CVE-2021-22704: Path Traversal
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists in Harmony/HMI Products Configured by Vijeo Designer (all versions prior to V6.2 SP11 ), Vijeo Designer Basic (all versions prior to V1.2), or EcoStruxure Machine Expert (all versions prior to V2.0) that could cause a Denial of Service or unauthorized access to system information when connecting to the Harmony HMI over FTP.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-22704?
CVE-2021-22704 is a CWE-22 vulnerability that exists in Harmony/HMI Products Configured by Vijeo Designer (all versions prior to V6.2 SP11), Vijeo Designer Basic (all versions prior to V1.2), or EcoStruxure Machine Expert (all versions prior to V2.0).
How severe is CVE-2021-22704?
CVE-2021-22704 has a severity rating of 9.1 (Critical).
Which software versions are affected by CVE-2021-22704?
Harmony/HMI Products Configured by Vijeo Designer (all versions prior to V6.2 SP11), Vijeo Designer Basic (all versions prior to V1.2), and EcoStruxure Machine Expert (all versions prior to V2.0) are affected by CVE-2021-22704.
How can I fix CVE-2021-22704?
To fix CVE-2021-22704, update Harmony/HMI Products Configured by Vijeo Designer to V6.2 SP11 or later, update Vijeo Designer Basic to V1.2 or later, and update EcoStruxure Machine Expert to V2.0 or later.
Where can I find more information about CVE-2021-22704?
You can find more information about CVE-2021-22704 at the following reference: http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-222-01