PLCs and SoMachine Basic (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Schneider Electric Modicon M221 PLCs and SoMachine Basic (Update A)
Last RevisedJuly 20, 2017
Alert CodeICSA-17-103-02A
## CVSS v3 10.0
ATTENTION: Remotely exploitable/low skill level to exploit. Public exploits are available.
Vendor: Schneider Electric
Equipment: Modicon M221 PLCs and SoMachine Basic
Vulnerability: Use of Hard-Coded Cryptographic Key, Protection Mechanism Failure
## UPDATE INFORMATION
This updated advisory is a follow-up to the original advisory titled ICSA-17-103-02 Schneider Electric Modicon M221 PLCs and SoMachine Basic that was published April 13, 2017
GHSA
GHSA-v5jg-gm3q-h894: Schneider Electric SoMachine Basic 1
ghsa_unreviewed·2022-05-13
CVE-2017-7574 [CRITICAL] CWE-798 GHSA-v5jg-gm3q-h894: Schneider Electric SoMachine Basic 1
Schneider Electric SoMachine Basic 1.4 SP1 and Schneider Electric Modicon TM221CE16R 1.3.3.3 devices have a hardcoded-key vulnerability. The Project Protection feature is used to prevent unauthorized users from opening an XML protected project file, by prompting the user for a password. This XML file is AES-CBC encrypted; however, the key used for encryption (SoMachineBasicSoMachineBasicSoMa) cannot be changed. After decrypting the XML file with this key, the user password can be found in the decrypted data. After reading the user password, the project can be opened and modified with the Schneider product.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2017-097-01http://www.securityfocus.com/bid/97518https://os-s.net/advisories/OSS-2017-02.pdfhttp://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2017-097-01http://www.securityfocus.com/bid/97518https://os-s.net/advisories/OSS-2017-02.pdf
2017-04-06
Published