First published: Mon Sep 25 2017(Updated: )
A path traversal information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an unauthenticated user can execute arbitrary code and exfiltrate files.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider Electric U.motion Builder | <=1.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7974 is classified as a high severity vulnerability due to its potential for arbitrary code execution and information disclosure.
To mitigate CVE-2017-7974, upgrade Schneider Electric U.motion Builder software to the latest version beyond 1.2.1.
CVE-2017-7974 affects users of Schneider Electric U.motion Builder versions 1.2.1 and earlier.
CVE-2017-7974 is a path traversal vulnerability that allows unauthorized access to sensitive files.
Yes, an unauthenticated user can exploit CVE-2017-7974 to execute arbitrary code and exfiltrate files.