CVE-2021-32497: Critical severity sick sopas engineering tool vulnerability
Published Dec 17, 2021
·Updated
SICK SOPAS ET before version 4.8.0 allows attackers to wrap any executable file into an SDD and provide this to a SOPAS ET user. When a user starts the emulator the executable is run without further checks.
Affected Software
1 affected component
SICK Sopas Engineering Tool<4.8.0
Remediation
Patch Available
Event History
Dec 17, 2021
CVE Published
via MITRE·04:09 PM
Data Sourced
via MITRE·04:09 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-32497?
CVE-2021-32497 is considered to have a high severity due to the risk of arbitrary code execution.
2
How do I fix CVE-2021-32497?
To mitigate CVE-2021-32497, update the SICK SOPAS ET software to version 4.8.0 or later.
3
What type of vulnerability is CVE-2021-32497?
CVE-2021-32497 is an arbitrary code execution vulnerability that affects the SICK SOPAS ET software.
4
Who is affected by CVE-2021-32497?
Users of SICK SOPAS ET versions prior to 4.8.0 are affected by CVE-2021-32497.
5
Can CVE-2021-32497 be exploited remotely?
Yes, CVE-2021-32497 can potentially be exploited remotely if an attacker provides a malicious SDD to the user.