A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). Affected devices are vulnerable to command injection via the web server port 443/tcp, if the parameter “Remote Operation” is enabled. The parameter is disabled by default.
The vulnerability could allow an unauthenticated remote attacker to perform arbitrary code execution on the device.
References
Configurations
History
No history.
Information
Published : 2023-04-11 10:15
Updated : 2023-07-11 18:15
NVD link : CVE-2023-28489
Mitre link : CVE-2023-28489
CVE.ORG link : CVE-2023-28489
JSON object : View
Products Affected
siemens
- cp-8050_firmware
- cp-8050
- cp-8031_firmware
- cp-8031
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')