First published: Thu Sep 02 2021(Updated: )
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists in Harmony/HMI Products Configured by Vijeo Designer (all versions prior to V6.2 SP11 ), Vijeo Designer Basic (all versions prior to V1.2), or EcoStruxure Machine Expert (all versions prior to V2.0) that could cause a Denial of Service or unauthorized access to system information when connecting to the Harmony HMI over FTP.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Vijeo Designer | <6.2.11 | |
Schneider-electric Harmony Gk | ||
Schneider-electric Harmony Gto | ||
Schneider-electric Harmony Gtu | ||
Schneider-electric Harmony Gtux | ||
Schneider-electric Harmony Sto | ||
Schneider-electric Harmony Stu | ||
Schneider-electric Vijeo Designer | <1.2 | |
Schneider-electric Harmony Gxu | ||
Schneider-electric Ecostruxure Machine Expert | <2.0 | |
Schneider-electric Ecostruxure Machine Expert | =2.0 | |
Schneider-electric Harmony Scu |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22704 is a CWE-22 vulnerability that exists in Harmony/HMI Products Configured by Vijeo Designer (all versions prior to V6.2 SP11), Vijeo Designer Basic (all versions prior to V1.2), or EcoStruxure Machine Expert (all versions prior to V2.0).
CVE-2021-22704 has a severity rating of 9.1 (Critical).
Harmony/HMI Products Configured by Vijeo Designer (all versions prior to V6.2 SP11), Vijeo Designer Basic (all versions prior to V1.2), and EcoStruxure Machine Expert (all versions prior to V2.0) are affected by CVE-2021-22704.
To fix CVE-2021-22704, update Harmony/HMI Products Configured by Vijeo Designer to V6.2 SP11 or later, update Vijeo Designer Basic to V1.2 or later, and update EcoStruxure Machine Expert to V2.0 or later.
You can find more information about CVE-2021-22704 at the following reference: http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-222-01