CVE-2017-9958
Summary
| CVE | CVE-2017-9958 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-09-26 01:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | An improper access control vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an improper handling of the system configuration can allow an attacker to execute arbitrary code under the context of root. |
Risk And Classification
Problem Types: CWE-732
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Schneider-electric | U.motion Builder | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 99344 | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Security Notification - U.motion Builder Software v1.5 | Schneider Electric | CONFIRM | www.schneider-electric.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.