An improper access control vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an improper handling of the system configuration can allow an attacker to execute arbitrary code under the context of root.
References
Link | Resource |
---|---|
http://www.schneider-electric.com/en/download/document/SEVD-2017-178-01/ | Vendor Advisory |
http://www.securityfocus.com/bid/99344 | Third Party Advisory VDB Entry |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: schneider
Published: 2017-06-28T00:00:00
Updated: 2017-09-26T09:57:01
Reserved: 2017-06-26T00:00:00
Link: CVE-2017-9958
JSON object: View
NVD Information
Status : Analyzed
Published: 2017-09-26T01:29:03.897
Modified: 2019-10-03T00:03:26.223
Link: CVE-2017-9958
JSON object: View
Redhat Information
No data.
CWE