CVE-2017-9956: High severity schneider electric u.motion builder vulnerability
An authentication bypass vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system contains a hard-coded valid session. An attacker can use that session ID as part of the HTTP cookie of a web request, resulting in authentication bypass
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9956?
CVE-2017-9956 is classified as a critical vulnerability due to its ability to allow authentication bypass.
How do I fix CVE-2017-9956?
To fix CVE-2017-9956, upgrade to a version of Schneider Electric U.motion Builder later than 1.2.1.
What happens if CVE-2017-9956 is exploited?
Exploiting CVE-2017-9956 allows an attacker to gain unauthorized access to the system by using a hard-coded valid session ID.
Which versions of Schneider Electric U.motion Builder are affected by CVE-2017-9956?
CVE-2017-9956 affects Schneider Electric U.motion Builder versions 1.2.1 and prior.
Is CVE-2017-9956 considered a serious security threat?
Yes, CVE-2017-9956 poses a serious security threat as it can allow attackers to bypass authentication mechanisms.