Session Identifier Vulnerability in SIPROTEC 5 Series by Siemens
CVE-2024-54017

6.9MEDIUM

What is CVE-2024-54017?

A session identifier vulnerability exists within the SIPROTEC 5 series by Siemens. This vulnerability is due to the insufficient randomness of values used in creating session identifiers. Consequently, an unauthenticated remote attacker may exploit this weakness to perform brute force attacks and potentially gain unauthorized read access to limited information hosted on the associated web server.

Affected Version(s)

SIPROTEC 5 6MD84 (CP300) 0

SIPROTEC 5 6MD85 (CP200) 0

SIPROTEC 5 6MD85 (CP300) V7.80

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.