{"api_version":"1","generated_at":"2026-07-23T06:34:27+00:00","cve":"CVE-2017-9960","urls":{"html":"https://cve.report/CVE-2017-9960","api":"https://cve.report/api/cve/CVE-2017-9960.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-9960","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-9960"},"summary":{"title":"CVE-2017-9960","description":"An information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system response to error provides more information than should be available to an unauthenticated user.","state":"PUBLIC","assigner":"cybersecurity@schneider-electric.com","published_at":"2017-09-26 01:29:00","updated_at":"2017-09-27 20:39:00"},"problem_types":["CWE-200"],"metrics":[],"references":[{"url":"http://www.securityfocus.com/bid/99344","name":"99344","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.schneider-electric.com/en/download/document/SEVD-2017-178-01/","name":"http://www.schneider-electric.com/en/download/document/SEVD-2017-178-01/","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Security Notification - U.motion Builder Software v1.5 | Schneider Electric","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-9960","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-9960","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"9960","vulnerable":"1","versionEndIncluding":"1.2.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"schneider-electric","cpe5":"u.motion_builder","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cybersecurity@schneider-electric.com","DATE_PUBLIC":"2017-06-28T00:00:00","ID":"CVE-2017-9960","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"U.Motion","version":{"version_data":[{"version_value":"U.motion Builder Versions 1.2.1 and prior."}]}}]},"vendor_name":"Schneider Electric SE"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system response to error provides more information than should be available to an unauthenticated user."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Information Exposure through an error message"}]}]},"references":{"reference_data":[{"name":"http://www.schneider-electric.com/en/download/document/SEVD-2017-178-01/","refsource":"CONFIRM","url":"http://www.schneider-electric.com/en/download/document/SEVD-2017-178-01/"},{"name":"99344","refsource":"BID","url":"http://www.securityfocus.com/bid/99344"}]}},"nvd":{"publishedDate":"2017-09-26 01:29:00","lastModifiedDate":"2017-09-27 20:39:00","problem_types":["CWE-200"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":3.9,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:schneider-electric:u.motion_builder:*:*:*:*:*:*:*:*","versionEndIncluding":"1.2.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"9960","Ordinal":"107600","Title":"CVE-2017-9960","CVE":"CVE-2017-9960","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"9960","Ordinal":"1","NoteData":"An information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system response to error provides more information than should be available to an unauthenticated user.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"9960","Ordinal":"2","NoteData":"2017-09-25","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"9960","Ordinal":"3","NoteData":"2017-09-26","Type":"Other","Title":"Modified"}]}}}