CVE-2017-9960: Infoleak
Published Sep 25, 2017
·Updated
An information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system response to error provides more information than should be available to an unauthenticated user.
Affected Software
1 affected component
Schneider-electric U.motion Builder<=1.2.1
Event History
Sep 25, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-9960?
The severity of CVE-2017-9960 is classified as medium risk due to the potential information disclosure.
2
How do I fix CVE-2017-9960?
To fix CVE-2017-9960, update to Schneider Electric U.motion Builder version 1.2.2 or later.
3
What type of vulnerability is CVE-2017-9960?
CVE-2017-9960 is an information disclosure vulnerability affecting U.motion Builder.
4
Who is affected by CVE-2017-9960?
CVE-2017-9960 affects users of Schneider Electric U.motion Builder software versions 1.2.1 and prior.
5
Can CVE-2017-9960 be exploited remotely?
CVE-2017-9960 can be exploited by unauthenticated users through specific error responses.