Command Injection Vulnerability in Siemens Desigo CC and Related Products
CVE-2021-31891
Key Information:
- Vendor
Siemens
- Vendor
- CVE Published:
- 14 September 2021
What is CVE-2021-31891?
A command injection vulnerability exists in multiple Siemens products that utilize the OIS Extension Module. This issue arises from the application's failure to properly neutralize special elements within specific HTTP GET requests. An unauthenticated remote attacker could exploit this flaw to execute arbitrary code with root privileges on the affected systems. It is crucial for users and administrators to implement measures to mitigate the risk associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Desigo CC All versions with OIS Extension Module
GMA-Manager All versions with OIS running on Debian 9 or earlier
Operation Scheduler All versions with OIS running on Debian 9 or earlier
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved