CyberSec.Space Logo
Back to CVE Browser

CVE-2021-31891

CRITICAL
10.0
CVSS Severity Score
EPSS Score0.0530%
EPSS Percentile29.15th
PublishedSep 14, 2021
Last ModifiedNov 21, 2024

Vulnerability Description

A vulnerability has been identified in Desigo CC (All versions with OIS Extension Module), GMA-Manager (All versions with OIS running on Debian 9 or earlier), Operation Scheduler (All versions with OIS running on Debian 9 or earlier), Siveillance Control (All versions with OIS running on Debian 9 or earlier), Siveillance Control Pro (All versions). The affected application incorrectly neutralizes special elements in a specific HTTP GET request which could lead to command injection. An unauthenticated remote attacker could exploit this vulnerability to execute arbitrary code on the system with root privileges.

Affected Platforms (CPE)

πŸ“¦
Siemens

Desigo Cc

All versions
πŸ“¦
Siemens

Siveillance Control Pro

All versions
πŸ“¦
Siemens

Gma Manager

All versions
πŸ“¦
Siemens

Operation Scheduler

All versions
πŸ“¦
Siemens

Siveillance Control

All versions

References & Advisories

Related Vulnerabilities