cbcvebase.
CVE-2021-22817
published 2022-02-09

CVE-2021-22817: A CWE-276: Incorrect Default Permissions vulnerability exists that could cause unauthorized access to the base installation directory leading to local…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.20%
9.9th percentile
A CWE-276: Incorrect Default Permissions vulnerability exists that could cause unauthorized access to the base installation directory leading to local privilege escalation. Affected Product: Harmony/Magelis iPC Series (All Versions), Vijeo Designer (All Versions prior to V6.2 SP11 Multiple HotFix 4), Vijeo Designer Basic (All Versions prior to V1.2.1)

Affected

5 ranges
VendorProductVersion rangeFixed in
pythonpillow>= 0 < 5.1.0-1ubuntu0.85.1.0-1ubuntu0.8
pythonpillow>= 0 < 7.0.0-4ubuntu0.67.0.0-4ubuntu0.6
schneider-electricvijeo_designer< 1.2.11.2.1
schneider-electricvijeo_designer< 6.26.2
schneider-electricvijeo_designer

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.