CVE-2017-9970: Schneider Electric Struxureon Gateway
High severity, CVSS 7.2. EPSS: 4.8% chance of exploitation in the next 30 days.
A remote code execution vulnerability exists in Schneider Electric's StruxureOn Gateway versions 1.1.3 and prior. Uploading a zip which contains carefully crafted metadata allows for the file to be uploaded to any directory on the host machine information which could lead to remote code execution.
Affected products
- Schneider Electric Struxureon Gateway: up to and including 1.1.3
Published 2018-02-12. Last modified 2026-06-17.