CVE-2021-41769: Input Validation

Published Jan 11, 2022
·
Updated

A vulnerability has been identified in SIPROTEC 5 6MD85 devices (CPU variant CP300) (All versions < V8.83), SIPROTEC 5 6MD86 devices (CPU variant CP300) (All versions < V8.83), SIPROTEC 5 6MD89 devices (CPU variant CP300) (All versions < V8.83), SIPROTEC 5 6MU85 devices (CPU variant CP300) (All versions < V8.83), SIPROTEC 5 7KE85 devices (CPU variant CP300) (All versions < V8.83), SIPROTEC 5 7SA82 devices (CPU variant CP100) (All versions < V8.83), SIPROTEC 5 7SA86 devices (CPU variant CP300) (All versions < V8.83), SIPROTEC 5 7SA87 devices (CPU variant CP300) (All versions < V8.83), SIPROTEC 5 7SD82 devices (CPU variant CP100) (All versions < V8.83), SIPROTEC 5 7SD86 devices (CPU variant CP300) (All versions < V8.83), SIPROTEC 5 7SD87 devices (CPU variant CP300) (All versions < V8.83), SIPROTEC 5 7SJ81 devices (CPU variant CP100) (All versions < V8.83), SIPROTEC 5 7SJ82 devices (CPU variant CP100) (All versions < V8.83), SIPROTEC 5 7SJ85 devices (CPU variant CP300) (All versions < V8.83), SIPROTEC 5 7SJ86 devices (CPU variant CP300) (All versions < V8.83), SIPROTEC 5 7SK82 devices (CPU variant CP100) (All versions < V8.83), SIPROTEC 5 7SK85 devices (CPU variant CP300) (All versions < V8.83), SIPROTEC 5 7SL82 devices (CPU variant CP100) (All versions < V8.83), SIPROTEC 5 7SL86 devices (CPU variant CP300) (All versions < V8.83), SIPROTEC 5 7SL87 devices (CPU variant CP300) (All versions < V8.83), SIPROTEC 5 7SS85 devices (CPU variant CP300) (All versions < V8.83), SIPROTEC 5 7ST85 devices (CPU variant CP300) (All versions < V8.83), SIPROTEC 5 7SX85 devices (CPU variant CP300) (All versions < V8.83), SIPROTEC 5 7UM85 devices (CPU variant CP300) (All versions < V8.83), SIPROTEC 5 7UT82 devices (CPU variant CP100) (All versions < V8.83), SIPROTEC 5 7UT85 devices (CPU variant CP300) (All versions < V8.83), SIPROTEC 5 7UT86 devices (CPU variant CP300) (All versions < V8.83), SIPROTEC 5 7UT87 devices (CPU variant CP300) (All versions < V8.83), SIPROTEC 5 7VE85 devices (CPU variant CP300) (All versions < V8.83), SIPROTEC 5 7VK87 devices (CPU variant CP300) (All versions < V8.83), SIPROTEC 5 Compact 7SX800 devices (CPU variant CP050) (All versions < V8.83). An improper input validation vulnerability in the web server could allow an unauthenticated user to access device information.

Affected Software

62 affected components
Siemens 6md85 Firmware<8.83
Siemens 6md85
Siemens 6md86 Firmware<8.83
Siemens 6md86
Siemens 6md89 Firmware<8.83
Siemens 6md89
Siemens 6mu85 Firmware<8.83
Siemens 6mu85
Siemens 7ke85 Firmware<8.83
Siemens 7ke85
Siemens 7sa82 Firmware<8.83
Siemens 7sa82
Siemens 7sa86 Firmware<8.83
Siemens 7sa86
Siemens 7sa87 Firmware<8.83
Siemens 7sa87
Siemens 7sd82 Firmware<8.83
Siemens 7sd82
Siemens 7sd86 Firmware<8.83
Siemens 7sd86
Siemens 7sd87 Firmware<8.83
Siemens 7sd87
Siemens 7sj81 Firmware<8.83
Siemens 7sj81
Siemens 7sj82 Firmware<8.83
Siemens 7sj82
Siemens 7sj85 Firmware<8.83
Siemens 7sj85
Siemens 7sj86 Firmware<8.83
Siemens 7sj86
Siemens 7sk82 Firmware<8.83
Siemens 7sk82
Siemens 7sk85 Firmware<8.83
Siemens 7sk85
Siemens 7sl82 Firmware<8.83
Siemens 7sl82
Siemens 7sl86 Firmware<8.83
Siemens 7sl86
Siemens 7sl87 Firmware<8.83
Siemens 7sl87
Siemens 7ss85 Firmware<8.83
Siemens 7ss85
Siemens 7st85 Firmware<8.83
Siemens 7st85
Siemens 7sx800 Firmware<8.83
Siemens 7sx800
Siemens 7sx85 Firmware<8.83
Siemens 7sx85
Siemens 7um85 Firmware<8.83
Siemens 7um85
Siemens 7ut82 Firmware<8.83
Siemens 7ut82
Siemens 7ut85 Firmware<8.83
Siemens 7ut85
Siemens 7ut86 Firmware<8.83
Siemens 7ut86
Siemens 7ut87 Firmware<8.83
Siemens 7ut87
Siemens 7ve85 Firmware<8.83
Siemens 7ve85
Siemens 7vk87 Firmware<8.83
Siemens 7vk87

Event History

Jan 11, 2022
CVE Published
via MITRE·11:27 AM
Data Sourced
via MITRE·11:27 AM
DescriptionWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2021-41769?

The severity of CVE-2021-41769 is high with a CVSS score of 7.5.

2

Which devices are affected by CVE-2021-41769?

SIPROTEC 5 6MD85, 6MD86, 6MD89, and 6MU85 devices are affected by CVE-2021-41769.

3

What is the affected software version of CVE-2021-41769?

The affected software version is < V8.83 for all the mentioned devices.

4

Where can I find more information about CVE-2021-41769?

More information about CVE-2021-41769 can be found at the following reference: [link](https://cert-portal.siemens.com/productcert/pdf/ssa-439673.pdf)

5

What is the CWE ID for CVE-2021-41769?

The CWE ID for CVE-2021-41769 is 20.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203