PT-2022-4104 · Unknown · Cp-8000 Master Module With I/O -25/+70°C+3
Published
2022-08-09
·
Updated
2025-10-20
·
CVE-2021-46304
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions)
CP-8000 MASTER MODULE WITH I/O -40/+70°C (All versions)
CP-8021 MASTER MODULE (All versions)
CP-8022 MASTER MODULE WITH GPRS (All versions)
Description
A vulnerability has been identified in the web server module of the affected components, which allows unauthenticated access to its web pages. This could allow an attacker to retrieve debug-level information from the component, such as internal network topology or connected systems. The issue is related to inadequate access control, which could enable a remote attacker to determine the devices used in the network.
Recommendations
For CP-8000 MASTER MODULE WITH I/O -25/+70°C, consider disabling the web server module until a patch is available.
For CP-8000 MASTER MODULE WITH I/O -40/+70°C, consider disabling the web server module until a patch is available.
For CP-8021 MASTER MODULE, consider disabling the web server module until a patch is available.
For CP-8022 MASTER MODULE WITH GPRS, consider disabling the web server module until a patch is available.
As a temporary workaround, restrict access to the web server module to minimize the risk of exploitation.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cp-8000 Master Module With I/O -25/+70°C
Cp-8000 Master Module With I/O -40/+70°C
Cp-8021 Master Module
Cp-8022 Master Module With Gprs