CVE-2021-31891
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability has been identified in Desigo CC (All versions with OIS Extension Module), GMA-Manager (All versions with OIS running on Debian 9 or earlier), Operation Scheduler (All versions with OIS running on Debian 9 or earlier), Siveillance Control (All versions with OIS running on Debian 9 or earlier), Siveillance Control Pro (All versions). The affected application incorrectly neutralizes special elements in a specific HTTP GET request which could lead to command injection. An unauthenticated remote attacker could exploit this vulnerability to execute arbitrary code on the system with root privileges.
Se ha identificado una vulnerabilidad en Desigo CC (Todas las versiones con módulo de extensión OIS), GMA-Manager (Todas las versiones con OIS que se ejecutan en Debian 9 o anterior), Operation Scheduler (Todas las versiones con OIS que se ejecutan en Debian 9 o anterior), Siveillance Control (Todas las versiones con OIS que se ejecutan en Debian 9 o anterior), Siveillance Control Pro (Todas las versiones). La aplicación afectada neutraliza incorrectamente elementos especiales en una petición HTTP GET específica que podría conllevar a una inyección de comandos. Un atacante remoto no autenticado podría aprovechar esta vulnerabilidad para ejecutar código arbitrario en el sistema con privilegios de root
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-04-29 CVE Reserved
- 2021-09-14 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-20 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-535380.pdf | 2021-09-28 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Siemens Search vendor "Siemens" | Gma-manager Search vendor "Siemens" for product "Gma-manager" | * | - |
Affected
| in | Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | <= 9.0 Search vendor "Debian" for product "Debian Linux" and version " <= 9.0" | - |
Safe
|
Siemens Search vendor "Siemens" | Operation Scheduler Search vendor "Siemens" for product "Operation Scheduler" | * | - |
Affected
| in | Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | <= 9.0 Search vendor "Debian" for product "Debian Linux" and version " <= 9.0" | - |
Safe
|
Siemens Search vendor "Siemens" | Siveillance Control Search vendor "Siemens" for product "Siveillance Control" | * | - |
Affected
| in | Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | <= 9.0 Search vendor "Debian" for product "Debian Linux" and version " <= 9.0" | - |
Safe
|
Siemens Search vendor "Siemens" | Desigo Cc Search vendor "Siemens" for product "Desigo Cc" | * | - |
Affected
| ||||||
Siemens Search vendor "Siemens" | Siveillance Control Pro Search vendor "Siemens" for product "Siveillance Control Pro" | * | - |
Affected
|