Improper Permissions in Siemens SIMATIC Products
CVE-2021-31894

8.8HIGH

Key Information:

Vendor
Siemens
Vendor
CVE Published:
13 July 2021

Summary

A vulnerability has been discovered in Siemens SIMATIC software, where a directory containing metafiles pertinent to device configurations possesses unnecessary write permissions. This flaw permits an attacker to alter the content of specific metafiles, providing them the means to manipulate device parameters or behavior during subsequent configurations by the affected software. It affects various versions of SIMATIC PCS 7, STEP 7, and associated products, necessitating immediate attention from users to prevent potential exploitation.

Affected Version(s)

SIMATIC PCS 7 V8.2 and earlier All versions

SIMATIC PCS 7 V9.X All versions < V9.1 SP2

SIMATIC PDM All versions < V9.2 SP2

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.