Security Weakness in SIPROTEC 5 Devices by Siemens
CVE-2024-38867
8.2HIGH
Key Information:
- Vendor
Siemens
- Status
- Vendor
- CVE Published:
- 9 July 2024
What is CVE-2024-38867?
Several SIPROTEC 5 devices by Siemens are affected by a vulnerability that allows unauthorized attackers to intercept and decrypt data transmitted over specific ports. This issue arises due to the support of weak ciphers on multiple communication channels, including those for web access and the DIGSI 5 utility. An attacker could exploit this weakness by positioning themselves in a man-in-the-middle scenario, leading potentially to unauthorized access to sensitive information transferred over the network.
Affected Version(s)
SIPROTEC 5 6MD84 (CP300) 0
SIPROTEC 5 6MD85 (CP200) 0
SIPROTEC 5 6MD85 (CP300) 0