IM
IronMonkey Threat Research

CVE-2021-22704 CRITICAL

Published: 2021-09-02 | Last Modified: 2024-11-21 | Status: Modified

Description

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists in Harmony/HMI Products Configured by Vijeo Designer (all versions prior to V6.2 SP11 ), Vijeo Designer Basic (all versions prior to V1.2), or EcoStruxure Machine Expert (all versions prior to V2.0) that could cause a Denial of Service or unauthorized access to system information when connecting to the Harmony HMI over FTP.

Additional Descriptions (1)

Una CWE-22: Una vulnerabilidad de Limitación Inapropiada de un Nombre de Ruta a un Directorio Restringido se presenta en los productos Harmony/HMI Configurados por Vijeo Designer (todas las versiones anteriores a V6.2 SP11 ), Vijeo Designer Basic (todas las versiones anteriores a V1.2) o EcoStruxure Machine Expert (todas las versiones anteriores a V2.0) que podría causar una denegación de servicio o un acceso no autorizado a la información del sistema cuando se conecta al Harmony HMI a través de FTP

CVSS Metrics

Base Score: 9.1 (CRITICAL)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactHIGH
Integrity ImpactNONE
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 3.9

Impact Score: 5.2

Base Score: 6.4 (MEDIUM)

AV:N/AC:L/Au:N/C:P/I:N/A:P

Access VectorNETWORK
Access ComplexityLOW
AuthenticationNONE
Confidentiality ImpactPARTIAL
Integrity ImpactNONE
Availability ImpactPARTIAL

Source: [email protected]

Type: Primary

Exploitability Score: 10.0

Impact Score: 4.9

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-22

Affected Products

Vendor Product Version Update Type
schneider-electric vijeo_designer * <built-in method update of dict object at 0x7e60e884c200> Application
schneider-electric vijeo_designer * <built-in method update of dict object at 0x7e60e884c580> Application
schneider-electric ecostruxure_machine_expert * <built-in method update of dict object at 0x7e61109d6d00> Application
schneider-electric ecostruxure_machine_expert 2.0 <built-in method update of dict object at 0x7e60ba2a4d40> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:schneider-electric:vijeo_designer:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:schneider-electric:harmony_gk:-:*:*:*:*:*:*:*
No cpe:2.3:h:schneider-electric:harmony_gto:-:*:*:*:*:*:*:*
No cpe:2.3:h:schneider-electric:harmony_gtu:-:*:*:*:*:*:*:*
No cpe:2.3:h:schneider-electric:harmony_gtux:-:*:*:*:*:*:*:*
No cpe:2.3:h:schneider-electric:harmony_sto:-:*:*:*:*:*:*:*
No cpe:2.3:h:schneider-electric:harmony_stu:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:schneider-electric:vijeo_designer:*:*:*:*:basic:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:schneider-electric:harmony_gxu:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:schneider-electric:ecostruxure_machine_expert:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:schneider-electric:ecostruxure_machine_expert:2.0:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:schneider-electric:harmony_scu:-:*:*:*:*:*:*:*
Notification
Message here