PT-2022-11482 · Siemens · Siprotec 5

Published

2022-01-11

·

Updated

2022-01-19

·

CVE-2021-41769

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SIPROTEC 5 6MD85 devices (CPU variant CP300) versions prior to V8.83 SIPROTEC 5 6MD86 devices (CPU variant CP300) versions prior to V8.83 SIPROTEC 5 6MD89 devices (CPU variant CP300) versions prior to V8.83 SIPROTEC 5 6MU85 devices (CPU variant CP300) versions prior to V8.83 SIPROTEC 5 7KE85 devices (CPU variant CP300) versions prior to V8.83 SIPROTEC 5 7SA82 devices (CPU variant CP100) versions prior to V8.83 SIPROTEC 5 7SA86 devices (CPU variant CP300) versions prior to V8.83 SIPROTEC 5 7SA87 devices (CPU variant CP300) versions prior to V8.83 SIPROTEC 5 7SD82 devices (CPU variant CP100) versions prior to V8.83 SIPROTEC 5 7SD86 devices (CPU variant CP300) versions prior to V8.83 SIPROTEC 5 7SD87 devices (CPU variant CP300) versions prior to V8.83 SIPROTEC 5 7SJ81 devices (CPU variant CP100) versions prior to V8.83 SIPROTEC 5 7SJ82 devices (CPU variant CP100) versions prior to V8.83 SIPROTEC 5 7SJ85 devices (CPU variant CP300) versions prior to V8.83 SIPROTEC 5 7SJ86 devices (CPU variant CP300) versions prior to V8.83 SIPROTEC 5 7SK82 devices (CPU variant CP100) versions prior to V8.83 SIPROTEC 5 7SK85 devices (CPU variant CP300) versions prior to V8.83 SIPROTEC 5 7SL82 devices (CPU variant CP100) versions prior to V8.83 SIPROTEC 5 7SL86 devices (CPU variant CP300) versions prior to V8.83 SIPROTEC 5 7SL87 devices (CPU variant CP300) versions prior to V8.83 SIPROTEC 5 7SS85 devices (CPU variant CP300) versions prior to V8.83 SIPROTEC 5 7ST85 devices (CPU variant CP300) versions prior to V8.83 SIPROTEC 5 7SX85 devices (CPU variant CP300) versions prior to V8.83 SIPROTEC 5 7UM85 devices (CPU variant CP300) versions prior to V8.83 SIPROTEC 5 7UT82 devices (CPU variant CP100) versions prior to V8.83 SIPROTEC 5 7UT85 devices (CPU variant CP300) versions prior to V8.83 SIPROTEC 5 7UT86 devices (CPU variant CP300) versions prior to V8.83 SIPROTEC 5 7UT87 devices (CPU variant CP300) versions prior to V8.83 SIPROTEC 5 7VE85 devices (CPU variant CP300) versions prior to V8.83 SIPROTEC 5 7VK87 devices (CPU variant CP300) versions prior to V8.83 SIPROTEC 5 Compact 7SX800 devices (CPU variant CP050) versions prior to V8.83
Description An improper input validation vulnerability in the web server could allow an unauthenticated user to access device information.
Recommendations Update SIPROTEC 5 6MD85 devices (CPU variant CP300) to version V8.83 or later. Update SIPROTEC 5 6MD86 devices (CPU variant CP300) to version V8.83 or later. Update SIPROTEC 5 6MD89 devices (CPU variant CP300) to version V8.83 or later. Update SIPROTEC 5 6MU85 devices (CPU variant CP300) to version V8.83 or later. Update SIPROTEC 5 7KE85 devices (CPU variant CP300) to version V8.83 or later. Update SIPROTEC 5 7SA82 devices (CPU variant CP100) to version V8.83 or later. Update SIPROTEC 5 7SA86 devices (CPU variant CP300) to version V8.83 or later. Update SIPROTEC 5 7SA87 devices (CPU variant CP300) to version V8.83 or later. Update SIPROTEC 5 7SD82 devices (CPU variant CP100) to version V8.83 or later. Update SIPROTEC 5 7SD86 devices (CPU variant CP300) to version V8.83 or later. Update SIPROTEC 5 7SD87 devices (CPU variant CP300) to version V8.83 or later. Update SIPROTEC 5 7SJ81 devices (CPU variant CP100) to version V8.83 or later. Update SIPROTEC 5 7SJ82 devices (CPU variant CP100) to version V8.83 or later. Update SIPROTEC 5 7SJ85 devices (CPU variant CP300) to version V8.83 or later. Update SIPROTEC 5 7SJ86 devices (CPU variant CP300) to version V8.83 or later. Update SIPROTEC 5 7SK82 devices (CPU variant CP100) to version V8.83 or later. Update SIPROTEC 5 7SK85 devices (CPU variant CP300) to version V8.83 or later. Update SIPROTEC 5 7SL82 devices (CPU variant CP100) to version V8.83 or later. Update SIPROTEC 5 7SL86 devices (CPU variant CP300) to version V8.83 or later. Update SIPROTEC 5 7SL87 devices (CPU variant CP300) to version V8.83 or later. Update SIPROTEC 5 7SS85 devices (CPU variant CP300) to version V8.83 or later. Update SIPROTEC 5 7ST85 devices (CPU variant CP300) to version V8.83 or later. Update SIPROTEC 5 7SX85 devices (CPU variant CP300) to version V8.83 or later. Update SIPROTEC 5 7UM85 devices (CPU variant CP300) to version V8.83 or later. Update SIPROTEC 5 7UT82 devices (CPU variant CP100) to version V8.83 or later. Update SIPROTEC 5 7UT85 devices (CPU variant CP300) to version V8.83 or later. Update SIPROTEC 5 7UT86 devices (CPU variant CP300) to version V8.83 or later. Update SIPROTEC 5 7UT87 devices (CPU variant CP300) to version V8.83 or later. Update SIPROTEC 5 7VE85 devices (CPU variant CP300) to version V8.83 or later. Update SIPROTEC 5 7VK87 devices (CPU variant CP300) to version V8.83 or later. Update SIPROTEC 5 Compact 7SX800 devices (CPU variant CP050) to version V8.83 or later.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-41769

Affected Products

Siprotec 5