Schneider-Electric U.Motion Builder vulnerabilities

24 known vulnerabilities affecting schneider-electric/u.motion_builder.

Total CVEs
24
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL5HIGH12MEDIUM7

Vulnerabilities

Page 2 of 2
CVE-2017-9958HIGHCVSS 7.8≤ 1.2.12017-09-26
CVE-2017-9958 [HIGH] CWE-732 CVE-2017-9958: An improper access control vulnerability exists in Schneider Electric's U.motion Builder software ve An improper access control vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an improper handling of the system configuration can allow an attacker to execute arbitrary code under the context of root.
nvd
CVE-2017-9956HIGHCVSS 7.3≤ 1.2.12017-09-26
CVE-2017-9956 [HIGH] CWE-798 CVE-2017-9956: An authentication bypass vulnerability exists in Schneider Electric's U.motion Builder software vers An authentication bypass vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system contains a hard-coded valid session. An attacker can use that session ID as part of the HTTP cookie of a web request, resulting in authentication bypass
nvd
CVE-2017-9960MEDIUMCVSS 5.3≤ 1.2.12017-09-26
CVE-2017-9960 [MEDIUM] CWE-200 CVE-2017-9960: An information disclosure vulnerability exists in Schneider Electric's U.motion Builder software ver An information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system response to error provides more information than should be available to an unauthenticated user.
nvd
CVE-2017-9959MEDIUMCVSS 5.5≤ 1.2.12017-09-26
CVE-2017-9959 [MEDIUM] CVE-2017-9959: A vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in A vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system accepts reboot in session from unauthenticated users, supporting a denial of service condition.
nvd