CVE-2017-9959 Information

Description

A vulnerability exists in Schneider Electric’s U.motion Builder software versions 1.2.1 and prior in which the system accepts reboot in session from unauthenticated users supporting a denial of service condition.

CVSS Vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Reference

http://www.schneider-electric.com/en/download/document/SEVD-2017-178-01/ http://www.securityfocus.com/bid/99344

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

NONE

Base Score

HIGH

Base Severity

5.5

Share on: