ID

VAR-202501-1355


CVE

CVE-2024-53649


TITLE

Siemens SIPROTEC 5 Improper File Access Restriction Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2025-01697

DESCRIPTION

A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.80), SIPROTEC 5 6MD85 (CP300) (All versions >= V7.80 < V9.80), SIPROTEC 5 6MD86 (CP300) (All versions >= V7.80 < V9.80), SIPROTEC 5 6MD89 (CP300) (All versions >= V7.80), SIPROTEC 5 6MU85 (CP300) (All versions >= V7.80 < V9.80), SIPROTEC 5 7KE85 (CP300) (All versions >= V7.80 < V9.80), SIPROTEC 5 7SA82 (CP100) (All versions >= V7.80), SIPROTEC 5 7SA82 (CP150) (All versions < V9.80), SIPROTEC 5 7SA86 (CP300) (All versions >= V7.80 < V9.80), SIPROTEC 5 7SA87 (CP300) (All versions >= V7.80 < V9.80), SIPROTEC 5 7SD82 (CP100) (All versions >= V7.80), SIPROTEC 5 7SD82 (CP150) (All versions < V9.80), SIPROTEC 5 7SD86 (CP300) (All versions >= V7.80 < V9.80), SIPROTEC 5 7SD87 (CP300) (All versions >= V7.80 < V9.80), SIPROTEC 5 7SJ81 (CP100) (All versions >= V7.80), SIPROTEC 5 7SJ81 (CP150) (All versions < V9.80), SIPROTEC 5 7SJ82 (CP100) (All versions >= V7.80), SIPROTEC 5 7SJ82 (CP150) (All versions < V9.80), SIPROTEC 5 7SJ85 (CP300) (All versions >= V7.80 < V9.80), SIPROTEC 5 7SJ86 (CP300) (All versions >= V7.80 < V9.80), SIPROTEC 5 7SK82 (CP100) (All versions >= V7.80), SIPROTEC 5 7SK82 (CP150) (All versions < V9.80), SIPROTEC 5 7SK85 (CP300) (All versions >= V7.80 < V9.80), SIPROTEC 5 7SL82 (CP100) (All versions >= V7.80), SIPROTEC 5 7SL82 (CP150) (All versions < V9.80), SIPROTEC 5 7SL86 (CP300) (All versions >= V7.80 < V9.80), SIPROTEC 5 7SL87 (CP300) (All versions >= V7.80 < V9.80), SIPROTEC 5 7SS85 (CP300) (All versions >= V7.80 < V9.80), SIPROTEC 5 7ST85 (CP300) (All versions), SIPROTEC 5 7ST86 (CP300) (All versions < V9.80), SIPROTEC 5 7SX82 (CP150) (All versions < V9.80), SIPROTEC 5 7SX85 (CP300) (All versions < V9.80), SIPROTEC 5 7SY82 (CP150) (All versions < V9.80), SIPROTEC 5 7UM85 (CP300) (All versions >= V7.80 < V9.80), SIPROTEC 5 7UT82 (CP100) (All versions >= V7.80), SIPROTEC 5 7UT82 (CP150) (All versions < V9.80), SIPROTEC 5 7UT85 (CP300) (All versions >= V7.80 < V9.80), SIPROTEC 5 7UT86 (CP300) (All versions >= V7.80 < V9.80), SIPROTEC 5 7UT87 (CP300) (All versions >= V7.80 < V9.80), SIPROTEC 5 7VE85 (CP300) (All versions >= V7.80 < V9.80), SIPROTEC 5 7VK87 (CP300) (All versions >= V7.80 < V9.80), SIPROTEC 5 7VU85 (CP300) (All versions < V9.80), SIPROTEC 5 Compact 7SX800 (CP050) (All versions < V9.80). Affected devices do not properly limit the path accessible via their webserver. This could allow an authenticated remote attacker to read arbitrary files from the filesystem of affected devices. SIPROTEC 5 devices provide a range of integrated protection, control, measurement and automation functions for substations and other application areas. Siemens SIPROTEC 5 has an improper file access restriction vulnerability

Trust: 1.44

sources: NVD: CVE-2024-53649 // CNVD: CNVD-2025-01697

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2025-01697

AFFECTED PRODUCTS

vendor:siemensmodel:siprotec compact 7sx800scope:eqversion:5<v9.80

Trust: 0.6

vendor:siemensmodel:siprotec 7sa82scope:eqversion:5<v9.80

Trust: 0.6

vendor:siemensmodel:siprotec 7sd82scope:eqversion:5<v9.80

Trust: 0.6

vendor:siemensmodel:siprotec 7sj81scope:eqversion:5<v9.80

Trust: 0.6

vendor:siemensmodel:siprotec 7sj82scope:eqversion:5<v9.80

Trust: 0.6

vendor:siemensmodel:siprotec 7sk82scope:eqversion:5<v9.80

Trust: 0.6

vendor:siemensmodel:siprotec 7sl82scope:eqversion:5<v9.80

Trust: 0.6

vendor:siemensmodel:siprotec 7sx82scope:eqversion:5<v9.80

Trust: 0.6

vendor:siemensmodel:siprotec 7sy82scope:eqversion:5<v9.80

Trust: 0.6

vendor:siemensmodel:siprotec 7ut82scope:eqversion:5<v9.80

Trust: 0.6

vendor:siemensmodel:siprotec 6md84scope:eqversion:5<v9.80

Trust: 0.6

vendor:siemensmodel:siprotec 6md85scope:eqversion:5>=v7.80,<v9.80

Trust: 0.6

vendor:siemensmodel:siprotec 6md86scope:eqversion:5>=v7.80,<v9.80

Trust: 0.6

vendor:siemensmodel:siprotec 6md89scope:eqversion:5>=v7.80

Trust: 0.6

vendor:siemensmodel:siprotec 6mu85scope:eqversion:5>=v7.80,<v9.80

Trust: 0.6

vendor:siemensmodel:siprotec 7ke85scope:eqversion:5>=v7.80,<v9.80

Trust: 0.6

vendor:siemensmodel:siprotec 7sa86scope:eqversion:5>=v7.80,<v9.80

Trust: 0.6

vendor:siemensmodel:siprotec 7sa87scope:eqversion:5>=v7.80,<v9.80

Trust: 0.6

vendor:siemensmodel:siprotec 7sd86scope:eqversion:5>=v7.80,<v9.80

Trust: 0.6

vendor:siemensmodel:siprotec 7sd87scope:eqversion:5>=v7.80,<v9.80

Trust: 0.6

vendor:siemensmodel:siprotec 7sj85scope:eqversion:5>=v7.80,<v9.80

Trust: 0.6

vendor:siemensmodel:siprotec 7sj86scope:eqversion:5>=v7.80,<v9.80

Trust: 0.6

vendor:siemensmodel:siprotec 7sk85scope:eqversion:5>=v7.80,<v9.80

Trust: 0.6

vendor:siemensmodel:siprotec 7sl86scope:eqversion:5>=v7.80,<v9.80

Trust: 0.6

vendor:siemensmodel:siprotec 7sl87scope:eqversion:5>=v7.80,<v9.80

Trust: 0.6

vendor:siemensmodel:siprotec 7ss85scope:eqversion:5>=v7.80,<v9.80

Trust: 0.6

vendor:siemensmodel:siprotec 7st85scope:eqversion:5

Trust: 0.6

vendor:siemensmodel:siprotec 7st86scope:eqversion:5<v9.80

Trust: 0.6

vendor:siemensmodel:siprotec 7sx85scope:eqversion:5<v9.80

Trust: 0.6

vendor:siemensmodel:siprotec 7um85scope:eqversion:5>=v7.80,<v9.80

Trust: 0.6

vendor:siemensmodel:siprotec 7ut85scope:eqversion:5>=v7.80,<v9.80

Trust: 0.6

vendor:siemensmodel:siprotec 7ut86scope:eqversion:5>=v7.80,<v9.80

Trust: 0.6

vendor:siemensmodel:siprotec 7ut87scope:eqversion:5>=v7.80,<v9.80

Trust: 0.6

vendor:siemensmodel:siprotec 7ve85scope:eqversion:5>=v7.80,<v9.80

Trust: 0.6

vendor:siemensmodel:siprotec 7vk87scope:eqversion:5>=v7.80,<v9.80

Trust: 0.6

vendor:siemensmodel:siprotec 7vu85scope:eqversion:5<v9.80

Trust: 0.6

vendor:siemensmodel:siprotec 7sa82scope:eqversion:5>=v7.80

Trust: 0.6

vendor:siemensmodel:siprotec 7sd82scope:eqversion:5>=v7.80

Trust: 0.6

vendor:siemensmodel:siprotec 7sj81scope:eqversion:5>=v7.80

Trust: 0.6

vendor:siemensmodel:siprotec 7sj82scope:eqversion:5>=v7.80

Trust: 0.6

vendor:siemensmodel:siprotec 7sl82scope:eqversion:5>=v7.80

Trust: 0.6

vendor:siemensmodel:siprotec 7ut82scope:eqversion:5>=v7.80

Trust: 0.6

vendor:siemensmodel:siprotec 7sk82scope:eqversion:5>=v7.80

Trust: 0.6

sources: CNVD: CNVD-2025-01697

CVSS

SEVERITY

CVSSV2

CVSSV3

productcert@siemens.com: CVE-2024-53649
value: HIGH

Trust: 1.0

CNVD: CNVD-2025-01697
value: HIGH

Trust: 0.6

CNVD: CNVD-2025-01697
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:C/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

productcert@siemens.com: CVE-2024-53649
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 3.6
version: 3.1

Trust: 1.0

sources: CNVD: CNVD-2025-01697 // NVD: CVE-2024-53649

PROBLEMTYPE DATA

problemtype:CWE-552

Trust: 1.0

sources: NVD: CVE-2024-53649

EXTERNAL IDS

db:NVDid:CVE-2024-53649

Trust: 1.6

db:SIEMENSid:SSA-194557

Trust: 1.6

db:CNVDid:CNVD-2025-01697

Trust: 0.6

sources: CNVD: CNVD-2025-01697 // NVD: CVE-2024-53649

REFERENCES

url:https://cert-portal.siemens.com/productcert/html/ssa-194557.html

Trust: 1.6

sources: CNVD: CNVD-2025-01697 // NVD: CVE-2024-53649

SOURCES

db:CNVDid:CNVD-2025-01697
db:NVDid:CVE-2024-53649

LAST UPDATE DATE

2025-01-19T23:31:23.893000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2025-01697date:2025-01-17T00:00:00
db:NVDid:CVE-2024-53649date:2025-01-14T11:15:16.820

SOURCES RELEASE DATE

db:CNVDid:CNVD-2025-01697date:2025-01-17T00:00:00
db:NVDid:CVE-2024-53649date:2025-01-14T11:15:16.820