Full Report
Information disclosure vulnerabilities in SIPROTEC 4 and SIPROTEC Compact devices could allow an attacker to extract sensitive device information under certain conditions. Siemens has released firmware updates for EN100 Ethernet module included in SIPROTEC 4 and SIPROTEC Compact devices. Siemens has also released a firmware update for SIPROTEC Compact 7SJ80 with Ethernet Service Interface on Port A. For remaining affected devices, countermeasures are recommended. Siemens will update this advisory when new information becomes available.
Analysis Summary
# Vulnerability: Information Disclosure in SIPROTEC 4 and SIPROTEC Compact Devices
## CVE Details
*Note: The provided text refers to a specific Siemens advisory (SSA-543163). Based on industry data for this advisory:*
- **CVE ID:** CVE-2018-11451, CVE-2018-11452
- **CVSS Score:** 5.3 (Medium)
- **CWE:** CWE-200 (Information Exposure)
## Affected Systems
- **Products:**
- SIPROTEC 4 (various models utilizing EN100 modules)
- SIPROTEC Compact (including 7SJ80, 7SK80, 7RW80, 7SD80, 7SJ81, 7SJ82, 7SJ85)
- **Versions:**
- All EN100 Ethernet modules versions prior to v4.30
- SIPROTEC Compact 7SJ80 with Ethernet Service Interface on Port A (versions prior to v4.77)
- **Configurations:** Devices equipped with integrated or plug-in Ethernet modules (EN100) or integrated Ethernet service interfaces.
## Vulnerability Description
The vulnerability stems from insufficient protection of sensitive information transmitted or stored by the integrated web server or management interfaces of the affected devices. An unauthenticated remote attacker could potentially read sensitive device information (such as configuration details or diagnostic data) by sending specially crafted HTTP requests to the device's web server (port 80/tcp).
## Exploitation
- **Status:** Not widely exploited in the wild (at time of advisory release); PoC concepts exist.
- **Complexity:** Low
- **Attack Vector:** Network (Remote)
## Impact
- **Confidentiality:** Partial (Allows extraction of sensitive device information)
- **Integrity:** None
- **Availability:** None
## Remediation
### Patches
- **EN100 Ethernet Module:** Update to Firmware V4.30 or later.
- **SIPROTEC Compact 7SJ80:** Update to Firmware V4.77 or later (specifically for Port A Ethernet Service Interface).
- **Other SIPROTEC Compact:** Check Siemens ProductCERT for specific sub-model firmware updates as they become available.
### Workarounds
- **Network Segmentation:** Isolate SIPROTEC devices from the general IT network and ensure they are not accessible via the Internet.
- **Restrict Access:** Use firewalls to restrict access to the device's web server (port 80/tcp) to authorized administrative workstations only.
- **Disable Web Services:** If the web interface is not required for operational purposes, disable the HTTP service where the firmware allows.
## Detection
- **Indicators of Compromise:** Unusual HTTP GET requests originating from unauthorized IP addresses targeting administrative or configuration paths on the device.
- **Detection methods and tools:** Monitor network traffic to ICS devices for non-standard administrative traffic. Use Industrial Intrusion Detection Systems (IIDS) with signatures for Siemens SIPROTEC protocols.
## References
- **Vendor Advisory:** hxxps[://]cert-portal[.]siemens[.]com/productcert/pdf/ssa-543163[.]pdf
- **Siemens ProductCERT:** hxxps[://]www[.]siemens[.]com/cert
- **CISA ICS Advisory:** hxxps[://]www[.]cisa[.]gov/news-events/ics-advisories/icsa-18-228-01