CVE-2021-22817

A CWE-276: Incorrect Default Permissions vulnerability exists that could cause unauthorized access to the base installation directory leading to local privilege escalation. Affected Product: Harmony/Magelis iPC Series (All Versions), Vijeo Designer (All Versions prior to V6.2 SP11 Multiple HotFix 4), Vijeo Designer Basic (All Versions prior to V1.2.1)
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
schneiderCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 11%
VendorProductVersion
schneider-electrichmibmuhi29d2801_firmware
*
schneider-electrichmibmusi29d2801_firmware
*
schneider-electrichmibmuci29d2w01_firmware
*
schneider-electrichmibmu0i29d2001_firmware
*
schneider-electrichmibmu0i29d200a_firmware
*
schneider-electrichmibmuhi29d4801_firmware
*
schneider-electrichmibmusi29d4801_firmware
*
schneider-electrichmibmuci29d4w01_firmware
*
schneider-electrichmibmu0i29d4001_firmware
*
schneider-electrichmibmu0i29d400a_firmware
*
schneider-electrichmibmu0i29di00a_firmware
*
schneider-electrichmibmu0i29de00a_firmware
*
schneider-electrichmibmphi74d2801_firmware
*
schneider-electrichmibmpsi74d2801_firmware
*
schneider-electrichmibmp0i74d2001_firmware
*
schneider-electrichmibmp0i74d200a_firmware
*
schneider-electrichmibmphi74d4801_firmware
*
schneider-electrichmibmpsi74d4801_firmware
*
schneider-electrichmibmp0i74d4001_firmware
*
schneider-electrichmibmp0i74d400a_firmware
*
schneider-electrichmibmp0i74di00a_firmware
*
schneider-electrichmibmp0i74de00a_firmware
*
schneider-electrichmibscea53d1l01_firmware
*
schneider-electrichmibmoma5ddf10l_firmware
*
schneider-electrichmibmoma5dd1e01_firmware
*
schneider-electrichmibmoma5dd1101_firmware
*
schneider-electrichmibmo0a5ddf10a_firmware
*
schneider-electrichmibmo0a5ddf101_firmware
*
schneider-electrichmibmo0a5dd1001_firmware
*
schneider-electrichmibmiea5dd1e01_firmware
*
schneider-electrichmibmiea5dd110l_firmware
*
schneider-electrichmibmiea5dd1101_firmware
*
schneider-electrichmibmiea5dd100a_firmware
*
schneider-electrichmibmiea5dd1001_firmware
*
schneider-electrichmibscea53d1l0t_firmware
*
schneider-electrichmibscea53d1l0a_firmware
*
schneider-electricvijeo_designer
𝑥
< 1.2.1
schneider-electricvijeo_designer
𝑥
< 6.2
schneider-electricvijeo_designer
6.2
schneider-electricvijeo_designer
6.2:sp1
schneider-electricvijeo_designer
6.2:sp10
schneider-electricvijeo_designer
6.2:sp11
schneider-electricvijeo_designer
6.2:sp2
schneider-electricvijeo_designer
6.2:sp3.1
schneider-electricvijeo_designer
6.2:sp5.1
schneider-electricvijeo_designer
6.2:sp6
schneider-electricvijeo_designer
6.2:sp7
schneider-electricvijeo_designer
6.2:sp8
schneider-electricvijeo_designer
6.2:sp9
𝑥
= Vulnerable software versions