Vulnerability Description
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause denial of service or unauthorized access to system information when interacting directly with a driver installed by Vijeo Designer or EcoStruxure Machine Expert
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Vijeo Designer | < 6.2.11 |
| Schneider-Electric | Harmony Gk | - |
| Schneider-Electric | Harmony Gto | - |
| Schneider-Electric | Harmony Gtu | - |
| Schneider-Electric | Harmony Gtux | - |
| Schneider-Electric | Harmony Sto | - |
| Schneider-Electric | Harmony Stu | - |
| Schneider-Electric | Ecostruxure Machine Expert | < 2.0 |
| Schneider-Electric | Harmony Hmiscu | - |
Related Weaknesses (CWE)
References
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-130-02PatchVendor Advisory
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-130-02PatchVendor Advisory
FAQ
What is CVE-2021-22705?
CVE-2021-22705 is a vulnerability with a CVSS score of 7.8 (HIGH). Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause denial of service or unauthorized access to system information when interacting directly w...
How severe is CVE-2021-22705?
CVE-2021-22705 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-22705?
Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric Vijeo Designer, Schneider-Electric Harmony Gk, Schneider-Electric Harmony Gto, Schneider-Electric Harmony Gtu, Schneider-Electric Harmony Gtux.