← All CVEs

CVE-2023-33919

high · 7.2

A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). The web interface of affected devices is vulnerable to command injection due to missing server side input sanitation. This could allow an authenticated privileged remote attacker to execute arbitrary code with root privileges.

7.2
CVSS
47.7%
EPSS (exploit prob.)
99th
EPSS percentile
2023-06-13
Published

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-77

Affected products

VendorProductAffected versions
siemenscpci85_firmware< v05
siemenscp-8031_master_moduleall versions
siemenscpci85_firmware< v05
siemenscp-8050_master_moduleall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2023-33919