CVE-2017-9970
12.02.2018, 23:29
A remote code execution vulnerability exists in Schneider Electric's StruxureOn Gateway versions 1.1.3 and prior. Uploading a zip which contains carefully crafted metadata allows for the file to be uploaded to any directory on the host machine information which could lead to remote code execution.Enginsight
Vendor | Product | Version |
---|---|---|
schneider-electric | struxureon_gateway | 𝑥 ≤ 1.1.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References