CVE-2025-40570 (CNNVD-202508-1032)
中文标题:
Siemens多款产品 安全漏洞
英文标题:
A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V10.0), SIPROTEC 5 6...
漏洞描述
中文描述:
Siemens SIPROTEC 5 6MD84等都是德国西门子(Siemens)公司的一款继电器设备。 Siemens多款产品存在安全漏洞,该漏洞源于未限制本地USB端口带宽,可能导致拒绝服务攻击。以下产品及版本受到影响:SIPROTEC 5 6MD84、SIPROTEC 5 6MD85、SIPROTEC 5 6MD86、SIPROTEC 5 6MD89、SIPROTEC 5 6MU85、SIPROTEC 5 7KE85、SIPROTEC 5 7SA82、SIPROTEC 5 7SA86、SIPROTEC 5 7SA87、SIPROTEC 5 7SD82、SIPROTEC 5 7SD86、SIPROTEC 5 7SD87、SIPROTEC 5 7SJ81、SIPROTEC 5 7SJ82、SIPROTEC 5 7SJ85、SIPROTEC 5 7SJ86、SIPROTEC 5 7SK82、SIPROTEC 5 7SK85、SIPROTEC 5 7SL82、SIPROTEC 5 7SL86、SIPROTEC 5 7SL87、SIPROTEC 5 7SS85、SIPROTEC 5 7ST85、SIPROTEC 5 7ST86、SIPROTEC 5 7SX82、SIPROTEC 5 7SX85、SIPROTEC 5 7SY82、SIPROTEC 5 7UM85、SIPROTEC 5 7UT82、SIPROTEC 5 7UT85、SIPROTEC 5 7UT86、SIPROTEC 5 7UT87、SIPROTEC 5 7VE85、SIPROTEC 5 7VK87、SIPROTEC 5 7VU85和SIPROTEC 5 Compact 7SX800 V10.0之前版本。
英文描述:
A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V10.0), SIPROTEC 5 6MD85 (CP300) (All versions >= V7.80 < V10.0), SIPROTEC 5 6MD86 (CP300) (All versions >= V7.80 < V10.0), SIPROTEC 5 6MD89 (CP300) (All versions >= V7.80 < V10.0), SIPROTEC 5 6MU85 (CP300) (All versions >= V7.80 < V10.0), SIPROTEC 5 7KE85 (CP300) (All versions >= V7.80 < V10.0), SIPROTEC 5 7SA82 (CP150) (All versions < V10.0), SIPROTEC 5 7SA86 (CP300) (All versions >= V7.80 < V10.0), SIPROTEC 5 7SA87 (CP300) (All versions >= V7.80 < V10.0), SIPROTEC 5 7SD82 (CP150) (All versions < V10.0), SIPROTEC 5 7SD86 (CP300) (All versions >= V7.80 < V10.0), SIPROTEC 5 7SD87 (CP300) (All versions >= V7.80 < V10.0), SIPROTEC 5 7SJ81 (CP150) (All versions < V10.0), SIPROTEC 5 7SJ82 (CP150) (All versions < V10.0), SIPROTEC 5 7SJ85 (CP300) (All versions >= V7.80 < V10.0), SIPROTEC 5 7SJ86 (CP300) (All versions >= V7.80 < V10.0), SIPROTEC 5 7SK82 (CP150) (All versions < V10.0), SIPROTEC 5 7SK85 (CP300) (All versions >= V7.80 < V10.0), SIPROTEC 5 7SL82 (CP150) (All versions < V10.0), SIPROTEC 5 7SL86 (CP300) (All versions >= V7.80 < V10.0), SIPROTEC 5 7SL87 (CP300) (All versions >= V7.80 < V10.0), SIPROTEC 5 7SS85 (CP300) (All versions >= V7.80 < V10.0), SIPROTEC 5 7ST85 (CP300) (All versions < V10.0), SIPROTEC 5 7ST86 (CP300) (All versions < V10.0), SIPROTEC 5 7SX82 (CP150) (All versions < V10.0), SIPROTEC 5 7SX85 (CP300) (All versions < V10.0), SIPROTEC 5 7SY82 (CP150) (All versions < V10.0), SIPROTEC 5 7UM85 (CP300) (All versions >= V7.80 < V10.0), SIPROTEC 5 7UT82 (CP150) (All versions < V10.0), SIPROTEC 5 7UT85 (CP300) (All versions >= V7.80 < V10.0), SIPROTEC 5 7UT86 (CP300) (All versions >= V7.80 < V10.0), SIPROTEC 5 7UT87 (CP300) (All versions >= V7.80 < V10.0), SIPROTEC 5 7VE85 (CP300) (All versions >= V7.80 < V10.0), SIPROTEC 5 7VK87 (CP300) (All versions >= V7.80 < V10.0), SIPROTEC 5 7VU85 (CP300) (All versions < V10.0), SIPROTEC 5 Compact 7SX800 (CP050) (All versions < V10.0). Affected devices do not properly limit the bandwidth for incoming network packets over their local USB port. This could allow an attacker with physical access to send specially crafted packets with high bandwidth to the affected devices thus forcing them to exhaust their memory and stop responding to any network traffic via the local USB port. Affected devices reset themselves automatically after a successful attack. The protection function is not affected of this vulnerability.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Siemens | SIPROTEC 5 6MD84 (CP300) | - | < V10.0 | - |
cpe:2.3:a:siemens:siprotec_5_6md84_(cp300):*:*:*:*:*:*:*:*
|
| Siemens | SIPROTEC 5 6MD85 (CP300) | - | < V10.0 | - |
cpe:2.3:a:siemens:siprotec_5_6md85_(cp300):*:*:*:*:*:*:*:*
|
| Siemens | SIPROTEC 5 6MD86 (CP300) | - | < V10.0 | - |
cpe:2.3:a:siemens:siprotec_5_6md86_(cp300):*:*:*:*:*:*:*:*
|
| Siemens | SIPROTEC 5 6MD89 (CP300) | - | < V10.0 | - |
cpe:2.3:a:siemens:siprotec_5_6md89_(cp300):*:*:*:*:*:*:*:*
|
| Siemens | SIPROTEC 5 6MU85 (CP300) | - | < V10.0 | - |
cpe:2.3:a:siemens:siprotec_5_6mu85_(cp300):*:*:*:*:*:*:*:*
|
| Siemens | SIPROTEC 5 7KE85 (CP300) | - | < V10.0 | - |
cpe:2.3:a:siemens:siprotec_5_7ke85_(cp300):*:*:*:*:*:*:*:*
|
| Siemens | SIPROTEC 5 7SA82 (CP150) | - | < V10.0 | - |
cpe:2.3:a:siemens:siprotec_5_7sa82_(cp150):*:*:*:*:*:*:*:*
|
| Siemens | SIPROTEC 5 7SA86 (CP300) | - | < V10.0 | - |
cpe:2.3:a:siemens:siprotec_5_7sa86_(cp300):*:*:*:*:*:*:*:*
|
| Siemens | SIPROTEC 5 7SA87 (CP300) | - | < V10.0 | - |
cpe:2.3:a:siemens:siprotec_5_7sa87_(cp300):*:*:*:*:*:*:*:*
|
| Siemens | SIPROTEC 5 7SD82 (CP150) | - | < V10.0 | - |
cpe:2.3:a:siemens:siprotec_5_7sd82_(cp150):*:*:*:*:*:*:*:*
|
| Siemens | SIPROTEC 5 7SD86 (CP300) | - | < V10.0 | - |
cpe:2.3:a:siemens:siprotec_5_7sd86_(cp300):*:*:*:*:*:*:*:*
|
| Siemens | SIPROTEC 5 7SD87 (CP300) | - | < V10.0 | - |
cpe:2.3:a:siemens:siprotec_5_7sd87_(cp300):*:*:*:*:*:*:*:*
|
| Siemens | SIPROTEC 5 7SJ81 (CP150) | - | < V10.0 | - |
cpe:2.3:a:siemens:siprotec_5_7sj81_(cp150):*:*:*:*:*:*:*:*
|
| Siemens | SIPROTEC 5 7SJ82 (CP150) | - | < V10.0 | - |
cpe:2.3:a:siemens:siprotec_5_7sj82_(cp150):*:*:*:*:*:*:*:*
|
| Siemens | SIPROTEC 5 7SJ85 (CP300) | - | < V10.0 | - |
cpe:2.3:a:siemens:siprotec_5_7sj85_(cp300):*:*:*:*:*:*:*:*
|
| Siemens | SIPROTEC 5 7SJ86 (CP300) | - | < V10.0 | - |
cpe:2.3:a:siemens:siprotec_5_7sj86_(cp300):*:*:*:*:*:*:*:*
|
| Siemens | SIPROTEC 5 7SK82 (CP150) | - | < V10.0 | - |
cpe:2.3:a:siemens:siprotec_5_7sk82_(cp150):*:*:*:*:*:*:*:*
|
| Siemens | SIPROTEC 5 7SK85 (CP300) | - | < V10.0 | - |
cpe:2.3:a:siemens:siprotec_5_7sk85_(cp300):*:*:*:*:*:*:*:*
|
| Siemens | SIPROTEC 5 7SL82 (CP150) | - | < V10.0 | - |
cpe:2.3:a:siemens:siprotec_5_7sl82_(cp150):*:*:*:*:*:*:*:*
|
| Siemens | SIPROTEC 5 7SL86 (CP300) | - | < V10.0 | - |
cpe:2.3:a:siemens:siprotec_5_7sl86_(cp300):*:*:*:*:*:*:*:*
|
| Siemens | SIPROTEC 5 7SL87 (CP300) | - | < V10.0 | - |
cpe:2.3:a:siemens:siprotec_5_7sl87_(cp300):*:*:*:*:*:*:*:*
|
| Siemens | SIPROTEC 5 7SS85 (CP300) | - | < V10.0 | - |
cpe:2.3:a:siemens:siprotec_5_7ss85_(cp300):*:*:*:*:*:*:*:*
|
| Siemens | SIPROTEC 5 7ST85 (CP300) | - | < V10.0 | - |
cpe:2.3:a:siemens:siprotec_5_7st85_(cp300):*:*:*:*:*:*:*:*
|
| Siemens | SIPROTEC 5 7ST86 (CP300) | - | < V10.0 | - |
cpe:2.3:a:siemens:siprotec_5_7st86_(cp300):*:*:*:*:*:*:*:*
|
| Siemens | SIPROTEC 5 7SX82 (CP150) | - | < V10.0 | - |
cpe:2.3:a:siemens:siprotec_5_7sx82_(cp150):*:*:*:*:*:*:*:*
|
| Siemens | SIPROTEC 5 7SX85 (CP300) | - | < V10.0 | - |
cpe:2.3:a:siemens:siprotec_5_7sx85_(cp300):*:*:*:*:*:*:*:*
|
| Siemens | SIPROTEC 5 7SY82 (CP150) | - | < V10.0 | - |
cpe:2.3:a:siemens:siprotec_5_7sy82_(cp150):*:*:*:*:*:*:*:*
|
| Siemens | SIPROTEC 5 7UM85 (CP300) | - | < V10.0 | - |
cpe:2.3:a:siemens:siprotec_5_7um85_(cp300):*:*:*:*:*:*:*:*
|
| Siemens | SIPROTEC 5 7UT82 (CP150) | - | < V10.0 | - |
cpe:2.3:a:siemens:siprotec_5_7ut82_(cp150):*:*:*:*:*:*:*:*
|
| Siemens | SIPROTEC 5 7UT85 (CP300) | - | < V10.0 | - |
cpe:2.3:a:siemens:siprotec_5_7ut85_(cp300):*:*:*:*:*:*:*:*
|
| Siemens | SIPROTEC 5 7UT86 (CP300) | - | < V10.0 | - |
cpe:2.3:a:siemens:siprotec_5_7ut86_(cp300):*:*:*:*:*:*:*:*
|
| Siemens | SIPROTEC 5 7UT87 (CP300) | - | < V10.0 | - |
cpe:2.3:a:siemens:siprotec_5_7ut87_(cp300):*:*:*:*:*:*:*:*
|
| Siemens | SIPROTEC 5 7VE85 (CP300) | - | < V10.0 | - |
cpe:2.3:a:siemens:siprotec_5_7ve85_(cp300):*:*:*:*:*:*:*:*
|
| Siemens | SIPROTEC 5 7VK87 (CP300) | - | < V10.0 | - |
cpe:2.3:a:siemens:siprotec_5_7vk87_(cp300):*:*:*:*:*:*:*:*
|
| Siemens | SIPROTEC 5 7VU85 (CP300) | - | < V10.0 | - |
cpe:2.3:a:siemens:siprotec_5_7vu85_(cp300):*:*:*:*:*:*:*:*
|
| Siemens | SIPROTEC 5 Compact 7SX800 (CP050) | - | < V10.0 | - |
cpe:2.3:a:siemens:siprotec_5_compact_7sx800_(cp050):*:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
CVSS评分详情
3.1 (cna)
LOWCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
4.0 (cna)
LOWCVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2025-40570 |
2025-11-11 15:23:20 | 2025-11-11 07:40:30 |
| NVD | nvd_CVE-2025-40570 |
2025-11-11 15:00:59 | 2025-11-11 07:48:19 |
| CNNVD | cnnvd_CNNVD-202508-1032 |
2025-11-11 15:12:53 | 2025-11-11 08:00:04 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 其他
- cnnvd_id: 未提取 -> CNNVD-202508-1032
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- data_sources: ['cve'] -> ['cve', 'nvd']