VulnerabilityModified
CVE-2017-9960
An information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system response to error provides more information than should be available to an unauthenticated user.
MEDIUM 5.3EPSS 1.06%
Does this matter?
Lower severity and a low EPSS score (1.06%). Track it; it rarely justifies an emergency change on its own.
Description
An information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system response to error provides more information than should be available to an unauthenticated user.
- CVSS 3.0
- 5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.06% probability · 63th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- schneider-electric/u.motion builder
- Source
- cybersecurity@se.com
References
- http://www.schneider-electric.com/en/download/document/SEVD-2017-178-01/Vendor Advisory
- http://www.securityfocus.com/bid/99344Third Party Advisory, VDB Entry
- http://www.schneider-electric.com/en/download/document/SEVD-2017-178-01/Vendor Advisory
- http://www.securityfocus.com/bid/99344Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.