CVE-2021-22705: Buffer Overflow
Published May 26, 2021
·Updated
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause denial of service or unauthorized access to system information when interacting directly with a driver installed by Vijeo Designer or EcoStruxure Machine Expert
Affected Software
9 affected components
Schneider-electric Vijeo Designer<6.2.11
Schneider-electric Harmony Gk
Schneider-electric Harmony Gto
Schneider-electric Harmony Gtu
Schneider-electric Harmony Gtux
Schneider-electric Harmony Sto
Schneider-electric Harmony Stu
Schneider-electric Ecostruxure Machine Expert<2.0
Schneider-electric Harmony Hmiscu
Remediation
Event History
May 26, 2021
CVE Published
via MITRE·07:19 PM
Data Sourced
via MITRE·07:19 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-22705.
2
What is the severity of CVE-2021-22705?
The severity of CVE-2021-22705 is high with a severity value of 7.8.
3
What is the affected software for CVE-2021-22705?
The affected software for CVE-2021-22705 includes Vijeo Designer 6.2.11 and EcoStruxure Machine Expert up to version 2.0.
4
What are the potential impacts of CVE-2021-22705?
The potential impacts of CVE-2021-22705 include denial of service or unauthorized access to system information.
5
How can I fix CVE-2021-22705?
To fix CVE-2021-22705, it is recommended to apply the necessary security patches provided by Schneider Electric.