Command Injection Vulnerability in Siemens Desigo CC and Related Products
CVE-2021-31891

10CRITICAL

Key Information:

Vendor
Siemens
Vendor
CVE Published:
14 September 2021

Summary

A command injection vulnerability exists in multiple Siemens products that utilize the OIS Extension Module. This issue arises from the application's failure to properly neutralize special elements within specific HTTP GET requests. An unauthenticated remote attacker could exploit this flaw to execute arbitrary code with root privileges on the affected systems. It is crucial for users and administrators to implement measures to mitigate the risk associated with this vulnerability.

Affected Version(s)

Desigo CC All versions with OIS Extension Module

GMA-Manager All versions with OIS running on Debian 9 or earlier

Operation Scheduler All versions with OIS running on Debian 9 or earlier

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.