Vulnerability Description
A CWE-276: Incorrect Default Permissions vulnerability exists that could cause unauthorized access to the base installation directory leading to local privilege escalation. Affected Product: Harmony/Magelis iPC Series (All Versions), Vijeo Designer (All Versions prior to V6.2 SP11 Multiple HotFix 4), Vijeo Designer Basic (All Versions prior to V1.2.1)
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Hmibmuhi29D2801 Firmware | All versions |
| Schneider-Electric | Hmibmuhi29D2801 | - |
| Schneider-Electric | Hmibmusi29D2801 Firmware | All versions |
| Schneider-Electric | Hmibmusi29D2801 | - |
| Schneider-Electric | Hmibmuci29D2W01 Firmware | All versions |
| Schneider-Electric | Hmibmuci29D2W01 | - |
| Schneider-Electric | Hmibmu0I29D2001 Firmware | All versions |
| Schneider-Electric | Hmibmu0I29D2001 | - |
| Schneider-Electric | Hmibmu0I29D200A Firmware | All versions |
| Schneider-Electric | Hmibmu0I29D200A | - |
| Schneider-Electric | Hmibmuhi29D4801 Firmware | All versions |
| Schneider-Electric | Hmibmuhi29D4801 | - |
| Schneider-Electric | Hmibmusi29D4801 Firmware | All versions |
| Schneider-Electric | Hmibmusi29D4801 | - |
| Schneider-Electric | Hmibmuci29D4W01 Firmware | All versions |
| Schneider-Electric | Hmibmuci29D4W01 | - |
| Schneider-Electric | Hmibmu0I29D4001 Firmware | All versions |
| Schneider-Electric | Hmibmu0I29D4001 | - |
| Schneider-Electric | Hmibmu0I29D400A Firmware | All versions |
| Schneider-Electric | Hmibmu0I29D400A | - |
Related Weaknesses (CWE)
References
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-039-06Vendor Advisory
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-039-06Vendor Advisory
FAQ
What is CVE-2021-22817?
CVE-2021-22817 is a vulnerability with a CVSS score of 7.8 (HIGH). A CWE-276: Incorrect Default Permissions vulnerability exists that could cause unauthorized access to the base installation directory leading to local privilege escalation. Affected Product: Harmony/M...
How severe is CVE-2021-22817?
CVE-2021-22817 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-22817?
Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric Hmibmuhi29D2801 Firmware, Schneider-Electric Hmibmuhi29D2801, Schneider-Electric Hmibmusi29D2801 Firmware, Schneider-Electric Hmibmusi29D2801, Schneider-Electric Hmibmuci29D2W01 Firmware.