Insufficient Entropy in Schneider Electric products - CVE-2021-22799

 

Insufficient Entropy in Schneider Electric products - CVE-2021-22799

Published: December 3, 2021


Vulnerability identifier: #VU58500
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-22799
CWE-ID: CWE-331
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information on the system.

The vulnerability exists due to insufficient entropy issue. A local user can decrypt the SESU proxy password from the registry.


Affected software

EcoStruxure Automation Maintenance Expert
OsiSense XX Configuration Software
Vijeo Designer
Versatile Software BLUE
Harmony XB5SSoft
Schneider Electric License Manager
Schneider Electric Floating License Manager
eXLhoist Configuration
Eurotherm iTools
Eurotherm Data Reviewer
EcoStruxure Automation Expert
EcoStruxure Power Design
EcoStruxure Plant Builder
EcoStruxure Machine Expert Basic
EcoStruxure Augmented Operator Advisor
Zelio Soft 2
SoMove
EcoStruxure Operator Terminal Expert
Software Update
EcoStruxure Machine Expert
EcoStruxure Process Expert
EcoStruxure Control Expert

How to mitigate CVE-2021-22799

Install updates from vendor's website.

Software Update - update to 2.5.2

External References

Related Security Bulletins