Full Report
SIPROTEC 5 is vulnerable to arbitrary file uploads by authenticated users using the DIGSI 5 protocol. This could allow an attacker to upload malicious configuration files, potentially causing a permanent denial of service condition. As a mitigation measure, users of the CP050 and CP150 device models are advised to upgrade to version 9.90 or later. For CP300 device models, devices 7ST85 and 7ST86 are advised to upgrade to version 10.00 or later, while the remaining models should upgrade to version 9.90 or later. These versions introduce an allow-list feature that restricts arbitrary file uploads and reduces the risk associated with this vulnerability. Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.
Analysis Summary
# Vulnerability: Arbitrary File Upload in Siemens SIPROTEC 5 via DIGSI 5 Protocol
## CVE Details
- **CVE ID:** CVE-2025-40808
- **CVSS Score:**
- **v4.0:** 6.9 (Medium)
- **v3.1:** 6.1 (Medium)
- **CWE:** CWE-434: Unrestricted Upload of File with Dangerous Type
## Affected Systems
- **Products:** Siemens SIPROTEC 5 and SIPROTEC 5 Compact devices.
- **Versions:**
- **CP100 Devices:** All versions (No fix planned).
- **CP050 / CP150 Devices:** Versions prior to v9.90.
- **CP300 Devices (7ST85, 7ST86):** Versions prior to v10.00.
- **Other CP300 Devices:** Versions prior to v9.90.
- **Configurations:** Devices utilizing the DIGSI 5 protocol for configuration and communication.
## Vulnerability Description
The vulnerability exists due to improper validation of files uploaded via the DIGSI 5 protocol. Authenticated users can upload arbitrary files to the device. Technically, this allows an attacker to overwrite or place malicious configuration files on the system, which can disrupt the logic of the protection device or potentially lead to unauthorized code execution.
## Exploitation
- **Status:** Not exploited in the wild (Reported by ENCS).
- **Complexity:** Low (Requires valid authentication).
- **Attack Vector:** Adjacent (Requires access to the network where the device communicates via DIGSI 5).
## Impact
- **Confidentiality:** None
- **Integrity:** High (Modification of system/configuration files).
- **Availability:** High (Can cause permanent Denial of Service (DoS) of the protection relay).
## Remediation
### Patches
Siemens has introduced an **allow-list feature** that restricts arbitrary file uploads in the following versions:
- **CP050, CP150, and standard CP300 models:** Upgrade to **v9.90** or later.
- **CP300 models 7ST85 and 7ST86:** Upgrade to **v10.00** or later.
- **CP100 models:** No fix is planned; users must rely on workarounds.
### Workarounds
- **Network Segmentation:** Protect network access using firewalls and VLANs to ensure only trusted engineering stations can communicate with the devices.
- **VPN:** Use secure VPN tunnels for any remote access to the DIGSI 5 protocol.
- **Operational Guidelines:** Adhere to Siemens' grid security guidelines to run devices in a protected environment.
- **Access Control:** Strictly limit the number of users with authenticated access to the DIGSI 5 protocol.
## Detection
- **Indicators of Compromise:** Unusual configuration change logs or unexpected device reboots/malfunctions.
- **Detection methods and tools:** Monitor network traffic for unusual file transfer activity over the DIGSI 5 protocol (typically associated with Siemens engineering software). Audit device logs for unauthorized authentication attempts or configuration modifications.
## References
- **Vendor Advisory:** hxxps://cert-portal[.]siemens[.]com/productcert/html/ssa-139483[.]html
- **Siemens Grid Security:** hxxps://www[.]siemens[.]com/gridsecurity
- **Siemens ProductCERT:** hxxps://www[.]siemens[.]com/cert/advisories