CVE-2021-31894: High severity siemens simatic pcs firmware vulnerability
A vulnerability has been identified in SIMATIC PCS 7 V8.2 and earlier (All versions), SIMATIC PCS 7 V9.X (All versions < V9.1 SP2), SIMATIC PDM (All versions < V9.2 SP2), SIMATIC STEP 7 V5.X (All versions < V5.7), SINAMICS STARTER (containing STEP 7 OEM version) (All versions < V5.4 SP2 HF1). A directory containing metafiles relevant to devices' configurations has write permissions. An attacker could leverage this vulnerability by changing the content of certain metafiles and subsequently manipulate parameters or behavior of devices that would be later configured by the affected software.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-31894.
Which software versions are affected by this vulnerability?
SIMATIC PCS 7 V8.2 and earlier, SIMATIC PCS 7 V9.X (All versions < V9.1 SP2), SIMATIC PDM (All versions < V9.2 SP2), SIMATIC STEP 7 V5.X (All versions < V5.7), SINAMICS STARTER (containing STEP 7 OEM version) (All versions < V5.4 SP2 HF1) are affected.
What is the severity rating of CVE-2021-31894?
The severity rating of CVE-2021-31894 is 8.8 (High).
How can I fix CVE-2021-31894?
To fix CVE-2021-31894, Siemens has released security updates. Please refer to the official Siemens security advisory (Reference link) for detailed instructions.
What is the Common Weakness Enumeration (CWE) ID associated with this vulnerability?
The Common Weakness Enumeration (CWE) ID associated with CVE-2021-31894 is 732.