PT-2022-12295 · Unknown · Cp-8000 Master Module With I/O -25/+70°C+3

Published

2022-01-11

·

Updated

2022-01-19

·

CVE-2021-45033

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CP-8000 MASTER MODULE WITH I/O -25/+70°C versions prior to V16.20 CP-8000 MASTER MODULE WITH I/O -40/+70°C versions prior to V16.20 CP-8021 MASTER MODULE versions prior to V16.20 CP-8022 MASTER MODULE WITH GPRS versions prior to V16.20
Description A vulnerability has been identified in the affected devices, where an undocumented debug port uses hard-coded default credentials. If this port is enabled by a privileged user, an attacker aware of the credentials could access an administrative debug shell on the affected device.
Recommendations For CP-8000 MASTER MODULE WITH I/O -25/+70°C versions prior to V16.20, update to version V16.20 or later. For CP-8000 MASTER MODULE WITH I/O -40/+70°C versions prior to V16.20, update to version V16.20 or later. For CP-8021 MASTER MODULE versions prior to V16.20, update to version V16.20 or later. For CP-8022 MASTER MODULE WITH GPRS versions prior to V16.20, update to version V16.20 or later. As a temporary workaround, consider disabling the undocumented debug port until a patch is available.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-45033

Affected Products

Cp-8000 Master Module With I/O -25/+70°C
Cp-8000 Master Module With I/O -40/+70°C
Cp-8021 Master Module
Cp-8022 Master Module With Gprs