Improper Input Validation in SIPROTEC 5 Devices by Siemens
CVE-2021-41769
7.5HIGH
Key Information:
- Vendor
- Siemens
- Status
- Vendor
- CVE Published:
- 11 January 2022
Summary
An improper input validation vulnerability has been identified in several SIPROTEC 5 devices, which could allow an unauthenticated user to obtain sensitive device information through the web server. This flaw impacts various models equipped with the CP300 and CP100 CPUs, potentially exposing critical operational data. Users should ensure devices are updated to versions equal to or greater than V8.83 to mitigate this risk.
Affected Version(s)
SIPROTEC 5 6MD85 devices (CPU variant CP300) All versions < V8.83
SIPROTEC 5 6MD86 devices (CPU variant CP300) All versions < V8.83
SIPROTEC 5 6MD89 devices (CPU variant CP300) All versions < V8.83
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved