CVE-2015-5374
A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP for EN100 Ethernet module : All versions < V1.11.00; Firmware variant DNP3 TCP for EN100 Ethernet module : All versions < V1.03; Firmware variant IEC 104 for EN100 Ethernet module : All versions < V1.21; EN100 Ethernet module included in SIPROTEC Merging Unit 6MU80 : All versions < 1.02.02. Specially crafted packets sent to port 50000/UDP could cause a denial-of-service of the affected device. A manual reboot may be required to recover the service of the device.
Published:Jul 18, 2015
Last Modified:Apr 12, 2025
EPS:Jul 18, 2015
EPSS Score:0.84825
CVSS Score:7.8
Affected Products
Vendor
Product
Action
Vendor
Siemens
Product
Siprotec 4
Siemens
Siprotec 4
Vendor
Siemens
Product
Siprotec Compact
Siemens
Siprotec Compact
Vendor
Siemens
Product
Siprotec Firmware
Siemens
Siprotec Firmware
Common Weakness Enumeration
No CWE recorded yet
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
