Undocumented Debug Port Vulnerability in Siemens CP-8000 and CP-8021 Modules
CVE-2021-45033
8.8HIGH
Key Information:
- Vendor
- Siemens
- Status
- Vendor
- CVE Published:
- 11 January 2022
Summary
A security flaw within Siemens CP-8000 and CP-8021 Master Modules allows for unauthorized access to an administrative debug shell due to an undocumented debug port secured by hard-coded default credentials. This vulnerability is particularly concerning as it can be exploited if the debug port is enabled by a privileged user, allowing attackers who possess this knowledge to leverage administrative capabilities on the affected devices.
Affected Version(s)
CP-8000 MASTER MODULE WITH I/O -25/+70°C All versions < V16.20
CP-8000 MASTER MODULE WITH I/O -40/+70°C All versions < V16.20
CP-8021 MASTER MODULE All versions < V16.20
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved