CVE-2021-22817
A CWE-276: Incorrect Default Permissions vulnerability exists that could cause unauthorized access to the base installation directory leading to local privilege escalation.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.20%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A CWE-276: Incorrect Default Permissions vulnerability exists that could cause unauthorized access to the base installation directory leading to local privilege escalation. Affected Product: Harmony/Magelis iPC Series (All Versions), Vijeo Designer (All Versions prior to V6.2 SP11 Multiple HotFix 4), Vijeo Designer Basic (All Versions prior to V1.2.1)
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.20% probability · 10th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-276
- Affected
- schneider-electric/hmibmuhi29d2801 firmware · schneider-electric/hmibmusi29d2801 firmware · schneider-electric/hmibmuci29d2w01 firmware · schneider-electric/hmibmu0i29d2001 firmware · schneider-electric/hmibmu0i29d200a firmware · schneider-electric/hmibmuhi29d4801 firmware · schneider-electric/hmibmusi29d4801 firmware · schneider-electric/hmibmuci29d4w01 firmware · schneider-electric/hmibmu0i29d4001 firmware · schneider-electric/hmibmu0i29d400a firmware · schneider-electric/hmibmu0i29di00a firmware · schneider-electric/hmibmu0i29de00a firmware · schneider-electric/hmibmphi74d2801 firmware · schneider-electric/hmibmpsi74d2801 firmware · schneider-electric/hmibmp0i74d2001 firmware · schneider-electric/hmibmp0i74d200a firmware · schneider-electric/hmibmphi74d4801 firmware · schneider-electric/hmibmpsi74d4801 firmware · schneider-electric/hmibmp0i74d4001 firmware · schneider-electric/hmibmp0i74d400a firmware · +17 more
- Source
- cybersecurity@se.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.