An improper access control vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an improper handling of the system configuration can allow an attacker to execute arbitrary code under the context of root.
References
Link | Resource |
---|---|
http://www.schneider-electric.com/en/download/document/SEVD-2017-178-01/ | Vendor Advisory |
http://www.securityfocus.com/bid/99344 | Third Party Advisory VDB Entry |
http://www.schneider-electric.com/en/download/document/SEVD-2017-178-01/ | Vendor Advisory |
http://www.securityfocus.com/bid/99344 | Third Party Advisory VDB Entry |
Configurations
History
21 Nov 2024, 03:37
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.schneider-electric.com/en/download/document/SEVD-2017-178-01/ - Vendor Advisory | |
References | () http://www.securityfocus.com/bid/99344 - Third Party Advisory, VDB Entry |
Information
Published : 2017-09-26 01:29
Updated : 2024-11-21 03:37
NVD link : CVE-2017-9958
Mitre link : CVE-2017-9958
CVE.ORG link : CVE-2017-9958
JSON object : View
Products Affected
schneider-electric
- u.motion_builder
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource