RULE(RULE ID:321913)

Rule General Information
Release Date: 2019-06-21
Rule Name: Schneider Umotion Builder Runscript Path Traversal Vulnerability (CVE-2017-7974)
Severity:
CVE ID:
Rule Protection Details
Description: A path traversal information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an unauthenticated user can execute arbitrary code and exfiltrate files.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Others
Reference: SecurityFocusBID:99344
http://www.schneider-electric.com/en/download/document/SEVD-2017-178-01/
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://www.schneider-electric.com/en/download/document/SEVD-2017-178-01/