CVE-2021-27388

CRITICAL

SINAMICS SL150 SM150 SM150i Firmware - Unauthenticated Denial of Service and Limited Command Execution via Sm@rtServer

Title source: llm
STIX 2.1

Description

SINAMICS medium voltage routable products are affected by a vulnerability in the Sm@rtServer component for remote access that could allow an unauthenticated attacker to cause a denial-of-service condition, and/or execution of limited configuration modifications and/or execution of limited control commands on the SINAMICS Medium Voltage Products, Remote Access (SINAMICS SL150: All versions, SINAMICS SM150: All versions, SINAMICS SM150i: All versions).

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0186
EPSS Percentile 83.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-20
Status published
Products (3)
siemens/sinamics_sl150_firmware
siemens/sinamics_sm150_firmware
siemens/sinamics_sm150i_firmware
Published Jun 15, 2021
Tracked Since Feb 18, 2026