CVE-2023-33921

A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). The affected devices contain an exposed UART console login interface. An attacker with direct physical access could try to bruteforce or crack the root password to login to the device.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:siemens:cpci85_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:cp-8050_master_module:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:siemens:cpci85_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:cp-8031_master_module:-:*:*:*:*:*:*:*

History

21 Nov 2024, 08:06

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/173370/Siemens-A8000-CP-8050-CP-8031-Code-Execution-Command-Injection.html - () http://packetstormsecurity.com/files/173370/Siemens-A8000-CP-8050-CP-8031-Code-Execution-Command-Injection.html -
References () http://seclists.org/fulldisclosure/2023/Jul/14 - () http://seclists.org/fulldisclosure/2023/Jul/14 -
References () https://cert-portal.siemens.com/productcert/pdf/ssa-731916.pdf - Patch, Vendor Advisory () https://cert-portal.siemens.com/productcert/pdf/ssa-731916.pdf - Patch, Vendor Advisory

11 Jul 2023, 18:15

Type Values Removed Values Added
References
  • (MISC) http://packetstormsecurity.com/files/173370/Siemens-A8000-CP-8050-CP-8031-Code-Execution-Command-Injection.html -

07 Jul 2023, 20:15

Type Values Removed Values Added
References
  • (MISC) http://seclists.org/fulldisclosure/2023/Jul/14 -

29 Jun 2023, 20:12

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.8
References (MISC) https://cert-portal.siemens.com/productcert/pdf/ssa-731916.pdf - (MISC) https://cert-portal.siemens.com/productcert/pdf/ssa-731916.pdf - Patch, Vendor Advisory
First Time Siemens cp-8031 Master Module
Siemens cp-8050 Master Module
Siemens cpci85 Firmware
Siemens
CPE cpe:2.3:o:siemens:cpci85_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:cp-8050_master_module:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:cp-8031_master_module:-:*:*:*:*:*:*:*
CWE NVD-CWE-Other

13 Jun 2023, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-06-13 09:15

Updated : 2024-11-21 08:06


NVD link : CVE-2023-33921

Mitre link : CVE-2023-33921

CVE.ORG link : CVE-2023-33921


JSON object : View

Products Affected

siemens

  • cpci85_firmware
  • cp-8031_master_module
  • cp-8050_master_module
CWE
CWE-749

Exposed Dangerous Method or Function

NVD-CWE-Other