Unauthenticated Access in Siemens CP-8000 and CP-8021 Series Products
CVE-2021-46304
7.5HIGH
Key Information:
- Vendor
Siemens
- Status
- Vendor
- CVE Published:
- 10 August 2022
What is CVE-2021-46304?
A vulnerability exists in multiple models of Siemens CP-8000 and CP-8021 Master Modules that permits the activation of a web server module, providing an avenue for unauthenticated access. This could enable attackers to retrieve sensitive debug-level information, which may include details about the internal network topology and lists of connected systems. The risk is significant as it exposes critical information that could be leveraged for further attacks or unauthorized access.
Affected Version(s)
CP-8000 MASTER MODULE WITH I/O -25/+70°C All versions
CP-8000 MASTER MODULE WITH I/O -40/+70°C All versions
CP-8021 MASTER MODULE All versions