CVE-2024-52504

Description

A vulnerability has been identified in SIPROTEC 4 6MD61 (All versions), SIPROTEC 4 6MD63 (All versions), SIPROTEC 4 6MD66 (All versions), SIPROTEC 4 6MD665 (All versions), SIPROTEC 4 7SA522 (All versions), SIPROTEC 4 7SA6 (All versions < V4.78), SIPROTEC 4 7SD5 (All versions < V4.78), SIPROTEC 4 7SD610 (All versions < V4.78), SIPROTEC 4 7SJ61 (All versions), SIPROTEC 4 7SJ62 (All versions), SIPROTEC 4 7SJ63 (All versions), SIPROTEC 4 7SJ64 (All versions), SIPROTEC 4 7SJ66 (All versions), SIPROTEC 4 7SS52 (All versions), SIPROTEC 4 7ST6 (All versions), SIPROTEC 4 7UM61 (All versions), SIPROTEC 4 7UM62 (All versions), SIPROTEC 4 7UT612 (All versions), SIPROTEC 4 7UT613 (All versions), SIPROTEC 4 7UT63 (All versions), SIPROTEC 4 7VE6 (All versions), SIPROTEC 4 7VK61 (All versions), SIPROTEC 4 7VU683 (All versions), SIPROTEC 4 Compact 7RW80 (All versions), SIPROTEC 4 Compact 7SD80 (All versions), SIPROTEC 4 Compact 7SJ80 (All versions), SIPROTEC 4 Compact 7SJ81 (All versions), SIPROTEC 4 Compact 7SK80 (All versions), SIPROTEC 4 Compact 7SK81 (All versions). Affected devices do not properly handle interrupted operations of file transfer. This could allow an unauthenticated remote attacker to cause a denial of service condition. To restore normal operations, the devices need to be restarted.

Category

8.7
CVSS
Severity: High
CVSS 4.0 •
CVSS 3.1 •
EPSS 0.08%
Affected: Siemens SIPROTEC 4 6MD61
Affected: Siemens SIPROTEC 4 6MD63
Affected: Siemens SIPROTEC 4 6MD66
Affected: Siemens SIPROTEC 4 6MD665
Affected: Siemens SIPROTEC 4 7SA522
Affected: Siemens SIPROTEC 4 7SA6
Affected: Siemens SIPROTEC 4 7SD5
Affected: Siemens SIPROTEC 4 7SD610
Affected: Siemens SIPROTEC 4 7SJ61
Affected: Siemens SIPROTEC 4 7SJ62
Affected: Siemens SIPROTEC 4 7SJ63
Affected: Siemens SIPROTEC 4 7SJ64
Affected: Siemens SIPROTEC 4 7SJ66
Affected: Siemens SIPROTEC 4 7SS52
Affected: Siemens SIPROTEC 4 7ST6
Affected: Siemens SIPROTEC 4 7UM61
Affected: Siemens SIPROTEC 4 7UM62
Affected: Siemens SIPROTEC 4 7UT612
Affected: Siemens SIPROTEC 4 7UT613
Affected: Siemens SIPROTEC 4 7UT63
Affected: Siemens SIPROTEC 4 7VE6
Affected: Siemens SIPROTEC 4 7VK61
Affected: Siemens SIPROTEC 4 7VU683
Affected: Siemens SIPROTEC 4 Compact 7RW80
Affected: Siemens SIPROTEC 4 Compact 7SD80
Affected: Siemens SIPROTEC 4 Compact 7SJ80
Affected: Siemens SIPROTEC 4 Compact 7SJ81
Affected: Siemens SIPROTEC 4 Compact 7SK80
Affected: Siemens SIPROTEC 4 Compact 7SK81
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2024-52504?
CVE-2024-52504 has been scored as a high severity vulnerability.
How to fix CVE-2024-52504?
To fix CVE-2024-52504, make sure you are using an up-to-date version of the affected component(s) by checking the vendor release notes. As for now, there are no other specific guidelines available.
Is CVE-2024-52504 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2024-52504 is being actively exploited. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2024-52504?
CVE-2024-52504 affects Siemens SIPROTEC 4 6MD61, Siemens SIPROTEC 4 6MD63, Siemens SIPROTEC 4 6MD66, Siemens SIPROTEC 4 6MD665, Siemens SIPROTEC 4 7SA522, Siemens SIPROTEC 4 7SA6, Siemens SIPROTEC 4 7SD5, Siemens SIPROTEC 4 7SD610, Siemens SIPROTEC 4 7SJ61, Siemens SIPROTEC 4 7SJ62, Siemens SIPROTEC 4 7SJ63, Siemens SIPROTEC 4 7SJ64, Siemens SIPROTEC 4 7SJ66, Siemens SIPROTEC 4 7SS52, Siemens SIPROTEC 4 7ST6, Siemens SIPROTEC 4 7UM61, Siemens SIPROTEC 4 7UM62, Siemens SIPROTEC 4 7UT612, Siemens SIPROTEC 4 7UT613, Siemens SIPROTEC 4 7UT63, Siemens SIPROTEC 4 7VE6, Siemens SIPROTEC 4 7VK61, Siemens SIPROTEC 4 7VU683, Siemens SIPROTEC 4 Compact 7RW80, Siemens SIPROTEC 4 Compact 7SD80, Siemens SIPROTEC 4 Compact 7SJ80, Siemens SIPROTEC 4 Compact 7SJ81, Siemens SIPROTEC 4 Compact 7SK80, Siemens SIPROTEC 4 Compact 7SK81.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.