Directory Traversal Vulnerability in CP-8031 and CP-8050 Master Modules by Siemens
CVE-2023-42796
7.5HIGH
Key Information:
- Vendor
Siemens
- Vendor
- CVE Published:
- 10 October 2023
What is CVE-2023-42796?
A vulnerability has been identified in the CP-8031 and CP-8050 MASTER MODULES from Siemens, where the web server does not adequately sanitize user input for the /sicweb-ajax/tmproot/ endpoint. This oversight allows an authenticated remote attacker to traverse directories on the affected systems, potentially enabling them to download arbitrary files. Furthermore, by exploiting active session IDs, there is a risk that attackers could escalate their privileges to that of an administrator, increasing the severity of the threat posed by this vulnerability.
Affected Version(s)
CP-8031 MASTER MODULE All versions < CPCI85 V05.11
CP-8050 MASTER MODULE All versions < CPCI85 V05.11