cbcvebase.
CVE-2021-22704
published 2021-09-02

CVE-2021-22704: A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists in Harmony/HMI Products Configured by Vijeo Designer (all versions…

PriorityP352critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
1.28%
66.7th percentile
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists in Harmony/HMI Products Configured by Vijeo Designer (all versions prior to V6.2 SP11 ), Vijeo Designer Basic (all versions prior to V1.2), or EcoStruxure Machine Expert (all versions prior to V2.0) that could cause a Denial of Service or unauthorized access to system information when connecting to the Harmony HMI over FTP.

Affected

4 ranges
VendorProductVersion rangeFixed in
schneider-electricecostruxure_machine_expert< 2.02.0
schneider-electricecostruxure_machine_expert
schneider-electricvijeo_designer< 6.2.116.2.11
schneider-electricvijeo_designer< 1.21.2

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.