CVE-2021-31337
Severity CVSS v4.0:
Pending analysis
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
28/06/2021
Last modified:
02/07/2021
Description
The Telnet service of the SIMATIC HMI Comfort Panels system component in affected products does not require authentication, which may allow a remote attacker to gain access to the device if the service is enabled. Telnet is disabled by default on the SINAMICS Medium Voltage Products (SINAMICS SL150: All versions, SINAMICS SM150: All versions, SINAMICS SM150i: All versions).
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:siemens:sinamics_sl150_firmware:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:siemens:sinamics_sl150:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:siemens:sinamics_sm150_firmware:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:siemens:sinamics_sm150:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:siemens:sinamics_sm150i_firmware:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:siemens:sinamics_sm150i:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



