HIGH · 8.1

CVE-2021-27395

A vulnerability has been identified in SIMATIC Process Historian 2013 and earlier (All versions), SIMATIC Process Historian 2014 (All versions < SP3 Update 6), SIMATIC Process Historian 2019 (All vers...

Vulnerability Description

A vulnerability has been identified in SIMATIC Process Historian 2013 and earlier (All versions), SIMATIC Process Historian 2014 (All versions < SP3 Update 6), SIMATIC Process Historian 2019 (All versions), SIMATIC Process Historian 2020 (All versions). An interface in the software that is used for critical functionalities lacks authentication, which could allow a malicious user to maliciously insert, modify or delete data.

CVSS Score

8.1

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
SiemensSimatic Process Historian 2013All versions
SiemensSimatic Process Historian 2014-
SiemensSimatic Process Historian 2019All versions
SiemensSimatic Process Historian 2020All versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-27395?

CVE-2021-27395 is a vulnerability with a CVSS score of 8.1 (HIGH). A vulnerability has been identified in SIMATIC Process Historian 2013 and earlier (All versions), SIMATIC Process Historian 2014 (All versions < SP3 Update 6), SIMATIC Process Historian 2019 (All vers...

How severe is CVE-2021-27395?

CVE-2021-27395 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-27395?

Check the references section above for vendor advisories and patch information. Affected products include: Siemens Simatic Process Historian 2013, Siemens Simatic Process Historian 2014, Siemens Simatic Process Historian 2019, Siemens Simatic Process Historian 2020.