Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause denial of service or unauthorized access to system information when interacting directly with a driver installed by Vijeo Designer or EcoStruxure Machine Expert
Se presenta una vulnerabilidad de Restricción Inapropiada de Operaciones dentro de los límites de un búfer de la memoria, que podría causar una denegación de servicio o acceso no autorizado a la información del sistema interactuando directamente con un controlador instalado por Vijeo Designer o EcoStruxure Machine Expert
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
| Attack Vector | LOCAL |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | LOW |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
AV:L/AC:L/Au:N/C:P/I:P/A:P
| Access Vector | LOCAL |
|---|---|
| Access Complexity | LOW |
| Authentication | NONE |
| Confidentiality Impact | PARTIAL |
| Integrity Impact | PARTIAL |
| Availability Impact | PARTIAL |
| Source | Type | Description |
|---|---|---|
| [email protected] | Secondary |
en
CWE-119
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| schneider-electric | vijeo_designer | * | <built-in method update of dict object at 0x7e60a88958c0> | Application |
| schneider-electric | ecostruxure_machine_expert | * | <built-in method update of dict object at 0x7e60a8896700> | Application |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:schneider-electric:vijeo_designer:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:harmony_gk:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:schneider-electric:harmony_gto:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:schneider-electric:harmony_gtu:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:schneider-electric:harmony_gtux:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:schneider-electric:harmony_sto:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:schneider-electric:harmony_stu:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:schneider-electric:ecostruxure_machine_expert:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:harmony_hmiscu:-:*:*:*:*:*:*:* |