cbcvebase.

Schneider-Electric U.Motion Builder vulnerabilities

24 known vulnerabilities affecting schneider-electric/u.motion_builder.

Total CVEs
24
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
3
Severity breakdown
CRITICAL5HIGH12MEDIUM7

Vulnerabilities

Page 2 of 2
CVE-2017-9959P4MEDIUMCVSS 5.5≤ 1.2.12017-09-26
CVE-2017-9959 [MEDIUM] CVE-2017-9959: A vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in A vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system accepts reboot in session from unauthenticated users, supporting a denial of service condition.
nvd
CVE-2018-7763P4MEDIUMCVSS 4.3fixed in 1.3.42018-07-03
CVE-2018-7763 [MEDIUM] CWE-22 CVE-2018-7763: The vulnerability exists within css.inc.php in Schneider Electric U.motion Builder software versions The vulnerability exists within css.inc.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The 'css' parameter contains a directory traversal vulnerability.
nvd
CVE-2018-7764P4MEDIUMCVSS 4.3fixed in 1.3.42018-07-03
CVE-2018-7764 [MEDIUM] CWE-22 CVE-2018-7764: The vulnerability exists within runscript.php applet in Schneider Electric U.motion Builder software The vulnerability exists within runscript.php applet in Schneider Electric U.motion Builder software versions prior to v1.3.4. There is a directory traversal vulnerability in the processing of the 's' parameter of the applet.
nvd
CVE-2018-7776P4MEDIUMCVSS 4.3fixed in 1.3.42018-07-03
CVE-2018-7776 [MEDIUM] CWE-200 CVE-2018-7776: The vulnerability exists within error.php in Schneider Electric U.motion Builder software versions p The vulnerability exists within error.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. System information is returned to the attacker that contains sensitive data.
nvd