CVE-2021-31894
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability has been identified in SIMATIC PCS 7 V8.2 and earlier (All versions), SIMATIC PCS 7 V9.X (All versions < V9.1 SP2), SIMATIC PDM (All versions < V9.2 SP2), SIMATIC STEP 7 V5.X (All versions < V5.7), SINAMICS STARTER (containing STEP 7 OEM version) (All versions < V5.4 SP2 HF1). A directory containing metafiles relevant to devices' configurations has write permissions. An attacker could leverage this vulnerability by changing the content of certain metafiles and subsequently manipulate parameters or behavior of devices that would be later configured by the affected software.
Se ha identificado una vulnerabilidad en SIMATIC PCS 7 V8.2 y anteriores (Todas las versiones), SIMATIC PCS 7 V9.X (Todas las versiones anteriores a V9.1 SP2), SIMATIC PDM (Todas las versiones anteriores a V9.2 SP2), SIMATIC STEP 7 V5.X (Todas las versiones anteriores a V5.7), SINAMICS STARTER (que contiene la versión OEM de STEP 7) (Todas las versiones anteriores a V5.4 SP2 HF1). Un directorio que contiene metafichas relevantes para las configuraciones de los dispositivos tiene permisos de escritura. Un atacante podría aprovechar esta vulnerabilidad cambiando el contenido de ciertos metaficheros y posteriormente manipular los parámetros o el comportamiento de los dispositivos que posteriormente serían configurados por el software afectado
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-04-29 CVE Reserved
- 2021-07-13 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-732: Incorrect Permission Assignment for Critical Resource
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-661034.pdf | 2022-08-10 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Siemens Search vendor "Siemens" | Simatic Pcs 7 Firmware Search vendor "Siemens" for product "Simatic Pcs 7 Firmware" | <= 8.2 Search vendor "Siemens" for product "Simatic Pcs 7 Firmware" and version " <= 8.2" | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Pcs 7 Search vendor "Siemens" for product "Simatic Pcs 7" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Pcs 7 Firmware Search vendor "Siemens" for product "Simatic Pcs 7 Firmware" | 9.0 Search vendor "Siemens" for product "Simatic Pcs 7 Firmware" and version "9.0" | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Pcs 7 Search vendor "Siemens" for product "Simatic Pcs 7" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Pdm Firmware Search vendor "Siemens" for product "Simatic Pdm Firmware" | - | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Pdm Search vendor "Siemens" for product "Simatic Pdm" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Step 7 Firmware Search vendor "Siemens" for product "Simatic Step 7 Firmware" | >= 5.0 < 5.7 Search vendor "Siemens" for product "Simatic Step 7 Firmware" and version " >= 5.0 < 5.7" | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Step 7 Search vendor "Siemens" for product "Simatic Step 7" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Sinamics Starter Firmware Search vendor "Siemens" for product "Sinamics Starter Firmware" | < 5.4 Search vendor "Siemens" for product "Sinamics Starter Firmware" and version " < 5.4" | - |
Affected
| in | Siemens Search vendor "Siemens" | Sinamics Starter Search vendor "Siemens" for product "Sinamics Starter" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Sinamics Starter Firmware Search vendor "Siemens" for product "Sinamics Starter Firmware" | 5.4 Search vendor "Siemens" for product "Sinamics Starter Firmware" and version "5.4" | - |
Affected
| in | Siemens Search vendor "Siemens" | Sinamics Starter Search vendor "Siemens" for product "Sinamics Starter" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Sinamics Starter Firmware Search vendor "Siemens" for product "Sinamics Starter Firmware" | 5.4 Search vendor "Siemens" for product "Sinamics Starter Firmware" and version "5.4" | hf1 |
Affected
| in | Siemens Search vendor "Siemens" | Sinamics Starter Search vendor "Siemens" for product "Sinamics Starter" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Sinamics Starter Firmware Search vendor "Siemens" for product "Sinamics Starter Firmware" | 5.4 Search vendor "Siemens" for product "Sinamics Starter Firmware" and version "5.4" | hf2 |
Affected
| in | Siemens Search vendor "Siemens" | Sinamics Starter Search vendor "Siemens" for product "Sinamics Starter" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Sinamics Starter Firmware Search vendor "Siemens" for product "Sinamics Starter Firmware" | 5.4 Search vendor "Siemens" for product "Sinamics Starter Firmware" and version "5.4" | sp1 |
Affected
| in | Siemens Search vendor "Siemens" | Sinamics Starter Search vendor "Siemens" for product "Sinamics Starter" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Sinamics Starter Firmware Search vendor "Siemens" for product "Sinamics Starter Firmware" | 5.4 Search vendor "Siemens" for product "Sinamics Starter Firmware" and version "5.4" | sp1_hf1 |
Affected
| in | Siemens Search vendor "Siemens" | Sinamics Starter Search vendor "Siemens" for product "Sinamics Starter" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Sinamics Starter Firmware Search vendor "Siemens" for product "Sinamics Starter Firmware" | 5.4 Search vendor "Siemens" for product "Sinamics Starter Firmware" and version "5.4" | sp2 |
Affected
| in | Siemens Search vendor "Siemens" | Sinamics Starter Search vendor "Siemens" for product "Sinamics Starter" | - | - |
Safe
|