CVE-2021-46304
Severity CVSS v4.0:
Pending analysis
Type:
CWE-284
Improper Access Control
Publication date:
10/08/2022
Last modified:
20/10/2025
Description
A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions), CP-8000 MASTER MODULE WITH I/O -40/+70°C (All versions), CP-8021 MASTER MODULE (All versions), CP-8022 MASTER MODULE WITH GPRS (All versions). The component allows to activate a web server module which provides unauthenticated access to its web pages. This could allow an attacker to retrieve debug-level information from the component such as internal network topology or connected systems.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:siemens:cp-8021_master_module_firmware:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:siemens:cp-8021_master_module:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:siemens:cp-8000_master_module_with_i\/o_-25\/\+70_firmware:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:siemens:cp-8000_master_module_with_i\/o_-25\/\+70:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:siemens:cp-8000_master_module_with_i\/o_-40\/\+70_firmware:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:siemens:cp-8000_master_module_with_i\/o_-40\/\+70:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:siemens:cp-8022_master_module_with_gprs_firmware:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:siemens:cp-8022_master_module_with_gprs:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



