« Volver al listado

CVE-2021-22705

Estado: ModificadaAlta (7.8)—

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause denial of service or unauthorized access to system information when interacting directly with a driver installed by Vijeo Designer or EcoStruxure Machine Expert

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-22705",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.6,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "cybersecurity@se.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Harmony HMI Products Configured by Vijeo Designer (all versions prior to V6.2 SP11 ) or EcoStruxure Machine Expert (all versions prior to V2.0)",
          "versions": [
            {
              "status": "affected",
              "version": "Harmony HMI Products Configured by Vijeo Designer (all versions prior to V6.2 SP11 ) or EcoStruxure Machine Expert (all versions prior to V2.0)"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-05-26T20:15:08.897",
  "references": [
    {
      "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-130-02",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cybersecurity@se.com"
    },
    {
      "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-130-02",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cybersecurity@se.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause denial of service or unauthorized access to system information when interacting directly with a driver installed by Vijeo Designer or EcoStruxure Machine Expert"
    },
    {
      "lang": "es",
      "value": "Se presenta una vulnerabilidad de Restricción Inapropiada de Operaciones dentro de los límites de un búfer de la memoria, que podría causar  una denegación de servicio o acceso no autorizado a la información del sistema interactuando directamente con un controlador instalado por Vijeo Designer o EcoStruxure Machine Expert"
    }
  ],
  "lastModified": "2026-06-17T03:37:36.000",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:schneider-electric:vijeo_designer:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C5F2F861-8F3B-40B0-9CC4-DB9776052C7A",
              "versionEndExcluding": "6.2.11"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:schneider-electric:harmony_gk:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "FDBAEC72-A63C-464D-8E62-C42959D4A871"
            },
            {
              "criteria": "cpe:2.3:h:schneider-electric:harmony_gto:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "3DDF1060-1FF5-41D5-A8ED-129492CC50A4"
            },
            {
              "criteria": "cpe:2.3:h:schneider-electric:harmony_gtu:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "9FCFA535-319D-4AB7-AB6C-B4BB0739B7F4"
            },
            {
              "criteria": "cpe:2.3:h:schneider-electric:harmony_gtux:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "AEA285A2-8EA7-473D-87A5-62E970BD25C3"
            },
            {
              "criteria": "cpe:2.3:h:schneider-electric:harmony_sto:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "68382B8C-4FB2-49AC-8CAE-2251400BE342"
            },
            {
              "criteria": "cpe:2.3:h:schneider-electric:harmony_stu:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "EB2002BD-8A77-414F-A530-A7D9350143F5"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_machine_expert:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B4DB52BF-192B-4167-872E-AAEC81ACAE7F",
              "versionEndExcluding": "2.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:schneider-electric:harmony_hmiscu:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "63E063B8-1179-48D2-A672-177AA1A0FCE1"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cybersecurity@se.com"
}