CVE-2021-31337: Critical severity siemens sinamics sl150 firmware vulnerability
The Telnet service of the SIMATIC HMI Comfort Panels system component in affected products does not require authentication, which may allow a remote attacker to gain access to the device if the service is enabled. Telnet is disabled by default on the SINAMICS Medium Voltage Products (SINAMICS SL150: All versions, SINAMICS SM150: All versions, SINAMICS SM150i: All versions).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-31337?
CVE-2021-31337 is a vulnerability in the Telnet service of the SIMATIC HMI Comfort Panels system component in affected products, which does not require authentication and may allow a remote attacker to gain access to the device if the service is enabled.
What is the severity of CVE-2021-31337?
CVE-2021-31337 has a severity rating of 9.8 (Critical).
Which products are affected by CVE-2021-31337?
CVE-2021-31337 affects Siemens Sinamics SL150 Firmware, Siemens Sinamics SM150 Firmware, and Siemens Sinamics SM150i Firmware.
Is Siemens Sinamics SL150 vulnerable to CVE-2021-31337?
No, Siemens Sinamics SL150 is not vulnerable to CVE-2021-31337.
How can I fix CVE-2021-31337?
To fix CVE-2021-31337, it is recommended to disable the Telnet service if not required or implement authentication mechanisms.