Project Subscriptions
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-16579 | Schneider Electric SoMachine Basic 1.4 SP1 and Schneider Electric Modicon TM221CE16R 1.3.3.3 devices have a hardcoded-key vulnerability. The Project Protection feature is used to prevent unauthorized users from opening an XML protected project file, by prompting the user for a password. This XML file is AES-CBC encrypted; however, the key used for encryption (SoMachineBasicSoMachineBasicSoMa) cannot be changed. After decrypting the XML file with this key, the user password can be found in the decrypted data. After reading the user password, the project can be opened and modified with the Schneider product. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 29 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-321 | |
| Metrics |
cvssV3_1
|
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-29T13:32:04.296Z
Reserved: 2017-04-06T00:00:00.000Z
Link: CVE-2017-7574
Updated: 2024-08-05T16:04:11.981Z
Status : Modified
Published: 2017-04-06T21:59:00.307
Modified: 2026-05-29T14:16:21.410
Link: CVE-2017-7574
No data.
OpenCVE Enrichment
No data.
EUVD