Vulnerability record · CVE-2018-7841 · published 22 May 2019
CVE-2018-7841: Schneider Electric U.motion Builder SQL injection allows code execution
Schneider Electric · U.Motion Builder
U.motion Builder version 1.3.4 contains a SQL injection flaw (CWE-89) that can lead to unwanted code execution when an improper set of characters is entered. It is remotely reachable with no authentication or user interaction and carries a critical CVSS score of 9.8, making it a serious risk for any deployment still running this end-of-life product.
Description
A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution when an improper set of characters is entered.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCritical CVSS 9.8, unauthenticated network-reachable code execution, confirmed KEV listing and very high EPSS probability make this an urgent risk, compounded by the product being end-of-life with no patch path.
What it is
U.motion Builder version 1.3.4 contains a SQL injection flaw (CWE-89) that can lead to unwanted code execution when an improper set of characters is entered. It is remotely reachable with no authentication or user interaction and carries a critical CVSS score of 9.8, making it a serious risk for any deployment still running this end-of-life product.
Impact
An unauthenticated attacker can inject SQL and achieve code execution, gaining full control over confidentiality, integrity and availability of the affected system. This can lead to complete compromise of the host running U.motion Builder.
Attack surface
The CVSS vector AV:N/AC:L/PR:N/UI:N indicates the flaw is reachable over the network with no privileges and no user interaction required. The description states the trigger is entering an improper set of characters, consistent with a remotely supplied input field.
Exploitation
CVE-2018-7841 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-04-15) and has an EPSS 30-day probability of 0.727 (99.4th percentile). Public exploit references exist on Packet Storm and the Full Disclosure mailing list, so active exploitation should be assumed.
What to do
- Disconnect or retire U.motion Builder 1.3.4, which is end-of-life per CISA's required action; do not rely on patching since no supported fix is indicated.
- If the product cannot be removed immediately, isolate it on a segmented network with strict firewall rules limiting access to trusted management hosts only.
- Monitor vendor advisory SEVD-2019-071-02 for any updated guidance and apply it if a supported replacement or fix becomes available.
- Inventory all instances of U.motion Builder across the environment and prioritize removal of any internet-facing or broadly reachable deployments.
Detection
- Search web and application logs for SQL metacharacters (quotes, comment sequences, UNION, stacked queries) in requests to U.motion Builder endpoints.
- Alert on unexpected child processes or command execution spawned by the U.motion Builder service, which would indicate successful code execution.
- Monitor network traffic to and from U.motion Builder hosts for anomalous outbound connections or unusual request patterns from external sources.
- Correlate IDS/IPS signatures for SQL injection and known exploit traffic against U.motion Builder hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-7841 to the Known Exploited Vulnerabilities catalog on 15 April 2022 as "Schneider Electric U.motion Builder SQL Injection Vulnerability". Required action: The impacted product is end-of-life and should be disconnected if still in use. Federal deadline 6 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/152862/Schneider-Electric-U.Motion-Builder-1.3.4-Command-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| http://seclists.org/fulldisclosure/2019/May/26 | ExploitMailing ListThird Party Advisory |
| https://www.schneider-electric.com/ww/en/download/document/SEVD-2019-071-02 | Vendor Advisory |
| http://packetstormsecurity.com/files/152862/Schneider-Electric-U.Motion-Builder-1.3.4-Command-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| http://seclists.org/fulldisclosure/2019/May/26 | ExploitMailing ListThird Party Advisory |
| https://www.schneider-electric.com/ww/en/download/document/SEVD-2019-071-02 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-7841 | US Government Resource |
Track CVE-2018-7841 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-7841), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.