Siemens has an update available to handle an improper input validation vulnerability in its SIPROTEC 5 products, according to a report with CISA.

Successful exploitation of this remotely exploitable vulnerability, which Siemens self-reported, could allow an unauthenticated attacker to read device information.

Siemens reports this vulnerability affects the following SIPROTEC 5 products:

  • Devices with the hardware variants CP050, CP100, and CP300
  • A full list of the affected devices was published in the Siemens Security Advisory SSA-439673

In the issue, there is an improper input validation vulnerability in the web server that could allow an unauthenticated user to access device information.

Schneider Bold

CVE-2021-41769 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 6.5.

The product sees use mainly in the energy sector, and on a global basis.

No known public exploits specifically target this vulnerability. However, an attacker with low skill level could leverage this low complexity vulnerability.

Siemens recommends updating to v8.83 or later versions.

Siemens recommends applying the provided security updates using the corresponding tooling and documented procedures made available with the product. If supported by the product, an automated means to apply the security updates across multiple product instances may be used. Siemens recommends prior validation of any security update, and supervision by trained staff of the update process in the target environment.

As a general security measure Siemens recommends protecting network access with appropriate mechanisms (e.g., firewalls, segmentation, VPN). Siemens also encourages users to configure the environment according to Siemens operational guidelines for industrial security in order to run the devices in a protected IT environment.

Siemens also recommends following security guidelines for Digital Grid Products.

For additional information, click on Siemens Security Advisory SSA-439673.

ISSSource

Pin It on Pinterest

Share This