First published: Tue Jan 14 2025(Updated: )
A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.80), SIPROTEC 5 6MD85 (CP300) (All versions >= V7.80 < V9.80), SIPROTEC 5 6MD86 (CP300) (All versions >= V7.80 < V9.80), SIPROTEC 5 6MD89 (CP300) (All versions >= V7.80 < V9.90), SIPROTEC 5 6MU85 (CP300) (All versions >= V7.80 < V9.80), SIPROTEC 5 7KE85 (CP300) (All versions >= V7.80 < V9.80), SIPROTEC 5 7SA82 (CP100) (All versions >= V7.80), SIPROTEC 5 7SA82 (CP150) (All versions < V9.80), SIPROTEC 5 7SA86 (CP300) (All versions >= V7.80 < V9.80), SIPROTEC 5 7SA87 (CP300) (All versions >= V7.80 < V9.80), SIPROTEC 5 7SD82 (CP100) (All versions >= V7.80), SIPROTEC 5 7SD82 (CP150) (All versions < V9.80), SIPROTEC 5 7SD86 (CP300) (All versions >= V7.80 < V9.80), SIPROTEC 5 7SD87 (CP300) (All versions >= V7.80 < V9.80), SIPROTEC 5 7SJ81 (CP100) (All versions >= V7.80), SIPROTEC 5 7SJ81 (CP150) (All versions < V9.80), SIPROTEC 5 7SJ82 (CP100) (All versions >= V7.80), SIPROTEC 5 7SJ82 (CP150) (All versions < V9.80), SIPROTEC 5 7SJ85 (CP300) (All versions >= V7.80 < V9.80), SIPROTEC 5 7SJ86 (CP300) (All versions >= V7.80 < V9.80), SIPROTEC 5 7SK82 (CP100) (All versions >= V7.80), SIPROTEC 5 7SK82 (CP150) (All versions < V9.80), SIPROTEC 5 7SK85 (CP300) (All versions >= V7.80 < V9.80), SIPROTEC 5 7SL82 (CP100) (All versions >= V7.80), SIPROTEC 5 7SL82 (CP150) (All versions < V9.80), SIPROTEC 5 7SL86 (CP300) (All versions >= V7.80 < V9.80), SIPROTEC 5 7SL87 (CP300) (All versions >= V7.80 < V9.80), SIPROTEC 5 7SS85 (CP300) (All versions >= V7.80 < V9.80), SIPROTEC 5 7ST85 (CP300) (All versions), SIPROTEC 5 7ST86 (CP300) (All versions < V9.80), SIPROTEC 5 7SX82 (CP150) (All versions < V9.80), SIPROTEC 5 7SX85 (CP300) (All versions < V9.80), SIPROTEC 5 7SY82 (CP150) (All versions < V9.80), SIPROTEC 5 7UM85 (CP300) (All versions >= V7.80 < V9.80), SIPROTEC 5 7UT82 (CP100) (All versions >= V7.80), SIPROTEC 5 7UT82 (CP150) (All versions < V9.80), SIPROTEC 5 7UT85 (CP300) (All versions >= V7.80 < V9.80), SIPROTEC 5 7UT86 (CP300) (All versions >= V7.80 < V9.80), SIPROTEC 5 7UT87 (CP300) (All versions >= V7.80 < V9.80), SIPROTEC 5 7VE85 (CP300) (All versions >= V7.80 < V9.80), SIPROTEC 5 7VK87 (CP300) (All versions >= V7.80 < V9.80), SIPROTEC 5 7VU85 (CP300) (All versions < V9.80), SIPROTEC 5 Compact 7SX800 (CP050) (All versions < V9.80). Affected devices do not properly limit the path accessible via their webserver. This could allow an authenticated remote attacker to read arbitrary files from the filesystem of affected devices.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens SIPROTEC 5 | <9.80 | |
Siemens 6md85 | >=7.80<9.80 | |
Siemens SIPROTEC 5 6MD86 firmware | >=7.80<9.80 | |
Siemens SIPROTEC 5 6MD89 firmware | >=7.80<9.90 | |
Siemens SIPROTEC 5 6MU85 Firmware | >=7.80<9.80 | |
Siemens SIPROTEC 5 7KE85 Firmware | >=7.80<9.80 | |
Siemens SIPROTEC 5 | >=7.80 | |
Siemens SIPROTEC 5 | <9.80 | |
Siemens SIPROTEC 5 7SA86 Firmware | >=7.80<9.80 | |
Siemens SIPROTEC 5 7SA87 Firmware | >=7.80<9.80 | |
Siemens SIPROTEC 5 Firmware | >=7.80 | |
Siemens SIPROTEC 5 Firmware | <9.80 | |
Siemens SIPROTEC 5 7SD86 firmware | >=7.80<9.80 | |
Siemens 7SD87 | >=7.80<9.80 | |
siemens SIPROTEC compact model 7sj81 | >=7.80 | |
siemens SIPROTEC compact model 7sj81 | <9.80 | |
Siemens SIPROTEC 5 Firmware | >=7.80 | |
Siemens SIPROTEC 5 Firmware | <9.80 | |
Siemens SIPROTEC 5 7SJ85 firmware | >=7.80<9.80 | |
Siemens SIPROTEC 5 7SJ86 (CP300) | >=7.80<9.80 | |
Siemens SIPROTEC 5 7SK82 Firmware | >=7.80 | |
Siemens SIPROTEC 5 7SK82 Firmware | <9.80 | |
Siemens SIPROTEC 5 | >=7.80<9.80 | |
Siemens SIPROTEC 5 7SL82 Firmware | >=7.80 | |
Siemens SIPROTEC 5 7SL82 Firmware | <9.80 | |
Siemens SIPROTEC 5 7SL86 firmware | >=7.80<9.80 | |
Siemens SIPROTEC 5 7SL87 (CP200) | >=7.80<9.80 | |
Siemens SIPROTEC 5 | >=7.80<9.80 | |
Siemens SIPROTEC 5 7ST85 (CP300) | ||
Siemens SIPROTEC 5 | <9.80 | |
Siemens SIPROTEC 5 | <9.80 | |
Siemens SIPROTEC 5 | <9.80 | |
Siemens SIPROTEC 5 | <9.80 | |
Siemens 7UM85 | >=7.80<9.80 | |
Siemens SIPROTEC 5 7UT82 firmware | >=7.80 | |
Siemens SIPROTEC 5 7UT82 firmware | <9.80 | |
Siemens SIPROTEC 5 | >=7.80<9.80 | |
Siemens SIPROTEC 5 7UT86 (CP200) | >=7.80<9.80 | |
Siemens SIPROTEC 5 7UT87 firmware | >=7.80<9.80 | |
siemens SIPROTEC 5 7VE85 firmware | >=7.80<9.80 | |
Siemens SIPROTEC 5 7VK87 | >=7.80<9.80 | |
Siemens SIPROTEC 5 | <9.80 | |
Siemens SIPROTEC 5 Compact 7SX800 | <9.80 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-53649 is rated as high due to its potential impact on security in affected systems.
To fix CVE-2024-53649, update affected Siemens SIPROTEC 5 devices to version 9.80 or later.
CVE-2024-53649 affects all versions of Siemens SIPROTEC 5 6MD84 prior to 9.80 and 6MD85/6MD86 from version 7.80 up to but not including 9.80.
Devices impacted by CVE-2024-53649 include various models of Siemens SIPROTEC 5 series such as 6MD84, 6MD85, and others.
Currently, the recommended action for CVE-2024-53649 is to upgrade to the latest software version, as there are no documented workarounds.