SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-31891

A vulnerability has been identified in Desigo CC (All versions with OIS Extension Module), GMA-Manager (All versions with OIS running on Debian 9 or earlier), Operation Scheduler (All versions with OIS running on Debian 9 or earlier), Siveillance…

CRITICAL 10.0EPSS 3.84%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (3.84%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

A vulnerability has been identified in Desigo CC (All versions with OIS Extension Module), GMA-Manager (All versions with OIS running on Debian 9 or earlier), Operation Scheduler (All versions with OIS running on Debian 9 or earlier), Siveillance Control (All versions with OIS running on Debian 9 or earlier), Siveillance Control Pro (All versions). The affected application incorrectly neutralizes special elements in a specific HTTP GET request which could lead to command injection. An unauthenticated remote attacker could exploit this vulnerability to execute arbitrary code on the system with root privileges.

CVSS 3.1
10.0 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS
3.84% probability · 90th percentile
CISA KEV
Not listed
Weakness
CWE-78
Affected
siemens/desigo cc · siemens/siveillance control pro · siemens/gma-manager · siemens/operation scheduler · siemens/siveillance control
Source
productcert@siemens.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.