QID 591421

QID 591421: Siemens EN100 Ethernet communication module and SIPROTEC 5 Relays Denial of Service (DoS) Vulnerability (SSA-635129)

AFFECTED PRODUCTS
Firmware variant IEC 61850 for EN100 Ethernet module: All versions prior to V4.33
Firmware variant PROFINET IO for EN100 Ethernet module: All versions
Firmware variant Modbus TCP for EN100 Ethernet module: All versions
Firmware variant DNP3 TCP for EN100 Ethernet module: All versions
Firmware variant IEC104 for EN100 Ethernet module: All versions prior to V1.22
SIPROTEC 5 relays with CPU variants CP300 and CP100 and the respective Ethernet communication modules: All versions prior to V7.80
SIPROTEC 5 relays with CPU variants CP200 and the respective Ethernet communication modules: All versions prior to V7.58

QID Detection Logic:
This QID checks for the Vulnerable version of Siemens-affected products using passive scanning.

Successful exploitation of this vulnerability can lead to disruption of service.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution

    Customers are advised to refer to Siemens MITIGATIONS section SSA-635129 for affected packages and patching details.Workaround:
    Workaround advised by the Vendor:
    Block access to port 102/tcp e.g. with an external firewall.

    CVEs related to QID 591421

    Software Advisories
    Advisory ID Software Component Link
    SSA-635129 URL Logo cert-portal.siemens.com/productcert/pdf/ssa-635129.pdf