Vulnerability record · CVE-2023-33919 · published 13 June 2023
CVE-2023-33919: Siemens CP-8031/CP-8050 master module web interface command injection
Siemens · Cpci85 Firmware
The web interface of Siemens CP-8031 and CP-8050 master modules running CPCI85 firmware before V05 fails to sanitize server-side input, allowing command injection. An authenticated privileged remote attacker can execute arbitrary code with root privileges on the device.
Description
A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). The web interface of affected devices is vulnerable to command injection due to missing server side input sanitation. This could allow an authenticated privileged remote attacker to execute arbitrary code with root privileges.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityRoot-level remote code execution on industrial control hardware with a high EPSS score and public exploit details, though it requires privileged authentication.
What it is
The web interface of Siemens CP-8031 and CP-8050 master modules running CPCI85 firmware before V05 fails to sanitize server-side input, allowing command injection. An authenticated privileged remote attacker can execute arbitrary code with root privileges on the device.
Impact
An attacker with privileged web access gains root-level code execution on the master module, enabling full control of the device and potential lateral movement into the protected control network.
Attack surface
Reachable over the network through the device web interface (AV:N, AC:L, PR:H, UI:N). Exploitation requires authenticated privileged access; no user interaction is needed.
Exploitation
Not listed in CISA KEV, but EPSS is high at 0.477 (98.8th percentile) and public exploit write-ups exist on Packet Storm and Full Disclosure. No ransomware usage is documented.
What to do
- Upgrade CPCI85 firmware to V05 or later per Siemens advisory SSA-731916.
- Restrict network access to the device web interface to trusted management hosts only.
- Enforce least privilege and strong authentication for web interface accounts; audit privileged users.
- Monitor Siemens advisories and apply follow-up patches as released.
Detection
- Alert on unexpected child processes or shell invocations spawned by the device web server.
- Monitor web interface requests for command metacharacters and anomalous parameters.
- Review authentication logs for privileged web logins from unusual source addresses.
- Baseline normal device behavior and flag outbound connections from the master module.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-33919 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-33919), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.