7.8
CVE-2021-22817
- EPSS 0.04%
- Published 09.02.2022 23:15:14
- Last modified 21.11.2024 05:50:43
- Source cybersecurity@se.com
- Teams watchlist Login
- Open Login
A CWE-276: Incorrect Default Permissions vulnerability exists that could cause unauthorized access to the base installation directory leading to local privilege escalation. Affected Product: Harmony/Magelis iPC Series (All Versions), Vijeo Designer (All Versions prior to V6.2 SP11 Multiple HotFix 4), Vijeo Designer Basic (All Versions prior to V1.2.1)
Data is provided by the National Vulnerability Database (NVD)
Schneider-electric ≫ Vijeo Designer SwEditionbasic Version < 1.2.1
Schneider-electric ≫ Vijeo Designer SwEdition- Version < 6.2
Schneider-electric ≫ Vijeo Designer Version6.2 Update- SwEdition-
Schneider-electric ≫ Vijeo Designer Version6.2 Updatesp1 SwEdition-
Schneider-electric ≫ Vijeo Designer Version6.2 Updatesp10 SwEdition-
Schneider-electric ≫ Vijeo Designer Version6.2 Updatesp11 SwEdition-
Schneider-electric ≫ Vijeo Designer Version6.2 Updatesp2 SwEdition-
Schneider-electric ≫ Vijeo Designer Version6.2 Updatesp3.1 SwEdition-
Schneider-electric ≫ Vijeo Designer Version6.2 Updatesp5.1 SwEdition-
Schneider-electric ≫ Vijeo Designer Version6.2 Updatesp6 SwEdition-
Schneider-electric ≫ Vijeo Designer Version6.2 Updatesp7 SwEdition-
Schneider-electric ≫ Vijeo Designer Version6.2 Updatesp8 SwEdition-
Schneider-electric ≫ Vijeo Designer Version6.2 Updatesp9 SwEdition-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.04% | 0.086 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|
CWE-276 Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.