CVE-2017-9959: Medium severity schneider electric u.motion builder vulnerability
A vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system accepts reboot in session from unauthenticated users, supporting a denial of service condition.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9959?
CVE-2017-9959 has been rated as a high-severity vulnerability due to its potential to allow unauthorized access leading to denial of service.
How do I fix CVE-2017-9959?
To fix CVE-2017-9959, upgrade the Schneider Electric U.motion Builder software to version 1.2.2 or later.
Who is affected by CVE-2017-9959?
Users of Schneider Electric's U.motion Builder software version 1.2.1 and prior are affected by CVE-2017-9959.
What type of attack does CVE-2017-9959 enable?
CVE-2017-9959 allows an attacker to perform a denial of service attack by sending reboot commands from an unauthenticated session.
When was CVE-2017-9959 disclosed?
CVE-2017-9959 was disclosed in 2017, highlighting a critical security flaw in Schneider Electric's software.