7.8

CVE-2021-22817

A CWE-276: Incorrect Default Permissions vulnerability exists that could cause unauthorized access to the base installation directory leading to local privilege escalation. Affected Product: Harmony/Magelis iPC Series (All Versions), Vijeo Designer (All Versions prior to V6.2 SP11 Multiple HotFix 4), Vijeo Designer Basic (All Versions prior to V1.2.1)

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Schneider-electricVijeo Designer SwEditionbasic Version < 1.2.1
Schneider-electricVijeo Designer SwEdition- Version < 6.2
Schneider-electricVijeo Designer Version6.2 Update- SwEdition-
Schneider-electricVijeo Designer Version6.2 Updatesp1 SwEdition-
Schneider-electricVijeo Designer Version6.2 Updatesp10 SwEdition-
Schneider-electricVijeo Designer Version6.2 Updatesp11 SwEdition-
Schneider-electricVijeo Designer Version6.2 Updatesp2 SwEdition-
Schneider-electricVijeo Designer Version6.2 Updatesp3.1 SwEdition-
Schneider-electricVijeo Designer Version6.2 Updatesp5.1 SwEdition-
Schneider-electricVijeo Designer Version6.2 Updatesp6 SwEdition-
Schneider-electricVijeo Designer Version6.2 Updatesp7 SwEdition-
Schneider-electricVijeo Designer Version6.2 Updatesp8 SwEdition-
Schneider-electricVijeo Designer Version6.2 Updatesp9 SwEdition-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.04% 0.086
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
CWE-276 Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.