First published: Wed Feb 09 2022(Updated: )
A CWE-276: Incorrect Default Permissions vulnerability exists that could cause unauthorized access to the base installation directory leading to local privilege escalation. Affected Product: Harmony/Magelis iPC Series (All Versions), Vijeo Designer (All Versions prior to V6.2 SP11 Multiple HotFix 4), Vijeo Designer Basic (All Versions prior to V1.2.1)
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider Electric HMIBMUHI29D2801 | ||
Schneider Electric HMIBMUHI29D2801 | ||
schneider-electric hmibmusi29d2801 | ||
Schneider Electric HMIBMUSI29D2801 | ||
Schneider Electric HMIBMUCI29D2W01 Firmware | ||
Schneider Electric HMIBMUCI29D2W01 | ||
schneider-electric hmibmu0i29d2001 | ||
Schneider Electric HMIBMU0I29D2001 | ||
schneider-electric hmibmu0i29d200a | ||
Schneider Electric HMIBMU0I29D200A | ||
Schneider Electric HMI BMU HI29D4801 | ||
Schneider Electric HMI BMU HI29D4801 | ||
Schneider Electric HMIBMUSI29D4801 Firmware | ||
Schneider Electric HMIBMUSI29D4801 Firmware | ||
Schneider Electric HMIBMUCI29D4W01 Firmware | ||
Schneider Electric HMI BMUCI29D4W01 | ||
Schneider Electric HMIBMU0I29D4001 Firmware | ||
schneider-electric hmibmu0i29d4001 firmware | ||
schneider-electric hmibmu0i29d400a | ||
Schneider Electric HMIBMU0I29D400A | ||
Schneider Electric HMIBMU0I29DI00A | ||
Schneider Electric HMIBMU0I29DI00A | ||
Schneider Electric HMIBMU0I29DE00A Firmware | ||
Schneider Electric HMIBMU0I29DE00A Firmware | ||
Schneider Electric HMIBMPHI74D2801 Firmware | ||
Schneider Electric HMI BM PHI 74D 2801 | ||
Schneider Electric HMIBMPSI74D2801 | ||
Schneider Electric HMIBMPSI74D2801 | ||
Schneider Electric HMI BMP0I 74D2001 | ||
Schneider Electric HMI BMP0I 74D2001 | ||
Schneider Electric HMIBMP0I74D200A Firmware | ||
Schneider Electric HMIBMP0I74D200A Firmware | ||
Schneider Electric HMIBM PHI 74D4801 Firmware | ||
Schneider Electric HMIBM PHI 74D4801 Firmware | ||
Schneider Electric HMI BMP SI 74D 4801 Firmware | ||
Schneider Electric HMIB-MPSI 74D4801 | ||
Schneider Electric HMIBMP0I74D4001 Firmware | ||
Schneider Electric HMI BMP0I74D4001 | ||
Schneider Electric HMI BMP0I74D400A | ||
Schneider Electric HMI BMP0I74D400A | ||
Schneider Electric HMI BMP0I74DI00A Firmware | ||
Schneider Electric HMI BMP0I74DI00A | ||
Schneider Electric HMI BMP0I74DE00A | ||
Schneider Electric HMI BMP0I74DE00A | ||
Schneider Electric HMIBSCEA53D1L01 Firmware | ||
Schneider Electric HMIBSCEA53D1L01 | ||
Schneider Electric HMIBMOMA5DDF10L Firmware | ||
Schneider Electric HMIBMOMA5DD10L | ||
Schneider Electric HMIBMOMA5DD1E01 Firmware | ||
Schneider Electric HMIBMOMA5DD1E01 | ||
Schneider Electric HMIBMOMA5DD1101 Firmware | ||
Schneider Electric HMIBMOMA5DD1101 Firmware | ||
schneider-electric hmibmo0a5ddf10a | ||
Schneider Electric HMIBMO0A5DD10 | ||
Schneider Electric HMIBMO0A5DD101 | ||
Schneider Electric HMIBMO0A5DD101 | ||
Schneider Electric HMIBMO0A5DD1001 Firmware | ||
schneider-electric hmibmo0a5dd1001 firmware | ||
Schneider Electric HMIBMI-EA5DD1E01 Firmware | ||
Schneider Electric HMI-BMIEA5DD1E01 | ||
Schneider Electric HMIBMIEA5DD110L Firmware | ||
Schneider Electric HMIBMIEA5DD110L | ||
Schneider Electric HMIBMOMA5DD1101 Firmware | ||
Schneider Electric HMIBMOMA5DD1101 Firmware | ||
Schneider Electric HMI BMI EA5 DD100A | ||
schneider-electric hmibmiea5dd100a firmware | ||
schneider-electric hmibmiea5dd1001 | ||
Schneider Electric HMIBMIEA5DD1001 | ||
Schneider Electric HMIBSCE A53D1L0T | ||
Schneider Electric HMIBSCE A53D1L0T | ||
Schneider Electric HMIBSCEA53D1L0A Firmware | ||
Schneider Electric HMIBSCEA53D1L0A Firmware | ||
Vijeo Designer | <1.2.1 | |
Vijeo Designer | <6.2 | |
Vijeo Designer | =6.2 | |
Vijeo Designer | =6.2-sp1 | |
Vijeo Designer | =6.2-sp10 | |
Vijeo Designer | =6.2-sp11 | |
Vijeo Designer | =6.2-sp2 | |
Vijeo Designer | =6.2-sp3.1 | |
Vijeo Designer | =6.2-sp5.1 | |
Vijeo Designer | =6.2-sp6 | |
Vijeo Designer | =6.2-sp7 | |
Vijeo Designer | =6.2-sp8 | |
Vijeo Designer | =6.2-sp9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-22817 is rated as high due to its potential for local privilege escalation.
To fix CVE-2021-22817, update to Vijeo Designer version 6.2 SP11 Multiple HotFix 4 or later.
CVE-2021-22817 affects all versions of Harmony/Magelis iPC Series and Vijeo Designer versions prior to 6.2 SP11 Multiple HotFix 4.
CVE-2021-22817 is classified as a CWE-276: Incorrect Default Permissions vulnerability.
The potential impact of CVE-2021-22817 includes unauthorized access to the base installation directory, leading to local privilege escalation.