← Back to browse · API

CVE-2023-28489

Severity
CRITICAL
CVSS
9.8
EPSS
0.02836
Risk score
40.19
CISA KEV
No
PoC
No
Published
2023-04-11
Modified
2025-02-13
First seen
2026-08-07
Aliases
EUVD-2023-32159, GHSA-X9QV-5M74-X74P
Products
Siemens:CP-8031 MASTER MODULE All versions < CPCI85 V05, Siemens:CP-8050 MASTER MODULE All versions < CPCI85 V05
Sources
euvd EUVD-2023-32159

Description

A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). Affected devices are vulnerable to command injection via the web server port 443/tcp, if the parameter “Remote Operation” is enabled. The parameter is disabled by default. The vulnerability could allow an unauthenticated remote attacker to perform arbitrary code execution on the device.

References