Back

CVE-2018-7836

CRITICAL

An unrestricted Upload of File with Dangerous Type vulnerability exists on numerous methods of the IIoT Monitor 3.1.38 software that could allow upload and execution of malicious files.

Published: Dec 24, 2018 Modified: Jun 17, 2026
CWE-434

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (1)

Vendor Product Version
schneider-electric iiot_monitor 3.1.38

GitHub Security Advisory GHSA-5r23-4mrh-r3pm

An unrestricted Upload of File with Dangerous Type vulnerability exists on numerous methods of...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 31.98%

Top 2% most likely to be exploited

Threat Score 48.8 / 100

Data Sources

NVD EPSS GitHub