CVE-2023-33921

A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). The affected devices contain an exposed UART console login interface. An attacker with direct physical access could try to bruteforce or crack the root password to login to the device.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:siemens:cpci85_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:cp-8050_master_module:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:siemens:cpci85_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:cp-8031_master_module:-:*:*:*:*:*:*:*

History

11 Jul 2023, 18:15

Type Values Removed Values Added
References
  • (MISC) http://packetstormsecurity.com/files/173370/Siemens-A8000-CP-8050-CP-8031-Code-Execution-Command-Injection.html -

07 Jul 2023, 20:15

Type Values Removed Values Added
References
  • (MISC) http://seclists.org/fulldisclosure/2023/Jul/14 -

29 Jun 2023, 20:12

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.8
CWE NVD-CWE-Other
References (MISC) https://cert-portal.siemens.com/productcert/pdf/ssa-731916.pdf - (MISC) https://cert-portal.siemens.com/productcert/pdf/ssa-731916.pdf - Patch, Vendor Advisory
CPE cpe:2.3:o:siemens:cpci85_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:cp-8031_master_module:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:cp-8050_master_module:-:*:*:*:*:*:*:*

13 Jun 2023, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-06-13 09:15

Updated : 2024-02-04 23:37


NVD link : CVE-2023-33921

Mitre link : CVE-2023-33921

CVE.ORG link : CVE-2023-33921


JSON object : View

Products Affected

siemens

  • cp-8031_master_module
  • cpci85_firmware
  • cp-8050_master_module
CWE
NVD-CWE-Other CWE-749

Exposed Dangerous Method or Function