PT-2022-12295 · Unknown · Cp-8000 Master Module With I/O -25/+70°C+3
Published
2022-01-11
·
Updated
2022-01-19
·
CVE-2021-45033
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CP-8000 MASTER MODULE WITH I/O -25/+70°C versions prior to V16.20
CP-8000 MASTER MODULE WITH I/O -40/+70°C versions prior to V16.20
CP-8021 MASTER MODULE versions prior to V16.20
CP-8022 MASTER MODULE WITH GPRS versions prior to V16.20
Description
A vulnerability has been identified in the affected devices, where an undocumented debug port uses hard-coded default credentials. If this port is enabled by a privileged user, an attacker aware of the credentials could access an administrative debug shell on the affected device.
Recommendations
For CP-8000 MASTER MODULE WITH I/O -25/+70°C versions prior to V16.20, update to version V16.20 or later.
For CP-8000 MASTER MODULE WITH I/O -40/+70°C versions prior to V16.20, update to version V16.20 or later.
For CP-8021 MASTER MODULE versions prior to V16.20, update to version V16.20 or later.
For CP-8022 MASTER MODULE WITH GPRS versions prior to V16.20, update to version V16.20 or later.
As a temporary workaround, consider disabling the undocumented debug port until a patch is available.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cp-8000 Master Module With I/O -25/+70°C
Cp-8000 Master Module With I/O -40/+70°C
Cp-8021 Master Module
Cp-8022 Master Module With Gprs