CVE-2023-33920

MEDIUM

CP-8031/8050 MASTER MODULE <CPCI85 V05 - Info Disclosure

Title source: llm
STIX 2.1

Description

A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). The affected devices contain the hash of the root password in a hard-coded form, which could be exploited for UART console login to the device. An attacker with direct physical access could exploit this vulnerability.

Scores

CVSS v3 6.8
EPSS 0.0013
EPSS Percentile 31.9%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-798
Status published
Products (1)
siemens/cpci85_firmware < v05
Published Jun 13, 2023
Tracked Since Feb 18, 2026