ID

VAR-202202-0404


CVE

CVE-2021-22817


TITLE

Schneider Electric Multiple product security vulnerabilities

Trust: 0.6

sources: CNNVD: CNNVD-202202-891

DESCRIPTION

A CWE-276: Incorrect Default Permissions vulnerability exists that could cause unauthorized access to the base installation directory leading to local privilege escalation. Affected Product: Harmony/Magelis iPC Series (All Versions), Vijeo Designer (All Versions prior to V6.2 SP11 Multiple HotFix 4), Vijeo Designer Basic (All Versions prior to V1.2.1)

Trust: 1.0

sources: NVD: CVE-2021-22817

AFFECTED PRODUCTS

vendor:schneider electricmodel:hmibmp0i74di00ascope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:hmibmoma5dd1e01scope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:hmibmphi74d4801scope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:hmibmp0i74de00ascope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:hmibmu0i29d400ascope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:vijeo designerscope:ltversion:6.2

Trust: 1.0

vendor:schneider electricmodel:hmibmo0a5ddf101scope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:hmibscea53d1l01scope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:hmibmu0i29d4001scope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:hmibmiea5dd1101scope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:hmibmu0i29d200ascope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:hmibmu0i29d2001scope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:hmibmusi29d4801scope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:hmibmp0i74d400ascope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:hmibscea53d1l0ascope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:hmibmiea5dd110lscope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:hmibmiea5dd1001scope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:hmibmiea5dd100ascope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:hmibmp0i74d2001scope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:hmibmoma5ddf10lscope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:hmibmphi74d2801scope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:hmibmoma5dd1101scope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:vijeo designerscope:eqversion:6.2

Trust: 1.0

vendor:schneider electricmodel:hmibmuci29d4w01scope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:hmibmuhi29d2801scope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:hmibmp0i74d4001scope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:hmibscea53d1l0tscope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:hmibmo0a5ddf10ascope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:hmibmpsi74d4801scope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:vijeo designerscope:ltversion:1.2.1

Trust: 1.0

vendor:schneider electricmodel:hmibmo0a5dd1001scope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:hmibmiea5dd1e01scope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:hmibmu0i29de00ascope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:hmibmu0i29di00ascope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:hmibmp0i74d200ascope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:hmibmuci29d2w01scope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:hmibmusi29d2801scope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:hmibmuhi29d4801scope:eqversion:*

Trust: 1.0

vendor:schneider electricmodel:hmibmpsi74d2801scope:eqversion:*

Trust: 1.0

sources: NVD: CVE-2021-22817

CVSS

SEVERITY

CVSSV2

CVSSV3

NVD: CVE-2021-22817
value: HIGH

Trust: 1.0

CNNVD: CNNVD-202202-891
value: HIGH

Trust: 0.6

NVD: CVE-2021-22817
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: FALSE
obtainAllPrivilege: FALSE
obtainUserPrivilege: FALSE
obtainOtherPrivilege: FALSE
userInteractionRequired: FALSE
version: 2.0

Trust: 1.0

NVD: CVE-2021-22817
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.1

Trust: 1.0

sources: CNNVD: CNNVD-202202-891 // NVD: CVE-2021-22817

PROBLEMTYPE DATA

problemtype:CWE-276

Trust: 1.0

sources: NVD: CVE-2021-22817

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202202-891

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202202-891

CONFIGURATIONS

sources: NVD: CVE-2021-22817

PATCH

title:Schneider Electric Various product security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqbyid.tag?id=184122

Trust: 0.6

sources: CNNVD: CNNVD-202202-891

EXTERNAL IDS

db:NVDid:CVE-2021-22817

Trust: 1.6

db:SCHNEIDERid:SEVD-2022-039-06

Trust: 1.6

db:CNNVDid:CNNVD-202202-891

Trust: 0.6

sources: CNNVD: CNNVD-202202-891 // NVD: CVE-2021-22817

REFERENCES

url:https://download.schneider-electric.com/files?p_doc_ref=sevd-2022-039-06

Trust: 1.6

url:https://nvd.nist.gov/vuln/detail/cve-2021-22817

Trust: 0.6

sources: CNNVD: CNNVD-202202-891 // NVD: CVE-2021-22817

SOURCES

db:CNNVDid:CNNVD-202202-891
db:NVDid:CVE-2021-22817

LAST UPDATE DATE

2022-05-04T10:10:21.397000+00:00


SOURCES UPDATE DATE

db:CNNVDid:CNNVD-202202-891date:2022-03-10T00:00:00
db:NVDid:CVE-2021-22817date:2022-02-16T16:57:00

SOURCES RELEASE DATE

db:CNNVDid:CNNVD-202202-891date:2022-02-09T00:00:00
db:NVDid:CVE-2021-22817date:2022-02-09T23:15:00