CVE Feed

    Dashboard / CVE / CVE-2021-22704

    CVE-2021-22704

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists in Harmony/HMI Products Configured by Vijeo Designer (all versions prior to V6.2 SP11 ), Vijeo Designer Basic (all versions prior to V1.2), or EcoStruxure Machine Expert (all versions prior to V2.0) that could cause a Denial of Service or unauthorized access to system information when connecting to the Harmony HMI over FTP.

    Published:Sep 2, 2021
    Last Modified:Nov 21, 2024
    EPS:Sep 2, 2021
    EPSS Score:0.00601
    CVSS Score:9.1

    Affected Products

    Vendor
    Schneider-electric
    Product
    Ecostruxure Machine Expert
    Vendor
    Schneider-electric
    Product
    Harmony Gk
    Vendor
    Schneider-electric
    Product
    Harmony Gto
    Vendor
    Schneider-electric
    Product
    Harmony Gtu
    Vendor
    Schneider-electric
    Product
    Harmony Gtux
    Vendor
    Schneider-electric
    Product
    Harmony Gxu
    Vendor
    Schneider-electric
    Product
    Harmony Scu
    Vendor
    Schneider-electric
    Product
    Harmony Sto
    Vendor
    Schneider-electric
    Product
    Harmony Stu
    Vendor
    Schneider-electric
    Product
    Vijeo Designer

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High