« Volver al listado

CVE-2021-45033

Estado: ModificadaAlta (8.8)—

A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions < V16.20), CP-8000 MASTER MODULE WITH I/O -40/+70°C (All versions < V16.20), CP-8021 MASTER MODULE (All versions < V16.20), CP-8022 MASTER MODULE WITH GPRS (All versions < V16.20). An undocumented debug port uses hard-coded default credentials. If this port is enabled by a privileged user, an attacker aware of the credentials could access an administrative debug shell on the affected device.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-45033",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 8.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:S/C:C/I:C/A:C",
          "authentication": "SINGLE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "productcert@siemens.com",
      "affectedData": [
        {
          "vendor": "Siemens",
          "product": "CP-8000 MASTER MODULE WITH I/O -25/+70°C",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V16.20"
            }
          ]
        },
        {
          "vendor": "Siemens",
          "product": "CP-8000 MASTER MODULE WITH I/O -40/+70°C",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V16.20"
            }
          ]
        },
        {
          "vendor": "Siemens",
          "product": "CP-8021 MASTER MODULE",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V16.20"
            }
          ]
        },
        {
          "vendor": "Siemens",
          "product": "CP-8022 MASTER MODULE WITH GPRS",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V16.20"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-01-11T12:15:10.093",
  "references": [
    {
      "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-324998.pdf",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "productcert@siemens.com"
    },
    {
      "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-324998.pdf",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "productcert@siemens.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-798"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-798"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions < V16.20), CP-8000 MASTER MODULE WITH I/O -40/+70°C (All versions < V16.20), CP-8021 MASTER MODULE (All versions < V16.20), CP-8022 MASTER MODULE WITH GPRS (All versions < V16.20). An undocumented debug port uses hard-coded default credentials. If this port is enabled by a privileged user, an attacker aware of the credentials could access an administrative debug shell on the affected device."
    },
    {
      "lang": "es",
      "value": "Se ha identificado una vulnerabilidad en el MÓDULO MASTER CP-8000 CON E/S -25/+70°C (Todas las versiones anteriores a V16.20), MÓDULO MASTER CP-8000 CON E/S -40/+70°C (Todas las versiones anteriores a V16.20), MÓDULO MASTER CP-8021 (Todas las versiones anteriores a V16.20), MÓDULO MASTER CP-8022 CON GPRS (Todas las versiones anteriores a V16.20). Un puerto de depuración no documentado usa credenciales por defecto embebidas. Si este puerto es habilitado por un usuario con privilegios, un atacante que conozca las credenciales podría acceder a un shell de depuración administrativo en el dispositivo afectado"
    }
  ],
  "lastModified": "2026-06-17T04:13:04.320",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:siemens:cp-8000_master_module_with_i\\/o_-25\\/\\+70_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6C5EE859-1395-4644-A272-3CA2823E2D26",
              "versionEndExcluding": "16.20"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:siemens:cp-8000_master_module_with_i\\/o_-25\\/\\+70:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "9836DAE0-946B-4B65-98DF-2B82F7F3AF94"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:siemens:cp-8000_master_module_with_i\\/o_-40\\/\\+70_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9A9D8EE5-3D2C-420C-9969-0910C6FB8342",
              "versionEndExcluding": "16.20"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:siemens:cp-8000_master_module_with_i\\/o_-40\\/\\+70:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "4A6D94AE-9F7E-46F0-92F6-C651E0EE580B"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:siemens:cp-8021_master_module_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8B97277D-0D30-4914-BA1E-1E5B07153A52",
              "versionEndExcluding": "16.20"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:siemens:cp-8021_master_module:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "F8820652-44D8-43EF-8865-BE8E7967829E"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:siemens:cp-8022_master_module_with_gprs_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FEA73D9E-CFAD-4DAF-9E34-51DBD2AF6FD6",
              "versionEndExcluding": "16.20"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:siemens:cp-8022_master_module_with_gprs:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "D6815071-0D49-4288-8128-B9A980ECB64C"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "productcert@siemens.com"
}