PT-2024-1085 · Unknown · Cp-8050 Master Module+1

Published

2024-01-09

·

Updated

2024-01-16

·

CVE-2023-42797

CVSS v2.0

8.3

High

VectorAV:N/AC:L/Au:M/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions CP-8031 MASTER MODULE versions prior to CPCI85 V05.20 CP-8050 MASTER MODULE versions prior to CPCI85 V05.20
Description A flaw has been identified in the network configuration service of affected devices, related to the conversion of ipv4 addresses, which could lead to an uninitialized variable being used in succeeding validation steps. This issue allows an authenticated remote attacker to inject commands that are executed on the device with root privileges during device startup by uploading specially crafted network configuration.
Recommendations For CP-8031 MASTER MODULE versions prior to CPCI85 V05.20, update to version CPCI85 V05.20 or later to resolve the issue. For CP-8050 MASTER MODULE versions prior to CPCI85 V05.20, update to version CPCI85 V05.20 or later to resolve the issue. As a temporary workaround, consider restricting access to the network configuration service to minimize the risk of exploitation.

Fix

Use of Uninitialized Resource

Weakness Enumeration

Related Identifiers

BDU:2024-00346
CVE-2023-42797

Affected Products

Cp-8031 Master Module
Cp-8050 Master Module