{
    "document": {
        "acknowledgments": [
            {
                "organization": "Siemens ProductCERT",
                "summary": "reporting these vulnerabilities to CISA."
            }
        ],
        "category": "Siemens Security Advisory",
        "csaf_version": "2.0",
        "distribution": {
            "text": "Disclosure is not limited",
            "tlp": {
                "label": "WHITE",
                "url": "https://us-cert.cisa.gov/tlp/"
            }
        },
        "notes": [
            {
                "category": "summary",
                "text": "Multiple vulnerabilities (also known as \"NUCLEUS:13\") have been identified in the Nucleus RTOS (real-time operating system) and reported in the Siemens Security Advisory SSA-044112: https://cert-portal.siemens.com/productcert/pdf/ssa-044112.pdf.\n\nThe products listed below use affected versions of the Nucleus software and inherently contain these vulnerabilities.\n\nSiemens has released updates for several affected products and recommends to update to the latest versions. Siemens recommends specific countermeasures for products where updates are not, or not yet available.",
                "title": "Summary"
            },
            {
                "category": "general",
                "text": "As a general security measure Siemens strongly recommends to protect network access to affected products with appropriate mechanisms. It is advised to follow recommended security practices in order to run the devices in a protected IT environment.",
                "title": "General Recommendations"
            },
            {
                "category": "general",
                "text": "For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories",
                "title": "Additional Resources"
            },
            {
                "category": "legal_disclaimer",
                "text": "Siemens Security Advisories are subject to the terms and conditions contained in Siemens' underlying license terms or other applicable agreements previously agreed to with Siemens (hereinafter \"License Terms\"). To the extent applicable to information, software or documentation made available in or through a Siemens Security Advisory, the Terms of Use of Siemens' Global Website (https://www.siemens.com/terms_of_use, hereinafter \"Terms of Use\"), in particular Sections 8-10 of the Terms of Use, shall apply additionally. In case of conflicts, the License Terms shall prevail over the Terms of Use.",
                "title": "Terms of Use"
            },
            {
                "category": "legal_disclaimer",
                "text": "All information products included in https://us-cert.cisa.gov/ics are provided \"as is\" for informational purposes only. The Department of Homeland Security (DHS) does not provide any warranties of any kind regarding any information contained within. DHS does not endorse any commercial product or service, referenced in this product or otherwise. Further dissemination of this product is governed by the Traffic Light Protocol (TLP) marking in the header. For more information about TLP, see https://us-cert.cisa.gov/tlp/.",
                "title": "Legal Notice"
            },
            {
                "category": "other",
                "text": "This CISA CSAF advisory was converted from Siemens ProductCERT's CSAF advisory.",
                "title": "Advisory Conversion Disclaimer"
            },
            {
                "category": "other",
                "text": "Multiple",
                "title": "Critical infrastructure sectors"
            },
            {
                "category": "other",
                "text": "Worldwide",
                "title": "Countries/areas deployed"
            },
            {
                "category": "other",
                "text": "Germany",
                "title": "Company headquarters location"
            },
            {
                "category": "general",
                "text": "CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.",
                "title": "Recommended Practices"
            },
            {
                "category": "general",
                "text": "Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.",
                "title": "Recommended Practices"
            },
            {
                "category": "general",
                "text": "Locate control system networks and remote devices behind firewalls and isolate them from business networks.",
                "title": "Recommended Practices"
            },
            {
                "category": "general",
                "text": "When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.",
                "title": "Recommended Practices"
            },
            {
                "category": "general",
                "text": "CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.",
                "title": "Recommended Practices"
            },
            {
                "category": "general",
                "text": "CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.",
                "title": "Recommended Practices"
            },
            {
                "category": "general",
                "text": "CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.",
                "title": "Recommended Practices"
            },
            {
                "category": "general",
                "text": "Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.",
                "title": "Recommended Practices"
            }
        ],
        "publisher": {
            "category": "other",
            "contact_details": "central@cisa.dhs.gov",
            "name": "CISA",
            "namespace": "https://www.cisa.gov/"
        },
        "references": [
            {
                "category": "self",
                "summary": "SSA-114589: Multiple Vulnerabilities in Nucleus RTOS based APOGEE, TALON and Desigo PXC/PXM Products - CSAF Version",
                "url": "https://cert-portal.siemens.com/productcert/csaf/ssa-114589.json"
            },
            {
                "category": "self",
                "summary": "SSA-114589: Multiple Vulnerabilities in Nucleus RTOS based APOGEE, TALON and Desigo PXC/PXM Products - TXT Version",
                "url": "https://cert-portal.siemens.com/productcert/txt/ssa-114589.txt"
            },
            {
                "category": "self",
                "summary": "SSA-114589: Multiple Vulnerabilities in Nucleus RTOS based APOGEE, TALON and Desigo PXC/PXM Products - PDF Version",
                "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-114589.pdf"
            },
            {
                "category": "self",
                "summary": "ICS Advisory ICSA-21-315-07 JSON",
                "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2021/icsa-21-315-07.json"
            },
            {
                "category": "self",
                "summary": "ICS Advisory ICSA-21-315-07 - Web Version",
                "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-21-315-07"
            },
            {
                "category": "external",
                "summary": "Recommended Practices",
                "url": "https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01"
            },
            {
                "category": "external",
                "summary": "Recommended Practices",
                "url": "https://www.cisa.gov/resources-tools/resources/ics-recommended-practices"
            },
            {
                "category": "external",
                "summary": "Recommended Practices",
                "url": "https://www.cisa.gov/topics/industrial-control-systems"
            },
            {
                "category": "external",
                "summary": "Recommended Practices",
                "url": "https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf"
            },
            {
                "category": "external",
                "summary": "Recommended Practices",
                "url": "https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf"
            },
            {
                "category": "external",
                "summary": "Recommended Practices",
                "url": "https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B"
            }
        ],
        "title": "Siemens Nucleus RTOS-based APOGEE and TALON Products (Update C)",
        "tracking": {
            "current_release_date": "2022-05-10T00:00:00.000000Z",
            "generator": {
                "engine": {
                    "name": "CISA CSAF Generator",
                    "version": "1.0.0"
                }
            },
            "id": "ICSA-21-315-07",
            "initial_release_date": "2021-11-09T00:00:00.000000Z",
            "revision_history": [
                {
                    "date": "2021-11-09T00:00:00.000000Z",
                    "legacy_version": "1.0",
                    "number": "1",
                    "summary": "Publication Date"
                },
                {
                    "date": "2021-12-14T00:00:00.000000Z",
                    "legacy_version": "1.1",
                    "number": "2",
                    "summary": "Added affected Desigo PXC/PXM products; updated corresponding mitigation measures; informed about planned solutions"
                },
                {
                    "date": "2022-04-12T00:00:00.000000Z",
                    "legacy_version": "1.2",
                    "number": "3",
                    "summary": "Added solutions for APOGEE PXC Compact (BACnet), APOGEE PXC Modular (BACnet), TALON TC Compact (BACnet), and TALON TC Modular (BACnet) products"
                },
                {
                    "date": "2022-05-10T00:00:00.000000Z",
                    "legacy_version": "1.3",
                    "number": "4",
                    "summary": "Added solutions for APOGEE PXC Compact (P2 Ethernet), APOGEE PXC Modular (P2 Ethernet), Desigo PXC Products, Desigo PXM Products"
                }
            ],
            "status": "final",
            "version": "4"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:all/*",
                                "product": {
                                    "name": "APOGEE MBC (PPC) (BACnet)",
                                    "product_id": "CSAFPID-0001"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "APOGEE MBC (PPC) (BACnet)"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:all/*",
                                "product": {
                                    "name": "APOGEE MBC (PPC) (P2 Ethernet)",
                                    "product_id": "CSAFPID-0002"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "APOGEE MBC (PPC) (P2 Ethernet)"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:all/*",
                                "product": {
                                    "name": "APOGEE MEC (PPC) (BACnet)",
                                    "product_id": "CSAFPID-0003"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "APOGEE MEC (PPC) (BACnet)"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:all/*",
                                "product": {
                                    "name": "APOGEE MEC (PPC) (P2 Ethernet)",
                                    "product_id": "CSAFPID-0004"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "APOGEE MEC (PPC) (P2 Ethernet)"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "<V3.5.4",
                                "product": {
                                    "name": "APOGEE PXC Compact (BACnet)",
                                    "product_id": "CSAFPID-0005"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "APOGEE PXC Compact (BACnet)"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "<V2.8.19",
                                "product": {
                                    "name": "APOGEE PXC Compact (P2 Ethernet)",
                                    "product_id": "CSAFPID-0006"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "APOGEE PXC Compact (P2 Ethernet)"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "<V3.5.4",
                                "product": {
                                    "name": "APOGEE PXC Modular (BACnet)",
                                    "product_id": "CSAFPID-0007"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "APOGEE PXC Modular (BACnet)"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "<V2.8.19",
                                "product": {
                                    "name": "APOGEE PXC Modular (P2 Ethernet)",
                                    "product_id": "CSAFPID-0008"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "APOGEE PXC Modular (P2 Ethernet)"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": ">=V2.3_and_<V6.30.016",
                                "product": {
                                    "name": "Desigo PXC00-E.D",
                                    "product_id": "CSAFPID-0009"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Desigo PXC00-E.D"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": ">=V2.3_and_<V6.30.016",
                                "product": {
                                    "name": "Desigo PXC00-U",
                                    "product_id": "CSAFPID-0010"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Desigo PXC00-U"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": ">=V2.3_and_<V6.30.016",
                                "product": {
                                    "name": "Desigo PXC001-E.D",
                                    "product_id": "CSAFPID-0011"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Desigo PXC001-E.D"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": ">=V2.3_and_<V6.30.016",
                                "product": {
                                    "name": "Desigo PXC12-E.D",
                                    "product_id": "CSAFPID-0012"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Desigo PXC12-E.D"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": ">=V2.3_and_<V6.30.016",
                                "product": {
                                    "name": "Desigo PXC22-E.D",
                                    "product_id": "CSAFPID-0013"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Desigo PXC22-E.D"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": ">=V2.3_and_<V6.30.016",
                                "product": {
                                    "name": "Desigo PXC22.1-E.D",
                                    "product_id": "CSAFPID-0014"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Desigo PXC22.1-E.D"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": ">=V2.3_and_<V6.30.016",
                                "product": {
                                    "name": "Desigo PXC36.1-E.D",
                                    "product_id": "CSAFPID-0015"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Desigo PXC36.1-E.D"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": ">=V2.3_and_<V6.30.016",
                                "product": {
                                    "name": "Desigo PXC50-E.D",
                                    "product_id": "CSAFPID-0016"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Desigo PXC50-E.D"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": ">=V2.3_and_<V6.30.016",
                                "product": {
                                    "name": "Desigo PXC64-U",
                                    "product_id": "CSAFPID-0017"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Desigo PXC64-U"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": ">=V2.3_and_<V6.30.016",
                                "product": {
                                    "name": "Desigo PXC100-E.D",
                                    "product_id": "CSAFPID-0018"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Desigo PXC100-E.D"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": ">=V2.3_and_<V6.30.016",
                                "product": {
                                    "name": "Desigo PXC128-U",
                                    "product_id": "CSAFPID-0019"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Desigo PXC128-U"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": ">=V2.3_and_<V6.30.016",
                                "product": {
                                    "name": "Desigo PXC200-E.D",
                                    "product_id": "CSAFPID-0020"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Desigo PXC200-E.D"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": ">=V2.3_and_<V6.30.016",
                                "product": {
                                    "name": "Desigo PXM20-E",
                                    "product_id": "CSAFPID-0021"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Desigo PXM20-E"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "<V3.5.4",
                                "product": {
                                    "name": "TALON TC Compact (BACnet)",
                                    "product_id": "CSAFPID-0022"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "TALON TC Compact (BACnet)"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "<V3.5.4",
                                "product": {
                                    "name": "TALON TC Modular (BACnet)",
                                    "product_id": "CSAFPID-0023"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "TALON TC Modular (BACnet)"
                    }
                ],
                "category": "vendor",
                "name": "Siemens"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2021-31344",
            "cwe": {
                "id": "CWE-843",
                "name": "Access of Resource Using Incompatible Type ('Type Confusion')"
            },
            "notes": [
                {
                    "category": "summary",
                    "text": "ICMP echo packets with fake IP options allow sending ICMP echo reply messages to arbitrary hosts on the network. (FSMD-2021-0004)",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-0001",
                    "CSAFPID-0002",
                    "CSAFPID-0003",
                    "CSAFPID-0004",
                    "CSAFPID-0005",
                    "CSAFPID-0006",
                    "CSAFPID-0007",
                    "CSAFPID-0008",
                    "CSAFPID-0009",
                    "CSAFPID-0010",
                    "CSAFPID-0011",
                    "CSAFPID-0012",
                    "CSAFPID-0013",
                    "CSAFPID-0014",
                    "CSAFPID-0015",
                    "CSAFPID-0016",
                    "CSAFPID-0017",
                    "CSAFPID-0018",
                    "CSAFPID-0019",
                    "CSAFPID-0020",
                    "CSAFPID-0021",
                    "CSAFPID-0022",
                    "CSAFPID-0023"
                ]
            },
            "references": [
                {
                    "summary": "CVE-2021-31344 - Desigo PXC00-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31344 - Desigo PXC00-U",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31344 - Desigo PXC001-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31344 - Desigo PXC12-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31344 - Desigo PXC22-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31344 - Desigo PXC22.1-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31344 - Desigo PXC36.1-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31344 - Desigo PXC50-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31344 - Desigo PXC64-U",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31344 - Desigo PXC100-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31344 - Desigo PXC128-U",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31344 - Desigo PXC200-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31344 - Desigo PXM20-E",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31344 Mitre 5.0 json",
                    "url": "https://cert-portal.siemens.com/productcert/mitre/CVE-2021-31344.json"
                }
            ],
            "remediations": [
                {
                    "category": "no_fix_planned",
                    "details": "Currently no fix is planned",
                    "product_ids": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Update to V3.5.4 or later version",
                    "product_ids": [
                        "CSAFPID-0005",
                        "CSAFPID-0007",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Update to V2.8.19 or later version",
                    "product_ids": [
                        "CSAFPID-0006",
                        "CSAFPID-0008"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Update to V6.30.016 or later version",
                    "product_ids": [
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021"
                    ],
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "category": "mitigation",
                    "details": "CVE-2021-31881, CVE-2021-31882, CVE-2021-31883, CVE-2021-31884: Disable the DHCP client and use static IP address configuration instead (Note that the DHCP client is disabled by default on APOGEE/TALON and Desigo products.)",
                    "product_ids": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0008",
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                },
                {
                    "category": "mitigation",
                    "details": "CVE-2021-31885, CVE-2021-31886, CVE-2021-31887, CVE-2021-31888: Disable the FTP service (Note that the FTP service is disabled by default on Desigo products.)",
                    "product_ids": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0008",
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C",
                        "version": "3.1"
                    },
                    "products": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0008",
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                }
            ],
            "title": "CVE-2021-31344"
        },
        {
            "cve": "CVE-2021-31345",
            "cwe": {
                "id": "CWE-1284",
                "name": "Improper Validation of Specified Quantity in Input"
            },
            "notes": [
                {
                    "category": "summary",
                    "text": "The total length of an UDP payload (set in the IP header) is unchecked. This may lead to various side effects, including Information Leak and Denial-of-Service conditions, depending on a user-defined applications that runs on top of the UDP protocol. (FSMD-2021-0006)",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-0001",
                    "CSAFPID-0002",
                    "CSAFPID-0003",
                    "CSAFPID-0004",
                    "CSAFPID-0005",
                    "CSAFPID-0006",
                    "CSAFPID-0007",
                    "CSAFPID-0008",
                    "CSAFPID-0009",
                    "CSAFPID-0010",
                    "CSAFPID-0011",
                    "CSAFPID-0012",
                    "CSAFPID-0013",
                    "CSAFPID-0014",
                    "CSAFPID-0015",
                    "CSAFPID-0016",
                    "CSAFPID-0017",
                    "CSAFPID-0018",
                    "CSAFPID-0019",
                    "CSAFPID-0020",
                    "CSAFPID-0021",
                    "CSAFPID-0022",
                    "CSAFPID-0023"
                ]
            },
            "references": [
                {
                    "summary": "CVE-2021-31345 - Desigo PXC00-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31345 - Desigo PXC00-U",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31345 - Desigo PXC001-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31345 - Desigo PXC12-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31345 - Desigo PXC22-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31345 - Desigo PXC22.1-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31345 - Desigo PXC36.1-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31345 - Desigo PXC50-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31345 - Desigo PXC64-U",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31345 - Desigo PXC100-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31345 - Desigo PXC128-U",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31345 - Desigo PXC200-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31345 - Desigo PXM20-E",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31345 Mitre 5.0 json",
                    "url": "https://cert-portal.siemens.com/productcert/mitre/CVE-2021-31345.json"
                }
            ],
            "remediations": [
                {
                    "category": "no_fix_planned",
                    "details": "Currently no fix is planned",
                    "product_ids": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Update to V3.5.4 or later version",
                    "product_ids": [
                        "CSAFPID-0005",
                        "CSAFPID-0007",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Update to V2.8.19 or later version",
                    "product_ids": [
                        "CSAFPID-0006",
                        "CSAFPID-0008"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Update to V6.30.016 or later version",
                    "product_ids": [
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021"
                    ],
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "category": "mitigation",
                    "details": "CVE-2021-31881, CVE-2021-31882, CVE-2021-31883, CVE-2021-31884: Disable the DHCP client and use static IP address configuration instead (Note that the DHCP client is disabled by default on APOGEE/TALON and Desigo products.)",
                    "product_ids": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0008",
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                },
                {
                    "category": "mitigation",
                    "details": "CVE-2021-31885, CVE-2021-31886, CVE-2021-31887, CVE-2021-31888: Disable the FTP service (Note that the FTP service is disabled by default on Desigo products.)",
                    "product_ids": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0008",
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C",
                        "version": "3.1"
                    },
                    "products": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0008",
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                }
            ],
            "title": "CVE-2021-31345"
        },
        {
            "cve": "CVE-2021-31346",
            "cwe": {
                "id": "CWE-1284",
                "name": "Improper Validation of Specified Quantity in Input"
            },
            "notes": [
                {
                    "category": "summary",
                    "text": "The total length of an ICMP payload (set in the IP header) is unchecked. This may lead to various side effects, including Information Leak and Denial-of-Service conditions, depending on the network buffer organization in memory. (FSMD-2021-0007)",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-0001",
                    "CSAFPID-0002",
                    "CSAFPID-0003",
                    "CSAFPID-0004",
                    "CSAFPID-0005",
                    "CSAFPID-0006",
                    "CSAFPID-0007",
                    "CSAFPID-0008",
                    "CSAFPID-0009",
                    "CSAFPID-0010",
                    "CSAFPID-0011",
                    "CSAFPID-0012",
                    "CSAFPID-0013",
                    "CSAFPID-0014",
                    "CSAFPID-0015",
                    "CSAFPID-0016",
                    "CSAFPID-0017",
                    "CSAFPID-0018",
                    "CSAFPID-0019",
                    "CSAFPID-0020",
                    "CSAFPID-0021",
                    "CSAFPID-0022",
                    "CSAFPID-0023"
                ]
            },
            "references": [
                {
                    "summary": "CVE-2021-31346 - Desigo PXC00-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31346 - Desigo PXC00-U",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31346 - Desigo PXC001-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31346 - Desigo PXC12-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31346 - Desigo PXC22-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31346 - Desigo PXC22.1-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31346 - Desigo PXC36.1-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31346 - Desigo PXC50-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31346 - Desigo PXC64-U",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31346 - Desigo PXC100-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31346 - Desigo PXC128-U",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31346 - Desigo PXC200-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31346 - Desigo PXM20-E",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31346 Mitre 5.0 json",
                    "url": "https://cert-portal.siemens.com/productcert/mitre/CVE-2021-31346.json"
                }
            ],
            "remediations": [
                {
                    "category": "no_fix_planned",
                    "details": "Currently no fix is planned",
                    "product_ids": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Update to V3.5.4 or later version",
                    "product_ids": [
                        "CSAFPID-0005",
                        "CSAFPID-0007",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Update to V2.8.19 or later version",
                    "product_ids": [
                        "CSAFPID-0006",
                        "CSAFPID-0008"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Update to V6.30.016 or later version",
                    "product_ids": [
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021"
                    ],
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "category": "mitigation",
                    "details": "CVE-2021-31881, CVE-2021-31882, CVE-2021-31883, CVE-2021-31884: Disable the DHCP client and use static IP address configuration instead (Note that the DHCP client is disabled by default on APOGEE/TALON and Desigo products.)",
                    "product_ids": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0008",
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                },
                {
                    "category": "mitigation",
                    "details": "CVE-2021-31885, CVE-2021-31886, CVE-2021-31887, CVE-2021-31888: Disable the FTP service (Note that the FTP service is disabled by default on Desigo products.)",
                    "product_ids": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0008",
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H/E:P/RL:O/RC:C",
                        "version": "3.1"
                    },
                    "products": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0008",
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                }
            ],
            "title": "CVE-2021-31346"
        },
        {
            "cve": "CVE-2021-31881",
            "cwe": {
                "id": "CWE-125",
                "name": "Out-of-bounds Read"
            },
            "notes": [
                {
                    "category": "summary",
                    "text": "When processing a DHCP OFFER message, the DHCP client application does not validate the length of the Vendor option(s), leading to Denial-of-Service conditions. (FSMD-2021-0008)",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-0001",
                    "CSAFPID-0002",
                    "CSAFPID-0003",
                    "CSAFPID-0004",
                    "CSAFPID-0005",
                    "CSAFPID-0006",
                    "CSAFPID-0007",
                    "CSAFPID-0008",
                    "CSAFPID-0009",
                    "CSAFPID-0010",
                    "CSAFPID-0011",
                    "CSAFPID-0012",
                    "CSAFPID-0013",
                    "CSAFPID-0014",
                    "CSAFPID-0015",
                    "CSAFPID-0016",
                    "CSAFPID-0017",
                    "CSAFPID-0018",
                    "CSAFPID-0019",
                    "CSAFPID-0020",
                    "CSAFPID-0021",
                    "CSAFPID-0022",
                    "CSAFPID-0023"
                ]
            },
            "references": [
                {
                    "summary": "CVE-2021-31881 - Desigo PXC00-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31881 - Desigo PXC00-U",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31881 - Desigo PXC001-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31881 - Desigo PXC12-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31881 - Desigo PXC22-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31881 - Desigo PXC22.1-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31881 - Desigo PXC36.1-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31881 - Desigo PXC50-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31881 - Desigo PXC64-U",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31881 - Desigo PXC100-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31881 - Desigo PXC128-U",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31881 - Desigo PXC200-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31881 - Desigo PXM20-E",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31881 Mitre 5.0 json",
                    "url": "https://cert-portal.siemens.com/productcert/mitre/CVE-2021-31881.json"
                }
            ],
            "remediations": [
                {
                    "category": "no_fix_planned",
                    "details": "Currently no fix is planned",
                    "product_ids": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Update to V3.5.4 or later version",
                    "product_ids": [
                        "CSAFPID-0005",
                        "CSAFPID-0007",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Update to V2.8.19 or later version",
                    "product_ids": [
                        "CSAFPID-0006",
                        "CSAFPID-0008"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Update to V6.30.016 or later version",
                    "product_ids": [
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021"
                    ],
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "category": "mitigation",
                    "details": "CVE-2021-31881, CVE-2021-31882, CVE-2021-31883, CVE-2021-31884: Disable the DHCP client and use static IP address configuration instead (Note that the DHCP client is disabled by default on APOGEE/TALON and Desigo products.)",
                    "product_ids": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0008",
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                },
                {
                    "category": "mitigation",
                    "details": "CVE-2021-31885, CVE-2021-31886, CVE-2021-31887, CVE-2021-31888: Disable the FTP service (Note that the FTP service is disabled by default on Desigo products.)",
                    "product_ids": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0008",
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H/E:P/RL:O/RC:C",
                        "version": "3.1"
                    },
                    "products": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0008",
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                }
            ],
            "title": "CVE-2021-31881"
        },
        {
            "cve": "CVE-2021-31882",
            "cwe": {
                "id": "CWE-119",
                "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer"
            },
            "notes": [
                {
                    "category": "summary",
                    "text": "The DHCP client application does not validate the length of the Domain Name Server IP option(s) (0x06) when processing DHCP ACK packets. This may lead to Denial-of-Service conditions. (FSMD-2021-0011)",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-0001",
                    "CSAFPID-0002",
                    "CSAFPID-0003",
                    "CSAFPID-0004",
                    "CSAFPID-0005",
                    "CSAFPID-0006",
                    "CSAFPID-0007",
                    "CSAFPID-0008",
                    "CSAFPID-0009",
                    "CSAFPID-0010",
                    "CSAFPID-0011",
                    "CSAFPID-0012",
                    "CSAFPID-0013",
                    "CSAFPID-0014",
                    "CSAFPID-0015",
                    "CSAFPID-0016",
                    "CSAFPID-0017",
                    "CSAFPID-0018",
                    "CSAFPID-0019",
                    "CSAFPID-0020",
                    "CSAFPID-0021",
                    "CSAFPID-0022",
                    "CSAFPID-0023"
                ]
            },
            "references": [
                {
                    "summary": "CVE-2021-31882 - Desigo PXC00-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31882 - Desigo PXC00-U",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31882 - Desigo PXC001-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31882 - Desigo PXC12-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31882 - Desigo PXC22-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31882 - Desigo PXC22.1-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31882 - Desigo PXC36.1-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31882 - Desigo PXC50-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31882 - Desigo PXC64-U",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31882 - Desigo PXC100-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31882 - Desigo PXC128-U",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31882 - Desigo PXC200-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31882 - Desigo PXM20-E",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31882 Mitre 5.0 json",
                    "url": "https://cert-portal.siemens.com/productcert/mitre/CVE-2021-31882.json"
                }
            ],
            "remediations": [
                {
                    "category": "no_fix_planned",
                    "details": "Currently no fix is planned",
                    "product_ids": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Update to V3.5.4 or later version",
                    "product_ids": [
                        "CSAFPID-0005",
                        "CSAFPID-0007",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Update to V2.8.19 or later version",
                    "product_ids": [
                        "CSAFPID-0006",
                        "CSAFPID-0008"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Update to V6.30.016 or later version",
                    "product_ids": [
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021"
                    ],
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "category": "mitigation",
                    "details": "CVE-2021-31881, CVE-2021-31882, CVE-2021-31883, CVE-2021-31884: Disable the DHCP client and use static IP address configuration instead (Note that the DHCP client is disabled by default on APOGEE/TALON and Desigo products.)",
                    "product_ids": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0008",
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                },
                {
                    "category": "mitigation",
                    "details": "CVE-2021-31885, CVE-2021-31886, CVE-2021-31887, CVE-2021-31888: Disable the FTP service (Note that the FTP service is disabled by default on Desigo products.)",
                    "product_ids": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0008",
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C",
                        "version": "3.1"
                    },
                    "products": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0008",
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                }
            ],
            "title": "CVE-2021-31882"
        },
        {
            "cve": "CVE-2021-31883",
            "cwe": {
                "id": "CWE-119",
                "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer"
            },
            "notes": [
                {
                    "category": "summary",
                    "text": "When processing a DHCP ACK message, the DHCP client application does not validate the length of the Vendor option(s), leading to Denial-of-Service conditions. (FSMD-2021-0013)",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-0001",
                    "CSAFPID-0002",
                    "CSAFPID-0003",
                    "CSAFPID-0004",
                    "CSAFPID-0005",
                    "CSAFPID-0006",
                    "CSAFPID-0007",
                    "CSAFPID-0008",
                    "CSAFPID-0009",
                    "CSAFPID-0010",
                    "CSAFPID-0011",
                    "CSAFPID-0012",
                    "CSAFPID-0013",
                    "CSAFPID-0014",
                    "CSAFPID-0015",
                    "CSAFPID-0016",
                    "CSAFPID-0017",
                    "CSAFPID-0018",
                    "CSAFPID-0019",
                    "CSAFPID-0020",
                    "CSAFPID-0021",
                    "CSAFPID-0022",
                    "CSAFPID-0023"
                ]
            },
            "references": [
                {
                    "summary": "CVE-2021-31883 - Desigo PXC00-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31883 - Desigo PXC00-U",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31883 - Desigo PXC001-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31883 - Desigo PXC12-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31883 - Desigo PXC22-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31883 - Desigo PXC22.1-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31883 - Desigo PXC36.1-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31883 - Desigo PXC50-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31883 - Desigo PXC64-U",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31883 - Desigo PXC100-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31883 - Desigo PXC128-U",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31883 - Desigo PXC200-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31883 - Desigo PXM20-E",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31883 Mitre 5.0 json",
                    "url": "https://cert-portal.siemens.com/productcert/mitre/CVE-2021-31883.json"
                }
            ],
            "remediations": [
                {
                    "category": "no_fix_planned",
                    "details": "Currently no fix is planned",
                    "product_ids": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Update to V3.5.4 or later version",
                    "product_ids": [
                        "CSAFPID-0005",
                        "CSAFPID-0007",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Update to V2.8.19 or later version",
                    "product_ids": [
                        "CSAFPID-0006",
                        "CSAFPID-0008"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Update to V6.30.016 or later version",
                    "product_ids": [
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021"
                    ],
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "category": "mitigation",
                    "details": "CVE-2021-31881, CVE-2021-31882, CVE-2021-31883, CVE-2021-31884: Disable the DHCP client and use static IP address configuration instead (Note that the DHCP client is disabled by default on APOGEE/TALON and Desigo products.)",
                    "product_ids": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0008",
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                },
                {
                    "category": "mitigation",
                    "details": "CVE-2021-31885, CVE-2021-31886, CVE-2021-31887, CVE-2021-31888: Disable the FTP service (Note that the FTP service is disabled by default on Desigo products.)",
                    "product_ids": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0008",
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H/E:P/RL:O/RC:C",
                        "version": "3.1"
                    },
                    "products": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0008",
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                }
            ],
            "title": "CVE-2021-31883"
        },
        {
            "cve": "CVE-2021-31884",
            "cwe": {
                "id": "CWE-170",
                "name": "Improper Null Termination"
            },
            "notes": [
                {
                    "category": "summary",
                    "text": "The DHCP client application assumes that the data supplied with the \u201cHostname\u201d DHCP option is NULL terminated. In cases when global hostname variable is not defined, this may lead to Out-of-bound reads, writes, and Denial-of-service conditions. (FSMD-2021-0014)",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-0001",
                    "CSAFPID-0002",
                    "CSAFPID-0003",
                    "CSAFPID-0004",
                    "CSAFPID-0005",
                    "CSAFPID-0006",
                    "CSAFPID-0007",
                    "CSAFPID-0008",
                    "CSAFPID-0009",
                    "CSAFPID-0010",
                    "CSAFPID-0011",
                    "CSAFPID-0012",
                    "CSAFPID-0013",
                    "CSAFPID-0014",
                    "CSAFPID-0015",
                    "CSAFPID-0016",
                    "CSAFPID-0017",
                    "CSAFPID-0018",
                    "CSAFPID-0019",
                    "CSAFPID-0020",
                    "CSAFPID-0021",
                    "CSAFPID-0022",
                    "CSAFPID-0023"
                ]
            },
            "references": [
                {
                    "summary": "CVE-2021-31884 - Desigo PXC00-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31884 - Desigo PXC00-U",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31884 - Desigo PXC001-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31884 - Desigo PXC12-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31884 - Desigo PXC22-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31884 - Desigo PXC22.1-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31884 - Desigo PXC36.1-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31884 - Desigo PXC50-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31884 - Desigo PXC64-U",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31884 - Desigo PXC100-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31884 - Desigo PXC128-U",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31884 - Desigo PXC200-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31884 - Desigo PXM20-E",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31884 Mitre 5.0 json",
                    "url": "https://cert-portal.siemens.com/productcert/mitre/CVE-2021-31884.json"
                }
            ],
            "remediations": [
                {
                    "category": "no_fix_planned",
                    "details": "Currently no fix is planned",
                    "product_ids": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Update to V3.5.4 or later version",
                    "product_ids": [
                        "CSAFPID-0005",
                        "CSAFPID-0007",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Update to V2.8.19 or later version",
                    "product_ids": [
                        "CSAFPID-0006",
                        "CSAFPID-0008"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Update to V6.30.016 or later version",
                    "product_ids": [
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021"
                    ],
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "category": "mitigation",
                    "details": "CVE-2021-31881, CVE-2021-31882, CVE-2021-31883, CVE-2021-31884: Disable the DHCP client and use static IP address configuration instead (Note that the DHCP client is disabled by default on APOGEE/TALON and Desigo products.)",
                    "product_ids": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0008",
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                },
                {
                    "category": "mitigation",
                    "details": "CVE-2021-31885, CVE-2021-31886, CVE-2021-31887, CVE-2021-31888: Disable the FTP service (Note that the FTP service is disabled by default on Desigo products.)",
                    "product_ids": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0008",
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C",
                        "version": "3.1"
                    },
                    "products": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0008",
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                }
            ],
            "title": "CVE-2021-31884"
        },
        {
            "cve": "CVE-2021-31885",
            "cwe": {
                "id": "CWE-805",
                "name": "Buffer Access with Incorrect Length Value"
            },
            "notes": [
                {
                    "category": "summary",
                    "text": "TFTP server application allows for reading the contents of the TFTP memory buffer via sending malformed TFTP commands. (FSMD-2021-0009)",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-0001",
                    "CSAFPID-0002",
                    "CSAFPID-0003",
                    "CSAFPID-0004",
                    "CSAFPID-0005",
                    "CSAFPID-0006",
                    "CSAFPID-0007",
                    "CSAFPID-0008",
                    "CSAFPID-0009",
                    "CSAFPID-0010",
                    "CSAFPID-0011",
                    "CSAFPID-0012",
                    "CSAFPID-0013",
                    "CSAFPID-0014",
                    "CSAFPID-0015",
                    "CSAFPID-0016",
                    "CSAFPID-0017",
                    "CSAFPID-0018",
                    "CSAFPID-0019",
                    "CSAFPID-0020",
                    "CSAFPID-0021",
                    "CSAFPID-0022",
                    "CSAFPID-0023"
                ]
            },
            "references": [
                {
                    "summary": "CVE-2021-31885 - Desigo PXC00-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31885 - Desigo PXC00-U",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31885 - Desigo PXC001-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31885 - Desigo PXC12-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31885 - Desigo PXC22-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31885 - Desigo PXC22.1-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31885 - Desigo PXC36.1-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31885 - Desigo PXC50-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31885 - Desigo PXC64-U",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31885 - Desigo PXC100-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31885 - Desigo PXC128-U",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31885 - Desigo PXC200-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31885 - Desigo PXM20-E",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31885 Mitre 5.0 json",
                    "url": "https://cert-portal.siemens.com/productcert/mitre/CVE-2021-31885.json"
                }
            ],
            "remediations": [
                {
                    "category": "no_fix_planned",
                    "details": "Currently no fix is planned",
                    "product_ids": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Update to V3.5.4 or later version",
                    "product_ids": [
                        "CSAFPID-0005",
                        "CSAFPID-0007",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Update to V2.8.19 or later version",
                    "product_ids": [
                        "CSAFPID-0006",
                        "CSAFPID-0008"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Update to V6.30.016 or later version",
                    "product_ids": [
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021"
                    ],
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "category": "mitigation",
                    "details": "CVE-2021-31881, CVE-2021-31882, CVE-2021-31883, CVE-2021-31884: Disable the DHCP client and use static IP address configuration instead (Note that the DHCP client is disabled by default on APOGEE/TALON and Desigo products.)",
                    "product_ids": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0008",
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                },
                {
                    "category": "mitigation",
                    "details": "CVE-2021-31885, CVE-2021-31886, CVE-2021-31887, CVE-2021-31888: Disable the FTP service (Note that the FTP service is disabled by default on Desigo products.)",
                    "product_ids": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0008",
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C",
                        "version": "3.1"
                    },
                    "products": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0008",
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                }
            ],
            "title": "CVE-2021-31885"
        },
        {
            "cve": "CVE-2021-31886",
            "cwe": {
                "id": "CWE-170",
                "name": "Improper Null Termination"
            },
            "notes": [
                {
                    "category": "summary",
                    "text": "FTP server does not properly validate the length of the \u201cUSER\u201d command, leading to stack-based buffer overflows. This may result in Denial-of-Service conditions and Remote Code Execution. (FSMD-2021-0010)",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-0001",
                    "CSAFPID-0002",
                    "CSAFPID-0003",
                    "CSAFPID-0004",
                    "CSAFPID-0005",
                    "CSAFPID-0006",
                    "CSAFPID-0007",
                    "CSAFPID-0008",
                    "CSAFPID-0009",
                    "CSAFPID-0010",
                    "CSAFPID-0011",
                    "CSAFPID-0012",
                    "CSAFPID-0013",
                    "CSAFPID-0014",
                    "CSAFPID-0015",
                    "CSAFPID-0016",
                    "CSAFPID-0017",
                    "CSAFPID-0018",
                    "CSAFPID-0019",
                    "CSAFPID-0020",
                    "CSAFPID-0021",
                    "CSAFPID-0022",
                    "CSAFPID-0023"
                ]
            },
            "references": [
                {
                    "summary": "CVE-2021-31886 - Desigo PXC00-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31886 - Desigo PXC00-U",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31886 - Desigo PXC001-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31886 - Desigo PXC12-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31886 - Desigo PXC22-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31886 - Desigo PXC22.1-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31886 - Desigo PXC36.1-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31886 - Desigo PXC50-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31886 - Desigo PXC64-U",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31886 - Desigo PXC100-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31886 - Desigo PXC128-U",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31886 - Desigo PXC200-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31886 - Desigo PXM20-E",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31886 Mitre 5.0 json",
                    "url": "https://cert-portal.siemens.com/productcert/mitre/CVE-2021-31886.json"
                }
            ],
            "remediations": [
                {
                    "category": "no_fix_planned",
                    "details": "Currently no fix is planned",
                    "product_ids": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Update to V3.5.4 or later version",
                    "product_ids": [
                        "CSAFPID-0005",
                        "CSAFPID-0007",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Update to V2.8.19 or later version",
                    "product_ids": [
                        "CSAFPID-0006",
                        "CSAFPID-0008"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Update to V6.30.016 or later version",
                    "product_ids": [
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021"
                    ],
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "category": "mitigation",
                    "details": "CVE-2021-31881, CVE-2021-31882, CVE-2021-31883, CVE-2021-31884: Disable the DHCP client and use static IP address configuration instead (Note that the DHCP client is disabled by default on APOGEE/TALON and Desigo products.)",
                    "product_ids": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0008",
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                },
                {
                    "category": "mitigation",
                    "details": "CVE-2021-31885, CVE-2021-31886, CVE-2021-31887, CVE-2021-31888: Disable the FTP service (Note that the FTP service is disabled by default on Desigo products.)",
                    "product_ids": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0008",
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C",
                        "version": "3.1"
                    },
                    "products": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0008",
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                }
            ],
            "title": "CVE-2021-31886"
        },
        {
            "cve": "CVE-2021-31887",
            "cwe": {
                "id": "CWE-170",
                "name": "Improper Null Termination"
            },
            "notes": [
                {
                    "category": "summary",
                    "text": "FTP server does not properly validate the length of the \u201cPWD/XPWD\u201d command, leading to stack-based buffer overflows. This may result in Denial-of-Service conditions and Remote Code Execution. (FSMD-2021-0016)",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-0001",
                    "CSAFPID-0002",
                    "CSAFPID-0003",
                    "CSAFPID-0004",
                    "CSAFPID-0005",
                    "CSAFPID-0006",
                    "CSAFPID-0007",
                    "CSAFPID-0008",
                    "CSAFPID-0009",
                    "CSAFPID-0010",
                    "CSAFPID-0011",
                    "CSAFPID-0012",
                    "CSAFPID-0013",
                    "CSAFPID-0014",
                    "CSAFPID-0015",
                    "CSAFPID-0016",
                    "CSAFPID-0017",
                    "CSAFPID-0018",
                    "CSAFPID-0019",
                    "CSAFPID-0020",
                    "CSAFPID-0021",
                    "CSAFPID-0022",
                    "CSAFPID-0023"
                ]
            },
            "references": [
                {
                    "summary": "CVE-2021-31887 - Desigo PXC00-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31887 - Desigo PXC00-U",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31887 - Desigo PXC001-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31887 - Desigo PXC12-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31887 - Desigo PXC22-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31887 - Desigo PXC22.1-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31887 - Desigo PXC36.1-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31887 - Desigo PXC50-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31887 - Desigo PXC64-U",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31887 - Desigo PXC100-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31887 - Desigo PXC128-U",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31887 - Desigo PXC200-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31887 - Desigo PXM20-E",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31887 Mitre 5.0 json",
                    "url": "https://cert-portal.siemens.com/productcert/mitre/CVE-2021-31887.json"
                }
            ],
            "remediations": [
                {
                    "category": "no_fix_planned",
                    "details": "Currently no fix is planned",
                    "product_ids": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Update to V3.5.4 or later version",
                    "product_ids": [
                        "CSAFPID-0005",
                        "CSAFPID-0007",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Update to V2.8.19 or later version",
                    "product_ids": [
                        "CSAFPID-0006",
                        "CSAFPID-0008"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Update to V6.30.016 or later version",
                    "product_ids": [
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021"
                    ],
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "category": "mitigation",
                    "details": "CVE-2021-31881, CVE-2021-31882, CVE-2021-31883, CVE-2021-31884: Disable the DHCP client and use static IP address configuration instead (Note that the DHCP client is disabled by default on APOGEE/TALON and Desigo products.)",
                    "product_ids": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0008",
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                },
                {
                    "category": "mitigation",
                    "details": "CVE-2021-31885, CVE-2021-31886, CVE-2021-31887, CVE-2021-31888: Disable the FTP service (Note that the FTP service is disabled by default on Desigo products.)",
                    "product_ids": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0008",
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C",
                        "version": "3.1"
                    },
                    "products": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0008",
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                }
            ],
            "title": "CVE-2021-31887"
        },
        {
            "cve": "CVE-2021-31888",
            "cwe": {
                "id": "CWE-170",
                "name": "Improper Null Termination"
            },
            "notes": [
                {
                    "category": "summary",
                    "text": "FTP server does not properly validate the length of the \u201cMKD/XMKD\u201d command, leading to stack-based buffer overflows. This may result in Denial-of-Service conditions and Remote Code Execution. (FSMD-2021-0018)",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-0001",
                    "CSAFPID-0002",
                    "CSAFPID-0003",
                    "CSAFPID-0004",
                    "CSAFPID-0005",
                    "CSAFPID-0006",
                    "CSAFPID-0007",
                    "CSAFPID-0008",
                    "CSAFPID-0009",
                    "CSAFPID-0010",
                    "CSAFPID-0011",
                    "CSAFPID-0012",
                    "CSAFPID-0013",
                    "CSAFPID-0014",
                    "CSAFPID-0015",
                    "CSAFPID-0016",
                    "CSAFPID-0017",
                    "CSAFPID-0018",
                    "CSAFPID-0019",
                    "CSAFPID-0020",
                    "CSAFPID-0021",
                    "CSAFPID-0022",
                    "CSAFPID-0023"
                ]
            },
            "references": [
                {
                    "summary": "CVE-2021-31888 - Desigo PXC00-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31888 - Desigo PXC00-U",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31888 - Desigo PXC001-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31888 - Desigo PXC12-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31888 - Desigo PXC22-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31888 - Desigo PXC22.1-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31888 - Desigo PXC36.1-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31888 - Desigo PXC50-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31888 - Desigo PXC64-U",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31888 - Desigo PXC100-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31888 - Desigo PXC128-U",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31888 - Desigo PXC200-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31888 - Desigo PXM20-E",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31888 Mitre 5.0 json",
                    "url": "https://cert-portal.siemens.com/productcert/mitre/CVE-2021-31888.json"
                }
            ],
            "remediations": [
                {
                    "category": "no_fix_planned",
                    "details": "Currently no fix is planned",
                    "product_ids": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Update to V3.5.4 or later version",
                    "product_ids": [
                        "CSAFPID-0005",
                        "CSAFPID-0007",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Update to V2.8.19 or later version",
                    "product_ids": [
                        "CSAFPID-0006",
                        "CSAFPID-0008"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Update to V6.30.016 or later version",
                    "product_ids": [
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021"
                    ],
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "category": "mitigation",
                    "details": "CVE-2021-31881, CVE-2021-31882, CVE-2021-31883, CVE-2021-31884: Disable the DHCP client and use static IP address configuration instead (Note that the DHCP client is disabled by default on APOGEE/TALON and Desigo products.)",
                    "product_ids": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0008",
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                },
                {
                    "category": "mitigation",
                    "details": "CVE-2021-31885, CVE-2021-31886, CVE-2021-31887, CVE-2021-31888: Disable the FTP service (Note that the FTP service is disabled by default on Desigo products.)",
                    "product_ids": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0008",
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C",
                        "version": "3.1"
                    },
                    "products": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0008",
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                }
            ],
            "title": "CVE-2021-31888"
        },
        {
            "cve": "CVE-2021-31889",
            "cwe": {
                "id": "CWE-191",
                "name": "Integer Underflow (Wrap or Wraparound)"
            },
            "notes": [
                {
                    "category": "summary",
                    "text": "Malformed TCP packets with a corrupted SACK option leads to Information Leaks and Denial-of-Service conditions. (FSMD-2021-0015)",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-0001",
                    "CSAFPID-0002",
                    "CSAFPID-0003",
                    "CSAFPID-0004",
                    "CSAFPID-0005",
                    "CSAFPID-0006",
                    "CSAFPID-0007",
                    "CSAFPID-0008",
                    "CSAFPID-0009",
                    "CSAFPID-0010",
                    "CSAFPID-0011",
                    "CSAFPID-0012",
                    "CSAFPID-0013",
                    "CSAFPID-0014",
                    "CSAFPID-0015",
                    "CSAFPID-0016",
                    "CSAFPID-0017",
                    "CSAFPID-0018",
                    "CSAFPID-0019",
                    "CSAFPID-0020",
                    "CSAFPID-0021",
                    "CSAFPID-0022",
                    "CSAFPID-0023"
                ]
            },
            "references": [
                {
                    "summary": "CVE-2021-31889 - Desigo PXC00-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31889 - Desigo PXC00-U",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31889 - Desigo PXC001-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31889 - Desigo PXC12-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31889 - Desigo PXC22-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31889 - Desigo PXC22.1-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31889 - Desigo PXC36.1-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31889 - Desigo PXC50-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31889 - Desigo PXC64-U",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31889 - Desigo PXC100-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31889 - Desigo PXC128-U",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31889 - Desigo PXC200-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31889 - Desigo PXM20-E",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31889 Mitre 5.0 json",
                    "url": "https://cert-portal.siemens.com/productcert/mitre/CVE-2021-31889.json"
                }
            ],
            "remediations": [
                {
                    "category": "no_fix_planned",
                    "details": "Currently no fix is planned",
                    "product_ids": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Update to V3.5.4 or later version",
                    "product_ids": [
                        "CSAFPID-0005",
                        "CSAFPID-0007",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Update to V2.8.19 or later version",
                    "product_ids": [
                        "CSAFPID-0006",
                        "CSAFPID-0008"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Update to V6.30.016 or later version",
                    "product_ids": [
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021"
                    ],
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "category": "mitigation",
                    "details": "CVE-2021-31881, CVE-2021-31882, CVE-2021-31883, CVE-2021-31884: Disable the DHCP client and use static IP address configuration instead (Note that the DHCP client is disabled by default on APOGEE/TALON and Desigo products.)",
                    "product_ids": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0008",
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                },
                {
                    "category": "mitigation",
                    "details": "CVE-2021-31885, CVE-2021-31886, CVE-2021-31887, CVE-2021-31888: Disable the FTP service (Note that the FTP service is disabled by default on Desigo products.)",
                    "product_ids": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0008",
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C",
                        "version": "3.1"
                    },
                    "products": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0008",
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                }
            ],
            "title": "CVE-2021-31889"
        },
        {
            "cve": "CVE-2021-31890",
            "cwe": {
                "id": "CWE-240",
                "name": "Improper Handling of Inconsistent Structural Elements"
            },
            "notes": [
                {
                    "category": "summary",
                    "text": "The total length of an TCP payload (set in the IP header) is unchecked. This may lead to various side effects, including Information Leak and Denial-of-Service conditions, depending on the network buffer organization in memory. (FSMD-2021-0017)",
                    "title": "Summary"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-0001",
                    "CSAFPID-0002",
                    "CSAFPID-0003",
                    "CSAFPID-0004",
                    "CSAFPID-0005",
                    "CSAFPID-0006",
                    "CSAFPID-0007",
                    "CSAFPID-0008",
                    "CSAFPID-0009",
                    "CSAFPID-0010",
                    "CSAFPID-0011",
                    "CSAFPID-0012",
                    "CSAFPID-0013",
                    "CSAFPID-0014",
                    "CSAFPID-0015",
                    "CSAFPID-0016",
                    "CSAFPID-0017",
                    "CSAFPID-0018",
                    "CSAFPID-0019",
                    "CSAFPID-0020",
                    "CSAFPID-0021",
                    "CSAFPID-0022",
                    "CSAFPID-0023"
                ]
            },
            "references": [
                {
                    "summary": "CVE-2021-31890 - Desigo PXC00-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31890 - Desigo PXC00-U",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31890 - Desigo PXC001-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31890 - Desigo PXC12-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31890 - Desigo PXC22-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31890 - Desigo PXC22.1-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31890 - Desigo PXC36.1-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31890 - Desigo PXC50-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31890 - Desigo PXC64-U",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31890 - Desigo PXC100-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31890 - Desigo PXC128-U",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31890 - Desigo PXC200-E.D",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31890 - Desigo PXM20-E",
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "summary": "CVE-2021-31890 Mitre 5.0 json",
                    "url": "https://cert-portal.siemens.com/productcert/mitre/CVE-2021-31890.json"
                }
            ],
            "remediations": [
                {
                    "category": "no_fix_planned",
                    "details": "Currently no fix is planned",
                    "product_ids": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Update to V3.5.4 or later version",
                    "product_ids": [
                        "CSAFPID-0005",
                        "CSAFPID-0007",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Update to V2.8.19 or later version",
                    "product_ids": [
                        "CSAFPID-0006",
                        "CSAFPID-0008"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Update to V6.30.016 or later version",
                    "product_ids": [
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021"
                    ],
                    "url": "https://support.industry.siemens.com/cs/ww/en/view/109810577"
                },
                {
                    "category": "mitigation",
                    "details": "CVE-2021-31881, CVE-2021-31882, CVE-2021-31883, CVE-2021-31884: Disable the DHCP client and use static IP address configuration instead (Note that the DHCP client is disabled by default on APOGEE/TALON and Desigo products.)",
                    "product_ids": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0008",
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                },
                {
                    "category": "mitigation",
                    "details": "CVE-2021-31885, CVE-2021-31886, CVE-2021-31887, CVE-2021-31888: Disable the FTP service (Note that the FTP service is disabled by default on Desigo products.)",
                    "product_ids": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0008",
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C",
                        "version": "3.1"
                    },
                    "products": [
                        "CSAFPID-0001",
                        "CSAFPID-0002",
                        "CSAFPID-0003",
                        "CSAFPID-0004",
                        "CSAFPID-0005",
                        "CSAFPID-0006",
                        "CSAFPID-0007",
                        "CSAFPID-0008",
                        "CSAFPID-0009",
                        "CSAFPID-0010",
                        "CSAFPID-0011",
                        "CSAFPID-0012",
                        "CSAFPID-0013",
                        "CSAFPID-0014",
                        "CSAFPID-0015",
                        "CSAFPID-0016",
                        "CSAFPID-0017",
                        "CSAFPID-0018",
                        "CSAFPID-0019",
                        "CSAFPID-0020",
                        "CSAFPID-0021",
                        "CSAFPID-0022",
                        "CSAFPID-0023"
                    ]
                }
            ],
            "title": "CVE-2021-31890"
        }
    ]
}