CVE-2024-38867

Description

A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.64), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP300) (All versions < V9.64), SIPROTEC 5 6MD86 (CP200) (All versions), SIPROTEC 5 6MD86 (CP300) (All versions < V9.64), SIPROTEC 5 6MD89 (CP300) (All versions < V9.64), SIPROTEC 5 6MU85 (CP300) (All versions < V9.64), SIPROTEC 5 7KE85 (CP200) (All versions), SIPROTEC 5 7KE85 (CP300) (All versions < V9.64), SIPROTEC 5 7SA82 (CP100) (All versions), SIPROTEC 5 7SA82 (CP150) (All versions < V9.65), SIPROTEC 5 7SA84 (CP200) (All versions), SIPROTEC 5 7SA86 (CP200) (All versions), SIPROTEC 5 7SA86 (CP300) (All versions < V9.65), SIPROTEC 5 7SA87 (CP200) (All versions), SIPROTEC 5 7SA87 (CP300) (All versions < V9.65), SIPROTEC 5 7SD82 (CP100) (All versions), SIPROTEC 5 7SD82 (CP150) (All versions < V9.65), SIPROTEC 5 7SD84 (CP200) (All versions), SIPROTEC 5 7SD86 (CP200) (All versions), SIPROTEC 5 7SD86 (CP300) (All versions < V9.65), SIPROTEC 5 7SD87 (CP200) (All versions), SIPROTEC 5 7SD87 (CP300) (All versions < V9.65), SIPROTEC 5 7SJ81 (CP100) (All versions < V8.89), SIPROTEC 5 7SJ81 (CP150) (All versions < V9.65), SIPROTEC 5 7SJ82 (CP100) (All versions < V8.89), SIPROTEC 5 7SJ82 (CP150) (All versions < V9.65), SIPROTEC 5 7SJ85 (CP200) (All versions), SIPROTEC 5 7SJ85 (CP300) (All versions < V9.65), SIPROTEC 5 7SJ86 (CP200) (All versions), SIPROTEC 5 7SJ86 (CP300) (All versions < V9.65), SIPROTEC 5 7SK82 (CP100) (All versions < V8.89), SIPROTEC 5 7SK82 (CP150) (All versions < V9.65), SIPROTEC 5 7SK85 (CP200) (All versions), SIPROTEC 5 7SK85 (CP300) (All versions < V9.65), SIPROTEC 5 7SL82 (CP100) (All versions), SIPROTEC 5 7SL82 (CP150) (All versions < V9.65), SIPROTEC 5 7SL86 (CP200) (All versions), SIPROTEC 5 7SL86 (CP300) (All versions < V9.65), SIPROTEC 5 7SL87 (CP200) (All versions), SIPROTEC 5 7SL87 (CP300) (All versions < V9.65), SIPROTEC 5 7SS85 (CP200) (All versions), SIPROTEC 5 7SS85 (CP300) (All versions < V9.64), SIPROTEC 5 7ST85 (CP200) (All versions), SIPROTEC 5 7ST85 (CP300) (All versions < V9.64), SIPROTEC 5 7ST86 (CP300) (All versions < V9.64), SIPROTEC 5 7SX82 (CP150) (All versions < V9.65), SIPROTEC 5 7SX85 (CP300) (All versions < V9.65), SIPROTEC 5 7UM85 (CP300) (All versions < V9.64), SIPROTEC 5 7UT82 (CP100) (All versions), SIPROTEC 5 7UT82 (CP150) (All versions < V9.65), SIPROTEC 5 7UT85 (CP200) (All versions), SIPROTEC 5 7UT85 (CP300) (All versions < V9.65), SIPROTEC 5 7UT86 (CP200) (All versions), SIPROTEC 5 7UT86 (CP300) (All versions < V9.65), SIPROTEC 5 7UT87 (CP200) (All versions), SIPROTEC 5 7UT87 (CP300) (All versions < V9.65), SIPROTEC 5 7VE85 (CP300) (All versions < V9.64), SIPROTEC 5 7VK87 (CP200) (All versions), SIPROTEC 5 7VK87 (CP300) (All versions < V9.65), SIPROTEC 5 7VU85 (CP300) (All versions < V9.64), SIPROTEC 5 Communication Module ETH-BA-2EL (Rev.1) (All versions < V9.62 installed on CP150 and CP300 devices), SIPROTEC 5 Communication Module ETH-BA-2EL (Rev.1) (All versions installed on CP200 devices), SIPROTEC 5 Communication Module ETH-BA-2EL (Rev.1) (All versions < V8.89 installed on CP100 devices), SIPROTEC 5 Communication Module ETH-BB-2FO (Rev. 1) (All versions installed on CP200 devices), SIPROTEC 5 Communication Module ETH-BB-2FO (Rev. 1) (All versions < V9.62 installed on CP150 and CP300 devices), SIPROTEC 5 Communication Module ETH-BB-2FO (Rev. 1) (All versions < V8.89 installed on CP100 devices), SIPROTEC 5 Communication Module ETH-BD-2FO (All versions < V9.62), SIPROTEC 5 Compact 7SX800 (CP050) (All versions < V9.64). The affected devices are supporting weak ciphers on several ports (443/tcp for web, 4443/tcp for DIGSI 5 and configurable port for syslog over TLS). This could allow an unauthorized attacker in a man-in-the-middle position to decrypt any data passed over to and from those ports.

Category

8.2
CVSS
Severity: High
CVSS 4.0 •
CVSS 3.1 •
EPSS 0.06%
Affected: Siemens SIPROTEC 5 6MD84 (CP300)
Affected: Siemens SIPROTEC 5 6MD85 (CP200)
Affected: Siemens SIPROTEC 5 6MD85 (CP300)
Affected: Siemens SIPROTEC 5 6MD86 (CP200)
Affected: Siemens SIPROTEC 5 6MD86 (CP300)
Affected: Siemens SIPROTEC 5 6MD89 (CP300)
Affected: Siemens SIPROTEC 5 6MU85 (CP300)
Affected: Siemens SIPROTEC 5 7KE85 (CP200)
Affected: Siemens SIPROTEC 5 7KE85 (CP300)
Affected: Siemens SIPROTEC 5 7SA82 (CP100)
Affected: Siemens SIPROTEC 5 7SA82 (CP150)
Affected: Siemens SIPROTEC 5 7SA84 (CP200)
Affected: Siemens SIPROTEC 5 7SA86 (CP200)
Affected: Siemens SIPROTEC 5 7SA86 (CP300)
Affected: Siemens SIPROTEC 5 7SA87 (CP200)
Affected: Siemens SIPROTEC 5 7SA87 (CP300)
Affected: Siemens SIPROTEC 5 7SD82 (CP100)
Affected: Siemens SIPROTEC 5 7SD82 (CP150)
Affected: Siemens SIPROTEC 5 7SD84 (CP200)
Affected: Siemens SIPROTEC 5 7SD86 (CP200)
Affected: Siemens SIPROTEC 5 7SD86 (CP300)
Affected: Siemens SIPROTEC 5 7SD87 (CP200)
Affected: Siemens SIPROTEC 5 7SD87 (CP300)
Affected: Siemens SIPROTEC 5 7SJ81 (CP100)
Affected: Siemens SIPROTEC 5 7SJ81 (CP150)
Affected: Siemens SIPROTEC 5 7SJ82 (CP100)
Affected: Siemens SIPROTEC 5 7SJ82 (CP150)
Affected: Siemens SIPROTEC 5 7SJ85 (CP200)
Affected: Siemens SIPROTEC 5 7SJ85 (CP300)
Affected: Siemens SIPROTEC 5 7SJ86 (CP200)
Affected: Siemens SIPROTEC 5 7SJ86 (CP300)
Affected: Siemens SIPROTEC 5 7SK82 (CP100)
Affected: Siemens SIPROTEC 5 7SK82 (CP150)
Affected: Siemens SIPROTEC 5 7SK85 (CP200)
Affected: Siemens SIPROTEC 5 7SK85 (CP300)
Affected: Siemens SIPROTEC 5 7SL82 (CP100)
Affected: Siemens SIPROTEC 5 7SL82 (CP150)
Affected: Siemens SIPROTEC 5 7SL86 (CP200)
Affected: Siemens SIPROTEC 5 7SL86 (CP300)
Affected: Siemens SIPROTEC 5 7SL87 (CP200)
Affected: Siemens SIPROTEC 5 7SL87 (CP300)
Affected: Siemens SIPROTEC 5 7SS85 (CP200)
Affected: Siemens SIPROTEC 5 7SS85 (CP300)
Affected: Siemens SIPROTEC 5 7ST85 (CP200)
Affected: Siemens SIPROTEC 5 7ST85 (CP300)
Affected: Siemens SIPROTEC 5 7ST86 (CP300)
Affected: Siemens SIPROTEC 5 7SX82 (CP150)
Affected: Siemens SIPROTEC 5 7SX85 (CP300)
Affected: Siemens SIPROTEC 5 7UM85 (CP300)
Affected: Siemens SIPROTEC 5 7UT82 (CP100)
Affected: Siemens SIPROTEC 5 7UT82 (CP150)
Affected: Siemens SIPROTEC 5 7UT85 (CP200)
Affected: Siemens SIPROTEC 5 7UT85 (CP300)
Affected: Siemens SIPROTEC 5 7UT86 (CP200)
Affected: Siemens SIPROTEC 5 7UT86 (CP300)
Affected: Siemens SIPROTEC 5 7UT87 (CP200)
Affected: Siemens SIPROTEC 5 7UT87 (CP300)
Affected: Siemens SIPROTEC 5 7VE85 (CP300)
Affected: Siemens SIPROTEC 5 7VK87 (CP200)
Affected: Siemens SIPROTEC 5 7VK87 (CP300)
Affected: Siemens SIPROTEC 5 7VU85 (CP300)
Affected: Siemens SIPROTEC 5 Communication Module ETH-BA-2EL (Rev.1)
Affected: Siemens SIPROTEC 5 Communication Module ETH-BA-2EL (Rev.1)
Affected: Siemens SIPROTEC 5 Communication Module ETH-BA-2EL (Rev.1)
Affected: Siemens SIPROTEC 5 Communication Module ETH-BB-2FO (Rev. 1)
Affected: Siemens SIPROTEC 5 Communication Module ETH-BB-2FO (Rev. 1)
Affected: Siemens SIPROTEC 5 Communication Module ETH-BB-2FO (Rev. 1)
Affected: Siemens SIPROTEC 5 Communication Module ETH-BD-2FO
Affected: Siemens SIPROTEC 5 Compact 7SX800 (CP050)
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2024-38867?
CVE-2024-38867 has been scored as a high severity vulnerability.
How to fix CVE-2024-38867?
To fix CVE-2024-38867, make sure you are using an up-to-date version of the affected component(s) by checking the vendor release notes. As for now, there are no other specific guidelines available.
Is CVE-2024-38867 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2024-38867 is being actively exploited. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2024-38867?
CVE-2024-38867 affects Siemens SIPROTEC 5 6MD84 (CP300), Siemens SIPROTEC 5 6MD85 (CP200), Siemens SIPROTEC 5 6MD85 (CP300), Siemens SIPROTEC 5 6MD86 (CP200), Siemens SIPROTEC 5 6MD86 (CP300), Siemens SIPROTEC 5 6MD89 (CP300), Siemens SIPROTEC 5 6MU85 (CP300), Siemens SIPROTEC 5 7KE85 (CP200), Siemens SIPROTEC 5 7KE85 (CP300), Siemens SIPROTEC 5 7SA82 (CP100), Siemens SIPROTEC 5 7SA82 (CP150), Siemens SIPROTEC 5 7SA84 (CP200), Siemens SIPROTEC 5 7SA86 (CP200), Siemens SIPROTEC 5 7SA86 (CP300), Siemens SIPROTEC 5 7SA87 (CP200), Siemens SIPROTEC 5 7SA87 (CP300), Siemens SIPROTEC 5 7SD82 (CP100), Siemens SIPROTEC 5 7SD82 (CP150), Siemens SIPROTEC 5 7SD84 (CP200), Siemens SIPROTEC 5 7SD86 (CP200), Siemens SIPROTEC 5 7SD86 (CP300), Siemens SIPROTEC 5 7SD87 (CP200), Siemens SIPROTEC 5 7SD87 (CP300), Siemens SIPROTEC 5 7SJ81 (CP100), Siemens SIPROTEC 5 7SJ81 (CP150), Siemens SIPROTEC 5 7SJ82 (CP100), Siemens SIPROTEC 5 7SJ82 (CP150), Siemens SIPROTEC 5 7SJ85 (CP200), Siemens SIPROTEC 5 7SJ85 (CP300), Siemens SIPROTEC 5 7SJ86 (CP200), Siemens SIPROTEC 5 7SJ86 (CP300), Siemens SIPROTEC 5 7SK82 (CP100), Siemens SIPROTEC 5 7SK82 (CP150), Siemens SIPROTEC 5 7SK85 (CP200), Siemens SIPROTEC 5 7SK85 (CP300), Siemens SIPROTEC 5 7SL82 (CP100), Siemens SIPROTEC 5 7SL82 (CP150), Siemens SIPROTEC 5 7SL86 (CP200), Siemens SIPROTEC 5 7SL86 (CP300), Siemens SIPROTEC 5 7SL87 (CP200), Siemens SIPROTEC 5 7SL87 (CP300), Siemens SIPROTEC 5 7SS85 (CP200), Siemens SIPROTEC 5 7SS85 (CP300), Siemens SIPROTEC 5 7ST85 (CP200), Siemens SIPROTEC 5 7ST85 (CP300), Siemens SIPROTEC 5 7ST86 (CP300), Siemens SIPROTEC 5 7SX82 (CP150), Siemens SIPROTEC 5 7SX85 (CP300), Siemens SIPROTEC 5 7UM85 (CP300), Siemens SIPROTEC 5 7UT82 (CP100), Siemens SIPROTEC 5 7UT82 (CP150), Siemens SIPROTEC 5 7UT85 (CP200), Siemens SIPROTEC 5 7UT85 (CP300), Siemens SIPROTEC 5 7UT86 (CP200), Siemens SIPROTEC 5 7UT86 (CP300), Siemens SIPROTEC 5 7UT87 (CP200), Siemens SIPROTEC 5 7UT87 (CP300), Siemens SIPROTEC 5 7VE85 (CP300), Siemens SIPROTEC 5 7VK87 (CP200), Siemens SIPROTEC 5 7VK87 (CP300), Siemens SIPROTEC 5 7VU85 (CP300), Siemens SIPROTEC 5 Communication Module ETH-BA-2EL (Rev.1), Siemens SIPROTEC 5 Communication Module ETH-BA-2EL (Rev.1), Siemens SIPROTEC 5 Communication Module ETH-BA-2EL (Rev.1), Siemens SIPROTEC 5 Communication Module ETH-BB-2FO (Rev. 1), Siemens SIPROTEC 5 Communication Module ETH-BB-2FO (Rev. 1), Siemens SIPROTEC 5 Communication Module ETH-BB-2FO (Rev. 1), Siemens SIPROTEC 5 Communication Module ETH-BD-2FO, Siemens SIPROTEC 5 Compact 7SX800 (CP050).
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.