SSA-767615 PUBLISHED CVSS 7.5 HIGH

Affected devices do not properly validate SNMP GET requests. This could allow an unauthenticated, remote attacker to retrieve sensitive information of the affected devices with SNMPv2 GET requests using default credentials.

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected Products

VendorProductVersions
SiemensSIPROTEC 5 7SJ85 (CP300)
SiemensSIPROTEC 5 7UT86 (CP300)
SiemensSIPROTEC 5 7SK85 (CP300)
SiemensSIPROTEC 5 7KE85 (CP300)
SiemensSIPROTEC 5 7SJ82 (CP150)
SiemensSIPROTEC 5 7VU85 (CP300)
SiemensSIPROTEC 5 7SA87 (CP300)
SiemensSIPROTEC 5 7UT82 (CP150)
SiemensSIPROTEC 5 Communication Module ETH-BA-2EL (Rev.2) V9.6
SiemensSIPROTEC 5 Communication Module ETH-BB-2FO (Rev. 2) V9.8
SiemensSIPROTEC 5 7SJ86 (CP300)
SiemensSIPROTEC 5 7SD82 (CP150)
SiemensSIPROTEC 5 7UT87 (CP300)
SiemensSIPROTEC 5 7SL82 (CP150)
SiemensSIPROTEC 5 7SJ81 (CP150)
SiemensSIPROTEC 5 7SD87 (CP300)
SiemensSIPROTEC 5 7SK82 (CP150)
SiemensSIPROTEC 5 7ST85 (CP300) V9.6x
SiemensSIPROTEC 5 Communication Module ETH-BA-2EL (Rev.2)
SiemensSIPROTEC 5 Communication Module ETH-BB-2FO (Rev. 2) V9.6

…and 28 more

Timeline

References

Open in Interactive Console →