Improper Permissions in Siemens SIMATIC Products
CVE-2021-31894
8.8HIGH
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 13 July 2021
Summary
A vulnerability has been discovered in Siemens SIMATIC software, where a directory containing metafiles pertinent to device configurations possesses unnecessary write permissions. This flaw permits an attacker to alter the content of specific metafiles, providing them the means to manipulate device parameters or behavior during subsequent configurations by the affected software. It affects various versions of SIMATIC PCS 7, STEP 7, and associated products, necessitating immediate attention from users to prevent potential exploitation.
Affected Version(s)
SIMATIC PCS 7 V8.2 and earlier All versions
SIMATIC PCS 7 V9.X All versions < V9.1 SP2
SIMATIC PDM All versions < V9.2 SP2
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved