CVE-2021-31891 is a critical command injection vulnerability affecting Siemens Desigo CC, GMA-Manager, Operation Scheduler, Siveillance Control, and Siveillance Control Pro products when utilizing the OIS Extension Module or running on Debian 9 or earlier. This flaw allows an unauthenticated remote attacker to execute arbitrary code with root privileges due to improper neutralization of special characters in HTTP GET requests. With a CVSS score of 10.0, it represents a severe risk, enabling full compromise of affected systems. Despite its critical nature, there is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and it has not been added to the CISA KEV catalog or observed in active exploitation. Community discussion and media coverage are also minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:siemens:desigo_cc:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:siemens:siveillance_control_pro:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:siemens:gma-manager:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:siemens:operation_scheduler:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:siemens:siveillance_control:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.