CVE-2017-9970

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
12/02/2018
Last modified:
09/03/2018

Description

A remote code execution vulnerability exists in Schneider Electric's StruxureOn Gateway versions 1.1.3 and prior. Uploading a zip which contains carefully crafted metadata allows for the file to be uploaded to any directory on the host machine information which could lead to remote code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:schneider-electric:struxureon_gateway:*:*:*:*:*:*:*:* 1.1.3 (including)