CVE-2017-7974

CRITICAL

Schneider Electric U.motion Builder <= 1.2.1 - Unauthenticated Path Traversal and Arbitrary File Read

Title source: llm
STIX 2.1

Description

A path traversal information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an unauthenticated user can execute arbitrary code and exfiltrate files.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/99344

Scores

CVSS v3 9.8
EPSS 0.0780
EPSS Percentile 92.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-22
Status published
Products (2)
Schneider Electric SE/U.Motion U.motion Builder Versions 1.2.1 and prior.
schneider-electric/u.motion_builder < 1.2.1
Published Sep 26, 2017
Tracked Since Feb 18, 2026