Command Injection Vulnerability in Siemens CP-8031 and CP-8050 Master Modules
CVE-2023-28489
9.8CRITICAL
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 11 April 2023
Summary
A vulnerability exists in the Siemens CP-8031 and CP-8050 Master Modules that exposes the devices to command injection risks through the web server on port 443/tcp. If the 'Remote Operation' parameter is enabled, an unauthenticated remote attacker can exploit this issue to execute arbitrary code on the affected modules. Though this parameter is disabled by default, organizations should ensure that their systems are properly configured and monitored to mitigate potential risks.
Affected Version(s)
CP-8031 MASTER MODULE All versions < CPCI85 V05
CP-8050 MASTER MODULE All versions < CPCI85 V05
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved