← Vulnerability feed

Vulnerability record · CVE-2021-22705 · published 26 May 2021

CVE-2021-22705: Schneider-electric vijeo designer memory buffer overflow vulnerability

Schneider Electric · Vijeo Designer

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause denial of service or unauthorized access to system information when interacting directly with a driver installed by Vijeo Designer or EcoStruxure Machine Expert

7.8 CVSS 3.1 High EPSS 0.25% · top 85.8% CWE-119 · Memory buffer overflow
7.8CVSS 3.1 base score, v2 4.6
0.25%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause denial of service or unauthorized access to system information when interacting directly with a driver installed by Vijeo Designer or EcoStruxure Machine Expert

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-22705 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-7487Schneider-electric ecostruxure machine expert insufficient verification of data authenticity vulnerabilityA CWE-345: Insufficient Verification of Data Authenticity vulnerability exists which could allow the attacker to execute malicious code on the Modico…EPSS 0.69%9.8CVE-2020-7489Schneider-electric ecostruxure machine expert injection vulnerabilityA CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability exists on EcoStruxure Mach…EPSS 1.6%9.1CVE-2021-22704Schneider-electric vijeo designer path traversal vulnerabilityA CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists in Harmony/HMI Products Configured by Vijeo Designer (all …EPSS 1.3%8.8CVE-2020-7501Schneider-electric vijeo designer hard-coded credentials vulnerabilityA CWE-798: Use of Hard-coded Credentials vulnerability exists in Vijeo Designer Basic (V1.1 HotFix 16 and prior) and Vijeo Designer (V6.2 SP9 and pri…EPSS 1.1%7.8CVE-2024-8306Schneider-electric vijeo designer improper privilege management vulnerabilityCWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentiality, integrity and availability…EPSS 0.21%7.8CVE-2021-22817Schneider-electric hmibmuhi29d2801 firmware incorrect default permissions vulnerabilityA CWE-276: Incorrect Default Permissions vulnerability exists that could cause unauthorized access to the base installation directory leading to loca…EPSS 0.20%7.8CVE-2020-7490Schneider-electric vijeo designer untrusted search path vulnerabilityA CWE-426: Untrusted Search Path vulnerability exists in Vijeo Designer Basic (V1.1 HotFix 15 and prior) and Vijeo Designer (V6.9 SP9 and prior), whi…EPSS 0.46%7.5CVE-2020-7488Schneider-electric ecostruxure machine expert cleartext transmission vulnerabilityA CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists which could leak sensitive information transmitted between the softwa…EPSS 0.88%

Source: NIST National Vulnerability Database (record CVE-2021-22705), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.