PT-2023-2290 · Siemens · Cp-8050+1
Christian Hager
+5
·
Published
2023-04-11
·
Updated
2023-07-11
·
CVE-2023-28489
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
CP-8031 MASTER MODULE versions prior to CPCI85 V05
CP-8050 MASTER MODULE versions prior to CPCI85 V05
Description
The issue is related to insufficient argument checking in the web server of the Siemens SICAM CP-8031 and CP-8050 processor control modules. This can be exploited by a remote attacker to execute arbitrary commands via the web server port 443/tcp if the
Remote Operation parameter is enabled. By default, the Remote Operation parameter is disabled. The vulnerability could allow an unauthenticated remote attacker to perform arbitrary code execution on the device.Recommendations
For CP-8031 MASTER MODULE versions prior to CPCI85 V05, update to version CPCI85 V05 or later to resolve the issue.
For CP-8050 MASTER MODULE versions prior to CPCI85 V05, update to version CPCI85 V05 or later to resolve the issue.
As a temporary workaround, consider disabling the
Remote Operation parameter to minimize the risk of exploitation.Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cp-8031
Cp-8050