CVE-2021-31891
Last modified
CVE-2021-31891 is a critical-severity vulnerability rated 10/10 on the CVSS scale. A vulnerability has been identified in Desigo CC (All versions with OIS Extension Module), GMA-Manager (All versions with OIS running on Debian 9 or earlier), Operation Scheduler (All versions with OIS running on Debian 9 or earlier), Siveillance Control (All versions with OIS running on Debian 9 or earlier), Siveillance Control Pro (All versions). The affected application incorrectly neutralizes special elements in a specific HTTP GET request which could lead to command injection. EPSS estimates a 3.84% chance of exploitation in the next 30 days.
Description
A vulnerability has been identified in Desigo CC (All versions with OIS Extension Module), GMA-Manager (All versions with OIS running on Debian 9 or earlier), Operation Scheduler (All versions with OIS running on Debian 9 or earlier), Siveillance Control (All versions with OIS running on Debian 9 or earlier), Siveillance Control Pro (All versions). The affected application incorrectly neutralizes special elements in a specific HTTP GET request which could lead to command injection. An unauthenticated remote attacker could exploit this vulnerability to execute arbitrary code on the system with root privileges.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Siemens | Desigo Cc | All versions |
| Siemens | Siveillance Control Pro | All versions |
| Siemens | Gma-Manager | All versions |
| Siemens | Operation Scheduler | All versions |
| Siemens | Siveillance Control | All versions |
References
- https://cert-portal.siemens.com/productcert/pdf/ssa-535380.pdfPatch, Vendor Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-535380.pdfPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-31891?
How severe is CVE-2021-31891?
How do I fix CVE-2021-31891?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-31886A vulnerability has been identified in APOGEE MBC (PPC) (BAC…9.8
- CVE-2021-31887A vulnerability has been identified in APOGEE MBC (PPC) (BAC…8.8
- CVE-2021-31888A vulnerability has been identified in APOGEE MBC (PPC) (BAC…8.8
- CVE-2021-31889A vulnerability has been identified in Capital Embedded AR C…9.1
- CVE-2021-3189The slashify package 1.0.0 for Node.js allows open-redirect …6.1
- CVE-2021-31890A vulnerability has been identified in Capital Embedded AR C…9.1
- CVE-2021-31892A vulnerability has been identified in SINUMERIK Analyse MyC…7.4
- CVE-2021-31893A vulnerability has been identified in SIMATIC PCS 7 V8.2 an…7.8
- CVE-2021-31894A vulnerability has been identified in SIMATIC PCS 7 V8.2 an…8.8
- CVE-2021-31895A vulnerability has been identified in RUGGEDCOM i800 (All v…8.1
- CVE-2021-31897In JetBrains WebStorm before 2021.1, code execution without …9.8
- CVE-2021-31898In JetBrains WebStorm before 2021.1, HTTP requests were used…7.5
Are you affected by CVE-2021-31891?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
