Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-28766


A vulnerability has been identified in SIPROTEC 5 6MD85 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 6MD86 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 6MD89 (CP300) (All versions >= V7.80 < V9.64), SIPROTEC 5 6MU85 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 7KE85 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 7SA82 (CP100) (All versions < V8.90), SIPROTEC 5 7SA82 (CP150) (All versions < V9.40), SIPROTEC 5 7SA86 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 7SA87 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 7SD82 (CP100) (All versions < V8.90), SIPROTEC 5 7SD82 (CP150) (All versions < V9.40), SIPROTEC 5 7SD86 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 7SD87 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 7SJ81 (CP100) (All versions < V8.89), SIPROTEC 5 7SJ81 (CP150) (All versions < V9.40), SIPROTEC 5 7SJ82 (CP100) (All versions < V8.89), SIPROTEC 5 7SJ82 (CP150) (All versions < V9.40), SIPROTEC 5 7SJ85 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 7SJ86 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 7SK82 (CP100) (All versions < V8.89), SIPROTEC 5 7SK82 (CP150) (All versions < V9.40), SIPROTEC 5 7SK85 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 7SL82 (CP100) (All versions < V8.90), SIPROTEC 5 7SL82 (CP150) (All versions < V9.40), SIPROTEC 5 7SL86 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 7SL87 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 7SS85 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 7ST85 (CP300) (All versions >= V7.80 < V9.64), SIPROTEC 5 7ST86 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 7SX82 (CP150) (All versions < V9.40), SIPROTEC 5 7SX85 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 7UM85 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 7UT82 (CP100) (All versions < V8.90), SIPROTEC 5 7UT82 (CP150) (All versions < V9.40), SIPROTEC 5 7UT85 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 7UT86 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 7UT87 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 7VE85 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 7VK87 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 7VU85 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 Communication Module ETH-BA-2EL (Rev.1) (All versions < V9.40 installed on CP150 and CP300 devices), SIPROTEC 5 Communication Module ETH-BA-2EL (Rev.1) (All versions < V8.89 installed on CP100 devices), SIPROTEC 5 Communication Module ETH-BB-2FO (Rev. 1) (All versions < V9.40 installed on CP150 and CP300 devices), SIPROTEC 5 Communication Module ETH-BB-2FO (Rev. 1) (All versions < V8.89 installed on CP100 devices), SIPROTEC 5 Communication Module ETH-BD-2FO (All versions < V9.40), SIPROTEC 5 Compact 7SX800 (CP050) (All versions < V9.40). Affected devices lack proper validation of http request parameters of the hosted web service. An unauthenticated remote attacker could send specially crafted packets that could cause denial of service condition of the target device.


Security Impact Summary

This vulnerability carries a HIGH severity rating with a CVSS v3.1 score of 7.5, indicating it can be exploited remotely over the network with relatively low complexity without requiring user interaction and does not require pre-existing privileges . The vulnerability impacts and availability (service disruption) for affected systems. Impacting 78 products from siemens, from siemens, from siemens and 75 others, organizations running these solutions should prioritize assessment and patching.

Historical Context

Reported in 2023, this vulnerability emerged during an era marked by increased sophistication in supply chain attacks, cloud infrastructure vulnerabilities, and software-as-a-service (SaaS) security challenges. Security practices during this period emphasized zero-trust architectures, container security, and API protection.


Published

2023-04-11T10:15:18.337

Last Modified

2025-11-11T21:15:34.250

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-476

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System siemens siprotec_5_6md85_firmware * Yes
Hardware siemens siprotec_5_6md85 cp200 No
Operating System siemens siprotec_5_6md85_firmware < 9.40 Yes
Hardware siemens siprotec_5_6md85 cp300 No
Operating System siemens siprotec_5_6md86_firmware * Yes
Hardware siemens siprotec_5_6md86 cp200 No
Operating System siemens siprotec_5_6md86_firmware < 9.40 Yes
Hardware siemens siprotec_5_6md86 cp300 No
Operating System siemens siprotec_5_6md89_firmware * Yes
Hardware siemens siprotec_5_6md89 cp300 No
Operating System siemens siprotec_5_6mu85_firmware < 9.40 Yes
Hardware siemens siprotec_5_6mu85 cp300 No
Operating System siemens siprotec_5_7ke85_firmware * Yes
Hardware siemens siprotec_5_7ke85 cp200 No
Operating System siemens siprotec_5_7ke85_firmware < 9.40 Yes
Hardware siemens siprotec_5_7ke85 cp300 No
Operating System siemens siprotec_5_7sa82_firmware * Yes
Hardware siemens siprotec_5_7sa82 cp100 No
Operating System siemens siprotec_5_7sa82_firmware < 9.40 Yes
Hardware siemens siprotec_5_7sa82 cp150 No
Operating System siemens siprotec_5_7sa86_firmware * Yes
Hardware siemens siprotec_5_7sa86 cp200 No
Operating System siemens siprotec_5_7sa86_firmware < 9.40 Yes
Hardware siemens siprotec_5_7sa86 cp300 No
Operating System siemens siprotec_5_7sa87_firmware * Yes
Hardware siemens siprotec_5_7sa87 cp200 No
Operating System siemens siprotec_5_7sa87_firmware < 9.40 Yes
Hardware siemens siprotec_5_7sa87 cp300 No
Operating System siemens siprotec_5_7sd82_firmware * Yes
Hardware siemens siprotec_5_7sd82 cp100 No
Operating System siemens siprotec_5_7sd82_firmware < 9.40 Yes
Hardware siemens siprotec_5_7sd82 cp150 No
Operating System siemens siprotec_5_7sd86_firmware * Yes
Hardware siemens siprotec_5_7sd86 cp200 No
Operating System siemens siprotec_5_7sd86_firmware < 9.40 Yes
Hardware siemens siprotec_5_7sd86 cp300 No
Operating System siemens siprotec_5_7sd87_firmware * Yes
Hardware siemens siprotec_5_7sd87 cp200 No
Operating System siemens siprotec_5_7sd87_firmware < 9.40 Yes
Hardware siemens siprotec_5_7sd87 cp300 No
Operating System siemens siprotec_5_7sj81_firmware * Yes
Hardware siemens siprotec_5_7sj81 cp100 No
Operating System siemens siprotec_5_7sj81_firmware < 9.40 Yes
Hardware siemens siprotec_5_7sj81 cp150 No
Operating System siemens siprotec_5_7sj82_firmware * Yes
Hardware siemens siprotec_5_7sj82 cp100 No
Operating System siemens siprotec_5_7sj82_firmware < 9.40 Yes
Hardware siemens siprotec_5_7sj82 cp150 No
Operating System siemens siprotec_5_7sj85_firmware * Yes
Hardware siemens siprotec_5_7sj85 cp200 No
Operating System siemens siprotec_5_7sj85_firmware < 9.40 Yes
Hardware siemens siprotec_5_7sj85 cp300 No
Operating System siemens siprotec_5_7sj86_firmware * Yes
Hardware siemens siprotec_5_7sj86 cp200 No
Operating System siemens siprotec_5_7sj86_firmware < 9.40 Yes
Hardware siemens siprotec_5_7sj86 cp300 No
Operating System siemens siprotec_5_7sk82_firmware * Yes
Hardware siemens siprotec_5_7sk82 cp100 No
Operating System siemens siprotec_5_7sk82_firmware < 9.40 Yes
Hardware siemens siprotec_5_7sk82 cp150 No
Operating System siemens siprotec_5_7sk85_firmware * Yes
Hardware siemens siprotec_5_7sk85 cp200 No
Operating System siemens siprotec_5_7sk85_firmware < 9.40 Yes
Hardware siemens siprotec_5_7sk85 cp300 No
Operating System siemens siprotec_5_7sl82_firmware * Yes
Hardware siemens siprotec_5_7sl82 cp100 No
Operating System siemens siprotec_5_7sl82_firmware < 9.40 Yes
Hardware siemens siprotec_5_7sl82 cp150 No
Operating System siemens siprotec_5_7sl86_firmware * Yes
Hardware siemens siprotec_5_7sl86 cp200 No
Operating System siemens siprotec_5_7sl86_firmware < 9.40 Yes
Hardware siemens siprotec_5_7sl86 cp300 No
Operating System siemens siprotec_5_7sl87_firmware * Yes
Hardware siemens siprotec_5_7sl87 cp200 No
Operating System siemens siprotec_5_7sl87_firmware < 9.40 Yes
Hardware siemens siprotec_5_7sl87 cp300 No
Operating System siemens siprotec_5_7ss85_firmware * Yes
Hardware siemens siprotec_5_7ss85 cp200 No
Operating System siemens siprotec_5_7ss85_firmware < 9.40 Yes
Hardware siemens siprotec_5_7ss85 cp300 No
Operating System siemens siprotec_5_7st85_firmware * Yes
Hardware siemens siprotec_5_7st85 cp200 No
Operating System siemens siprotec_5_7st85_firmware * Yes
Hardware siemens siprotec_5_7st85 cp300 No
Operating System siemens siprotec_5_7sx85_firmware < 9.40 Yes
Hardware siemens siprotec_5_7sx85 cp300 No
Operating System siemens siprotec_5_7um85_firmware < 9.40 Yes
Hardware siemens siprotec_5_7um85 cp300 No
Operating System siemens siprotec_5_7ut82_firmware * Yes
Hardware siemens siprotec_5_7ut82 cp100 No
Operating System siemens siprotec_5_7ut82_firmware < 9.40 Yes
Hardware siemens siprotec_5_7ut82 cp150 No
Operating System siemens siprotec_5_7ut85_firmware * Yes
Hardware siemens siprotec_5_7ut85 cp200 No
Operating System siemens siprotec_5_7ut85_firmware < 9.40 Yes
Hardware siemens siprotec_5_7ut85 cp300 No
Operating System siemens siprotec_5_7ut86_firmware * Yes
Hardware siemens siprotec_5_7ut86 cp200 No
Operating System siemens siprotec_5_7ut86_firmware < 9.40 Yes
Hardware siemens siprotec_5_7ut86 cp300 No
Operating System siemens siprotec_5_7ut87_firmware * Yes
Hardware siemens siprotec_5_7ut87 cp200 No
Operating System siemens siprotec_5_7ut87_firmware < 9.40 Yes
Hardware siemens siprotec_5_7ut87 cp300 No
Operating System siemens siprotec_5_7ve85_firmware < 9.40 Yes
Hardware siemens siprotec_5_7ve85 cp300 No
Operating System siemens siprotec_5_7vk87_firmware * Yes
Hardware siemens siprotec_5_7vk87 cp200 No
Operating System siemens siprotec_5_7vk87_firmware < 9.40 Yes
Hardware siemens siprotec_5_7vk87 cp300 No
Operating System siemens siprotec_5_communication_module_ethba2el_firmware < 9.40 Yes
Hardware siemens siprotec_5_communication_module_ethba2el - No
Operating System siemens siprotec_5_communication_module_ethbb2fo_firmware < 9.40 Yes
Hardware siemens siprotec_5_communication_module_ethbb2fo - No
Operating System siemens siprotec_5_communication_module_ethbd2fo_firmware < 9.40 Yes
Hardware siemens siprotec_5_communication_module_ethbd2fo - No
Operating System siemens siprotec_5_compact_7sx800_firmware < 9.40 Yes
Hardware siemens siprotec_5_compact_7sx800 cp050 No
Operating System siemens siprotec_5_7sa84_firmware * Yes
Hardware siemens siprotec_5_7sa84 cp200 No
Operating System siemens siprotec_5_7sd84_firmware * Yes
Hardware siemens siprotec_5_7sd84 cp200 No
Operating System siemens siprotec_5_7st86_firmware * Yes
Hardware siemens siprotec_5_7st86 cp300 No
Operating System siemens siprotec_5_7sx82_firmware < 9.40 Yes
Hardware siemens siprotec_5_7sx82 cp150 No
Operating System siemens siprotec_5_7vu85_firmware < 9.40 Yes
Hardware siemens siprotec_5_7vu85 cp300 No

References

How SecUtils Interprets This CVE

SecUtils normalizes and enriches National Vulnerability Database (NVD) records by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and providing structured context for security teams. For siemens's affected products, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference data to enable rapid vulnerability prioritization and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and security operations.