CRITICAL🇵🇱 Wersja polska

CVE-2021-27388

CVSS 9.8v3.1pub. 2021-06-15upd. 2024-11-21

SINAMICS medium voltage routable products are affected by a vulnerability in the Sm@rtServer component for remote access that could allow an unauthenticated attacker to cause a denial-of-service condition, and/or execution of limited configuration modifications and/or execution of limited control commands on the SINAMICS Medium Voltage Products, Remote Access (SINAMICS SL150: All versions, SINAMICS SM150: All versions, SINAMICS SM150i: All versions).

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Siemens Sinamics Sl150

    HW
    Siemens
    all versions
  • Siemens Sinamics Sl150 Firmware

    OS
    Siemens
    all versions
  • Siemens Sinamics Sm150

    HW
    Siemens
    all versions
  • Siemens Sinamics Sm150 Firmware

    OS
    Siemens
    all versions
  • Siemens Sinamics Sm150i

    HW
    Siemens
    all versions
  • Siemens Sinamics Sm150i Firmware

    OS
    Siemens
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2021-31337CRITICAL9.8PL ✓same product

Brak uwierzytelnienia w usłudze Telnet komponentu SIMATIC HMI w produktach Siemens SINAMICS

CVE-2021-27384CRITICAL9.8PL ✓same product

Siemens SmartVNC — podatność out-of-bounds w obsłudze układu urządzenia (RCE)

CVE-2020-15798CRITICAL9.8PL ✓same product

Brak uwierzytelnienia w usłudze telnet paneli Siemens SIMATIC HMI

CVE-2021-27383HIGH7.5same product

A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variant...

CVE-2021-27385HIGH7.5same product

A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variant...