Improper Permissions in Siemens SIMATIC Products
CVE-2021-31894
Key Information:
- Vendor
Siemens
- Vendor
- CVE Published:
- 13 July 2021
What is CVE-2021-31894?
A vulnerability has been discovered in Siemens SIMATIC software, where a directory containing metafiles pertinent to device configurations possesses unnecessary write permissions. This flaw permits an attacker to alter the content of specific metafiles, providing them the means to manipulate device parameters or behavior during subsequent configurations by the affected software. It affects various versions of SIMATIC PCS 7, STEP 7, and associated products, necessitating immediate attention from users to prevent potential exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SIMATIC PCS 7 V8.2 and earlier All versions
SIMATIC PCS 7 V9.X All versions < V9.1 SP2
SIMATIC PDM All versions < V9.2 SP2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved