Description
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists in Harmony/HMI Products Configured by Vijeo Designer (all versions prior to V6.2 SP11 ), Vijeo Designer Basic (all versions prior to V1.2), or EcoStruxure Machine Expert (all versions prior to V2.0) that could cause a Denial of Service or unauthorized access to system information when connecting to the Harmony HMI over FTP.
Published: 2021-09-02
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-9839 A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists in Harmony/HMI Products Configured by Vijeo Designer (all versions prior to V6.2 SP11 ), Vijeo Designer Basic (all versions prior to V1.2), or EcoStruxure Machine Expert (all versions prior to V2.0) that could cause a Denial of Service or unauthorized access to system information when connecting to the Harmony HMI over FTP.
History

No history.

Subscriptions

Schneider-electric Ecostruxure Machine Expert Harmony Gk Harmony Gto Harmony Gtu Harmony Gtux Harmony Gxu Harmony Scu Harmony Sto Harmony Stu Vijeo Designer
cve-icon MITRE

Status: PUBLISHED

Assigner: schneider

Published:

Updated: 2024-08-03T18:51:07.445Z

Reserved: 2021-01-06T00:00:00.000Z

Link: CVE-2021-22704

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-09-02T17:15:08.060

Modified: 2024-11-21T05:50:29.773

Link: CVE-2021-22704

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses