First published: Mon Sep 25 2017(Updated: )
A vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the web service contains a hidden system account with a hardcoded password. An attacker can use this information to log into the system with high-privilege credentials.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider Electric U.motion Builder | <=1.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-9957 is classified as high due to the presence of a hidden system account with a hardcoded password.
To fix CVE-2017-9957, upgrade to a version of Schneider Electric's U.motion Builder software that is later than 1.2.1.
All versions of Schneider Electric's U.motion Builder software prior to version 1.2.1 are affected by CVE-2017-9957.
An attacker can exploit CVE-2017-9957 to log into the system using high-privilege credentials through the hidden system account.
Currently, no official workaround is provided for CVE-2017-9957; upgrading is the only recommended solution.