CVE-2021-22817
https://notcve.org/view.php?id=CVE-2021-22817
A CWE-276: Incorrect Default Permissions vulnerability exists that could cause unauthorized access to the base installation directory leading to local privilege escalation. Affected Product: Harmony/Magelis iPC Series (All Versions), Vijeo Designer (All Versions prior to V6.2 SP11 Multiple HotFix 4), Vijeo Designer Basic (All Versions prior to V1.2.1) Una CWE-276: Se presenta una vulnerabilidad de Permisos incorrectos por Defecto que podría causar un acceso no autorizado al directorio de instalación base conllevando a una escalada de privilegios local. Producto afectado: Harmony/Magelis iPC Series (todas las versiones), Vijeo Designer (todas las versiones anteriores a V6.2 SP11 Multiple HotFix 4), Vijeo Designer Basic (todas las versiones anteriores a V1.2.1) • https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-039-06 • CWE-276: Incorrect Default Permissions •
CVE-2021-22704
https://notcve.org/view.php?id=CVE-2021-22704
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists in Harmony/HMI Products Configured by Vijeo Designer (all versions prior to V6.2 SP11 ), Vijeo Designer Basic (all versions prior to V1.2), or EcoStruxure Machine Expert (all versions prior to V2.0) that could cause a Denial of Service or unauthorized access to system information when connecting to the Harmony HMI over FTP. Una CWE-22: Una vulnerabilidad de Limitación Inapropiada de un Nombre de Ruta a un Directorio Restringido se presenta en los productos Harmony/HMI Configurados por Vijeo Designer (todas las versiones anteriores a V6.2 SP11 ), Vijeo Designer Basic (todas las versiones anteriores a V1.2) o EcoStruxure Machine Expert (todas las versiones anteriores a V2.0) que podría causar una denegación de servicio o un acceso no autorizado a la información del sistema cuando se conecta al Harmony HMI a través de FTP • http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-222-01 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2021-22705
https://notcve.org/view.php?id=CVE-2021-22705
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause denial of service or unauthorized access to system information when interacting directly with a driver installed by Vijeo Designer or EcoStruxure Machine Expert Se presenta una vulnerabilidad de Restricción Inapropiada de Operaciones dentro de los límites de un búfer de la memoria, que podría causar una denegación de servicio o acceso no autorizado a la información del sistema interactuando directamente con un controlador instalado por Vijeo Designer o EcoStruxure Machine Expert • https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-130-02 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2020-7501
https://notcve.org/view.php?id=CVE-2020-7501
A CWE-798: Use of Hard-coded Credentials vulnerability exists in Vijeo Designer Basic (V1.1 HotFix 16 and prior) and Vijeo Designer (V6.2 SP9 and prior) which could cause unauthorized read and write when downloading and uploading project or firmware into Vijeo Designer Basic and Vijeo Designer. Una CWE-798: Se presenta una vulnerabilidad de uso de Credenciales Embebidas en Vijeo Designer Basic (versiones V1.1 HotFix 16 y anteriores) y Vijeo Designer (versiones V6.2 SP9 y anteriores), lo que podría causar lectura y escritura no autorizadas al descargar y cargar proyectos o firmware en Vijeo Designer Basic y Vijeo Designer • https://www.se.com/ww/en/download/document/SEVD-2020-133-02 • CWE-798: Use of Hard-coded Credentials •
CVE-2020-7490
https://notcve.org/view.php?id=CVE-2020-7490
A CWE-426: Untrusted Search Path vulnerability exists in Vijeo Designer Basic (V1.1 HotFix 15 and prior) and Vijeo Designer (V6.9 SP9 and prior), which could cause arbitrary code execution on the system running Vijeo Basic when a malicious DLL library is loaded by the Product. CWE-426: hay una vulnerabilidad de Ruta de Búsqueda No Confiable en Vijeo Designer Basic (versiones anteriores a la versión V1.1 HotFix 15 y anteriores) y Vijeo Designer (versiones V6.9 SP9 y anteriores), lo que podría causar una ejecución de código arbitraria en el sistema que ejecuta Vijeo Basic cuando una biblioteca DLL maliciosa es cargada por el producto. • https://www.se.com/ww/en/download/document/SEVD-2020-105-03 • CWE-426: Untrusted Search Path •