LiveActive security incident?Get immediate response
CVE Record

CVE-2018-7823: A Environment (CWE-2) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all reference...

A Environment (CWE-2) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references, all versions prior to firmware V1.10.0.0) which could cause remote launch of SoMachine Basic when sending crafted ethernet message.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

This CVE affects Schneider Electric SoMachine Basic and Modicon M221 controllers. A crafted Ethernet message could remotely launch SoMachine Basic. The source bundle does not provide CVSS, impact detail beyond launch behavior, or evidence of exploitation.

Executive priority

Treat this as an OT exposure review item, not a confirmed exploitation emergency. Prioritize sites where M221 controllers or engineering workstations are reachable from broader networks.

Technical view

The record describes an environment-class vulnerability in SoMachine Basic all versions and Modicon M221 all references before firmware V1.10.0.0. The trigger is a crafted Ethernet message causing remote launch of SoMachine Basic. Authentication requirements, network position, and full impact are not stated.

Likely exposure

Organizations using Schneider Electric Modicon M221 controllers below firmware V1.10.0.0 or SoMachine Basic should assess exposure, especially on engineering or OT Ethernet networks.

Exploitation context

CISA KEV is false in the provided bundle, and no cited source states active exploitation. The record only says crafted Ethernet traffic can trigger the behavior.

Researcher notes

Evidence is sparse: no CVSS vector, no CWE detail beyond CWE-2 wording, and no exploit-status support. Avoid assuming controller compromise; the documented behavior is remote launch of SoMachine Basic.

Mitigation direction

  • Confirm Schneider Electric advisory SEVD-2019-045-01 guidance.
  • Upgrade Modicon M221 firmware to V1.10.0.0 or later where applicable.
  • Identify whether SoMachine Basic is installed on engineering workstations.
  • Restrict OT Ethernet access to trusted engineering networks.
  • Monitor for unexpected SoMachine Basic launches or related workstation activity.

Validation and detection

  • Inventory Modicon M221 firmware versions across all sites.
  • Check engineering workstations for SoMachine Basic installations.
  • Review OT network paths that can reach M221 controllers.
  • Confirm remediation status against Schneider Electric advisory guidance.
  • Document any unsupported or still-exposed assets for risk acceptance.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2018-7823 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/aSoMachine Basic and Modicon M221, SoMachine Basic, all versions Modicon M221, all references, all versions prior to firmware V1.10.0.0SoMachine Basic and Modicon M221, SoMachine Basic, all versions Modicon M221, all references, all versions prior to firmware V1.10.0.0Listed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.