First published: Tue Jun 13 2023(Updated: )
A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). The affected devices contain an exposed UART console login interface. An attacker with direct physical access could try to bruteforce or crack the root password to login to the device.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Cpci85 Firmware | <v05 | |
Siemens Cp-8050 Master Module | ||
Siemens Cp-8031 Master Module |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-33921 is considered high severity due to the potential for unauthorized access via an exposed UART console.
To mitigate CVE-2023-33921, update the affected devices to the CPCI85 V05 firmware or later.
CVE-2023-33921 affects all versions of the CP-8031 MASTER MODULE and CP-8050 MASTER MODULE prior to CPCI85 V05.
An attacker with physical access can exploit CVE-2023-33921 to brute force or crack the root password using the exposed UART console.
If immediate patching is not feasible for CVE-2023-33921, restrict physical access to the affected devices to prevent exploitation.