← Back

CVE-2021-31894

nvd nist
Published: Jul 13, 2021Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Exploitability: 2.0 / Impact: 6.0
Source: NVD

Description

A vulnerability has been identified in SIMATIC PCS 7 V8.2 and earlier (All versions), SIMATIC PCS 7 V9.X (All versions < V9.1 SP2), SIMATIC PDM (All versions < V9.2 SP2), SIMATIC STEP 7 V5.X (All versions < V5.7), SINAMICS STARTER (containing STEP 7 OEM version) (All versions < V5.4 SP2 HF1). A directory containing metafiles relevant to devices' configurations has write permissions. An attacker could leverage this vulnerability by changing the content of certain metafiles and subsequently manipulate parameters or behavior of devices that would be later configured by the affected software.

Affected (11)

4 products
Simatic Pcs 7 Firmware
Simatic Pdm Firmware
Simatic Step 7 Firmware
Sinamics Starter Firmware
Configuration A
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Siemens
Up to 8.2
Version 9.0
Running on/withPlatform Versions
Siemens
Simatic Pcs 7
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Simatic Pdm
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 5.0 to 5.7
Running on/withPlatform Versions
Siemens
Simatic Step 7
All versions
Configuration D
7 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Siemens
Before 5.4
Version 5.4
Version 5.4 hf1
Version 5.4 hf2
Version 5.4 sp1
Version 5.4 sp1_hf1
Version 5.4 sp2
Running on/withPlatform Versions
Siemens
Sinamics Starter
All versions

References (2)

Source: productcert@siemens.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.