Siemens SIPROTEC 5 Products

As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens’ ProductCERT Security Advisories (CERT Services | Services | Siemens Global).

View CSAF

1. EXECUTIVE SUMMARY

  • CVSS v4 7.1
  • ATTENTION: Exploitable remotely/low attack complexity
  • Vendor: Siemens
  • Equipment: SIPROTEC 5
  • Vulnerability: Files or Directories Accessible to External Parties

2. RISK EVALUATION

Successful exploitation of this vulnerability could allow an authenticated remote attacker to read arbitrary files or the entire filesystem of the device.

3. TECHNICAL DETAILS

3.1 AFFECTED PRODUCTS

Siemens reports that the following products are affected:

  • Siemens SIPROTEC 5 6MD84 (CP300): Versions prior to 9.80
  • Siemens SIPROTEC 5 7SA87 (CP300): Versions 7.80 up to but not including 9.80
  • Siemens SIPROTEC 5 7SD82 (CP100): Versions 7.80 and after
  • Siemens SIPROTEC 5 7SD82 (CP150): Versions prior to 9.80
  • Siemens SIPROTEC 5 7SD86 (CP300): Versions 7.80 up to but not including 9.80
  • Siemens SIPROTEC 5 7SD87 (CP300): Versions 7.80 up to but not including 9.80
  • Siemens SIPROTEC 5 7SJ81 (CP100): Versions 7.80 and after
  • Siemens SIPROTEC 5 7SJ81 (CP150): Versions prior to 9.80
  • Siemens SIPROTEC 5 7SJ82 (CP100): Versions 7.80 and after
  • Siemens SIPROTEC 5 7SJ82 (CP150): Versions prior to 9.80
  • Siemens SIPROTEC 5 7SJ85 (CP300): Versions 7.80 up to but not including 9.80
  • Siemens SIPROTEC 5 6MD85 (CP300): Versions 7.80 up to but not including 9.80
  • Siemens SIPROTEC 5 7SJ86 (CP300): Versions 7.80 up to but not including 9.80
  • Siemens SIPROTEC 5 7SK82 (CP100): Versions 7.80 and after
  • Siemens SIPROTEC 5 7SK82 (CP150): Versions prior to 9.80
  • Siemens SIPROTEC 5 7SK85 (CP300): Versions 7.80

    […]
    Content was cut in order to protect the source.Please visit the source for the rest of the article.

    This article has been indexed from All CISA Advisories

    Read the original article: