Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-46304


A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions), CP-8000 MASTER MODULE WITH I/O -40/+70°C (All versions), CP-8021 MASTER MODULE (All versions), CP-8022 MASTER MODULE WITH GPRS (All versions). The component allows to activate a web server module which provides unauthenticated access to its web pages. This could allow an attacker to retrieve debug-level information from the component such as internal network topology or connected systems.


Published

2022-08-10T12:15:11.567

Last Modified

2024-11-21T06:33:50.907

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-284
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System siemens cp-8021_master_module_firmware * Yes
Hardware siemens cp-8021_master_module - No
Operating System siemens cp-8000_master_module_with_i\/o_-25\/\+70_firmware * Yes
Hardware siemens cp-8000_master_module_with_i\/o_-25\/\+70 - No
Operating System siemens cp-8000_master_module_with_i\/o_-40\/\+70_firmware * Yes
Hardware siemens cp-8000_master_module_with_i\/o_-40\/\+70 - No
Operating System siemens cp-8022_master_module_with_gprs_firmware * Yes
Hardware siemens cp-8022_master_module_with_gprs - No

References