6.8
CVSSv2

CVE-2021-31337

Published: 28/06/2021 Updated: 02/07/2021
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The Telnet service of the SIMATIC HMI Comfort Panels system component in affected products does not require authentication, which may allow a remote malicious user to gain access to the device if the service is enabled. Telnet is disabled by default on the SINAMICS Medium Voltage Products (SINAMICS SL150: All versions, SINAMICS SM150: All versions, SINAMICS SM150i: All versions).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

siemens sinamics_sl150_firmware

siemens sinamics_sm150_firmware

siemens sinamics_sm150i_firmware

Github Repositories

An embarrassingly simple wrapper for trivy + k8s

trivyal_pursuit If you enjoy chasing down probably-unexploitable-but-you-can-never-be-sure vulnerabilities in Kubernetes, then you've found something Install git clone git@githubcom:alex-hamlin/trivyal_pursuitgit cd trivyal_pursuit gem install bundler bundle install Authentication If you can authenticate with kubectl, you're all set Run For a list of full comma