CVE-2017-9958
HIGHSchneider-electric U.motion Builder - Incorrect Permission Assignment
Title source: ruleDescription
An improper access control vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an improper handling of the system configuration can allow an attacker to execute arbitrary code under the context of root.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
http://www.schneider-electric.com/en/download/document/SEVD-2017-178-01/
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/99344
Scores
CVSS v3
7.8
EPSS
0.0006
EPSS Percentile
16.9%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-732
Status
published
Products (2)
Schneider Electric SE/U.Motion
U.motion Builder Versions 1.2.1 and prior.
schneider-electric/u.motion_builder
< 1.2.1
Published
Sep 26, 2017
Tracked Since
Feb 18, 2026