Lucene search

K
nvd[email protected]NVD:CVE-2023-33920
HistoryJun 13, 2023 - 9:15 a.m.

CVE-2023-33920

2023-06-1309:15:18
CWE-798
web.nvd.nist.gov
1
vulnerability
cp-8031
cp-8050
master module
hard-coded
root password
hash
uart console
login
direct physical access
exploit

CVSS3

6.8

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

6.6

Confidence

High

EPSS

0.001

Percentile

18.6%

A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). The affected devices contain the hash of the root password in a hard-coded form, which could be exploited for UART console login to the device. An attacker with direct physical access could exploit this vulnerability.

Affected configurations

Nvd
Node
siemenscpci85_firmwareRange<v05
AND
siemenscp-8050_master_moduleMatch-
Node
siemenscpci85_firmwareRange<v05
AND
siemenscp-8031_master_moduleMatch-
VendorProductVersionCPE
siemenscpci85_firmware*cpe:2.3:o:siemens:cpci85_firmware:*:*:*:*:*:*:*:*
siemenscp-8050_master_module-cpe:2.3:h:siemens:cp-8050_master_module:-:*:*:*:*:*:*:*
siemenscp-8031_master_module-cpe:2.3:h:siemens:cp-8031_master_module:-:*:*:*:*:*:*:*

CVSS3

6.8

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

6.6

Confidence

High

EPSS

0.001

Percentile

18.6%

Related for NVD:CVE-2023-33920