CVE-2021-27388: Input Validation
SINAMICS medium voltage routable products are affected by a vulnerability in the Sm@rtServer component for remote access that could allow an unauthenticated attacker to cause a denial-of-service condition, and/or execution of limited configuration modifications and/or execution of limited control commands on the SINAMICS Medium Voltage Products, Remote Access (SINAMICS SL150: All versions, SINAMICS SM150: All versions, SINAMICS SM150i: All versions).
Affected Software
Event History
Frequently Asked Questions
Which products are affected by CVE-2021-27388?
SINAMICS SL150 Firmware, SINAMICS SM150 Firmware, and SINAMICS SM150i Firmware.
What is the severity of CVE-2021-27388?
The severity of CVE-2021-27388 is critical with a CVSS score of 9.8.
What is the vulnerability description of CVE-2021-27388?
CVE-2021-27388 is a vulnerability in the Sm@rtServer component for remote access in SINAMICS medium voltage routable products, which could allow an unauthenticated attacker to cause a denial-of-service condition, and/or execution of limited configuration modifications and/or execution of limited control commands.
How can an attacker exploit CVE-2021-27388?
An attacker can exploit CVE-2021-27388 by sending specially crafted network packets to the affected Sm@rtServer component for remote access.
Is there a fix available for CVE-2021-27388?
Yes, Siemens has released a security update to address the vulnerability. It is recommended to update to the latest firmware version for the affected products.