IM
IronMonkey Threat Research

CVE-2021-22705 HIGH

Published: 2021-05-26 | Last Modified: 2024-11-21 | Status: Modified

Description

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause denial of service or unauthorized access to system information when interacting directly with a driver installed by Vijeo Designer or EcoStruxure Machine Expert

Additional Descriptions (1)

Se presenta una vulnerabilidad de Restricción Inapropiada de Operaciones dentro de los límites de un búfer de la memoria, que podría causar una denegación de servicio o acceso no autorizado a la información del sistema interactuando directamente con un controlador instalado por Vijeo Designer o EcoStruxure Machine Expert

CVSS Metrics

Base Score: 7.8 (HIGH)

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack VectorLOCAL
Attack ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactHIGH
Integrity ImpactHIGH
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 1.8

Impact Score: 5.9

Base Score: 4.6 (MEDIUM)

AV:L/AC:L/Au:N/C:P/I:P/A:P

Access VectorLOCAL
Access ComplexityLOW
AuthenticationNONE
Confidentiality ImpactPARTIAL
Integrity ImpactPARTIAL
Availability ImpactPARTIAL

Source: [email protected]

Type: Primary

Exploitability Score: 3.9

Impact Score: 6.4

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-119

Affected Products

Vendor Product Version Update Type
schneider-electric vijeo_designer * <built-in method update of dict object at 0x7e60a88958c0> Application
schneider-electric ecostruxure_machine_expert * <built-in method update of dict object at 0x7e60a8896700> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:schneider-electric:vijeo_designer:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:schneider-electric:harmony_gk:-:*:*:*:*:*:*:*
No cpe:2.3:h:schneider-electric:harmony_gto:-:*:*:*:*:*:*:*
No cpe:2.3:h:schneider-electric:harmony_gtu:-:*:*:*:*:*:*:*
No cpe:2.3:h:schneider-electric:harmony_gtux:-:*:*:*:*:*:*:*
No cpe:2.3:h:schneider-electric:harmony_sto:-:*:*:*:*:*:*:*
No cpe:2.3:h:schneider-electric:harmony_stu:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:schneider-electric:ecostruxure_machine_expert:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:schneider-electric:harmony_hmiscu:-:*:*:*:*:*:*:*
Notification
Message here