A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). Affected devices are vulnerable to command injection via the web server port 443/tcp, if the parameter “Remote Operation” is enabled. The parameter is disabled by default.
The vulnerability could allow an unauthenticated remote attacker to perform arbitrary code execution on the device.
References
Configurations
History
21 Nov 2024, 07:55
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.com/files/173370/Siemens-A8000-CP-8050-CP-8031-Code-Execution-Command-Injection.html - | |
References | () http://seclists.org/fulldisclosure/2023/Jul/14 - | |
References | () https://cert-portal.siemens.com/productcert/pdf/ssa-472454.pdf - Vendor Advisory |
11 Jul 2023, 18:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
07 Jul 2023, 20:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
Information
Published : 2023-04-11 10:15
Updated : 2024-11-21 07:55
NVD link : CVE-2023-28489
Mitre link : CVE-2023-28489
CVE.ORG link : CVE-2023-28489
JSON object : View
Products Affected
siemens
- cp-8031
- cp-8050
- cp-8050_firmware
- cp-8031_firmware
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')