Lucene search

K
nvd[email protected]NVD:CVE-2023-28489
HistoryApr 11, 2023 - 10:15 a.m.

CVE-2023-28489

2023-04-1110:15:18
CWE-77
web.nvd.nist.gov
3
cp-8031
cp-8050
command injection
web server
remote operation
arbitrary code execution
vulnerability

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.9

Confidence

High

EPSS

0.014

Percentile

86.7%

A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). Affected devices are vulnerable to command injection via the web server port 443/tcp, if the parameter β€œRemote Operation” is enabled. The parameter is disabled by default.
The vulnerability could allow an unauthenticated remote attacker to perform arbitrary code execution on the device.

Affected configurations

Nvd
Node
siemenscp-8031Match-
AND
siemenscp-8031_firmwareRange<cpci85_v05
Node
siemenscp-8050Match-
AND
siemenscp-8050_firmwareRange<cpci85_v05
VendorProductVersionCPE
siemenscp-8031-cpe:2.3:h:siemens:cp-8031:-:*:*:*:*:*:*:*
siemenscp-8031_firmware*cpe:2.3:o:siemens:cp-8031_firmware:*:*:*:*:*:*:*:*
siemenscp-8050-cpe:2.3:h:siemens:cp-8050:-:*:*:*:*:*:*:*
siemenscp-8050_firmware*cpe:2.3:o:siemens:cp-8050_firmware:*:*:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.9

Confidence

High

EPSS

0.014

Percentile

86.7%