QID 590641

Date Published: 2022-01-04

QID 590641: Siemens SIPROTEC 5 Ethernet plug-in communication modules and devices Multiple Vulnerabilities (SSA-632562)

AFFECTED PRODUCTS
SIPROTEC 5 devices with CPU variants CP300 and CP100:All versions prior to V7.91
SIPROTEC 5 devices with CPU variants CP200:All versions prior to V7.59
SIPROTEC 5 devices with CPU variants CP300 and CP100: All versions prior to V8.01

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

These vulnerabilities could allow an attacker to leverage various attacks, e.g. to execute arbitrary code over the network.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution

    Customers are advised to update to latest versionSSA-632562: for affected packages and patching details.

    Software Advisories
    Advisory ID Software Component Link
    https://cert-portal.siemens.com/productcert/pdf/ssa-632562.pdf URL Logo cert-portal.siemens.com/productcert/pdf/ssa-632562.pdf