Insufficient Entropy in Schneider Electric products - CVE-2021-22799
Published: December 3, 2021
Vulnerability identifier: #VU58500
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-22799
CWE-ID: CWE-331
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain access to sensitive information on the system.
The vulnerability exists due to insufficient entropy issue. A local user can decrypt the SESU proxy password from the registry.
Affected software
EcoStruxure Automation Maintenance Expert
OsiSense XX Configuration Software
Vijeo Designer
Versatile Software BLUE
Harmony XB5SSoft
Schneider Electric License Manager
Schneider Electric Floating License Manager
eXLhoist Configuration
Eurotherm iTools
Eurotherm Data Reviewer
EcoStruxure Automation Expert
EcoStruxure Power Design
EcoStruxure Plant Builder
EcoStruxure Machine Expert Basic
EcoStruxure Augmented Operator Advisor
Zelio Soft 2
SoMove
EcoStruxure Operator Terminal Expert
Software Update
EcoStruxure Machine Expert
EcoStruxure Process Expert
EcoStruxure Control Expert
OsiSense XX Configuration Software
Vijeo Designer
Versatile Software BLUE
Harmony XB5SSoft
Schneider Electric License Manager
Schneider Electric Floating License Manager
eXLhoist Configuration
Eurotherm iTools
Eurotherm Data Reviewer
EcoStruxure Automation Expert
EcoStruxure Power Design
EcoStruxure Plant Builder
EcoStruxure Machine Expert Basic
EcoStruxure Augmented Operator Advisor
Zelio Soft 2
SoMove
EcoStruxure Operator Terminal Expert
Software Update
EcoStruxure Machine Expert
EcoStruxure Process Expert
EcoStruxure Control Expert
How to mitigate CVE-2021-22799
Install updates from vendor's website.
Software Update - update to 2.5.2