A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions < V16.20), CP-8000 MASTER MODULE WITH I/O -40/+70°C (All versions < V16.20), CP-8021 MASTER MODULE (All versions < V16.20), CP-8022 MASTER MODULE WITH GPRS (All versions < V16.20). The web server of the affected system allows access to logfiles and diagnostic data generated by a privileged user. An unauthenticated attacker could access the files by knowing the corresponding download links.
[
{
"product": "CP-8000 MASTER MODULE WITH I/O -25/+70°C",
"vendor": "Siemens",
"versions": [
{
"status": "affected",
"version": "All versions < V16.20"
}
]
},
{
"product": "CP-8000 MASTER MODULE WITH I/O -40/+70°C",
"vendor": "Siemens",
"versions": [
{
"status": "affected",
"version": "All versions < V16.20"
}
]
},
{
"product": "CP-8021 MASTER MODULE",
"vendor": "Siemens",
"versions": [
{
"status": "affected",
"version": "All versions < V16.20"
}
]
},
{
"product": "CP-8022 MASTER MODULE WITH GPRS",
"vendor": "Siemens",
"versions": [
{
"status": "affected",
"version": "All versions < V16.20"
}
]
}
]