CVE-2017-9958

HIGH

Schneider-electric U.motion Builder - Incorrect Permission Assignment

Title source: rule
STIX 2.1

Description

An improper access control vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an improper handling of the system configuration can allow an attacker to execute arbitrary code under the context of root.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/99344

Scores

CVSS v3 7.8
EPSS 0.0006
EPSS Percentile 16.9%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-732
Status published
Products (2)
Schneider Electric SE/U.Motion U.motion Builder Versions 1.2.1 and prior.
schneider-electric/u.motion_builder < 1.2.1
Published Sep 26, 2017
Tracked Since Feb 18, 2026