CVE-2021-31337
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Telnet service of the SIMATIC HMI Comfort Panels system component in affected products does not require authentication, which may allow a remote attacker to gain access to the device if the service is enabled. Telnet is disabled by default on the SINAMICS Medium Voltage Products (SINAMICS SL150: All versions, SINAMICS SM150: All versions, SINAMICS SM150i: All versions).
El servicio Telnet del componente del sistema SIMATIC HMI Comfort Panels en los productos afectados no requiere autenticación, lo que puede permitir a un atacante remoto conseguir acceso al dispositivo si el servicio está habilitado. Telnet está desactivado por defecto en los productos SINAMICS Medium Voltage (SINAMICS SL150: Todas las versiones, SINAMICS SM150: Todas las versiones, SINAMICS SM150i: Todas las versiones)
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-04-15 CVE Reserved
- 2021-06-28 CVE Published
- 2024-03-13 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-306: Missing Authentication for Critical Function
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://us-cert.cisa.gov/ics/advisories/icsa-21-131-04 | Not Applicable |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Siemens Search vendor "Siemens" | Sinamics Sl150 Firmware Search vendor "Siemens" for product "Sinamics Sl150 Firmware" | * | - |
Affected
| in | Siemens Search vendor "Siemens" | Sinamics Sl150 Search vendor "Siemens" for product "Sinamics Sl150" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Sinamics Sm150 Firmware Search vendor "Siemens" for product "Sinamics Sm150 Firmware" | * | - |
Affected
| in | Siemens Search vendor "Siemens" | Sinamics Sm150 Search vendor "Siemens" for product "Sinamics Sm150" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Sinamics Sm150i Firmware Search vendor "Siemens" for product "Sinamics Sm150i Firmware" | * | - |
Affected
| in | Siemens Search vendor "Siemens" | Sinamics Sm150i Search vendor "Siemens" for product "Sinamics Sm150i" | - | - |
Safe
|