← Back

CVE-2021-31893

nvd nist
Published: Jul 13, 2021Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

A vulnerability has been identified in SIMATIC PCS 7 V8.2 and earlier (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3), SIMATIC PDM (All versions < V9.2), SIMATIC STEP 7 V5.X (All versions < V5.6 SP2 HF3), SINAMICS STARTER (containing STEP 7 OEM version) (All versions < V5.4 HF2). The affected software contains a buffer overflow vulnerability while handling certain files that could allow a local attacker to trigger a denial-of-service condition or potentially lead to remote code execution.

Affected (10)

4 products
Simatic Pcs Firmware
Simatic Pdm Firmware
Simatic Step 7 Firmware
Sinamics Starter Firmware
Configuration A
4 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Siemens
Up to 8.2
Version 9.0
Version 9.0 sp1
Version 9.0 sp2
Running on/withPlatform Versions
Siemens
Simatic Pcs
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 9.2
Running on/withPlatform Versions
Siemens
Simatic Pdm
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 5.6
Running on/withPlatform Versions
Siemens
Simatic Step 7
All versions
Configuration D
4 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Siemens
Before 5.4
Version 5.4
Version 5.4 hotfix_1
Version 5.4 hotfix_2
Running on/withPlatform Versions
Siemens
Sinamics Starter
All versions

References (2)

Source: productcert@siemens.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.