Security Weakness in SIPROTEC 5 Devices by Siemens
CVE-2024-38867

5.9MEDIUM

Key Information:

Summary

Several SIPROTEC 5 devices by Siemens are affected by a vulnerability that allows unauthorized attackers to intercept and decrypt data transmitted over specific ports. This issue arises due to the support of weak ciphers on multiple communication channels, including those for web access and the DIGSI 5 utility. An attacker could exploit this weakness by positioning themselves in a man-in-the-middle scenario, leading potentially to unauthorized access to sensitive information transferred over the network.

Affected Version(s)

SIPROTEC 5 6MD84 (CP300) 0

SIPROTEC 5 6MD85 (CP200) 0

SIPROTEC 5 6MD85 (CP300) 0

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.