Critical severity9.8NVD Advisory· Published Sep 26, 2017· Updated May 13, 2026
CVE-2017-9957
CVE-2017-9957
Description
A vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the web service contains a hidden system account with a hardcoded password. An attacker can use this information to log into the system with high-privilege credentials.
Affected products
2- cpe:2.3:a:schneider-electric:u.motion_builder:*:*:*:*:*:*:*:*Range: <=1.2.1
- Schneider Electric SE/U.Motionv5Range: U.motion Builder Versions 1.2.1 and prior.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.schneider-electric.com/en/download/document/SEVD-2017-178-01/nvdVendor Advisory
- www.securityfocus.com/bid/99344nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.