CVE-2018-7785: Command Injection
In Schneider Electric U.motion Builder software versions prior to v1.3.4, a remote command injection allows authentication bypass.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Schneider Electric U.motion Builderto a version that resolves this vulnerability.Fixed in v1.3.4
Event History
Frequently Asked Questions
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2018-7785.
What is the severity level of CVE-2018-7785?
The severity level of CVE-2018-7785 is critical with a score of 9.8.
What software versions are affected by CVE-2018-7785?
Versions prior to v1.3.4 of Schneider Electric U.motion Builder software are affected by CVE-2018-7785.
What is the description of CVE-2018-7785?
CVE-2018-7785 is a remote command injection vulnerability in Schneider Electric U.motion Builder software versions prior to v1.3.4, which allows authentication bypass.
How can I fix CVE-2018-7785?
To fix CVE-2018-7785, upgrade Schneider Electric U.motion Builder software to version 1.3.4 or later.