CVE-2017-9960
UnknownEPSS 1.06%
Last modified
CVE-2017-9960 is a vulnerability of currently unknown severity. An information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system response to error provides more information than should be available to an unauthenticated user.. EPSS estimates a 1.06% chance of exploitation in the next 30 days.
Description
An information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system response to error provides more information than should be available to an unauthenticated user.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | U.Motion Builder | <= 1.2.1 |
References
- http://www.securityfocus.com/bid/99344Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/99344Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-9960?
An information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system response to error provides more information than should be available to an unauthenticated user.
How severe is CVE-2017-9960?
Severity scoring for CVE-2017-9960 is pending analysis. The EPSS model estimates a 1.06% probability of exploitation in the next 30 days.
How do I fix CVE-2017-9960?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-9954The getvalue function in tekhex.c in the Binary File Descrip…
- CVE-2017-9955The get_build_id function in opncls.c in the Binary File Des…
- CVE-2017-9956An authentication bypass vulnerability exists in Schneider E…
- CVE-2017-9957A vulnerability exists in Schneider Electric's U.motion Buil…
- CVE-2017-9958An improper access control vulnerability exists in Schneider…
- CVE-2017-9959A vulnerability exists in Schneider Electric's U.motion Buil…
- CVE-2017-9961A vulnerability exists in Schneider Electric's Pro-Face GP P…
- CVE-2017-9962Schneider Electric's ClearSCADA versions released prior to A…
- CVE-2017-9963A cross-site request forgery vulnerability exists on the Sec…
- CVE-2017-9964A Path Traversal issue was discovered in Schneider Electric …
- CVE-2017-9965An exposure of sensitive information vulnerability exists in…
- CVE-2017-9966A privilege escalation vulnerability exists in Schneider Ele…
Are you affected by CVE-2017-9960?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
