First published: Mon Sep 25 2017(Updated: )
An information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system response to error provides more information than should be available to an unauthenticated user.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider Electric U.motion Builder | <=1.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-9960 is classified as medium risk due to the potential information disclosure.
To fix CVE-2017-9960, update to Schneider Electric U.motion Builder version 1.2.2 or later.
CVE-2017-9960 is an information disclosure vulnerability affecting U.motion Builder.
CVE-2017-9960 affects users of Schneider Electric U.motion Builder software versions 1.2.1 and prior.
CVE-2017-9960 can be exploited by unauthenticated users through specific error responses.