CVE-2017-7973

CRITICAL EXPLOITED

Schneider Electric U.motion Builder <= 1.2.1 - Unauthenticated SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2017-7973 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

A SQL injection vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an unauthenticated user can use calls to various paths allowing performance of arbitrary SQL commands against the underlying database.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/99344

Scores

CVSS v3 9.8
EPSS 0.0034
EPSS Percentile 56.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2026-03-05
CWE
CWE-89
Status published
Products (2)
Schneider Electric SE/U.Motion U.motion Builder Versions 1.2.1 and prior.
schneider-electric/u.motion_builder < 1.2.1
Published Sep 26, 2017
Tracked Since Feb 18, 2026