CVE-2018-7787
published 2018-07-03CVE-2018-7787: In Schneider Electric U.motion Builder software versions prior to v1.3.4, this vulnerability is due to improper validation of input of context parameter in…
PriorityP426medium5.3CVSS 3.0
AVNACLPRNUINSUCLINAN
EPSS
1.10%
61.9th percentile
In Schneider Electric U.motion Builder software versions prior to v1.3.4, this vulnerability is due to improper validation of input of context parameter in HTTP GET request.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | u.motion_builder | < 1.3.4 | 1.3.4 |
| schneider_electric_se | u.motion_builder | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w7rq-mwf7-vprq: In Schneider Electric U
ghsa_unreviewed·2022-05-14
CVE-2018-7787 [MEDIUM] CWE-20 GHSA-w7rq-mwf7-vprq: In Schneider Electric U
In Schneider Electric U.motion Builder software versions prior to v1.3.4, this vulnerability is due to improper validation of input of context parameter in HTTP GET request.
CISA ICS
Schneider Electric U.motion Builder
cisa_ics·2018-06-18·CVSS 9.8
[CRITICAL] Schneider Electric U.motion Builder
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Schneider Electric U.motion Builder
Last RevisedJune 18, 2018
Alert CodeICSA-18-163-01
## 1. EXECUTIVE SUMMARY
-
CVSS v3 10.0
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: Schneider Electric
- Equipment: U.motion Builder
- Vulnerabilities: Command Injection, Cross-site Scripting, and Improper Input Validation
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow remote code execution.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following U.motion Builder Software versions are affected:
- U.motion Builder ve
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-07-03
Published