CVE-2021-41617
View CSAF Summary Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS va...
Affects 14 products across 6 vendors.
The CVE-2021-41617 affects OpenSSH versions 6.2 through 8.x before 8.8, leading to privilege escalation due to improper initialization of supplemental groups. This issue can be exploited in non-default configurations, allowing helper programs to run with elevated privileges. The CVSS score is 7.0, indicating a high severity, and a public proof of concept is available, though no known exploits are in the wild. Affected vendors include Fedora, Fujitsu-Siemens, NetApp, OpenBSD, Oracle, Siemens, and Starwind Software.
BSID: BS-2021-GLOBAL-074526-H • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2021-41617?
What is the CVSS score for CVE-2021-41617?
Is CVE-2021-41617 actively exploited?
How do I remediate CVE-2021-41617?
What systems are affected by CVE-2021-41617?
What NERC-CIP standard applies to CVE-2021-41617?
What IEC 62443 requirement maps to CVE-2021-41617?
| CVE ID | CVE-2021-41617 |
|---|---|
| BSID | BS-2021-GLOBAL-074526-H BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
| Published | 2026-07-28 |
| Last Modified | 2026-07-28 |
| ICS Relevance | 75% |
| Verticals | |
| Source | NVD |
View CSAF Summary Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant). Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. The following versions of Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP are affected: SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) vers:intdot/>=3.1.6
Source: NIST NVD / MITRE CVE Database
The vulnerability arises when certain non-default configurations are used in OpenSSH, causing helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand to run with privileges associated with group memberships of the sshd process. This can lead to privilege escalation, allowing an attacker to gain higher privileges than intended.
Exploitation Likelihood: MEDIUM
| Vendor | Product | Fixed Version |
|---|---|---|
| Fedoraproject | Fedora | — |
| Netapp | Aff A250 Firmware | — |
| Netapp | Aff A250 | — |
| Netapp | Aff 500F Firmware | — |
| Netapp | Aff 500F | — |
| Netapp | Hci Management Node | — |
| Netapp | Solidfire | — |
| Netapp | Clustered Data Ontap | — |
| Netapp | Ontap Select Deploy Administration Utility | — |
| Netapp | Active Iq Unified Manager | — |
| Openbsd | Openssh | — |
| Oracle | Http Server | — |
| Oracle | Zfs Storage Appliance Kit | — |
| Siemens | — | — |
| Starwindsoftware | Starwind Virtual San | — |
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
Ensure that OpenSSH is configured to use default settings or that supplemental groups are properly initialized. Regularly audit and monitor SSH configurations and logs for any suspicious activity.
No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.
This CVE violates CIP-007-R2 because it allows unauthorized access to critical cyber assets, which can compromise the security and reliability of the power system.
This CVE maps to SR 7.6 because it involves a vulnerability that can lead to unauthorized access and privilege escalation, which can compromise the security of the industrial control system.
Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.
SAGE Enrichment Record — provenance & audit hash
| Model | Qwen/Qwen2.5-72B-Instruct-AWQ |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 3c952af7006386e6e86af71788f6aea8410b57fdf3bb6c86a4b9d8ff03a9f67f6d524534fe3794cff17f3f282ccf16062cbacd66362b1af64a7067fc77f47e61 |
ICS/OT Vulnerability Intelligence for Your Environment
BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.
Join free →