Publication Date: 2018-03-08
Last Update: 2021-07-13
Current Version: V1.5
CVSS v3.1 Base Score: 7.5

Affected Product and Versions Remediation
DIGSI 4:
All versions < V4.92
Update to V4.92
https://support.industry.siemens.com/cs/ww/en/view/109740980
EN100 Ethernet module DNP3 variant:
All versions < V1.05.00
Update to V1.05.00 and configure DIGSI 4 connection password
https://support.industry.siemens.com/cs/us/en/view/109745821
EN100 Ethernet module IEC 104 variant:
All versions
See recommendations from section Workarounds and Mitigations
EN100 Ethernet module IEC 61850 variant:
All versions < V4.30
Update to V4.30 and configure DIGSI 4 connection password
https://support.industry.siemens.com/cs/us/en/view/109745821
EN100 Ethernet module Modbus TCP variant:
All versions
See recommendations from section Workarounds and Mitigations
EN100 Ethernet module PROFINET IO variant:
All versions
See recommendations from section Workarounds and Mitigations
Other SIPROTEC 4 relays:
All versions
only affected by CVE-2018-4839
See recommendations from section Workarounds and Mitigations
Other SIPROTEC Compact relays:
All versions
only affected by CVE-2018-4839
See recommendations from section Workarounds and Mitigations
SIPROTEC 4 7SD80:
All versions < V4.70
only affected by CVE-2018-4839
Update to V4.70
https://support.industry.siemens.com/cs/us/en/view/109742758
SIPROTEC 4 7SJ61:
All versions < V4.96
only affected by CVE-2018-4839
Update to V4.96
https://support.industry.siemens.com/cs/us/en/view/109743551
SIPROTEC 4 7SJ62:
All versions < V4.96
only affected by CVE-2018-4839
Update to V4.96
https://support.industry.siemens.com/cs/us/en/view/109743551
SIPROTEC 4 7SJ64:
All versions < V4.96
only affected by CVE-2018-4839
Update to V4.96
https://support.industry.siemens.com/cs/us/en/view/109743551
SIPROTEC 4 7SJ66:
All versions < V4.30
only affected by CVE-2018-4839
Update to V4.30
https://support.industry.siemens.com/cs/us/en/view/109743555
SIPROTEC Compact 7SJ80:
All versions < V4.77
only affected by CVE-2018-4839
Update to V4.77
https://support.industry.siemens.com/cs/us/en/view/109742699
SIPROTEC Compact 7SK80:
All versions < V4.77
only affected by CVE-2018-4839
Update to V4.77
https://support.industry.siemens.com/cs/us/en/view/109742712

CVSS v3.1 Base Score 4.0
CVSS Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N/E:P/RL:O/RC:C
CWE: CWE-326: Inadequate Encryption Strength

CVSS v3.1 Base Score 7.5
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:P/RL:O/RC:C
CWE: CWE-306: Missing Authentication for Critical Function

https://www.siemens.com/cert/advisories