First published: Tue Jul 03 2018(Updated: )
In Schneider Electric U.motion Builder software versions prior to v1.3.4, a remote command injection allows authentication bypass.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric U.motion Builder | <1.3.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE ID of this vulnerability is CVE-2018-7785.
The severity level of CVE-2018-7785 is critical with a score of 9.8.
Versions prior to v1.3.4 of Schneider Electric U.motion Builder software are affected by CVE-2018-7785.
CVE-2018-7785 is a remote command injection vulnerability in Schneider Electric U.motion Builder software versions prior to v1.3.4, which allows authentication bypass.
To fix CVE-2018-7785, upgrade Schneider Electric U.motion Builder software to version 1.3.4 or later.