CVE-2021-31891: OS Command Injection
A vulnerability has been identified in Desigo CC (All versions with OIS Extension Module), GMA-Manager (All versions with OIS running on Debian 9 or earlier), Operation Scheduler (All versions with OIS running on Debian 9 or earlier), Siveillance Control (All versions with OIS running on Debian 9 or earlier), Siveillance Control Pro (All versions). The affected application incorrectly neutralizes special elements in a specific HTTP GET request which could lead to command injection. An unauthenticated remote attacker could exploit this vulnerability to execute arbitrary code on the system with root privileges.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-31891?
The severity of CVE-2021-31891 is critical with a severity value of 10.
Which software versions are affected by CVE-2021-31891?
Desigo CC (All versions with OIS Extension Module), GMA-Manager (All versions with OIS running on Debian 9 or earlier), Operation Scheduler (All versions with OIS running on Debian 9 or earlier), Siveillance Control (All versions with OIS running on Debian 9 or earlier) are affected by CVE-2021-31891.
How can I fix CVE-2021-31891?
Apply the necessary security updates or patches provided by Siemens to fix CVE-2021-31891.
What is the Common Weakness Enumeration (CWE) for CVE-2021-31891?
The Common Weakness Enumeration (CWE) for CVE-2021-31891 is CWE-77 and CWE-78.
Where can I find more information about CVE-2021-31891?
You can find more information about CVE-2021-31891 at https://cert-portal.siemens.com/productcert/pdf/ssa-535380.pdf.