Improper Permissions in Siemens SIMATIC Products
CVE-2021-31894
8.8HIGH
Key Information:
- Vendor
Siemens
- Vendor
- CVE Published:
- 13 July 2021
What is CVE-2021-31894?
A vulnerability has been discovered in Siemens SIMATIC software, where a directory containing metafiles pertinent to device configurations possesses unnecessary write permissions. This flaw permits an attacker to alter the content of specific metafiles, providing them the means to manipulate device parameters or behavior during subsequent configurations by the affected software. It affects various versions of SIMATIC PCS 7, STEP 7, and associated products, necessitating immediate attention from users to prevent potential exploitation.
Affected Version(s)
SIMATIC PCS 7 V8.2 and earlier All versions
SIMATIC PCS 7 V9.X All versions < V9.1 SP2
SIMATIC PDM All versions < V9.2 SP2