Improper Input Validation in SIPROTEC 5 Devices by Siemens
CVE-2021-41769

7.5HIGH

Summary

An improper input validation vulnerability has been identified in several SIPROTEC 5 devices, which could allow an unauthenticated user to obtain sensitive device information through the web server. This flaw impacts various models equipped with the CP300 and CP100 CPUs, potentially exposing critical operational data. Users should ensure devices are updated to versions equal to or greater than V8.83 to mitigate this risk.

Affected Version(s)

SIPROTEC 5 6MD85 devices (CPU variant CP300) All versions < V8.83

SIPROTEC 5 6MD86 devices (CPU variant CP300) All versions < V8.83

SIPROTEC 5 6MD89 devices (CPU variant CP300) All versions < V8.83

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.