A vulnerability has been identified in Firmware variant IEC 61850 for EN100 Ethernet module (All versions < V4.33), Firmware variant PROFINET IO for EN100 Ethernet module (All versions), Firmware variant Modbus TCP for EN100 Ethernet module (All versions), Firmware variant DNP3 TCP for EN100 Ethernet module (All versions), Firmware variant IEC104 for EN100 Ethernet module (All versions < V1.22), SIPROTEC 5 relays with CPU variants CP300 and CP100 and the respective Ethernet communication modules (All versions < V7.80), SIPROTEC 5 relays with CPU variants CP200 and the respective Ethernet communication modules (All versions < V7.58)
Published Jul 23, 2018
7.5
HIGHCVSS 3.0
EPSS 2.39%
Description
A vulnerability has been identified in Firmware variant IEC 61850 for EN100 Ethernet module (All versions < V4.33), Firmware variant PROFINET IO for EN100 Ethernet module (All versions), Firmware variant Modbus TCP for EN100 Ethernet module (All versions), Firmware variant DNP3 TCP for EN100 Ethernet module (All versions), Firmware variant IEC104 for EN100 Ethernet module (All versions < V1.22), SIPROTEC 5 relays with CPU variants CP300 and CP100 and the respective Ethernet communication modules (All versions < V7.80), SIPROTEC 5 relays with CPU variants CP200 and the respective Ethernet communication modules (All versions < V7.58). Specially crafted packets to port 102/tcp could cause a denial-of-service condition in the affected products. A manual restart is required to recover the EN100 module functionality of the affected devices. Successful exploitation requires an attacker with network access to send multiple packets to the affected products or modules. As a precondition the IEC 61850-MMS communication needs to be activated on the affected products or modules. No user interaction or privileges are required to exploit the vulnerability. The vulnerability could allow causing a Denial-of-Service condition of the network functionality of the device, compromising the availability of the system. At the time of advisory publication no public exploitation of this security vulnerability was known.
Affected products
-
- Version All versionsStatusaffectedConstraints-
- Version
-
- Version All versions < V4.33StatusaffectedConstraints-
- Version
-
- Version All versions < V1.22StatusaffectedConstraints-
- Version
-
- Version All versionsStatusaffectedConstraints-
- Version
-
- Version All versionsStatusaffectedConstraints-
- Version
-
- Version All versions < V7.58StatusaffectedConstraints-
- Version All versions < V7.80StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Siemens AG | Firmware variant DNP3 TCP for EN100 Ethernet module | n/a |
| |||||||||
| Siemens AG | Firmware variant IEC 61850 for EN100 Ethernet module | n/a |
| |||||||||
| Siemens AG | Firmware variant IEC104 for EN100 Ethernet module | n/a |
| |||||||||
| Siemens AG | Firmware variant Modbus TCP for EN100 Ethernet module | n/a |
| |||||||||
| Siemens AG | Firmware variant PROFINET IO for EN100 Ethernet module | n/a |
| |||||||||
| Siemens AG | n/a | n/a |
|
Configuration 1
- n/a
- < 4.33
- n/a
- n/a
- n/a
Configuration 2
- < 7.80
- n/a
- < 7.80
Running on/with
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
AV:N/AC:L/Au:N/C:N/I:N/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v5
Table of values (16 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 2.39% (0.02389) | 83.35th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.39% (0.02389) | 81.72th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.24% (0.00242) | 64.63th | v3 (v2023.03.01) |
| May 7, 2024 | 0.24% (0.00242) | 64.05th | v3 (v2023.03.01) |
| Mar 11, 2024 | 0.34% (0.00343) | 70.92th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.29% (0.00289) | 68.05th | v3 (v2023.03.01) |
| Jul 17, 2023 | 0.29% (0.00289) | 64.70th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.24% (0.00241) | 60.22th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.95% (0.00954) | 36.37th | v2 (v2022.01.01) |
| Sep 2, 2022 | 0.95% (0.00954) | 34.50th | v2 (v2022.01.01) |
| Apr 1, 2022 | 0.95% (0.00954) | 32.50th | v2 (v2022.01.01) |
| Feb 4, 2022 | 0.95% (0.00954) | 16.28th | v2 (v2022.01.01) |
| Feb 3, 2022 | 0.83% (0.00833) | 24.58th | v1 |
| Jan 6, 2022 | 0.83% (0.00833) | 23.96th | v1 |
| Sep 1, 2021 | 0.83% (0.00833) | 57.50th | v1 |
| Apr 14, 2021 | 0.83% (0.00833) | 0.00th | v1 |
References (3)
- https://cert-portal.siemens.com/productcert/pdf/ssa-325546.pdf x_refsource_CONFIRMMitigationPatchVendor Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-635129.pdf x_refsource_CONFIRMMitigationPatchVendor Advisory
- https://www.securityfocus.com/bid/106221 vdb-entryx_refsource_BID
| Link | Providers | Tags |
|---|---|---|
| https://cert-portal.siemens.com/productcert/pdf/ssa-325546.pdf | x_refsource_CONFIRMMitigationPatchVendor Advisory | |
| https://cert-portal.siemens.com/productcert/pdf/ssa-635129.pdf | x_refsource_CONFIRMMitigationPatchVendor Advisory | |
| https://www.securityfocus.com/bid/106221 | vdb-entryx_refsource_BID |
Change history (0)
No recorded changes yet.