CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Siemens SIPROTEC 5 Using DIGSI5 Protocol

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 281

As cited

Copy frozen at (site build).

vulnerabilities

Siemens SIPROTEC 5 Using DIGSI5 Protocol

Siemens SIPROTEC 5 devices using the DIGSI 5 protocol are vulnerable to arbitrary file uploads by authenticated users, which could result in denial of service or code execution. Siemens recommends upgrading affected device models to specific patched versions: CP050 and CP150 models to version 9.90 or later, CP300 models 7ST85 and 7ST86 to version 10.00 or later, and other CP300 models to version 9.90 or later. The vulnerability affects dozens of SIPROTEC 5 device models across critical infrastructure sectors including energy, manufacturing, and transportation.

Why it matters: Authenticated file upload could cause denial of service in critical infrastructure protection relays; organizations should prioritize patching based on their device models and current versions.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Siemens SIPROTEC 5 Using DIGSI5 Protocol

Siemens SIPROTEC 5 devices using the DIGSI 5 protocol are vulnerable to arbitrary file uploads by authenticated users, which could result in denial of service or code execution. Siemens recommends upgrading affected device models to specific patched versions: CP050 and CP150 models to version 9.90 or later, CP300 models 7ST85 and 7ST86 to version 10.00 or later, and other CP300 models to version 9.90 or later. The vulnerability affects dozens of SIPROTEC 5 device models across critical infrastructure sectors including energy, manufacturing, and transportation.

Why it matters: Authenticated file upload could cause denial of service in critical infrastructure protection relays; organizations should prioritize patching based on their device models and current versions.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary