{"api_version":"1","generated_at":"2026-07-23T04:25:21+00:00","cve":"CVE-2017-9969","urls":{"html":"https://cve.report/CVE-2017-9969","api":"https://cve.report/api/cve/CVE-2017-9969.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-9969","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-9969"},"summary":{"title":"CVE-2017-9969","description":"An information disclosure vulnerability exists in Schneider Electric's IGSS Mobile application version 3.01 and prior. Passwords are stored in clear text in the configuration which can result in exposure of sensitive information.","state":"PUBLIC","assigner":"cybersecurity@schneider-electric.com","published_at":"2018-02-12 23:29:00","updated_at":"2019-10-03 00:03:00"},"problem_types":["CWE-522"],"metrics":[],"references":[{"url":"http://www.securityfocus.com/bid/103046","name":"103046","refsource":"BID","tags":["Third Party Advisory","VDB Entry","Vendor Advisory"],"title":"Schneider Electric IGSS Mobile CVE-2017-9969 Local Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.schneider-electric.com/en/download/document/SEVD-2018-039-02/","name":"https://www.schneider-electric.com/en/download/document/SEVD-2018-039-02/","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Security Notification- IGSS Mobile | Download Schneider Electric","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://ics-cert.us-cert.gov/advisories/ICSA-18-046-03","name":"https://ics-cert.us-cert.gov/advisories/ICSA-18-046-03","refsource":"MISC","tags":["Third Party Advisory","US Government Resource"],"title":"Schneider Electric IGSS Mobile | CISA","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-9969","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-9969","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"9969","vulnerable":"1","versionEndIncluding":"3.01","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"schneider-electric","cpe5":"igss_mobile","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"android","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"9969","vulnerable":"1","versionEndIncluding":"3.01","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"schneider-electric","cpe5":"igss_mobile","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"iphone_os","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cybersecurity@schneider-electric.com","DATE_PUBLIC":"2018-02-12T00:00:00","ID":"CVE-2017-9969","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An information disclosure vulnerability exists in Schneider Electric's IGSS Mobile application version 3.01 and prior. Passwords are stored in clear text in the configuration which can result in exposure of sensitive information."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"103046","refsource":"BID","url":"http://www.securityfocus.com/bid/103046"},{"name":"https://www.schneider-electric.com/en/download/document/SEVD-2018-039-02/","refsource":"CONFIRM","url":"https://www.schneider-electric.com/en/download/document/SEVD-2018-039-02/"},{"name":"https://ics-cert.us-cert.gov/advisories/ICSA-18-046-03","refsource":"MISC","url":"https://ics-cert.us-cert.gov/advisories/ICSA-18-046-03"}]}},"nvd":{"publishedDate":"2018-02-12 23:29:00","lastModifiedDate":"2019-10-03 00:03:00","problem_types":["CWE-522"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":6.7,"baseSeverity":"MEDIUM"},"exploitabilityScore":0.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":2.1},"severity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:schneider-electric:igss_mobile:*:*:*:*:*:iphone_os:*:*","versionEndIncluding":"3.01","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:schneider-electric:igss_mobile:*:*:*:*:*:android:*:*","versionEndIncluding":"3.01","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"9969","Ordinal":"107609","Title":"CVE-2017-9969","CVE":"CVE-2017-9969","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"9969","Ordinal":"1","NoteData":"An information disclosure vulnerability exists in Schneider Electric's IGSS Mobile application version 3.01 and prior. Passwords are stored in clear text in the configuration which can result in exposure of sensitive information.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"9969","Ordinal":"2","NoteData":"2018-02-12","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"9969","Ordinal":"3","NoteData":"2018-02-17","Type":"Other","Title":"Modified"}]}}}