7.5
CWE
476
Advisory Published
Updated

CVE-2023-28766: Null Pointer Dereference

First published: Tue Apr 11 2023(Updated: )

A vulnerability has been identified in SIPROTEC 5 6MD85 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 6MD86 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 6MD89 (CP300) (All versions >= V7.80 < V9.60), SIPROTEC 5 6MU85 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 7KE85 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 7SA82 (CP100) (All versions), SIPROTEC 5 7SA82 (CP150) (All versions < V9.40), SIPROTEC 5 7SA86 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 7SA87 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 7SD82 (CP100) (All versions), SIPROTEC 5 7SD82 (CP150) (All versions < V9.40), SIPROTEC 5 7SD86 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 7SD87 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 7SJ81 (CP100) (All versions), SIPROTEC 5 7SJ81 (CP150) (All versions < V9.40), SIPROTEC 5 7SJ82 (CP100) (All versions), SIPROTEC 5 7SJ82 (CP150) (All versions < V9.40), SIPROTEC 5 7SJ85 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 7SJ86 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 7SK82 (CP100) (All versions), SIPROTEC 5 7SK82 (CP150) (All versions < V9.40), SIPROTEC 5 7SK85 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 7SL82 (CP100) (All versions), SIPROTEC 5 7SL82 (CP150) (All versions < V9.40), SIPROTEC 5 7SL86 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 7SL87 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 7SS85 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 7ST85 (CP300) (All versions >= V7.80 < V9.60), SIPROTEC 5 7ST86 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 7SX82 (CP150) (All versions < V9.40), SIPROTEC 5 7SX85 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 7UM85 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 7UT82 (CP100) (All versions), SIPROTEC 5 7UT82 (CP150) (All versions < V9.40), SIPROTEC 5 7UT85 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 7UT86 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 7UT87 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 7VE85 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 7VK87 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 7VU85 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 Communication Module ETH-BA-2EL (All versions < V9.40), SIPROTEC 5 Communication Module ETH-BB-2FO (All versions < V9.40), SIPROTEC 5 Communication Module ETH-BD-2FO (All versions < V9.40), SIPROTEC 5 Compact 7SX800 (CP050) (All versions < V9.40). Affected devices lack proper validation of http request parameters of the hosted web service. An unauthenticated remote attacker could send specially crafted packets that could cause denial of service condition of the target device.

Credit: productcert@siemens.com

Affected SoftwareAffected VersionHow to fix
All of
Siemens 6md85=cp200
Siemens SIPROTEC 5 6MD85 firmware
All of
Siemens 6md85=cp300
Siemens SIPROTEC 5 6MD85 firmware<9.40
All of
Siemens SIPROTEC 5 6MD86 firmware=cp200
Siemens SIPROTEC 5 6MD86
All of
Siemens SIPROTEC 5 6MD86 firmware=cp300
Siemens SIPROTEC 5 6MD86<9.40
All of
Siemens SIPROTEC 5 6MD89 firmware=cp300
Siemens SIPROTEC 5 6MD89
All of
Siemens SIPROTEC 5 6MU85 Firmware=cp300
Siemens SIPROTEC 5 6MU85<9.40
All of
Siemens SIPROTEC 5 7KE85 Firmware=cp200
Siemens SIPROTEC 5 Firmware
All of
Siemens SIPROTEC 5 7KE85 Firmware=cp300
Siemens SIPROTEC 5 Firmware<9.40
All of
Siemens SIPROTEC 5=cp100
Siemens SIPROTEC 5 7SA82
All of
Siemens SIPROTEC 5=cp150
Siemens SIPROTEC 5 7SA82<9.40
All of
Siemens SIPROTEC 5 7SA86 Firmware=cp200
Siemens SIPROTEC 5 7SA86 Firmware
All of
Siemens SIPROTEC 5 7SA86 Firmware=cp300
Siemens SIPROTEC 5 7SA86 Firmware<9.40
All of
Siemens SIPROTEC 5 7SA87 Firmware=cp200
Siemens SIPROTEC 5 7SA87
All of
Siemens SIPROTEC 5 7SA87 Firmware=cp300
Siemens SIPROTEC 5 7SA87<9.40
All of
Siemens SIPROTEC 5 Firmware=cp100
Siemens Siprotec 5 7sd82
All of
Siemens SIPROTEC 5 Firmware=cp150
Siemens Siprotec 5 7sd82<9.40
All of
Siemens SIPROTEC 5 7SD86
Siemens SIPROTEC 5 7SD86 firmware=cp200
All of
Siemens SIPROTEC 5 7SD86<9.40
Siemens SIPROTEC 5 7SD86 firmware=cp300
All of
Siemens SIPROTEC 5 Firmware
Siemens 7SD87=cp200
All of
Siemens SIPROTEC 5 Firmware<9.40
Siemens 7SD87=cp300
All of
Siemens SIPROTEC 5 7SJ81
siemens SIPROTEC compact model 7sj81=cp100
All of
Siemens SIPROTEC 5 7SJ81<9.40
siemens SIPROTEC compact model 7sj81=cp150
All of
Siemens SIPROTEC 5 7SJ82 firmware
Siemens SIPROTEC 5 Firmware=cp100
All of
Siemens SIPROTEC 5 7SJ82 firmware<9.40
Siemens SIPROTEC 5 Firmware=cp150
All of
Siemens SIPROTEC 5 7SJ85 firmware
Siemens SIPROTEC 5 7SJ85 firmware=cp200
All of
Siemens SIPROTEC 5 7SJ85 firmware<9.40
Siemens SIPROTEC 5 7SJ85 firmware=cp300
All of
Siemens SIPROTEC 5 7SJ86
Siemens SIPROTEC 5 7SJ86 (CP300)=cp200
All of
Siemens SIPROTEC 5 7SJ86<9.40
Siemens SIPROTEC 5 7SJ86 (CP300)=cp300
All of
Siemens SIPROTEC 5 7SK82 Firmware
Siemens SIPROTEC 5 7SK82 Firmware=cp100
All of
Siemens SIPROTEC 5 7SK82 Firmware<9.40
Siemens SIPROTEC 5 7SK82 Firmware=cp150
All of
Siemens SIPROTEC 5 7SK85
Siemens SIPROTEC 5=cp200
All of
Siemens SIPROTEC 5 7SK85<9.40
Siemens SIPROTEC 5=cp300
All of
Siemens SIPROTEC 5 7SL82
Siemens SIPROTEC 5 7SL82 Firmware=cp100
All of
Siemens SIPROTEC 5 7SL82<9.40
Siemens SIPROTEC 5 7SL82 Firmware=cp150
All of
Siemens SIPROTEC 5 7SL86
Siemens SIPROTEC 5 7SL86 firmware=cp200
All of
Siemens SIPROTEC 5 7SL86<9.40
Siemens SIPROTEC 5 7SL86 firmware=cp300
All of
siemens SIPROTEC 5 7SL87 firmware
Siemens SIPROTEC 5 7SL87 (CP200)=cp200
All of
siemens SIPROTEC 5 7SL87 firmware<9.40
Siemens SIPROTEC 5 7SL87 (CP200)=cp300
All of
Siemens SIPROTEC 5 Firmware
Siemens SIPROTEC 5=cp200
All of
Siemens SIPROTEC 5 Firmware<9.40
Siemens SIPROTEC 5=cp300
All of
Siemens SIPROTEC 5 7ST85
Siemens SIPROTEC 5 7ST85 (CP300)=cp200
All of
Siemens SIPROTEC 5 7ST85
Siemens SIPROTEC 5 7ST85 (CP300)=cp300
All of
Siemens SIPROTEC 5 7SX85<9.40
Siemens SIPROTEC 5=cp300
All of
Siemens SIPROTEC 5 7UM85 Firmware<9.40
Siemens 7UM85=cp300
All of
Siemens SIPROTEC 5 Firmware
Siemens SIPROTEC 5 7UT82 firmware=cp100
All of
Siemens SIPROTEC 5 Firmware<9.40
Siemens SIPROTEC 5 7UT82 firmware=cp150
All of
Siemens SIPROTEC 5 7UT85
Siemens SIPROTEC 5=cp200
All of
Siemens SIPROTEC 5 7UT85<9.40
Siemens SIPROTEC 5=cp300
All of
Siemens SIPROTEC 5 7UT86
Siemens SIPROTEC 5 7UT86 (CP200)=cp200
All of
Siemens SIPROTEC 5 7UT86<9.40
Siemens SIPROTEC 5 7UT86 (CP200)=cp300
All of
Siemens SIPROTEC 5 7UT87
Siemens SIPROTEC 5 7UT87 firmware=cp200
All of
Siemens SIPROTEC 5 7UT87<9.40
Siemens SIPROTEC 5 7UT87 firmware=cp300
All of
siemens SIPROTEC 5 7VE85<9.40
siemens SIPROTEC 5 7VE85 firmware=cp300
All of
Siemens SIPROTEC 5 7VK87
Siemens SIPROTEC 5 7VK87=cp200
All of
Siemens SIPROTEC 5 7VK87<9.40
Siemens SIPROTEC 5 7VK87=cp300
All of
Siemens SIPROTEC 5 Communication Module ethba2el firmware<9.40
Siemens SIPROTEC 5 Communication Module ETH-BA-2EL
All of
Siemens SIPROTEC 5 Communication Module ETH-BB-2FO<9.40
Siemens SIPROTEC 5 Communication Module ETH-BB-2FO
All of
Siemens SIPROTEC 5 Communication Module ETH-BD-2FO<9.40
Siemens SIPROTEC 5 Communication Module ETH-BD-2FO
All of
Siemens SIPROTEC 5 Compact 7SX800<9.40
Siemens SIPROTEC 5 Compact 7SX800=cp050
All of
Siemens SIPROTEC 5 7SA84
Siemens SIPROTEC 5 7SA84 Firmware=cp200
All of
Siemens SIPROTEC 5 7SD84
Siemens SIPROTEC 5 7SD84 Firmware=cp200
All of
Siemens SIPROTEC 5 7ST86 Firmware
Siemens SIPROTEC 5=cp300
All of
Siemens SIPROTEC 5 7SX82<9.40
Siemens SIPROTEC 5=cp150
All of
siemens SIPROTEC 5 7VU85 firmware<9.40
Siemens SIPROTEC 5=cp300
Siemens SIPROTEC 5 6MD85 firmware
Siemens 6md85=cp200
Siemens SIPROTEC 5 6MD85 firmware<9.40
Siemens 6md85=cp300
Siemens SIPROTEC 5 6MD86
Siemens SIPROTEC 5 6MD86 firmware=cp200
Siemens SIPROTEC 5 6MD86<9.40
Siemens SIPROTEC 5 6MD86 firmware=cp300
Siemens SIPROTEC 5 6MD89
Siemens SIPROTEC 5 6MD89 firmware=cp300
Siemens SIPROTEC 5 6MU85<9.40
Siemens SIPROTEC 5 6MU85 Firmware=cp300
Siemens SIPROTEC 5 Firmware
Siemens SIPROTEC 5 7KE85 Firmware=cp200
Siemens SIPROTEC 5 Firmware<9.40
Siemens SIPROTEC 5 7KE85 Firmware=cp300
Siemens SIPROTEC 5 7SA82
Siemens SIPROTEC 5=cp100
Siemens SIPROTEC 5 7SA82<9.40
Siemens SIPROTEC 5=cp150
Siemens SIPROTEC 5 7SA86 Firmware
Siemens SIPROTEC 5 7SA86 Firmware=cp200
Siemens SIPROTEC 5 7SA86 Firmware<9.40
Siemens SIPROTEC 5 7SA86 Firmware=cp300
Siemens SIPROTEC 5 7SA87
Siemens SIPROTEC 5 7SA87 Firmware=cp200
Siemens SIPROTEC 5 7SA87<9.40
Siemens SIPROTEC 5 7SA87 Firmware=cp300
Siemens Siprotec 5 7sd82
Siemens SIPROTEC 5 Firmware=cp100
Siemens Siprotec 5 7sd82<9.40
Siemens SIPROTEC 5 Firmware=cp150
Siemens SIPROTEC 5 7SD86
Siemens SIPROTEC 5 7SD86 firmware=cp200
Siemens SIPROTEC 5 7SD86<9.40
Siemens SIPROTEC 5 7SD86 firmware=cp300
Siemens SIPROTEC 5 Firmware
Siemens 7SD87=cp200
Siemens SIPROTEC 5 Firmware<9.40
Siemens 7SD87=cp300
Siemens SIPROTEC 5 7SJ81
siemens SIPROTEC compact model 7sj81=cp100
Siemens SIPROTEC 5 7SJ81<9.40
siemens SIPROTEC compact model 7sj81=cp150
Siemens SIPROTEC 5 7SJ82 firmware
Siemens SIPROTEC 5 Firmware=cp100
Siemens SIPROTEC 5 7SJ82 firmware<9.40
Siemens SIPROTEC 5 Firmware=cp150
Siemens SIPROTEC 5 7SJ85 firmware
Siemens SIPROTEC 5 7SJ85 firmware=cp200
Siemens SIPROTEC 5 7SJ85 firmware<9.40
Siemens SIPROTEC 5 7SJ85 firmware=cp300
Siemens SIPROTEC 5 7SJ86
Siemens SIPROTEC 5 7SJ86 (CP300)=cp200
Siemens SIPROTEC 5 7SJ86<9.40
Siemens SIPROTEC 5 7SJ86 (CP300)=cp300
Siemens SIPROTEC 5 7SK82 Firmware
Siemens SIPROTEC 5 7SK82 Firmware=cp100
Siemens SIPROTEC 5 7SK82 Firmware<9.40
Siemens SIPROTEC 5 7SK82 Firmware=cp150
Siemens SIPROTEC 5 7SK85
Siemens SIPROTEC 5=cp200
Siemens SIPROTEC 5 7SK85<9.40
Siemens SIPROTEC 5=cp300
Siemens SIPROTEC 5 7SL82
Siemens SIPROTEC 5 7SL82 Firmware=cp100
Siemens SIPROTEC 5 7SL82<9.40
Siemens SIPROTEC 5 7SL82 Firmware=cp150
Siemens SIPROTEC 5 7SL86
Siemens SIPROTEC 5 7SL86 firmware=cp200
Siemens SIPROTEC 5 7SL86<9.40
Siemens SIPROTEC 5 7SL86 firmware=cp300
siemens SIPROTEC 5 7SL87 firmware
Siemens SIPROTEC 5 7SL87 (CP200)=cp200
siemens SIPROTEC 5 7SL87 firmware<9.40
Siemens SIPROTEC 5 7SL87 (CP200)=cp300
Siemens SIPROTEC 5 Firmware
Siemens SIPROTEC 5=cp200
Siemens SIPROTEC 5 Firmware<9.40
Siemens SIPROTEC 5=cp300
Siemens SIPROTEC 5 7ST85
Siemens SIPROTEC 5 7ST85 (CP300)=cp200
Siemens SIPROTEC 5 7ST85 (CP300)=cp300
Siemens SIPROTEC 5 7SX85<9.40
Siemens SIPROTEC 5=cp300
Siemens SIPROTEC 5 7UM85 Firmware<9.40
Siemens 7UM85=cp300
Siemens SIPROTEC 5 Firmware
Siemens SIPROTEC 5 7UT82 firmware=cp100
Siemens SIPROTEC 5 Firmware<9.40
Siemens SIPROTEC 5 7UT82 firmware=cp150
Siemens SIPROTEC 5 7UT85
Siemens SIPROTEC 5=cp200
Siemens SIPROTEC 5 7UT85<9.40
Siemens SIPROTEC 5=cp300
Siemens SIPROTEC 5 7UT86
Siemens SIPROTEC 5 7UT86 (CP200)=cp200
Siemens SIPROTEC 5 7UT86<9.40
Siemens SIPROTEC 5 7UT86 (CP200)=cp300
Siemens SIPROTEC 5 7UT87
Siemens SIPROTEC 5 7UT87 firmware=cp200
Siemens SIPROTEC 5 7UT87<9.40
Siemens SIPROTEC 5 7UT87 firmware=cp300
siemens SIPROTEC 5 7VE85<9.40
siemens SIPROTEC 5 7VE85 firmware=cp300
Siemens SIPROTEC 5 7VK87
Siemens SIPROTEC 5 7VK87=cp200
Siemens SIPROTEC 5 7VK87<9.40
Siemens SIPROTEC 5 7VK87=cp300
Siemens SIPROTEC 5 Communication Module ethba2el firmware<9.40
Siemens SIPROTEC 5 Communication Module ETH-BA-2EL
Siemens SIPROTEC 5 Communication Module ETH-BB-2FO<9.40
Siemens SIPROTEC 5 Communication Module ETH-BB-2FO
Siemens SIPROTEC 5 Communication Module ETH-BD-2FO<9.40
Siemens SIPROTEC 5 Communication Module ETH-BD-2FO
Siemens SIPROTEC 5 Compact 7SX800<9.40
Siemens SIPROTEC 5 Compact 7SX800=cp050
Siemens SIPROTEC 5 7SA84
Siemens SIPROTEC 5 7SA84 Firmware=cp200
Siemens SIPROTEC 5 7SD84
Siemens SIPROTEC 5 7SD84 Firmware=cp200
Siemens SIPROTEC 5 7ST86 Firmware
Siemens SIPROTEC 5=cp300
Siemens SIPROTEC 5 7SX82<9.40
Siemens SIPROTEC 5=cp150
siemens SIPROTEC 5 7VU85 firmware<9.40
Siemens SIPROTEC 5=cp300

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2023-28766?

    The severity of CVE-2023-28766 is classified as critical.

  • How do I fix CVE-2023-28766?

    To fix CVE-2023-28766, update the affected Siemens SIPROTEC 5 firmware to versions 9.40 or later.

  • What products are affected by CVE-2023-28766?

    CVE-2023-28766 affects various models including SIPROTEC 5 6MD85, 6MD86, 6MD89, 6MU85, and 7KE85 with firmware versions prior to 9.40.

  • Can CVE-2023-28766 be exploited remotely?

    Yes, CVE-2023-28766 can potentially be exploited remotely, allowing unauthorized access to the affected systems.

  • What impact does CVE-2023-28766 have on systems?

    The impact of CVE-2023-28766 may include unauthorized control or disruption of the affected Siemens SIPROTEC 5 devices.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203