Lucene search

K
cveSiemensCVE-2023-28489
HistoryApr 11, 2023 - 10:15 a.m.

CVE-2023-28489

2023-04-1110:15:18
CWE-77
siemens
web.nvd.nist.gov
79
cve-2023-28489
cp-8031
cp-8050
master module
command injection
web server
remote operation
arbitrary code execution
nvd

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.8

Confidence

High

EPSS

0.014

Percentile

86.7%

A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). Affected devices are vulnerable to command injection via the web server port 443/tcp, if the parameter β€œRemote Operation” is enabled. The parameter is disabled by default.
The vulnerability could allow an unauthenticated remote attacker to perform arbitrary code execution on the device.

Affected configurations

Nvd
Node
siemenscp-8031Match-
AND
siemenscp-8031_firmwareRange<cpci85_v05
Node
siemenscp-8050Match-
AND
siemenscp-8050_firmwareRange<cpci85_v05
VendorProductVersionCPE
siemenscp-8031-cpe:2.3:h:siemens:cp-8031:-:*:*:*:*:*:*:*
siemenscp-8031_firmware*cpe:2.3:o:siemens:cp-8031_firmware:*:*:*:*:*:*:*:*
siemenscp-8050-cpe:2.3:h:siemens:cp-8050:-:*:*:*:*:*:*:*
siemenscp-8050_firmware*cpe:2.3:o:siemens:cp-8050_firmware:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "Siemens",
    "product": "CP-8031 MASTER MODULE",
    "versions": [
      {
        "version": "All versions < CPCI85 V05",
        "status": "affected"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "vendor": "Siemens",
    "product": "CP-8050 MASTER MODULE",
    "versions": [
      {
        "version": "All versions < CPCI85 V05",
        "status": "affected"
      }
    ],
    "defaultStatus": "unknown"
  }
]

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.8

Confidence

High

EPSS

0.014

Percentile

86.7%