CVE-2021-31894 PUBLISHED CVSS 7.199999809265137 HIGH

A vulnerability has been identified in SIMATIC PCS 7 V8.2 and earlier (All versions), SIMATIC PCS 7 V9.X (All versions < V9.1 SP2), SIMATIC PDM (All versions < V9.2 SP2), SIMATIC STEP 7 V5.X (All versions < V5.7), SINAMICS STARTER (containing STEP 7 OEM version) (All versions < V5.4 SP2 HF1). A directory containing metafiles relevant to devices' configurations has write permissions. An attacker could leverage this vulnerability by changing the content of certain metafiles and subsequently manipulate parameters or behavior of devices that would be later configured by the affected software.

EPSS 0.03% · 8.1th percentile

Risk Scores

CVSS v2.0
7.199999809265137
EPSS Score
0.03%
8.1th percentile

Affected Products

VendorProductVersions
siemenssimatic_pdm_firmware
SiemensSINAMICS STARTER (containing STEP 7 OEM version)All versions < V5.4 SP2 HF1
SiemensSIMATIC STEP 7 V5.XAll versions < V5.7
SiemensSIMATIC PCS 7 V8.2 and earlierAll versions
siemenssimatic_step_7_firmware5.0
SiemensSIMATIC PCS 7 V9.XAll versions < V9.1 SP2
SiemensSIMATIC PDMAll versions < V9.2 SP2
siemenssinamics_starter_firmware5.4, 5.4, 5.4
siemenssimatic_pcs_7_firmware9.0, 0

Timeline

References

Open in Interactive Console →