ID

VAR-202112-0810


CVE

CVE-2021-42022


TITLE

SIMATIC eaSie PCS 7 Skill  Past traversal vulnerability in package

Trust: 0.8

sources: JVNDB: JVNDB-2021-016371

DESCRIPTION

A vulnerability has been identified in SIMATIC eaSie PCS 7 Skill Package (All versions < V21.00 SP3). When downloading files, the affected systems do not properly neutralize special elements within the pathname. An attacker could then cause the pathname to resolve to a location outside of the restricted directory on the server and read unexpected critical files. The affected file download function is disabled by default. SIMATIC eaSie is Siemens' digital assistant automation concept for automation and process control technology, "Totally Integrated Automation"

Trust: 2.16

sources: NVD: CVE-2021-42022 // JVNDB: JVNDB-2021-016371 // CNVD: CNVD-2021-100375

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2021-100375

AFFECTED PRODUCTS

vendor:siemensmodel:simatic easie pcs 7 skillscope:lteversion:20.07

Trust: 1.0

vendor:siemensmodel:simatic easie pcs 7 skillscope:eqversion:21.00

Trust: 1.0

vendor:シーメンスmodel:simatic easie pcs 7 skillscope:eqversion:21.00 sp3

Trust: 0.8

vendor:シーメンスmodel:simatic easie pcs 7 skillscope:eqversion: -

Trust: 0.8

vendor:siemensmodel:simatic easie pcs skill package sp3scope:eqversion:7<v21.00

Trust: 0.6

sources: CNVD: CNVD-2021-100375 // JVNDB: JVNDB-2021-016371 // NVD: CVE-2021-42022

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-42022
value: MEDIUM

Trust: 1.0

NVD: CVE-2021-42022
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2021-100375
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-202112-1122
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2021-42022
severity: LOW
baseScore: 3.5
vectorString: AV:N/AC:M/AU:S/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 6.8
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2021-100375
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:L/AU:S/C:C/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2021-42022
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 3.6
version: 3.1

Trust: 1.0

NVD: CVE-2021-42022
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2021-100375 // JVNDB: JVNDB-2021-016371 // CNNVD: CNNVD-202112-1122 // NVD: CVE-2021-42022

PROBLEMTYPE DATA

problemtype:CWE-22

Trust: 1.0

problemtype:Path traversal (CWE-22) [ others ]

Trust: 0.8

sources: JVNDB: JVNDB-2021-016371 // NVD: CVE-2021-42022

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202112-1122

TYPE

path traversal

Trust: 0.6

sources: CNNVD: CNNVD-202112-1122

PATCH

title:SSA-199605url:https://cert-portal.siemens.com/productcert/pdf/ssa-199605.pdf

Trust: 0.8

title:Patch for SIMATIC eaSie PCS 7 Skill Package (6DL5424- 0BX00-0AV8) Arbitrary File Download Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/306251

Trust: 0.6

title:Siemens SIMATIC PCS 7 Repair measures for path traversal vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=175043

Trust: 0.6

sources: CNVD: CNVD-2021-100375 // JVNDB: JVNDB-2021-016371 // CNNVD: CNNVD-202112-1122

EXTERNAL IDS

db:NVDid:CVE-2021-42022

Trust: 3.8

db:SIEMENSid:SSA-199605

Trust: 2.2

db:ICS CERTid:ICSA-21-350-11

Trust: 1.4

db:JVNid:JVNVU96592426

Trust: 0.8

db:JVNDBid:JVNDB-2021-016371

Trust: 0.8

db:CNVDid:CNVD-2021-100375

Trust: 0.6

db:CS-HELPid:SB2022010608

Trust: 0.6

db:CNNVDid:CNNVD-202112-1122

Trust: 0.6

sources: CNVD: CNVD-2021-100375 // JVNDB: JVNDB-2021-016371 // CNNVD: CNNVD-202112-1122 // NVD: CVE-2021-42022

REFERENCES

url:https://cert-portal.siemens.com/productcert/pdf/ssa-199605.pdf

Trust: 2.2

url:https://nvd.nist.gov/vuln/detail/cve-2021-42022

Trust: 1.4

url:https://jvn.jp/vu/jvnvu96592426/

Trust: 0.8

url:https://www.cisa.gov/uscert/ics/advisories/icsa-21-350-11

Trust: 0.8

url:https://www.cybersecurity-help.cz/vdb/sb2022010608

Trust: 0.6

url:https://us-cert.cisa.gov/ics/advisories/icsa-21-350-11

Trust: 0.6

url:https://vigilance.fr/vulnerability/siemens-simatic-easie-pcs-7-skill-package-directory-traversal-37069

Trust: 0.6

sources: CNVD: CNVD-2021-100375 // JVNDB: JVNDB-2021-016371 // CNNVD: CNNVD-202112-1122 // NVD: CVE-2021-42022

CREDITS

Siemens reported this vulnerability to CISA.

Trust: 0.6

sources: CNNVD: CNNVD-202112-1122

SOURCES

db:CNVDid:CNVD-2021-100375
db:JVNDBid:JVNDB-2021-016371
db:CNNVDid:CNNVD-202112-1122
db:NVDid:CVE-2021-42022

LAST UPDATE DATE

2024-11-23T21:16:35.695000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2021-100375date:2022-01-26T00:00:00
db:JVNDBid:JVNDB-2021-016371date:2022-12-13T08:54:00
db:CNNVDid:CNNVD-202112-1122date:2022-01-07T00:00:00
db:NVDid:CVE-2021-42022date:2024-11-21T06:27:06.027

SOURCES RELEASE DATE

db:CNVDid:CNVD-2021-100375date:2021-12-16T00:00:00
db:JVNDBid:JVNDB-2021-016371date:2022-12-13T00:00:00
db:CNNVDid:CNNVD-202112-1122date:2021-12-14T00:00:00
db:NVDid:CVE-2021-42022date:2021-12-14T12:15:09.863