Command Injection Vulnerability in CP-8031 and CP-8050 Master Modules by Siemens
CVE-2023-33919
7.2HIGH
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 13 June 2023
Summary
A command injection vulnerability exists in the web interface of the CP-8031 MASTER MODULE and CP-8050 MASTER MODULE from Siemens. Due to inadequate server-side input validation, an authenticated privileged remote attacker may exploit this weakness to execute arbitrary code with root-level privileges. This can lead to significant security risks and possible takeover of the affected devices.
Affected Version(s)
CP-8031 MASTER MODULE All versions < CPCI85 V05
CP-8050 MASTER MODULE All versions < CPCI85 V05
References
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved