vendor:
Siemens SIPROTEC 4 and SIPROTEC Compact EN100 Ethernet Module
by:
M. Can Kurnaz
7.5
CVSS
HIGH
Denial of Service
CWE
Product Name: Siemens SIPROTEC 4 and SIPROTEC Compact EN100 Ethernet Module
Affected Version From: All devices that include the EN100 Ethernet module version V4.24 or prior.
Affected Version To: V4.24
Patch Exists: NO
Related CWE: CVE-2015-5374
CPE:
Platforms Tested: Siemens SIPROTEC 4 (multiple versions < V4.25)
2018
Siemens SIPROTEC 4 and SIPROTEC Compact EN100 Ethernet Module < V4.25 - Denial of Service
The exploit allows an attacker to perform a Denial of Service attack on Siemens SIPROTEC 4 and SIPROTEC Compact EN100 Ethernet Module versions below V4.25. The vulnerability is identified as CVE-2015-5374.
Mitigation:
Update the devices to version V4.25 or later.