VDB

CVE-2021-45033

CVE-2021-45033 PUBLISHED CVSS 8.800000190734863 HIGH

A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions < V16.20), CP-8000 MASTER MODULE WITH I/O -40/+70°C (All versions < V16.20), CP-8021 MASTER MODULE (All versions < V16.20), CP-8022 MASTER MODULE WITH GPRS (All versions < V16.20). An undocumented debug port uses hard-coded default credentials. If this port is enabled by a privileged user, an attacker aware of the credentials could access an administrative debug shell on the affected device.

EPSS 0.28% · 51.9th percentile

Risk Scores

CVSS v3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.28%
51.9th percentile

Affected Products

VendorProductVersions
SiemensCP-8021 MASTER MODULEAll versions < V16.20
siemenscp-8021_master_module_firmware0
siemenscp-8000_master_module_with_i\/o_-40\/\+70_firmware0
SiemensCP-8022 MASTER MODULE WITH GPRSAll versions < V16.20
siemenscp-8000_master_module_with_i\/o_-25\/\+70_firmware0
siemenscp-8022_master_module_with_gprs_firmware0
SiemensCP-8000 MASTER MODULE WITH I/O -40/+70°CAll versions < V16.20
SiemensCP-8000 MASTER MODULE WITH I/O -25/+70°CAll versions < V16.20

Timeline

  • Jan 11, 2022 CVE Published
  • Jan 12, 2022 EPSS Score
  • Mar 6, 2022 EPSS Score
  • Apr 29, 2022 EPSS Score
  • Jun 21, 2022 EPSS Score
  • Aug 14, 2022 EPSS Score
  • Oct 7, 2022 EPSS Score
  • Nov 29, 2022 EPSS Score
  • Jan 21, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Mar 15, 2023 EPSS Score
  • May 8, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›