QID 591417

QID 591417: Siemens EN100 Ethernet Communication Module and SIPROTEC 5 Relays Denial of Service (DoS) Vulnerabilities (SSA-104088)

The EN100 Ethernet communication module and SIPROTEC 5 relays are affected by a security vulnerability which could allow an attacker to conduct a Denial-of-Service attack over the network.

AFFECTED PRODUCTS
Firmware variant IEC 61850 for EN100 Ethernet module: All versions prior to V4.35
Firmware variant MODBUS TCP for EN100 Ethernet module: All versions
Firmware variant DNP3 TCP for EN100 Ethernet module: All versions
Firmware variant IEC104 for EN100 Ethernet module: All versions
Firmware variant Profinet IO for EN100 Ethernet module: All versions
SIPROTEC 5 relays with CPU variants CP300 and CP100 and the respective Ethernet communication modules: All versions prior to V7.82
SIPROTEC 5 relays with CPU variants CP200 and the respective Ethernet communication modules: All versions prior to V7.58

QID Detection Logic:
This QID checks for the Vulnerable version of Siemens affected products using passive scanning.

Successful exploitation of this vulnerability can cause a denial of service condition.

  • CVSS V3 rated as Medium - 5.9 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution

    Customers are advised to refer to Siemens MITIGATIONS section SSA-104088 for affected packages and patching details.

    CVEs related to QID 591417

    Software Advisories
    Advisory ID Software Component Link
    SSA-104088 URL Logo cert-portal.siemens.com/productcert/pdf/ssa-104088.pdf