CVE-2017-7974: Schneider Electric U.motion Builder

Critical severity, CVSS 9.8. EPSS: 4.6% chance of exploitation in the next 30 days.

A path traversal information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an unauthenticated user can execute arbitrary code and exfiltrate files.

Affected products

Published 2017-09-26. Last modified 2026-06-17.