CVE-2021-22705

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause denial of service or unauthorized access to system information when interacting directly with a driver installed by Vijeo Designer or EcoStruxure Machine Expert
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:schneider-electric:vijeo_designer:*:*:*:*:*:*:*:*
OR cpe:2.3:h:schneider-electric:harmony_gk:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:harmony_gto:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:harmony_gtu:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:harmony_gtux:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:harmony_sto:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:harmony_stu:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:schneider-electric:ecostruxure_machine_expert:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:harmony_hmiscu:-:*:*:*:*:*:*:*

History

31 Jan 2022, 19:33

Type Values Removed Values Added
CPE cpe:2.3:a:se:ecostruxure_machine_expert:*:*:*:*:*:*:*:* cpe:2.3:a:schneider-electric:ecostruxure_machine_expert:*:*:*:*:*:*:*:*

27 Aug 2021, 17:39

Type Values Removed Values Added
CPE cpe:2.3:a:schneider-electric:ecostruxure_machine_expert:*:*:*:*:*:*:*:* cpe:2.3:a:se:ecostruxure_machine_expert:*:*:*:*:*:*:*:*

07 Jun 2021, 18:51

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 4.6
v3 : 7.8
CPE cpe:2.3:h:schneider-electric:harmony_hmiscu:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:harmony_gto:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:harmony_gtu:-:*:*:*:*:*:*:*
cpe:2.3:a:schneider-electric:vijeo_designer:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:harmony_stu:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:harmony_gk:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:harmony_gtux:-:*:*:*:*:*:*:*
cpe:2.3:a:schneider-electric:ecostruxure_machine_expert:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:harmony_sto:-:*:*:*:*:*:*:*
References (MISC) https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-130-02 - (MISC) https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-130-02 - Patch, Vendor Advisory

26 May 2021, 20:49

Type Values Removed Values Added
CWE CWE-119

26 May 2021, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-05-26 20:15

Updated : 2024-02-04 21:47


NVD link : CVE-2021-22705

Mitre link : CVE-2021-22705

CVE.ORG link : CVE-2021-22705


JSON object : View

Products Affected

schneider-electric

  • harmony_gtu
  • harmony_stu
  • harmony_gk
  • ecostruxure_machine_expert
  • harmony_sto
  • harmony_hmiscu
  • harmony_gtux
  • harmony_gto
  • vijeo_designer
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer