CVE-2021-22716
published 2021-04-13CVE-2021-22716: A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could allow remote code execution when an unprivileged user modifies…
PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.77%
51.1th percentile
A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could allow remote code execution when an unprivileged user modifies a file. Affected Product: C-Bus Toolkit (V1.15.9 and prior)
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| msrc | microsoft_365_apps_for_enterprise_for_32-bit_systems | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_64-bit_systems | — | — |
| msrc | microsoft_excel_2013_rt_service_pack_1 | — | — |
| msrc | microsoft_excel_2013_service_pack_1 | — | — |
| msrc | microsoft_excel_2016 | — | — |
| msrc | microsoft_office_2019_for_32-bit_editions | — | — |
| msrc | microsoft_office_2019_for_64-bit_editions | — | — |
| msrc | microsoft_office_2019_for_mac | — | — |
| msrc | microsoft_office_ltsc_2021_for_32-bit_editions | — | — |
| msrc | microsoft_office_ltsc_2021_for_64-bit_editions | — | — |
| msrc | microsoft_office_ltsc_for_mac_2021 | — | — |
| msrc | microsoft_office_online_server | — | — |
| msrc | microsoft_office_web_apps_server_2013_service_pack_1 | — | — |
| msrc | microsoft_sharepoint_enterprise_server_2013_service_pack_1 | — | — |
| schneider-electric | c-bus_toolkit | <= 1.15.7 | — |
| schneider_electric | c-bus_toolkit | >= V < 1.15.9 | 1.15.9 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Excel Information Disclosure Vulnerability
vendor_msrc·2022-02-08·CVSS 5.5
CVE-2022-22716 [MEDIUM] Microsoft Excel Information Disclosure Vulnerability
Microsoft Excel Information Disclosure Vulnerability
FAQ: Are the updates for the Microsoft Office for Mac currently available?
The security update for Microsoft Office 2019 for Mac and Microsoft Office LTSC for Mac 2021 are not immediately available. The updates will be released as soon as possible, and when they are available, customers will be notified via a revision to this CVE information.
FAQ: Is the Preview Pane an attack vector for this vulnerability?
No, the Preview Pane is not an attack vector.
FAQ: What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerability is uninitialized memory.
Microsoft Office Excel: Microsoft Office Excel
Microsoft: Microsoft
Customer Actio
CISA ICS
Schneider Electric C-Bus Toolkit
cisa_ics·2021-04-15·CVSS 7.8
[HIGH] Schneider Electric C-Bus Toolkit
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Schneider Electric C-Bus Toolkit
Last RevisedApril 15, 2021
Alert CodeICSA-21-105-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Schneider Electric
- Equipment: C-Bus Toolkit
- Vulnerabilities: Improper Privilege Management, Path Traversal
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities may allow remote code execution.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of C-Bus Toolkit are affected:
- C-Bus Toolkit v1.15.7 and prior
## 3.2 VULNERABILITY OVERVIEW
##
GHSA
GHSA-h57p-xqpc-6hj8: A CWE-269: Improper Privilege Management vulnerability exists in C-Bus Toolkit (V1
ghsa_unreviewed·2022-05-24
CVE-2021-22716 [HIGH] CWE-269 GHSA-h57p-xqpc-6hj8: A CWE-269: Improper Privilege Management vulnerability exists in C-Bus Toolkit (V1
A CWE-269: Improper Privilege Management vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) that could allow a remote code execution when an unprivileged user modifies a file.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-103-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2021-103-01_C-Bus_Toolkit_C-Gate_Server_Security_Notification.pdfhttps://us-cert.cisa.gov/ics/advisories/icsa-21-105-01https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-103-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2021-103-01_C-Bus_Toolkit_C-Gate_Server_Security_Notification.pdfhttps://us-cert.cisa.gov/ics/advisories/icsa-21-105-01
2021-04-13
Published