CVE-2023-36380

A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05.11 (only with activated debug support)), CP-8050 MASTER MODULE (All versions < CPCI85 V05.11 (only with activated debug support)). The affected devices contain a hard-coded ID in the SSH `authorized_keys` configuration file. An attacker with knowledge of the corresponding private key could login to the device via SSH. Only devices with activated debug support are affected.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:siemens:cp-8050_firmware:*:*:*:*:cpci85:*:*:*
cpe:2.3:h:siemens:cp-8050:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:siemens:cp-8031_firmware:*:*:*:*:cpci85:*:*:*
cpe:2.3:h:siemens:cp-8031:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-10-10 11:15

Updated : 2023-10-17 14:23


NVD link : CVE-2023-36380

Mitre link : CVE-2023-36380

CVE.ORG link : CVE-2023-36380


JSON object : View

Products Affected

siemens

  • cp-8050_firmware
  • cp-8031
  • cp-8050
  • cp-8031_firmware
CWE
CWE-798

Use of Hard-coded Credentials