HIGH🇵🇱 Wersja polska

CVE-2021-22705

CVSS 7.8v3.1pub. 2021-05-26upd. 2024-11-21

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause denial of service or unauthorized access to system information when interacting directly with a driver installed by Vijeo Designer or EcoStruxure Machine Expert

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Schneider Electric Ecostruxure Machine Expert

    APP
    Schneider-Electric
    < 2.0
  • Schneider Electric Harmony Gk

    HW
    Schneider-Electric
    all versions
  • Schneider Electric Harmony Gto

    HW
    Schneider-Electric
    all versions
  • Schneider Electric Harmony Gtu

    HW
    Schneider-Electric
    all versions
  • Schneider Electric Harmony Gtux

    HW
    Schneider-Electric
    all versions
  • Schneider Electric Harmony Hmiscu

    HW
    Schneider-Electric
    all versions
  • Schneider Electric Harmony Sto

    HW
    Schneider-Electric
    all versions
  • Schneider Electric Harmony Stu

    HW
    Schneider-Electric
    all versions
  • Schneider Electric Vijeo Designer

    APP
    Schneider-Electric
    < 6.2.11
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
DoS
CWE
References

Related vulnerabilities

CVE-2021-22704CRITICAL9.1PL ✓same product

Path Traversal w produktach Schneider Electric Harmony HMI via FTP

CVE-2020-7487CRITICAL9.8PL ✓same product

Niewystarczająca weryfikacja autentyczności danych w sterownikach Schneider Electric Modicon

CVE-2020-7489CRITICAL9.8PL ✓same product

Podatność Injection w oprogramowaniu Schneider Electric – podstawianie DLL

CVE-2024-8306HIGH7.8same product

CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of conf...

CVE-2021-22817HIGH7.8same product

A CWE-276: Incorrect Default Permissions vulnerability exists that could cause unauthorized access to the base...