← Vulnerability feed

Vulnerability record · CVE-2023-33919 · published 13 June 2023

CVE-2023-33919: Siemens CP-8031/CP-8050 master module web interface command injection

Siemens · Cpci85 Firmware

The web interface of Siemens CP-8031 and CP-8050 master modules running CPCI85 firmware before V05 fails to sanitize server-side input, allowing command injection. An authenticated privileged remote attacker can execute arbitrary code with root privileges on the device.

7.2 CVSS 3.1 High EPSS 48% · top 1.2% CWE-77 · Command injection
7.2CVSS 3.1 base score
48%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
9References
17 Jun 2026Last modified by NVD

Description

A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). The web interface of affected devices is vulnerable to command injection due to missing server side input sanitation. This could allow an authenticated privileged remote attacker to execute arbitrary code with root privileges.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityRoot-level remote code execution on industrial control hardware with a high EPSS score and public exploit details, though it requires privileged authentication.

What it is

The web interface of Siemens CP-8031 and CP-8050 master modules running CPCI85 firmware before V05 fails to sanitize server-side input, allowing command injection. An authenticated privileged remote attacker can execute arbitrary code with root privileges on the device.

Impact

An attacker with privileged web access gains root-level code execution on the master module, enabling full control of the device and potential lateral movement into the protected control network.

Attack surface

Reachable over the network through the device web interface (AV:N, AC:L, PR:H, UI:N). Exploitation requires authenticated privileged access; no user interaction is needed.

Exploitation

Not listed in CISA KEV, but EPSS is high at 0.477 (98.8th percentile) and public exploit write-ups exist on Packet Storm and Full Disclosure. No ransomware usage is documented.

What to do

  • Upgrade CPCI85 firmware to V05 or later per Siemens advisory SSA-731916.
  • Restrict network access to the device web interface to trusted management hosts only.
  • Enforce least privilege and strong authentication for web interface accounts; audit privileged users.
  • Monitor Siemens advisories and apply follow-up patches as released.

Detection

  • Alert on unexpected child processes or shell invocations spawned by the device web server.
  • Monitor web interface requests for command metacharacters and anomalous parameters.
  • Review authentication logs for privileged web logins from unusual source addresses.
  • Baseline normal device behavior and flag outbound connections from the master module.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-33919 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

6.8CVE-2023-33920Siemens cpci85 firmware hard-coded credentials vulnerabilityA vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). The affe…EPSS 0.36%6.8CVE-2023-33921Siemens cpci85 firmware vulnerabilityA vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). The affe…EPSS 0.39%9.8CVE-2026-8037Progress LoadMaster API OS Command Injection RCEProgress LoadMaster (and related ADC products) contain an OS command injection flaw in multiple API command endpoints where unsanitized input is pass…KEVEPSS 77%analysed8.7CVE-2026-42271LiteLLM MCP test endpoints allow authenticated OS command injectionLiteLLM versions 1.74.2 through before 1.83.7 expose two MCP preview endpoints (POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list) th…KEVEPSS 13%analysed7.2CVE-2025-29635D-Link DIR-823X command injection in set_prohibiting handlerD-Link DIR-823X firmware (240126 and 240802) contains a command injection flaw in the /goform/set_prohibiting POST handler. An attacker who already h…KEVEPSS 88%analysed8.1CVE-2026-22719VMware Aria Operations command injection during support-assisted migrationVMware Aria Operations contains a command injection flaw (CWE-77) that an unauthenticated attacker can use to run arbitrary commands, potentially ach…KEVEPSS 18%analysed8.7CVE-2025-4008Meteobridge web interface command injection without authenticationThe Meteobridge web interface, built from CGI shell scripts and C, exposes an endpoint vulnerable to command injection. Because the endpoint also lac…KEVEPSS 94%analysed6.1CVE-2025-59689Libraesva ESG command injection via compressed email attachmentLibraesva Email Security Gateway versions 4.5 through 5.5.x before 5.5.7 are vulnerable to command injection triggered by a compressed email attachme…KEVEPSS 1.9%analysed

Source: NIST National Vulnerability Database (record CVE-2023-33919), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.