Schneider Electric StruxureOn Gateway CVE-2017-9970 Arbitrary File Upload Vulnerability
BID:103052
CVE-2017-9970 |Info
Schneider Electric StruxureOn Gateway CVE-2017-9970 Arbitrary File Upload Vulnerability
| Bugtraq ID: | 103052 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-9970 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 15 2018 12:00AM |
| Updated: | Feb 15 2018 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Schneider-Electric StruxureOn Gateway 1.0 |
| Not Vulnerable: |
Schneider-Electric StruxureOn Gateway 1.2 |
Discussion
Schneider Electric StruxureOn Gateway CVE-2017-9970 Arbitrary File Upload Vulnerability
Schneider Electric StruxureOn Gateway is prone to an arbitrary file-upload vulnerability.
An attacker may leverage these issues to upload arbitrary files to the affected computer; this can result in arbitrary code execution within the context of the vulnerable application.
Versions prior to Schneider Electric StruxureOn Gateway 1.2 are vulnerable.
Schneider Electric StruxureOn Gateway is prone to an arbitrary file-upload vulnerability.
An attacker may leverage these issues to upload arbitrary files to the affected computer; this can result in arbitrary code execution within the context of the vulnerable application.
Versions prior to Schneider Electric StruxureOn Gateway 1.2 are vulnerable.
Solution / Fix
Schneider Electric StruxureOn Gateway CVE-2017-9970 Arbitrary File Upload Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.