CVE-2017-9957: Critical severity schneider electric u.motion builder vulnerability
A vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the web service contains a hidden system account with a hardcoded password. An attacker can use this information to log into the system with high-privilege credentials.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9957?
The severity of CVE-2017-9957 is classified as high due to the presence of a hidden system account with a hardcoded password.
How do I fix CVE-2017-9957?
To fix CVE-2017-9957, upgrade to a version of Schneider Electric's U.motion Builder software that is later than 1.2.1.
Which versions of U.motion Builder are affected by CVE-2017-9957?
All versions of Schneider Electric's U.motion Builder software prior to version 1.2.1 are affected by CVE-2017-9957.
What can an attacker do with CVE-2017-9957?
An attacker can exploit CVE-2017-9957 to log into the system using high-privilege credentials through the hidden system account.
Is there a workaround for CVE-2017-9957 if I cannot upgrade immediately?
Currently, no official workaround is provided for CVE-2017-9957; upgrading is the only recommended solution.