QID 591041

Date Published: 2022-09-16

QID 591041: Siemens SIPROTEC 5 Information Disclosure Vulnerability (SSA-439673)

AFFECTED PRODUCTS
SIPROTEC 5 6MD85 devices (CPU variant CP300):All versions prior to V8.83
SIPROTEC 5 6MD86 devices (CPU variant CP300):All versions prior to V8.83
SIPROTEC 5 6MD89 devices (CPU variant CP300):All versions prior to V8.83
SIPROTEC 5 6MU85 devices (CPU variant CP300):All versions prior to V8.83
SIPROTEC 5 7KE85 devices (CPU variant CP300):All versions prior to V8.83
SIPROTEC 5 7SA82 devices (CPU variant CP100):All versions prior to V8.83
SIPROTEC 5 7SA86 devices (CPU variant CP300):All versions prior to V8.83
SIPROTEC 5 7SA87 devices (CPU variant CP300):All versions prior to V8.83
SIPROTEC 5 7SD82 devices (CPU variant CP100):All versions prior to V8.83
SIPROTEC 5 7SD86 devices (CPU variant CP300):All versions prior to V8.83
SIPROTEC 5 7SD87 devices (CPU variant CP300):All versions prior to V8.83
SIPROTEC 5 7SJ81 devices (CPU variant CP100):All versions prior to V8.83
SIPROTEC 5 7SJ82 devices (CPU variant CP100):All versions prior to V8.83
SIPROTEC 5 7SJ85 devices (CPU variant CP300):All versions prior to V8.83
SIPROTEC 5 7SJ86 devices (CPU variant CP300):All versions prior to V8.83
SIPROTEC 5 7SK82 devices (CPU variant CP100):All versions prior to V8.83
SIPROTEC 5 7SK85 devices (CPU variant CP300):All versions prior to V8.83
SIPROTEC 5 7SL82 devices (CPU variant CP100):All versions prior to V8.83
SIPROTEC 5 7SL86 devices (CPU variant CP300):All versions prior to V8.83
SIPROTEC 5 7SL87 devices (CPU variant CP300):All versions prior to V8.83
SIPROTEC 5 7SS85 devices (CPU variant CP300):All versions prior to V8.83
SIPROTEC 5 7ST85 devices (CPU variant CP300):All versions prior to V8.83
SIPROTEC 5 7SX85 devices (CPU variant CP300):All versions prior to V8.83
SIPROTEC 5 7UM85 devices (CPU variant CP300):All versions prior to V8.83
SIPROTEC 5 7UT82 devices (CPU variant CP100):All versions prior to V8.83
SIPROTEC 5 7UT85 devices (CPU variant CP300):All versions prior to V8.83
SIPROTEC 5 7UT86 devices (CPU variant CP300):All versions prior to V8.83
SIPROTEC 5 7UT87 devices (CPU variant CP300):All versions prior to V8.83
SIPROTEC 5 7VE85 devices (CPU variant CP300):All versions prior to V8.83
SIPROTEC 5 7VK87 devices (CPU variant CP300):All versions prior to V8.83
SIPROTEC 5 Compact 7SX800 devices (CPUvariant CP050):All versions prior to V8.83

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

An information disclosure vulnerability in SIPROTEC 5 products could allow an unauthenticated attacker to read device information.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ssa-439673 for affected packages and patching details.

    CVEs related to QID 591041

    Software Advisories
    Advisory ID Software Component Link
    ssa-439673 URL Logo cert-portal.siemens.com/productcert/pdf/ssa-439673.pdf