Incorrect Default Permission vulnerability exists in SoMove (V2.8.1) and prior which could cause elevation of privilege and provide full access control to local system users to SoMove component and services when a SoMove installer script is launched.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HSchneider Electric Somove
APPSchneider-Electric≤ 2.8.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2018-7239HIGH7.8same product
A DLL hijacking vulnerability exists in Schneider Electric's SoMove Software and associated DTM software compo...
CVE-2014-9200HIGH7.5same product
Stack-based buffer overflow in an unspecified DLL file in a DTM development kit in Schneider Electric Unity Pr...
CVE-2013-0662HIGH9.3same product
Multiple stack-based buffer overflows in ModbusDrv.exe in Schneider Electric Modbus Serial Driver 1.10 through...
CVE-2018-7841CRITICAL9.8⚠ KEVPL ✓same vendor
SQL Injection z RCE w Schneider Electric U.Motion Builder 1.3.4
CVE-2024-10575CRITICAL10.0PL ✓same vendor
Brak autoryzacji w Schneider Electric EcoStruxure IT Gateway (CVSS 10.0)