A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). Affected devices are vulnerable to command injection via the web server port 443/tcp, if the parameter “Remote Operation” is enabled. The parameter is disabled by default. The vulnerability could allow an unauthenticated remote attacker to perform arbitrary code execution on the device.
2023-04-11T10:15:18.280
2024-11-21T07:55:12.923
Modified
CVSSv3.1: 9.8 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | siemens | cp-8031_firmware | < cpci85_v05 | Yes |
Hardware | siemens | cp-8031 | - | No |
Operating System | siemens | cp-8050_firmware | < cpci85_v05 | Yes |
Hardware | siemens | cp-8050 | - | No |