CVE-2017-7974: Path Traversal
A path traversal information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an unauthenticated user can execute arbitrary code and exfiltrate files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7974?
CVE-2017-7974 is classified as a high severity vulnerability due to its potential for arbitrary code execution and information disclosure.
How do I fix CVE-2017-7974?
To mitigate CVE-2017-7974, upgrade Schneider Electric U.motion Builder software to the latest version beyond 1.2.1.
Who is affected by CVE-2017-7974?
CVE-2017-7974 affects users of Schneider Electric U.motion Builder versions 1.2.1 and earlier.
What type of vulnerability is CVE-2017-7974?
CVE-2017-7974 is a path traversal vulnerability that allows unauthorized access to sensitive files.
Can an unauthenticated user exploit CVE-2017-7974?
Yes, an unauthenticated user can exploit CVE-2017-7974 to execute arbitrary code and exfiltrate files.