Denial of Service Vulnerability in Siemens SIPROTEC 5 Series
CVE-2023-28766

7.5HIGH

Key Information:

Summary

A vulnerability in multiple models of the Siemens SIPROTEC 5 series has been discovered, where improper validation of HTTP request parameters in the hosted web service could allow an unauthenticated remote attacker to send specially crafted packets. This could lead to a denial of service condition, impacting the availability and proper functioning of the affected devices. Users are encouraged to review the versions affected and apply necessary updates to mitigate this security risk.

Affected Version(s)

SIPROTEC 5 6MD85 (CP300) V7.80

SIPROTEC 5 6MD86 (CP300) V7.80

SIPROTEC 5 6MD89 (CP300) V7.80

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.