← Back

CVE-2021-40359

nvd nist
Published: Nov 9, 2021Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD (Secondary)

Description

A vulnerability has been identified in OpenPCS 7 V8.2 (All versions), OpenPCS 7 V9.0 (All versions < V9.0 Upd4), OpenPCS 7 V9.1 (All versions), SIMATIC BATCH V8.2 (All versions), SIMATIC BATCH V9.0 (All versions), SIMATIC BATCH V9.1 (All versions), SIMATIC NET PC Software V14 (All versions), SIMATIC NET PC Software V15 (All versions), SIMATIC NET PC Software V16 (All versions < V16 Update 6), SIMATIC NET PC Software V17 (All versions < V17 SP1), SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3 UC04), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP1), SIMATIC Route Control V8.2 (All versions), SIMATIC Route Control V9.0 (All versions), SIMATIC Route Control V9.1 (All versions), SIMATIC WinCC V15 and earlier (All versions < V15 SP1 Update 7), SIMATIC WinCC V16 (All versions < V16 Update 5), SIMATIC WinCC V17 (All versions < V17 Update 2), SIMATIC WinCC V7.4 (All versions < V7.4 SP1 Update 19), SIMATIC WinCC V7.5 (All versions < V7.5 SP2 Update 5). When downloading files, the affected systems do not properly neutralize special elements within the pathname. An attacker could then cause the pathname to resolve to a location outside of the restricted directory on the server and read unexpected critical files.

Affected (39)

5 products
Simatic Batch
Simatic Net Pc
Simatic Route Control
Simatic Wincc
Simaticpcs 7
Configuration A
39 vulnerable
Vulnerable SoftwareAffected Versions
Siemens
Version 8.2
Version 8.2 upd_9
Version 9.0
Version 9.0 sp1
Version 9.0 sp1_update_1
Version 9.0 sp1_update_2
Version 9.0 sp1_update_3
Version 9.0 sp1_update_4
Version 9.1
Siemens
Version 14
Version 15
Version 16
Version 16 update1
Version 17
Siemens
Version 8.2
Version 9.0
Version 9.1
Siemens
Up to 7.4
Version 15
Version 16
Version 16 update1
Version 16 update2
Version 16 update3
Version 16 update4
Version 17
Version 17 update1
Version 7.5
Version 7.5
Version 7.5 sp1
Version 7.5 sp1_update1
Version 7.5 sp1_update2
Version 7.5 sp2
Version 7.5 sp2_update1
Version 7.5 sp2_update2
Version 7.5 sp2_update3
Version 7.5 sp2_update4
Siemens
Up to 8.2
From 9.0 to 9.1
Version 9.1

References (2)

Source: productcert@siemens.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.