Vulnerability Description
A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). The affected devices contain the hash of the root password in a hard-coded form, which could be exploited for UART console login to the device. An attacker with direct physical access could exploit this vulnerability.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Siemens | Cpci85 Firmware | < v05 |
| Siemens | Cp-8050 Master Module | - |
| Siemens | Cp-8031 Master Module | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/173370/Siemens-A8000-CP-8050-CP-8031-Code-E
- http://seclists.org/fulldisclosure/2023/Jul/14
- https://cert-portal.siemens.com/productcert/pdf/ssa-731916.pdfPatchVendor Advisory
- http://packetstormsecurity.com/files/173370/Siemens-A8000-CP-8050-CP-8031-Code-E
- http://seclists.org/fulldisclosure/2023/Jul/14
- https://cert-portal.siemens.com/productcert/pdf/ssa-731916.pdfPatchVendor Advisory
FAQ
What is CVE-2023-33920?
CVE-2023-33920 is a vulnerability with a CVSS score of 6.8 (MEDIUM). A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). The affected devices contain the hash of the root password ...
How severe is CVE-2023-33920?
CVE-2023-33920 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-33920?
Check the references section above for vendor advisories and patch information. Affected products include: Siemens Cpci85 Firmware, Siemens Cp-8050 Master Module, Siemens Cp-8031 Master Module.