PT-2022-27389 · Siemens · Siprotec 5
Published
2022-12-13
·
Updated
2024-05-14
·
CVE-2022-45044
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
SIPROTEC 5 6MD84 (CP300) versions prior to V9.50
SIPROTEC 5 6MD85 (CP200) versions
SIPROTEC 5 6MD85 (CP300) versions prior to V9.50
SIPROTEC 5 6MD86 (CP200) versions
SIPROTEC 5 6MD86 (CP300) versions prior to V9.50
SIPROTEC 5 6MD89 (CP300) versions prior to V9.64
SIPROTEC 5 6MU85 (CP300) versions prior to V9.50
SIPROTEC 5 7KE85 (CP200) versions
SIPROTEC 5 7KE85 (CP300) versions prior to V9.64
SIPROTEC 5 7SA82 (CP100) versions
SIPROTEC 5 7SA82 (CP150) versions prior to V9.50
SIPROTEC 5 7SA84 (CP200) versions
SIPROTEC 5 7SA86 (CP200) versions
SIPROTEC 5 7SA86 (CP300) versions prior to V9.50
SIPROTEC 5 7SA87 (CP200) versions
SIPROTEC 5 7SA87 (CP300) versions prior to V9.50
SIPROTEC 5 7SD82 (CP100) versions
SIPROTEC 5 7SD82 (CP150) versions prior to V9.50
SIPROTEC 5 7SD84 (CP200) versions
SIPROTEC 5 7SD86 (CP200) versions
SIPROTEC 5 7SD86 (CP300) versions prior to V9.50
SIPROTEC 5 7SD87 (CP200) versions
SIPROTEC 5 7SD87 (CP300) versions prior to V9.50
SIPROTEC 5 7SJ81 (CP100) versions prior to V8.89
SIPROTEC 5 7SJ81 (CP150) versions prior to V9.50
SIPROTEC 5 7SJ82 (CP100) versions prior to V8.89
SIPROTEC 5 7SJ82 (CP150) versions prior to V9.50
SIPROTEC 5 7SJ85 (CP200) versions
SIPROTEC 5 7SJ85 (CP300) versions prior to V9.50
SIPROTEC 5 7SJ86 (CP200) versions
SIPROTEC 5 7SJ86 (CP300) versions prior to V9.50
SIPROTEC 5 7SK82 (CP100) versions prior to V8.89
SIPROTEC 5 7SK82 (CP150) versions prior to V9.50
SIPROTEC 5 7SK85 (CP200) versions
SIPROTEC 5 7SK85 (CP300) versions prior to V9.50
SIPROTEC 5 7SL82 (CP100) versions
SIPROTEC 5 7SL82 (CP150) versions prior to V9.50
SIPROTEC 5 7SL86 (CP200) versions
SIPROTEC 5 7SL86 (CP300) versions prior to V9.50
SIPROTEC 5 7SL87 (CP200) versions
SIPROTEC 5 7SL87 (CP300) versions prior to V9.50
SIPROTEC 5 7SS85 (CP200) versions
SIPROTEC 5 7SS85 (CP300) versions prior to V9.50
SIPROTEC 5 7ST85 (CP200) versions
SIPROTEC 5 7ST85 (CP300) versions prior to V9.64
SIPROTEC 5 7ST86 (CP300) versions prior to V9.64
SIPROTEC 5 7SX82 (CP150) versions prior to V9.50
SIPROTEC 5 7SX85 (CP300) versions prior to V9.50
SIPROTEC 5 7UM85 (CP300) versions prior to V9.50
SIPROTEC 5 7UT82 (CP100) versions
SIPROTEC 5 7UT82 (CP150) versions prior to V9.50
SIPROTEC 5 7UT85 (CP200) versions
SIPROTEC 5 7UT85 (CP300) versions prior to V9.50
SIPROTEC 5 7UT86 (CP200) versions
SIPROTEC 5 7UT86 (CP300) versions prior to V9.50
SIPROTEC 5 7UT87 (CP200) versions
SIPROTEC 5 7UT87 (CP300) versions prior to V9.50
SIPROTEC 5 7VE85 (CP300) versions prior to V9.50
SIPROTEC 5 7VK87 (CP200) versions
SIPROTEC 5 7VK87 (CP300) versions prior to V9.50
SIPROTEC 5 7VU85 (CP300) versions prior to V9.50
SIPROTEC 5 Communication Module ETH-BA-2EL versions prior to V8.89 installed on CP100 devices
SIPROTEC 5 Communication Module ETH-BA-2EL versions prior to V9.50 installed on CP150 and CP300 devices
SIPROTEC 5 Communication Module ETH-BA-2EL versions installed on CP200 devices
SIPROTEC 5 Communication Module ETH-BB-2FO versions prior to V8.89 installed on CP100 devices
SIPROTEC 5 Communication Module ETH-BB-2FO versions prior to V9.50 installed on CP150 and CP300 devices
SIPROTEC 5 Communication Module ETH-BB-2FO versions installed on CP200 devices
SIPROTEC 5 Communication Module ETH-BD-2FO versions prior to V9.50
SIPROTEC 5 Compact 7SX800 (CP050) versions prior to V9.50
Description
The affected devices do not properly restrict secure client-initiated renegotiations within the SSL and TLS protocols. This could allow an attacker to create a denial of service condition on the ports 443/tcp and 4443/tcp for the duration of the attack.
Recommendations
For SIPROTEC 5 6MD84 (CP300) versions prior to V9.50, update to version V9.50 or later.
For SIPROTEC 5 6MD85 (CP200) versions, update to a version that properly restricts secure client-initiated renegotiations.
For SIPROTEC 5 6MD85 (CP300) versions prior to V9.50, update to version V9.50 or later.
For SIPROTEC 5 6MD86 (CP200) versions, update to a version that properly restricts secure client-initiated renegotiations.
For SIPROTEC 5 6MD86 (CP300) versions prior to V9.50, update to version V9.50 or later.
For SIPROTEC 5 6MD89 (CP300) versions prior to V9.64, update to version V9.64 or later.
For SIPROTEC 5 6MU85 (CP300) versions prior to V9.50, update to version V9.50 or later.
For SIPROTEC 5 7KE85 (CP200) versions, update to a version that properly restricts secure client-initiated renegotiations.
For SIPROTEC 5 7KE85 (CP300) versions prior to V9.64, update to version V9.64 or later.
For SIPROTEC 5 7SA82 (CP100) versions, update to a version that properly restricts secure client-initiated renegotiations.
For SIPROTEC 5 7SA82 (CP150) versions prior to V9.50, update to version V9.50 or later.
For SIPROTEC 5 7SA84 (CP200) versions, update to a version that properly restricts secure client-initiated renegotiations.
For SIPROTEC 5 7SA86 (CP200) versions, update to a version that properly restricts secure client-initiated renegotiations.
For SIPROTEC 5 7SA86 (CP300) versions prior to V9.50, update to version V9.50 or later.
For SIPROTEC 5 7SA87 (CP200) versions, update to a version that properly restricts secure client-initiated renegotiations.
For SIPROTEC 5 7SA87 (CP300) versions prior to V9.50, update to version V9.50 or later.
For SIPROTEC 5 7SD82 (CP100) versions, update to a version that properly restricts secure client-initiated renegotiations.
For SIPROTEC 5 7SD82 (CP150) versions prior to V9.50, update to version V9.50 or later.
For SIPROTEC 5 7SD84 (CP200) versions, update to a version that properly restricts secure client-initiated renegotiations.
For SIPROTEC 5 7SD86 (CP200) versions, update to a version that properly restricts secure client-initiated renegotiations.
For SIPROTEC 5 7SD86 (CP300) versions prior to V9.50, update to version V9.50 or later.
For SIPROTEC 5 7SD87 (CP200) versions, update to a version that properly restricts secure client-initiated renegotiations.
For SIPROTEC 5 7SD87 (CP300) versions prior to V9.50, update to version V9.50 or later.
For SIPROTEC 5 7SJ81 (CP100) versions prior to V8.89, update to version V8.89 or later.
For SIPROTEC 5 7SJ81 (CP150) versions prior to V9.50, update to version V9.50 or later.
For SIPROTEC 5 7SJ82 (CP100) versions prior to V8.89, update to version V8.89 or later.
For SIPROTEC 5 7SJ82 (CP150) versions prior to V9.50, update to version V9.50 or later.
For SIPROTEC 5 7SJ85 (CP200) versions, update to a version that properly restricts secure client-initiated renegotiations.
For SIPROTEC 5 7SJ85 (CP300) versions prior to V9.50, update to version V9.50 or later.
For SIPROTEC 5 7SJ86 (CP200) versions, update to a version that properly restricts secure client-initiated renegotiations.
For SIPROTEC 5 7SJ86 (CP300) versions prior to V9.50, update to version V9.50 or later.
For SIPROTEC 5 7SK82 (CP100) versions prior to V8.89, update to version V8.89 or later.
For SIPROTEC 5 7SK82 (CP150) versions prior to V9.50, update to version V9.50 or later.
For SIPROTEC 5 7SK85 (CP200) versions, update to a version that properly restricts secure client-initiated renegotiations.
For SIPROTEC 5 7SK85 (CP300) versions prior to V9.50, update to version V9.50 or later.
For SIPROTEC 5 7SL82 (CP100) versions, update to a version that properly restricts secure client-initiated renegotiations.
For SIPROTEC 5 7SL82 (CP150) versions prior to V9.50, update to version V9.50 or later.
For SIPROTEC 5 7SL86 (CP200) versions, update to a version that properly restricts secure client-initiated renegotiations.
For SIPROTEC 5 7SL86 (CP300) versions prior to V9.50, update to version V9.50 or later.
For SIPROTEC 5 7SL87 (CP200) versions, update to a version that properly restricts secure client-initiated renegotiations.
For SIPROTEC 5 7SL87 (CP300) versions prior to V9.50, update to version V9.50 or later.
For SIPROTEC 5 7SS85 (CP200) versions, update to a version that properly restricts secure client-initiated renegotiations.
For SIPROTEC 5 7SS85 (CP300) versions prior to V9.50, update to version V9.50 or later.
For SIPROTEC 5 7ST85 (CP200) versions, update to a version that properly restricts secure client-initiated renegotiations.
For SIPROTEC 5 7ST85 (CP300) versions prior to V9.64, update to version V9.64 or later.
For SIPROTEC 5 7ST86 (CP300) versions prior to V9.64, update to version V9.64 or later.
For SIPROTEC 5 7SX82 (CP150) versions prior to V9.50, update to version V9.50 or later.
For SIPROTEC 5 7SX85 (CP300) versions prior to V9.50, update to version V9.50 or later.
For SIPROTEC 5 7UM85 (CP300) versions prior to V9.50, update to version V9.50 or later.
For SIPROTEC 5 7UT82 (CP100) versions, update to a version that properly restricts secure client-initiated renegotiations.
For SIPROTEC 5 7UT82 (CP150) versions prior to V9.50, update to version V9.50 or later.
For SIPROTEC 5 7UT85 (CP200) versions, update to a version that properly restricts secure client-initiated renegotiations.
For SIPROTEC 5 7UT85 (CP300) versions prior to V9.50, update to version V9.50 or later.
For SIPROTEC 5 7UT86 (CP200) versions, update to a version that properly restricts secure client-initiated renegotiations.
For SIPROTEC 5 7UT86 (CP300) versions prior to V9.50, update to version V9.50 or later.
For SIPROTEC 5 7UT87 (CP200) versions, update to a version that properly restricts secure client-initiated renegotiations.
For SIPROTEC 5 7UT87 (CP300) versions prior to V9.50, update to version V9.50 or later.
For SIPROTEC 5 7VE85 (CP300) versions prior to V9.50, update to version V9.50 or later.
For SIPROTEC 5 7VK87 (CP200) versions, update to a version that properly restricts secure client-initiated renegotiations.
For SIPROTEC 5 7VK87 (CP300) versions prior to V9.50, update to version V9.50 or later.
For SIPROTEC 5 7VU85 (CP300) versions prior to V9.50, update to version V9.50 or later.
For SIPROTEC 5 Communication Module ETH-BA-2EL versions prior to V8.89 installed on CP100 devices, update to version V8.89 or later.
For SIPROTEC 5 Communication Module ETH-BA-2EL versions prior to V9.50 installed on CP150 and CP300 devices, update to version V9.50 or later.
For SIPROTEC 5 Communication Module ETH-BA-2EL versions installed on CP200 devices, update to a version that properly restricts secure client-initiated renegotiations.
For SIPROTEC 5 Communication Module ETH-BB-2FO versions prior to V8.89 installed on CP100 devices, update to version V8.89 or later.
For SIPROTEC 5 Communication Module ETH-BB-2FO versions prior to V9.50 installed on CP150 and CP300 devices, update to version V9.50 or later.
For SIPROTEC 5 Communication Module ETH-BB-2FO versions installed on CP200 devices, update to a version that properly restricts secure client-initiated renegotiations.
For SIPROTEC 5 Communication Module ETH-BD-2FO versions prior to V9.50, update to version V9.50 or later.
For SIPROTEC 5 Compact 7SX800 (CP050) versions prior to V9.50, update to version V9.50 or later.
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Siprotec 5