CVE-2023-42797

A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05.20), CP-8050 MASTER MODULE (All versions < CPCI85 V05.20). The network configuration service of affected devices contains a flaw in the conversion of ipv4 addresses that could lead to an uninitialized variable being used in succeeding validation steps. By uploading specially crafted network configuration, an authenticated remote attacker could be able to inject commands that are executed on the device with root privileges during device startup.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:siemens:sicam_a8000_cp-8050_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:sicam_a8000_cp-8050:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:siemens:sicam_a8000_cp-8031_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:sicam_a8000_cp-8031:-:*:*:*:*:*:*:*

History

16 Jan 2024, 15:29

Type Values Removed Values Added
References () https://cert-portal.siemens.com/productcert/pdf/ssa-583634.pdf - () https://cert-portal.siemens.com/productcert/pdf/ssa-583634.pdf - Patch, Vendor Advisory
First Time Siemens sicam A8000 Cp-8031 Firmware
Siemens sicam A8000 Cp-8031
Siemens sicam A8000 Cp-8050
Siemens sicam A8000 Cp-8050 Firmware
Siemens
CPE cpe:2.3:h:siemens:sicam_a8000_cp-8031:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:sicam_a8000_cp-8050_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:sicam_a8000_cp-8050:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:sicam_a8000_cp-8031_firmware:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : 6.6
v2 : unknown
v3 : 7.2

09 Jan 2024, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-09 10:15

Updated : 2024-02-28 20:54


NVD link : CVE-2023-42797

Mitre link : CVE-2023-42797

CVE.ORG link : CVE-2023-42797


JSON object : View

Products Affected

siemens

  • sicam_a8000_cp-8031_firmware
  • sicam_a8000_cp-8050_firmware
  • sicam_a8000_cp-8031
  • sicam_a8000_cp-8050
CWE
CWE-908

Use of Uninitialized Resource