CVE-2021-31891 Information

Share on:

Description

A vulnerability has been identified in Desigo CC (All versions with OIS Extension Module) GMA-Manager (All versions with OIS running on Debian 9 or earlier) Operation Scheduler (All versions with OIS running on Debian 9 or earlier) Siveillance Control (All versions with OIS running on Debian 9 or earlier) Siveillance Control Pro (All versions). The affected application incorrectly neutralizes special elements in a specific HTTP GET request which could lead to command injection. An unauthenticated remote attacker could exploit this vulnerability to execute arbitrary code on the system with root privileges.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Reference

https://cert-portal.siemens.com/productcert/pdf/ssa-535380.pdf

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

CHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

10.0