VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-201807-1864 CVE-2018-7766 Schneider Electric U.motion Builder track_getdata Remote code execution vulnerability CVSS V2: 6.8
CVSS V3: 8.8
Severity: HIGH
The vulnerability exists within processing of track_getdata.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the id input parameter. Authentication is not required to exploit this vulnerability.The specific flaw exists within processing of track_getdata.php, which is exposed on the web service with no authentication. A remote attacker can leverage this vulnerability to execute arbitrary commands against the database
VAR-201807-1867 CVE-2018-7769 Schneider Electric U.motion Builder xmlserver Remote code execution vulnerability CVSS V2: 6.8
CVSS V3: 8.8
Severity: HIGH
The vulnerability exists within processing of xmlserver.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the id input parameter. Authentication is not required to exploit this vulnerability. The specific flaw exists within processing of xmlserver.php, which is exposed on the web service with no authentication. A remote attacker can leverage this vulnerability to execute arbitrary commands against the database
VAR-201709-1221 CVE-2017-9958 Schneider Electric U.motion Builder Local Privilege Escalation Vulnerability CVSS V2: 7.2
CVSS V3: 7.8
Severity: HIGH
An improper access control vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an improper handling of the system configuration can allow an attacker to execute arbitrary code under the context of root. Schneider Electric U.motion Builder Software Contains an access control vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Authentication is required to exploit this vulnerability.The specific flaw exists within the handling of the system configuration. The web administration account is set up with the ability to sudo without a password. U.motion Builder is a generator product from Schneider Electric, France. An SQL-injection vulnerability 2. A directory-traversal vulnerability 3. An authentication bypass vulnerability 4. An information-disclosure vulnerability 5. A local code-execution vulnerability 6. A local denial-of-Service vulnerability 7. Failed exploits can result in a denial-of-service condition
VAR-201709-1077 CVE-2017-9960 Schneider Electric U.motion Builder Error Message Path Vulnerability CVSS V2: 5.0
CVSS V3: 5.3
Severity: MEDIUM
An information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system response to error provides more information than should be available to an unauthenticated user. Authentication is not required to exploit this vulnerability.The specific flaw exists within externalframe.php. Exception information is returned to the attacker that contains sensitive path information. This can be leveraged by an attacker in conjunction with other vulnerabilities to execute arbitrary code on the system. An SQL-injection vulnerability 2. A directory-traversal vulnerability 3. An authentication bypass vulnerability 4. An information-disclosure vulnerability 5. A local code-execution vulnerability 6. A local denial-of-Service vulnerability 7. Failed exploits can result in a denial-of-service condition
VAR-201706-1046 No CVE Schneider Electric U.motion Builder syslog_getdata Remote code execution vulnerability CVSS V2: 7.5
CVSS V3: -
Severity: HIGH
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Schneider Electric U.motion Builder. Authentication is not required to exploit this vulnerability. The specific flaw exists within processing of syslog_getdata.php, which is exposed on the web service with no authentication. The underlying SQLite database query is subject to SQL injection on the type, level, is_handled, and last_log_id input parameters. A remote attacker can leverage these vulnerabilities to execute arbitrary commands against the database. U.motion Builder is a generator product from Schneider Electric, France
VAR-201807-1865 CVE-2018-7767 Schneider Electric U.motion Builder editobject Remote code execution vulnerability CVSS V2: 6.8
CVSS V3: 8.8
Severity: HIGH
The vulnerability exists within processing of editobject.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the type input parameter. Authentication is not required to exploit this vulnerability.The specific flaw exists within processing of the editobject.php, which is exposed on the web service with no authentication. A remote attacker can leverage this vulnerability to execute arbitrary commands against the database
VAR-201807-1871 CVE-2018-7773 Schneider Electric U.motion Builder nfcserver Remote code execution vulnerability CVSS V2: 6.8
CVSS V3: 8.8
Severity: HIGH
The vulnerability exists within processing of nfcserver.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the sessionid input parameter. Authentication is not required to exploit this vulnerability.The specific flaw exists within processing of nfcserver.php, which is exposed on the web service with no authentication. A remote attacker can leverage this vulnerability to execute arbitrary commands against the database
VAR-201807-1872 CVE-2018-7774 Schneider Electric U.motion Builder Remote code execution vulnerability CVSS V2: 6.8
CVSS V3: 8.8
Severity: HIGH
The vulnerability exists within processing of localize.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the username input parameter. Authentication is not required to exploit this vulnerability.The specific flaw exists within processing of localize.php, which is exposed on the web service with no authentication. A remote attacker can leverage this vulnerability to execute arbitrary commands against the database
VAR-201807-1861 CVE-2018-7763 Schneider Electric U.motion Builder Software Path Traversal Vulnerability CVSS V2: 4.3
CVSS V3: 4.3
Severity: MEDIUM
The vulnerability exists within css.inc.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The 'css' parameter contains a directory traversal vulnerability. Authentication is not required to exploit this vulnerability. The specific flaw exists within css.inc.php. An attacker can leverage this to disclose files
VAR-201709-1076 CVE-2017-9959 Schneider Electric U.motion Builder Software Access control vulnerability CVSS V2: 4.9
CVSS V3: 5.5
Severity: MEDIUM
A vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system accepts reboot in session from unauthenticated users, supporting a denial of service condition. Schneider Electric U.motion Builder Software Contains an access control vulnerability.Service operation interruption (DoS) There is a possibility of being put into a state. This vulnerability allows remote attackers to deny service on vulnerable installations of Schneider Electric U.motion Builder. Authentication is not required to exploit this vulnerability. The specific flaw exists within processing of message_simple_html.php, which is exposed on the web service. The reboot option of the applet reboots the system. This flaw allows a remote attacker to perpetually reboot the system, denying service to all users. U.motion Builder is a generator product from Schneider Electric, France. An SQL-injection vulnerability 2. A directory-traversal vulnerability 3. An information-disclosure vulnerability 5. A local code-execution vulnerability 6. A local denial-of-Service vulnerability 7. An information-disclosure vulnerability Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database, bypass authentication mechanism, obtain sensitive information, execute arbitrary code and perform unauthorized actions. Failed exploits can result in a denial-of-service condition
VAR-201807-1866 CVE-2018-7768 Schneider Electric U.motion Builder loadtemplate Remote code execution vulnerability CVSS V2: 6.8
CVSS V3: 8.8
Severity: HIGH
The vulnerability exists within processing of loadtemplate.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the tpl input parameter. Authentication is not required to exploit this vulnerability.The specific flaw exists within processing of loadtemplate.php, which is exposed on the web service with no authentication. A remote attacker can leverage this vulnerability to execute arbitrary commands against the database
VAR-201706-1044 No CVE Schneider Electric U.motion Builder file_picker Remote code execution vulnerability CVSS V2: 6.5
CVSS V3: -
Severity: MEDIUM
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Schneider Electric U.Motion Builder. User authentication is required to exploit this vulnerability.The specific flaw exists within file_picker.php. The upload path specified by the user is not constrained, so any logged-in user can upload files to any location in the system that is writable by the web service. An attacker can leverage this to execute code on the system in the context of the web server. U.motion Builder is a generator product from Schneider Electric, France
VAR-201807-1849 CVE-2018-7776 Schneider Electric U.motion Builder Information Disclosure Vulnerability CVSS V2: 4.3
CVSS V3: 4.3
Severity: MEDIUM
The vulnerability exists within error.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. System information is returned to the attacker that contains sensitive data. Authentication is not required to exploit this vulnerability. The specific flaw exists within error.php. This can be leveraged by an attacker in conjunction with other vulnerabilities to execute arbitrary code on the system
VAR-201706-1202 No CVE (0Day) Schneider Electric U.motion Builder sendmail email_attachment Parameter Absolute Path Traversal Information Disclosure Vulnerability CVSS V2: 7.8
CVSS V3: -
Severity: HIGH
This vulnerability allows remote attackers to extract arbitrary files on vulnerable installations of Schneider Electric U.motion Builder. Authentication is not required to exploit this vulnerability. The specific flaw exists within processing of sendmail.php. The applet allows callers to select arbitrary files to send to an arbitrary email address. This allows the attacker to exfiltrate arbitrary files from the system.
VAR-201709-1220 CVE-2017-9957 Schneider Electric U.motion Builder Software Vulnerabilities related to the use of hard-coded credentials CVSS V2: 7.5
CVSS V3: 9.8
Severity: CRITICAL
A vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the web service contains a hidden system account with a hardcoded password. An attacker can use this information to log into the system with high-privilege credentials. This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Schneider Electric U.motion Builder.The specific flaw exists within the configuration of the product. U.motion Builder is a generator product from Schneider Electric, France. An SQL-injection vulnerability 2. A directory-traversal vulnerability 3. An authentication bypass vulnerability 4. An information-disclosure vulnerability 5. A local code-execution vulnerability 6. A local denial-of-Service vulnerability 7. An information-disclosure vulnerability Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database, bypass authentication mechanism, obtain sensitive information, execute arbitrary code and perform unauthorized actions. Failed exploits can result in a denial-of-service condition
VAR-201709-1219 CVE-2017-9956 Schneider Electric U.motion Builder Software Vulnerabilities related to the use of hard-coded credentials CVSS V2: 7.5
CVSS V3: 7.3
Severity: HIGH
An authentication bypass vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system contains a hard-coded valid session. An attacker can use that session ID as part of the HTTP cookie of a web request, resulting in authentication bypass. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of session management. The application has a hard-coded static session ID. U.motion Builder is a generator product from Schneider Electric, France. An SQL-injection vulnerability 2. A directory-traversal vulnerability 3. An information-disclosure vulnerability 5. A local code-execution vulnerability 6. A local denial-of-Service vulnerability 7. An information-disclosure vulnerability Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database, bypass authentication mechanism, obtain sensitive information, execute arbitrary code and perform unauthorized actions. Failed exploits can result in a denial-of-service condition
VAR-201807-1863 CVE-2018-7765 Schneider Electric U.motion Builder track_import_export Remote code execution vulnerability CVSS V2: 6.8
CVSS V3: 8.8
Severity: HIGH
The vulnerability exists within processing of track_import_export.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the object_id input parameter. Authentication is not required to exploit this vulnerability. The specific flaw exists within processing of track_import_export.php, which is exposed on the web service with no authentication. A remote attacker can leverage this vulnerability to execute arbitrary commands against the database
VAR-201706-1045 No CVE Schneider Electric U.motion Builder SOAP Remote code execution vulnerability CVSS V2: 7.5
CVSS V3: -
Severity: HIGH
This vulnerability allows remote attackers to execute arbitrary SQL commands on vulnerable installations of Schneider Electric U.Motion Builder. Authentication is not required to exploit this vulnerability.The specific flaw exists within processing of SOAP requests by the web service. The system allows SOAP requests to perform arbitrary SQL commands. An attacker can leverage this vulnerability to execute arbitrary code in the context of the database. U.motion Builder is a generator product from Schneider Electric, France
VAR-201807-1869 CVE-2018-7771 Schneider Electric U.motion Builder Software Path Traversal Vulnerability CVSS V2: 6.0
CVSS V3: 8.0
Severity: HIGH
The vulnerability exists within processing of editscript.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. A directory traversal vulnerability allows a caller with standard user privileges to write arbitrary php files anywhere in the web service directory tree. Schneider Electric U.motion Builder Software Contains a path traversal vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Authentication is required to exploit this vulnerability.The specific flaw exists within processing of editscript.php. An attacker can leverage this vulnerability to execute arbitrary code in the context of the web server
VAR-201706-1124 No CVE There is a stack overflow vulnerability in the InitialSDK method of the SoftNVR-IA NVRLV control of the Morsa video surveillance system CVSS V2: 4.9
CVSS V3: -
Severity: MEDIUM
Mosha Video Surveillance System SoftNVR-IA is a real-time IP video monitoring software developed by Mosha Technology (Shanghai) Co., Ltd. There is a stack overflow vulnerability in the InitialSDK method of the NVRLV control of Mosha Video Surveillance System SoftNVR-IA. By tricking users into following specific links, an attacker can execute arbitrary code.