Publication Date: 2019-07-09
Last Update: 2020-05-12
Current Version: V1.3
CVSS v3.1 Base Score: 7.5

Affected Product and Versions Remediation
SIPROTEC 5 device types 6MD85, 6MD86, 6MD89, 7UM85, 7SA87, 7SD87, 7SL87, 7VK87, 7SA82, 7SA86, 7SD82, 7SD86, 7SL82, 7SL86, 7SJ86, 7SK82, 7SK85, 7SJ82, 7SJ85, 7UT82, 7UT85, 7UT86, 7UT87 and 7VE85 with CPU variants CP300 and CP100 and the respective Ethernet communication modules:
All versions < V7.90

Update to V7.90 or later version.

Search for "SIPROTEC 5 - DIGSI Device Drivers" on the Siemens Industry Online Support site.

The latest firmware version for the communication modules can also be found on each device specific download page.

Applying the update causes the device / module to go through a single restart cycle.


https://support.industry.siemens.com/cs/ww/en/
SIPROTEC 5 device types 7SS85 and 7KE85:
All versions < V8.01

Update to V8.01 or later version.

Search for "SIPROTEC 5 - DIGSI Device Drivers" on the Siemens Industry Online Support site.

Applying the update causes the device / module to go through a single restart cycle.


https://support.industry.siemens.com/cs/ww/en/
All other SIPROTEC 5 device types with CPU variants CP300 and CP100 and the respective Ethernet communication modules:
All versions
See recommendations from section Workarounds and Mitigations
SIPROTEC 5 device types with CPU variants CP200 and the respective Ethernet communication modules:
All versions < V7.59
only affected by CVE-2019-10931

Update to V7.59 or later version.

Search for "SIPROTEC 5 - DIGSI Device Drivers" on the Siemens Industry Online Support site.

The latest firmware version for the communication modules can also be found on each device specific download page.

Applying the update causes the device / module to go through a single restart cycle.


https://support.industry.siemens.com/cs/ww/en/
SIPROTEC 5 device types with CPU variants CP200 and the respective Ethernet communication modules:
All versions
only affected by CVE-2019-10930
See recommendations from section Workarounds and Mitigations
DIGSI 5 engineering software:
All versions < V7.90
Update to V7.90 or later version and activate the client authorization feature
https://support.industry.siemens.com/cs/us/en/view/109767686

CVSS v3.1 Base Score 7.3
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
CWE: CWE-552: Files or Directories Accessible to External Parties

CVSS v3.1 Base Score 7.5
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C
CWE: CWE-248: Uncaught Exception

https://www.siemens.com/cert/advisories