Undocumented Debug Port Vulnerability in Siemens CP-8000 and CP-8021 Modules
CVE-2021-45033

8.8HIGH

Summary

A security flaw within Siemens CP-8000 and CP-8021 Master Modules allows for unauthorized access to an administrative debug shell due to an undocumented debug port secured by hard-coded default credentials. This vulnerability is particularly concerning as it can be exploited if the debug port is enabled by a privileged user, allowing attackers who possess this knowledge to leverage administrative capabilities on the affected devices.

Affected Version(s)

CP-8000 MASTER MODULE WITH I/O -25/+70°C All versions < V16.20

CP-8000 MASTER MODULE WITH I/O -40/+70°C All versions < V16.20

CP-8021 MASTER MODULE All versions < V16.20

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.