{"api_version":"1","generated_at":"2026-07-23T06:15:54+00:00","cve":"CVE-2017-9958","urls":{"html":"https://cve.report/CVE-2017-9958","api":"https://cve.report/api/cve/CVE-2017-9958.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-9958","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-9958"},"summary":{"title":"CVE-2017-9958","description":"An improper access control vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an improper handling of the system configuration can allow an attacker to execute arbitrary code under the context of root.","state":"PUBLIC","assigner":"cybersecurity@schneider-electric.com","published_at":"2017-09-26 01:29:00","updated_at":"2019-10-03 00:03:00"},"problem_types":["CWE-732"],"metrics":[],"references":[{"url":"http://www.securityfocus.com/bid/99344","name":"99344","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.schneider-electric.com/en/download/document/SEVD-2017-178-01/","name":"http://www.schneider-electric.com/en/download/document/SEVD-2017-178-01/","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Security Notification - U.motion Builder Software v1.5 | Schneider Electric","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-9958","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-9958","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"9958","vulnerable":"1","versionEndIncluding":"1.2.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"schneider-electric","cpe5":"u.motion_builder","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cybersecurity@schneider-electric.com","DATE_PUBLIC":"2017-06-28T00:00:00","ID":"CVE-2017-9958","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"U.Motion","version":{"version_data":[{"version_value":"U.motion Builder Versions 1.2.1 and prior."}]}}]},"vendor_name":"Schneider Electric SE"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An improper access control vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an improper handling of the system configuration can allow an attacker to execute arbitrary code under the context of root."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Improper Access Control"}]}]},"references":{"reference_data":[{"name":"http://www.schneider-electric.com/en/download/document/SEVD-2017-178-01/","refsource":"CONFIRM","url":"http://www.schneider-electric.com/en/download/document/SEVD-2017-178-01/"},{"name":"99344","refsource":"BID","url":"http://www.securityfocus.com/bid/99344"}]}},"nvd":{"publishedDate":"2017-09-26 01:29:00","lastModifiedDate":"2019-10-03 00:03:00","problem_types":["CWE-732"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":7.2},"severity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:schneider-electric:u.motion_builder:*:*:*:*:*:*:*:*","versionEndIncluding":"1.2.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"9958","Ordinal":"107598","Title":"CVE-2017-9958","CVE":"CVE-2017-9958","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"9958","Ordinal":"1","NoteData":"An improper access control vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an improper handling of the system configuration can allow an attacker to execute arbitrary code under the context of root.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"9958","Ordinal":"2","NoteData":"2017-09-25","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"9958","Ordinal":"3","NoteData":"2017-09-26","Type":"Other","Title":"Modified"}]}}}