A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists in Harmony/HMI Products Configured by Vijeo Designer (all versions prior to V6.2 SP11 ), Vijeo Designer Basic (all versions prior to V1.2), or EcoStruxure Machine Expert (all versions prior to V2.0) that could cause a Denial of Service or unauthorized access to system information when connecting to the Harmony HMI over FTP.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HSchneider Electric Ecostruxure Machine Expert
APPSchneider-Electric2.0< 2.0Schneider Electric Harmony Gk
HWSchneider-Electricall versionsSchneider Electric Harmony Gto
HWSchneider-Electricall versionsSchneider Electric Harmony Gtu
HWSchneider-Electricall versionsSchneider Electric Harmony Gtux
HWSchneider-Electricall versionsSchneider Electric Harmony Gxu
HWSchneider-Electricall versionsSchneider Electric Harmony Scu
HWSchneider-Electricall versionsSchneider Electric Harmony Sto
HWSchneider-Electricall versionsSchneider Electric Harmony Stu
HWSchneider-Electricall versionsSchneider Electric Vijeo Designer
APPSchneider-Electric< 1.2< 6.2.11
Related vulnerabilities
Podatność Injection w oprogramowaniu Schneider Electric – podstawianie DLL
Niewystarczająca weryfikacja autentyczności danych w sterownikach Schneider Electric Modicon
CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of conf...
A CWE-276: Incorrect Default Permissions vulnerability exists that could cause unauthorized access to the base...
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause ...