Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause denial of service or unauthorized access to system information when interacting directly with a driver installed by Vijeo Designer or EcoStruxure Machine Expert
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HSchneider Electric Ecostruxure Machine Expert
APPSchneider-Electric< 2.0Schneider Electric Harmony Gk
HWSchneider-Electricall versionsSchneider Electric Harmony Gto
HWSchneider-Electricall versionsSchneider Electric Harmony Gtu
HWSchneider-Electricall versionsSchneider Electric Harmony Gtux
HWSchneider-Electricall versionsSchneider Electric Harmony Hmiscu
HWSchneider-Electricall versionsSchneider Electric Harmony Sto
HWSchneider-Electricall versionsSchneider Electric Harmony Stu
HWSchneider-Electricall versionsSchneider Electric Vijeo Designer
APPSchneider-Electric< 6.2.11
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
DoS
CWE
Related vulnerabilities
CVE-2021-22704CRITICAL9.1PL ✓same product
Path Traversal w produktach Schneider Electric Harmony HMI via FTP
CVE-2020-7487CRITICAL9.8PL ✓same product
Niewystarczająca weryfikacja autentyczności danych w sterownikach Schneider Electric Modicon
CVE-2020-7489CRITICAL9.8PL ✓same product
Podatność Injection w oprogramowaniu Schneider Electric – podstawianie DLL
CVE-2024-8306HIGH7.8same product
CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of conf...
CVE-2021-22817HIGH7.8same product
A CWE-276: Incorrect Default Permissions vulnerability exists that could cause unauthorized access to the base...