PT-2022-27389 · Siemens · Siprotec 5

CVE-2022-45044

·

Published

2022-12-13

·

Updated

2024-05-14

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions SIPROTEC 5 6MD84 (CP300) versions prior to V9.50 SIPROTEC 5 6MD85 (CP200) versions SIPROTEC 5 6MD85 (CP300) versions prior to V9.50 SIPROTEC 5 6MD86 (CP200) versions SIPROTEC 5 6MD86 (CP300) versions prior to V9.50 SIPROTEC 5 6MD89 (CP300) versions prior to V9.64 SIPROTEC 5 6MU85 (CP300) versions prior to V9.50 SIPROTEC 5 7KE85 (CP200) versions SIPROTEC 5 7KE85 (CP300) versions prior to V9.64 SIPROTEC 5 7SA82 (CP100) versions SIPROTEC 5 7SA82 (CP150) versions prior to V9.50 SIPROTEC 5 7SA84 (CP200) versions SIPROTEC 5 7SA86 (CP200) versions SIPROTEC 5 7SA86 (CP300) versions prior to V9.50 SIPROTEC 5 7SA87 (CP200) versions SIPROTEC 5 7SA87 (CP300) versions prior to V9.50 SIPROTEC 5 7SD82 (CP100) versions SIPROTEC 5 7SD82 (CP150) versions prior to V9.50 SIPROTEC 5 7SD84 (CP200) versions SIPROTEC 5 7SD86 (CP200) versions SIPROTEC 5 7SD86 (CP300) versions prior to V9.50 SIPROTEC 5 7SD87 (CP200) versions SIPROTEC 5 7SD87 (CP300) versions prior to V9.50 SIPROTEC 5 7SJ81 (CP100) versions prior to V8.89 SIPROTEC 5 7SJ81 (CP150) versions prior to V9.50 SIPROTEC 5 7SJ82 (CP100) versions prior to V8.89 SIPROTEC 5 7SJ82 (CP150) versions prior to V9.50 SIPROTEC 5 7SJ85 (CP200) versions SIPROTEC 5 7SJ85 (CP300) versions prior to V9.50 SIPROTEC 5 7SJ86 (CP200) versions SIPROTEC 5 7SJ86 (CP300) versions prior to V9.50 SIPROTEC 5 7SK82 (CP100) versions prior to V8.89 SIPROTEC 5 7SK82 (CP150) versions prior to V9.50 SIPROTEC 5 7SK85 (CP200) versions SIPROTEC 5 7SK85 (CP300) versions prior to V9.50 SIPROTEC 5 7SL82 (CP100) versions SIPROTEC 5 7SL82 (CP150) versions prior to V9.50 SIPROTEC 5 7SL86 (CP200) versions SIPROTEC 5 7SL86 (CP300) versions prior to V9.50 SIPROTEC 5 7SL87 (CP200) versions SIPROTEC 5 7SL87 (CP300) versions prior to V9.50 SIPROTEC 5 7SS85 (CP200) versions SIPROTEC 5 7SS85 (CP300) versions prior to V9.50 SIPROTEC 5 7ST85 (CP200) versions SIPROTEC 5 7ST85 (CP300) versions prior to V9.64 SIPROTEC 5 7ST86 (CP300) versions prior to V9.64 SIPROTEC 5 7SX82 (CP150) versions prior to V9.50 SIPROTEC 5 7SX85 (CP300) versions prior to V9.50 SIPROTEC 5 7UM85 (CP300) versions prior to V9.50 SIPROTEC 5 7UT82 (CP100) versions SIPROTEC 5 7UT82 (CP150) versions prior to V9.50 SIPROTEC 5 7UT85 (CP200) versions SIPROTEC 5 7UT85 (CP300) versions prior to V9.50 SIPROTEC 5 7UT86 (CP200) versions SIPROTEC 5 7UT86 (CP300) versions prior to V9.50 SIPROTEC 5 7UT87 (CP200) versions SIPROTEC 5 7UT87 (CP300) versions prior to V9.50 SIPROTEC 5 7VE85 (CP300) versions prior to V9.50 SIPROTEC 5 7VK87 (CP200) versions SIPROTEC 5 7VK87 (CP300) versions prior to V9.50 SIPROTEC 5 7VU85 (CP300) versions prior to V9.50 SIPROTEC 5 Communication Module ETH-BA-2EL versions prior to V8.89 installed on CP100 devices SIPROTEC 5 Communication Module ETH-BA-2EL versions prior to V9.50 installed on CP150 and CP300 devices SIPROTEC 5 Communication Module ETH-BA-2EL versions installed on CP200 devices SIPROTEC 5 Communication Module ETH-BB-2FO versions prior to V8.89 installed on CP100 devices SIPROTEC 5 Communication Module ETH-BB-2FO versions prior to V9.50 installed on CP150 and CP300 devices SIPROTEC 5 Communication Module ETH-BB-2FO versions installed on CP200 devices SIPROTEC 5 Communication Module ETH-BD-2FO versions prior to V9.50 SIPROTEC 5 Compact 7SX800 (CP050) versions prior to V9.50
Description The affected devices do not properly restrict secure client-initiated renegotiations within the SSL and TLS protocols. This could allow an attacker to create a denial of service condition on the ports 443/tcp and 4443/tcp for the duration of the attack.
Recommendations For SIPROTEC 5 6MD84 (CP300) versions prior to V9.50, update to version V9.50 or later. For SIPROTEC 5 6MD85 (CP200) versions, update to a version that properly restricts secure client-initiated renegotiations. For SIPROTEC 5 6MD85 (CP300) versions prior to V9.50, update to version V9.50 or later. For SIPROTEC 5 6MD86 (CP200) versions, update to a version that properly restricts secure client-initiated renegotiations. For SIPROTEC 5 6MD86 (CP300) versions prior to V9.50, update to version V9.50 or later. For SIPROTEC 5 6MD89 (CP300) versions prior to V9.64, update to version V9.64 or later. For SIPROTEC 5 6MU85 (CP300) versions prior to V9.50, update to version V9.50 or later. For SIPROTEC 5 7KE85 (CP200) versions, update to a version that properly restricts secure client-initiated renegotiations. For SIPROTEC 5 7KE85 (CP300) versions prior to V9.64, update to version V9.64 or later. For SIPROTEC 5 7SA82 (CP100) versions, update to a version that properly restricts secure client-initiated renegotiations. For SIPROTEC 5 7SA82 (CP150) versions prior to V9.50, update to version V9.50 or later. For SIPROTEC 5 7SA84 (CP200) versions, update to a version that properly restricts secure client-initiated renegotiations. For SIPROTEC 5 7SA86 (CP200) versions, update to a version that properly restricts secure client-initiated renegotiations. For SIPROTEC 5 7SA86 (CP300) versions prior to V9.50, update to version V9.50 or later. For SIPROTEC 5 7SA87 (CP200) versions, update to a version that properly restricts secure client-initiated renegotiations. For SIPROTEC 5 7SA87 (CP300) versions prior to V9.50, update to version V9.50 or later. For SIPROTEC 5 7SD82 (CP100) versions, update to a version that properly restricts secure client-initiated renegotiations. For SIPROTEC 5 7SD82 (CP150) versions prior to V9.50, update to version V9.50 or later. For SIPROTEC 5 7SD84 (CP200) versions, update to a version that properly restricts secure client-initiated renegotiations. For SIPROTEC 5 7SD86 (CP200) versions, update to a version that properly restricts secure client-initiated renegotiations. For SIPROTEC 5 7SD86 (CP300) versions prior to V9.50, update to version V9.50 or later. For SIPROTEC 5 7SD87 (CP200) versions, update to a version that properly restricts secure client-initiated renegotiations. For SIPROTEC 5 7SD87 (CP300) versions prior to V9.50, update to version V9.50 or later. For SIPROTEC 5 7SJ81 (CP100) versions prior to V8.89, update to version V8.89 or later. For SIPROTEC 5 7SJ81 (CP150) versions prior to V9.50, update to version V9.50 or later. For SIPROTEC 5 7SJ82 (CP100) versions prior to V8.89, update to version V8.89 or later. For SIPROTEC 5 7SJ82 (CP150) versions prior to V9.50, update to version V9.50 or later. For SIPROTEC 5 7SJ85 (CP200) versions, update to a version that properly restricts secure client-initiated renegotiations. For SIPROTEC 5 7SJ85 (CP300) versions prior to V9.50, update to version V9.50 or later. For SIPROTEC 5 7SJ86 (CP200) versions, update to a version that properly restricts secure client-initiated renegotiations. For SIPROTEC 5 7SJ86 (CP300) versions prior to V9.50, update to version V9.50 or later. For SIPROTEC 5 7SK82 (CP100) versions prior to V8.89, update to version V8.89 or later. For SIPROTEC 5 7SK82 (CP150) versions prior to V9.50, update to version V9.50 or later. For SIPROTEC 5 7SK85 (CP200) versions, update to a version that properly restricts secure client-initiated renegotiations. For SIPROTEC 5 7SK85 (CP300) versions prior to V9.50, update to version V9.50 or later. For SIPROTEC 5 7SL82 (CP100) versions, update to a version that properly restricts secure client-initiated renegotiations. For SIPROTEC 5 7SL82 (CP150) versions prior to V9.50, update to version V9.50 or later. For SIPROTEC 5 7SL86 (CP200) versions, update to a version that properly restricts secure client-initiated renegotiations. For SIPROTEC 5 7SL86 (CP300) versions prior to V9.50, update to version V9.50 or later. For SIPROTEC 5 7SL87 (CP200) versions, update to a version that properly restricts secure client-initiated renegotiations. For SIPROTEC 5 7SL87 (CP300) versions prior to V9.50, update to version V9.50 or later. For SIPROTEC 5 7SS85 (CP200) versions, update to a version that properly restricts secure client-initiated renegotiations. For SIPROTEC 5 7SS85 (CP300) versions prior to V9.50, update to version V9.50 or later. For SIPROTEC 5 7ST85 (CP200) versions, update to a version that properly restricts secure client-initiated renegotiations. For SIPROTEC 5 7ST85 (CP300) versions prior to V9.64, update to version V9.64 or later. For SIPROTEC 5 7ST86 (CP300) versions prior to V9.64, update to version V9.64 or later. For SIPROTEC 5 7SX82 (CP150) versions prior to V9.50, update to version V9.50 or later. For SIPROTEC 5 7SX85 (CP300) versions prior to V9.50, update to version V9.50 or later. For SIPROTEC 5 7UM85 (CP300) versions prior to V9.50, update to version V9.50 or later. For SIPROTEC 5 7UT82 (CP100) versions, update to a version that properly restricts secure client-initiated renegotiations. For SIPROTEC 5 7UT82 (CP150) versions prior to V9.50, update to version V9.50 or later. For SIPROTEC 5 7UT85 (CP200) versions, update to a version that properly restricts secure client-initiated renegotiations. For SIPROTEC 5 7UT85 (CP300) versions prior to V9.50, update to version V9.50 or later. For SIPROTEC 5 7UT86 (CP200) versions, update to a version that properly restricts secure client-initiated renegotiations. For SIPROTEC 5 7UT86 (CP300) versions prior to V9.50, update to version V9.50 or later. For SIPROTEC 5 7UT87 (CP200) versions, update to a version that properly restricts secure client-initiated renegotiations. For SIPROTEC 5 7UT87 (CP300) versions prior to V9.50, update to version V9.50 or later. For SIPROTEC 5 7VE85 (CP300) versions prior to V9.50, update to version V9.50 or later. For SIPROTEC 5 7VK87 (CP200) versions, update to a version that properly restricts secure client-initiated renegotiations. For SIPROTEC 5 7VK87 (CP300) versions prior to V9.50, update to version V9.50 or later. For SIPROTEC 5 7VU85 (CP300) versions prior to V9.50, update to version V9.50 or later. For SIPROTEC 5 Communication Module ETH-BA-2EL versions prior to V8.89 installed on CP100 devices, update to version V8.89 or later. For SIPROTEC 5 Communication Module ETH-BA-2EL versions prior to V9.50 installed on CP150 and CP300 devices, update to version V9.50 or later. For SIPROTEC 5 Communication Module ETH-BA-2EL versions installed on CP200 devices, update to a version that properly restricts secure client-initiated renegotiations. For SIPROTEC 5 Communication Module ETH-BB-2FO versions prior to V8.89 installed on CP100 devices, update to version V8.89 or later. For SIPROTEC 5 Communication Module ETH-BB-2FO versions prior to V9.50 installed on CP150 and CP300 devices, update to version V9.50 or later. For SIPROTEC 5 Communication Module ETH-BB-2FO versions installed on CP200 devices, update to a version that properly restricts secure client-initiated renegotiations. For SIPROTEC 5 Communication Module ETH-BD-2FO versions prior to V9.50, update to version V9.50 or later. For SIPROTEC 5 Compact 7SX800 (CP050) versions prior to V9.50, update to version V9.50 or later.

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-45044

Affected Products

Siprotec 5