File Access Vulnerability in Siemens A8000 CP Master Modules
CVE-2021-45034
7.5HIGH
Key Information:
- Vendor
Siemens
- Status
- Vendor
- CVE Published:
- 11 January 2022
What is CVE-2021-45034?
A vulnerability exists in the web server of Siemens A8000 CP Master Modules that permits an unauthenticated attacker to access sensitive log files and diagnostic data generated by privileged users. The issue arises from missing authentication mechanisms that allow unauthorized users to download files if they possess the corresponding links. This vulnerability affects multiple versions of the CP-8000 MASTER MODULE and CP-8021/8022 devices, exposing critical operational information.
Affected Version(s)
CP-8000 MASTER MODULE WITH I/O -25/+70°C All versions < V16.20
CP-8000 MASTER MODULE WITH I/O -40/+70°C All versions < V16.20
CP-8021 MASTER MODULE All versions < V16.20