Description
A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions < V16.20), CP-8000 MASTER MODULE WITH I/O -40/+70°C (All versions < V16.20), CP-8021 MASTER MODULE (All versions < V16.20), CP-8022 MASTER MODULE WITH GPRS (All versions < V16.20). The web server of the affected system allows access to logfiles and diagnostic data generated by a privileged user. An unauthenticated attacker could access the files by knowing the corresponding download links.
Published: 2022-01-11
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-31831 A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions < V16.20), CP-8000 MASTER MODULE WITH I/O -40/+70°C (All versions < V16.20), CP-8021 MASTER MODULE (All versions < V16.20), CP-8022 MASTER MODULE WITH GPRS (All versions < V16.20). The web server of the affected system allows access to logfiles and diagnostic data generated by a privileged user. An unauthenticated attacker could access the files by knowing the corresponding download links.
History

No history.

Subscriptions

Siemens Cp-8000 Master Module With I\/o -25\/\+70 Cp-8000 Master Module With I\/o -25\/\+70 Firmware Cp-8000 Master Module With I\/o -40\/\+70 Cp-8000 Master Module With I\/o -40\/\+70 Firmware Cp-8021 Master Module Cp-8021 Master Module Firmware Cp-8022 Master Module With Gprs Cp-8022 Master Module With Gprs Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published:

Updated: 2024-08-04T04:32:13.633Z

Reserved: 2021-12-13T00:00:00.000Z

Link: CVE-2021-45034

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-01-11T12:15:10.143

Modified: 2024-11-21T06:31:50.140

Link: CVE-2021-45034

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses