Command Injection Vulnerability in Siemens Desigo CC and Related Products
CVE-2021-31891
10CRITICAL
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 14 September 2021
Summary
A command injection vulnerability exists in multiple Siemens products that utilize the OIS Extension Module. This issue arises from the application's failure to properly neutralize special elements within specific HTTP GET requests. An unauthenticated remote attacker could exploit this flaw to execute arbitrary code with root privileges on the affected systems. It is crucial for users and administrators to implement measures to mitigate the risk associated with this vulnerability.
Affected Version(s)
Desigo CC All versions with OIS Extension Module
GMA-Manager All versions with OIS running on Debian 9 or earlier
Operation Scheduler All versions with OIS running on Debian 9 or earlier
References
CVSS V3.1
Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved