CVE-2021-31894 - CVE House
Back to Database
Status published High CVE-2021-31894

A vulnerability has been identified in SIMATIC PCS 7 V8.2...

Vulnerability Description

A vulnerability has been identified in SIMATIC PCS 7 V8.2 and earlier (All versions), SIMATIC PCS 7 V9.X (All versions < V9.1 SP2), SIMATIC PDM (All versions < V9.2 SP2), SIMATIC STEP 7 V5.X (All versions < V5.7), SINAMICS STARTER (containing STEP 7 OEM version) (All versions < V5.4 SP2 HF1). A directory containing metafiles relevant to devices' configurations has write permissions. An attacker could leverage this vulnerability by changing the content of certain metafiles and subsequently manipulate parameters or behavior of devices that would be later configured by the affected software.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-31894

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

SIMATIC PCS 7 V8.2 and earlier, SIMATIC PCS 7 V9.X, SIMATIC PDM, SIMATIC STEP 7 V5.X, SINAMICS STARTER (containing STEP 7 OEM version)
Vulnerable Versions:
All versions, All versions < V9.1 SP2, All versions < V9.2 SP2, All versions < V5.7, All versions < V5.4 SP2 HF1

Timeline

Official Publish: July 13th, 2021
Last Modified: August 3rd, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Weaknesses (CWE)