PT-2023-5961 · Unknown · Cp-8031 Master Module+1

Published

2023-10-10

·

Updated

2023-10-17

·

CVE-2023-36380

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions CP-8031 MASTER MODULE versions prior to CPCI85 V05.11 CP-8050 MASTER MODULE versions prior to CPCI85 V05.11
Description A vulnerability has been identified in the CP-8031 and CP-8050 MASTER MODULES, where the affected devices contain a hard-coded ID in the SSH authorized keys configuration file. This could allow an attacker with knowledge of the corresponding private key to login to the device via SSH. Only devices with activated debug support are affected.
Recommendations For CP-8031 MASTER MODULE versions prior to CPCI85 V05.11, consider disabling the SSH access or restricting the use of the authorized keys file until a patch is available. For CP-8050 MASTER MODULE versions prior to CPCI85 V05.11, consider disabling the SSH access or restricting the use of the authorized keys file until a patch is available. As a temporary workaround, consider deactivating the debug support to minimize the risk of exploitation.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-06661
CVE-2023-36380

Affected Products

Cp-8031 Master Module
Cp-8050 Master Module