54% (91) 560 views 2 pages

StruxureOn Gateway Security Notification (CVE-2017-9970)

AI-enhanced description

This document is a security notification from Schneider Electric regarding a remote code execution vulnerability (CVE-2017-9970) in the StruxureOn Gateway product. It details that uploading a zip file with crafted metadata allows file upload to any directory, leading to remote code execution, and recommends upgrading to version 1.2 or changing default passwords as mitigation.

Uploaded by MARIANA.JONES
Download
/ 2
Loading document…