PT-2024-1085 · Unknown · Cp-8050 Master Module+1
Published
2024-01-09
·
Updated
2024-01-16
·
CVE-2023-42797
CVSS v2.0
8.3
High
| Vector | AV:N/AC:L/Au:M/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
CP-8031 MASTER MODULE versions prior to CPCI85 V05.20
CP-8050 MASTER MODULE versions prior to CPCI85 V05.20
Description
A flaw has been identified in the network configuration service of affected devices, related to the conversion of ipv4 addresses, which could lead to an uninitialized variable being used in succeeding validation steps. This issue allows an authenticated remote attacker to inject commands that are executed on the device with root privileges during device startup by uploading specially crafted network configuration.
Recommendations
For CP-8031 MASTER MODULE versions prior to CPCI85 V05.20, update to version CPCI85 V05.20 or later to resolve the issue.
For CP-8050 MASTER MODULE versions prior to CPCI85 V05.20, update to version CPCI85 V05.20 or later to resolve the issue.
As a temporary workaround, consider restricting access to the network configuration service to minimize the risk of exploitation.
Fix
Use of Uninitialized Resource
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cp-8031 Master Module
Cp-8050 Master Module