CVE-2023-33919

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Jun 13, 2023
Updated: Jul 4, 2024
CWE ID 77

Summary

CVE-2023-33919 is a newly identified vulnerability affecting the CP-8031 MASTER MODULE and CP-8050 MASTER MODULE, with all versions below CPCI85 V05. The issue lies in the lack of server-side input sanitation in the web interface of these devices. This vulnerability allows authenticated, privileged remote attackers to inject malicious commands, potentially leading to the execution of arbitrary code with root privileges. This poses a significant risk for unauthorized system manipulation and potential data breaches.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share