Command Injection Vulnerability in Siemens CP-8031 and CP-8050 Master Modules
CVE-2023-28489

9.8CRITICAL

Key Information:

Vendor
Siemens
Vendor
CVE Published:
11 April 2023

Summary

A vulnerability exists in the Siemens CP-8031 and CP-8050 Master Modules that exposes the devices to command injection risks through the web server on port 443/tcp. If the 'Remote Operation' parameter is enabled, an unauthenticated remote attacker can exploit this issue to execute arbitrary code on the affected modules. Though this parameter is disabled by default, organizations should ensure that their systems are properly configured and monitored to mitigate potential risks.

Affected Version(s)

CP-8031 MASTER MODULE All versions < CPCI85 V05

CP-8050 MASTER MODULE All versions < CPCI85 V05

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.