An improper access control vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an improper handling of the system configuration can allow an attacker to execute arbitrary code under the context of root.
References
Link | Resource |
---|---|
http://www.schneider-electric.com/en/download/document/SEVD-2017-178-01/ | Vendor Advisory |
http://www.securityfocus.com/bid/99344 | Third Party Advisory VDB Entry |
Configurations
Information
Published : 2017-09-25 18:29
Updated : 2019-10-02 17:03
NVD link : CVE-2017-9958
Mitre link : CVE-2017-9958
JSON object : View
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource
Products Affected
schneider-electric
- u.motion_builder