PT-2025-2974 · Siemens · Siprotec 5 7Sa87+16
Constantin Schieber-Knöbl
+2
·
Published
2025-01-14
·
Updated
2025-01-15
·
CVE-2024-53649
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SIPROTEC 5 6MD84 (CP300) versions prior to V9.80
SIPROTEC 5 6MD85 (CP300) versions 7.80 through 9.79
SIPROTEC 5 6MD86 (CP300) versions 7.80 through 9.79
SIPROTEC 5 6MD89 (CP300) versions 7.80 through 9.89
SIPROTEC 5 6MU85 (CP300) versions 7.80 through 9.79
SIPROTEC 5 7KE85 (CP300) versions 7.80 through 9.79
SIPROTEC 5 7SA82 (CP100) versions 7.80 and later
SIPROTEC 5 7SA82 (CP150) versions prior to V9.80
SIPROTEC 5 7SA86 (CP300) versions 7.80 through 9.79
SIPROTEC 5 7SA87 (CP300) versions 7.80 through 9.79
SIPROTEC 5 7SD82 (CP100) versions 7.80 and later
SIPROTEC 5 7SD82 (CP150) versions prior to V9.80
SIPROTEC 5 7SD86 (CP300) versions 7.80 through 9.79
SIPROTEC 5 7SD87 (CP300) versions 7.80 through 9.79
SIPROTEC 5 7SJ81 (CP100) versions 7.80 and later
SIPROTEC 5 7SJ81 (CP150) versions prior to V9.80
SIPROTEC 5 7SJ82 (CP100) versions 7.80 and later
SIPROTEC 5 7SJ82 (CP150) versions prior to V9.80
SIPROTEC 5 7SJ85 (CP300) versions 7.80 through 9.79
SIPROTEC 5 7SJ86 (CP300) versions 7.80 through 9.79
SIPROTEC 5 7SK82 (CP100) versions 7.80 and later
SIPROTEC 5 7SK82 (CP150) versions prior to V9.80
SIPROTEC 5 7SK85 (CP300) versions 7.80 through 9.79
SIPROTEC 5 7SL82 (CP100) versions 7.80 and later
SIPROTEC 5 7SL82 (CP150) versions prior to V9.80
SIPROTEC 5 7SL86 (CP300) versions 7.80 through 9.79
SIPROTEC 5 7SL87 (CP300) versions 7.80 through 9.79
SIPROTEC 5 7SS85 (CP300) versions 7.80 through 9.79
SIPROTEC 5 7ST85 (CP300) versions prior to V9.80
SIPROTEC 5 7ST86 (CP300) versions prior to V9.80
SIPROTEC 5 7SX82 (CP150) versions prior to V9.80
SIPROTEC 5 7SX85 (CP300) versions prior to V9.80
SIPROTEC 5 7SY82 (CP150) versions prior to V9.80
SIPROTEC 5 7UM85 (CP300) versions 7.80 through 9.79
SIPROTEC 5 7UT82 (CP100) versions 7.80 and later
SIPROTEC 5 7UT82 (CP150) versions prior to V9.80
SIPROTEC 5 7UT85 (CP300) versions 7.80 through 9.79
SIPROTEC 5 7UT86 (CP300) versions 7.80 through 9.79
SIPROTEC 5 7UT87 (CP300) versions 7.80 through 9.79
SIPROTEC 5 7VE85 (CP300) versions 7.80 through 9.79
SIPROTEC 5 7VK87 (CP300) versions 7.80 through 9.79
SIPROTEC 5 7VU85 (CP300) versions prior to V9.80
SIPROTEC 5 Compact 7SX800 (CP050) versions prior to V9.80
Description
The affected devices do not properly limit the path accessible via their webserver, allowing an authenticated remote attacker to read arbitrary files from the filesystem of affected devices.
Recommendations
For SIPROTEC 5 6MD84 (CP300) versions prior to V9.80, update to version V9.80 or later.
For SIPROTEC 5 6MD85 (CP300) versions 7.80 through 9.79, update to version V9.80 or later.
For SIPROTEC 5 6MD86 (CP300) versions 7.80 through 9.79, update to version V9.80 or later.
For SIPROTEC 5 6MD89 (CP300) versions 7.80 through 9.89, update to version V9.90 or later.
For SIPROTEC 5 6MU85 (CP300) versions 7.80 through 9.79, update to version V9.80 or later.
For SIPROTEC 5 7KE85 (CP300) versions 7.80 through 9.79, update to version V9.80 or later.
For SIPROTEC 5 7SA82 (CP100) versions 7.80 and later, restrict access to the webserver until a patch is available.
For SIPROTEC 5 7SA82 (CP150) versions prior to V9.80, update to version V9.80 or later.
For SIPROTEC 5 7SA86 (CP300) versions 7.80 through 9.79, update to version V9.80 or later.
For SIPROTEC 5 7SA87 (CP300) versions 7.80 through 9.79, update to version V9.80 or later.
For SIPROTEC 5 7SD82 (CP100) versions 7.80 and later, restrict access to the webserver until a patch is available.
For SIPROTEC 5 7SD82 (CP150) versions prior to V9.80, update to version V9.80 or later.
For SIPROTEC 5 7SD86 (CP300) versions 7.80 through 9.79, update to version V9.80 or later.
For SIPROTEC 5 7SD87 (CP300) versions 7.80 through 9.79, update to version V9.80 or later.
For SIPROTEC 5 7SJ81 (CP100) versions 7.80 and later, restrict access to the webserver until a patch is available.
For SIPROTEC 5 7SJ81 (CP150) versions prior to V9.80, update to version V9.80 or later.
For SIPROTEC 5 7SJ82 (CP100) versions 7.80 and later, restrict access to the webserver until a patch is available.
For SIPROTEC 5 7SJ82 (CP150) versions prior to V9.80, update to version V9.80 or later.
For SIPROTEC 5 7SJ85 (CP300) versions 7.80 through 9.79, update to version V9.80 or later.
For SIPROTEC 5 7SJ86 (CP300) versions 7.80 through 9.79, update to version V9.80 or later.
For SIPROTEC 5 7SK82 (CP100) versions 7.80 and later, restrict access to the webserver until a patch is available.
For SIPROTEC 5 7SK82 (CP150) versions prior to V9.80, update to version V9.80 or later.
For SIPROTEC 5 7SK85 (CP300) versions 7.80 through 9.79, update to version V9.80 or later.
For SIPROTEC 5 7SL82 (CP100) versions 7.80 and later, restrict access to the webserver until a patch is available.
For SIPROTEC 5 7SL82 (CP150) versions prior to V9.80, update to version V9.80 or later.
For SIPROTEC 5 7SL86 (CP300) versions 7.80 through 9.79, update to version V9.80 or later.
For SIPROTEC 5 7SL87 (CP300) versions 7.80 through 9.79, update to version V9.80 or later.
For SIPROTEC 5 7SS85 (CP300) versions 7.80 through 9.79, update to version V9.80 or later.
For SIPROTEC 5 7ST85 (CP300) versions prior to V9.80, update to version V9.80 or later.
For SIPROTEC 5 7ST86 (CP300) versions prior to V9.80, update to version V9.80 or later.
For SIPROTEC 5 7SX82 (CP150) versions prior to V9.80, update to version V9.80 or later.
For SIPROTEC 5 7SX85 (CP300) versions prior to V9.80, update to version V9.80 or later.
For SIPROTEC 5 7SY82 (CP150) versions prior to V9.80, update to version V9.80 or later.
For SIPROTEC 5 7UM85 (CP300) versions 7.80 through 9.79, update to version V9.80 or later.
For SIPROTEC 5 7UT82 (CP100) versions 7.80 and later, restrict access to the webserver until a patch is available.
For SIPROTEC 5 7UT82 (CP150) versions prior to V9.80, update to version V9.80 or later.
For SIPROTEC 5 7UT85 (CP300) versions 7.80 through 9.79, update to version V9.80 or later.
For SIPROTEC 5 7UT86 (CP300) versions 7.80 through 9.79, update to version V9.80 or later.
For SIPROTEC 5 7UT87 (CP300) versions 7.80 through 9.79, update to version V9.80 or later.
For SIPROTEC 5 7VE85 (CP300) versions 7.80 through 9.79, update to version V9.80 or later.
For SIPROTEC 5 7VK87 (CP300) versions 7.80 through 9.79, update to version V9.80 or later.
For SIPROTEC 5 7VU85 (CP300) versions prior to V9.80, update to version V9.80 or later.
For SIPROTEC 5 Compact 7SX800 (CP050) versions prior to V9.80, update to version V9.80 or later.
Fix
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Siprotec 5 6Md84
Siprotec 5 6Md85
Siprotec 5 6Md86
Siprotec 5 6Md89
Siprotec 5 7Ke85
Siprotec 5 7Sa82
Siprotec 5 7Sa86
Siprotec 5 7Sa87
Siprotec 5 7St86
Siprotec 5 7Sj81
Siprotec 5 7Sj85
Siprotec 5 7St85
Siprotec 5 7Um85
Siprotec 5 7Ut82
Siprotec 5 7Ut87
Siprotec 5 7Vk87
Siprotec 5 Compact 7Sx800