First published: Tue Sep 14 2021(Updated: )
A vulnerability has been identified in SIPROTEC 5 relays with CPU variants CP050 (All versions < V8.80), SIPROTEC 5 relays with CPU variants CP100 (All versions < V8.80), SIPROTEC 5 relays with CPU variants CP300 (All versions < V8.80). Specially crafted packets sent to port 4443/tcp could cause a Denial-of-Service condition.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens SIPROTEC 5 | <8.80 | |
Siemens SIPROTEC 5 with CPU variant CP100 | <8.80 | |
Siemens SIPROTEC 5 with CPU variant CP300 | <8.80 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-33720 is a vulnerability identified in SIPROTEC 5 relays with CPU variants CP050, CP100, and CP300. Specially crafted packets sent to port 4443/tcp could cause a DoS condition.
CVE-2021-33720 affects Siemens SIPROTEC 5 relays with CPU variants CP050, CP100, and CP300. It allows an attacker to cause a DoS condition by sending specially crafted packets to port 4443/tcp.
The severity of CVE-2021-33720 is high, with a severity value of 7.5.
To fix CVE-2021-33720, Siemens recommends updating the affected SIPROTEC 5 relays to version 8.80 or higher.
You can find more information about CVE-2021-33720 in the Siemens ProductCERT advisory at https://cert-portal.siemens.com/productcert/pdf/ssa-847986.pdf.