Security Weakness in SIPROTEC 5 Devices by Siemens
CVE-2024-38867

8.2HIGH

Key Information:

Summary

Several SIPROTEC 5 devices by Siemens are affected by a vulnerability that allows unauthorized attackers to intercept and decrypt data transmitted over specific ports. This issue arises due to the support of weak ciphers on multiple communication channels, including those for web access and the DIGSI 5 utility. An attacker could exploit this weakness by positioning themselves in a man-in-the-middle scenario, leading potentially to unauthorized access to sensitive information transferred over the network.

Affected Version(s)

SIPROTEC 5 6MD84 (CP300) 0

SIPROTEC 5 6MD85 (CP200) 0

SIPROTEC 5 6MD85 (CP300) 0

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

.