Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-22704

Опубликовано: 02 сент. 2021
Источник: nvd
CVSS3: 9.1
CVSS2: 6.4
EPSS Низкий

Описание

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists in Harmony/HMI Products Configured by Vijeo Designer (all versions prior to V6.2 SP11 ), Vijeo Designer Basic (all versions prior to V1.2), or EcoStruxure Machine Expert (all versions prior to V2.0) that could cause a Denial of Service or unauthorized access to system information when connecting to the Harmony HMI over FTP.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:schneider-electric:vijeo_designer:*:*:*:*:*:*:*:*
Версия до 6.2.11 (исключая)

Одно из

cpe:2.3:h:schneider-electric:harmony_gk:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:harmony_gto:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:harmony_gtu:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:harmony_gtux:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:harmony_sto:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:harmony_stu:-:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:a:schneider-electric:vijeo_designer:*:*:*:*:basic:*:*:*
Версия до 1.2 (исключая)
cpe:2.3:h:schneider-electric:harmony_gxu:-:*:*:*:*:*:*:*
Конфигурация 3

Одновременно

Одно из

cpe:2.3:a:schneider-electric:ecostruxure_machine_expert:*:*:*:*:*:*:*:*
Версия до 2.0 (исключая)
cpe:2.3:a:schneider-electric:ecostruxure_machine_expert:2.0:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:harmony_scu:-:*:*:*:*:*:*:*

EPSS

Процентиль: 69%
0.00601
Низкий

9.1 Critical

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-22

Связанные уязвимости

github
больше 3 лет назад

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists in Harmony/HMI Products Configured by Vijeo Designer (all versions prior to V6.2 SP11 ), Vijeo Designer Basic (all versions prior to V1.2), or EcoStruxure Machine Expert (all versions prior to V2.0) that could cause a Denial of Service or unauthorized access to system information when connecting to the Harmony HMI over FTP.

EPSS

Процентиль: 69%
0.00601
Низкий

9.1 Critical

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-22