Siemens SIPROTEC 4 and SIPROTEC 4 Compact Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in multiple SIPROTEC 4 and SIPROTEC 4 Compact devices. The issue arises because these devices do not properly manage interrupted file transfer operations, potentially allowing an unauthenticated remote attacker to disrupt service. Affected devices require a restart to resume normal operations.

Impact

Exploitation of this vulnerability leads to a denial-of-service condition, causing the device to become unresponsive and requiring a manual restart to restore functionality.

Remediation

Siemens has released updates for certain affected products. For SIPROTEC 4 7SA6, 7SD5, and 7SD610, users should update to version 4.78 or later. For other products, no fix is currently planned.

Added: Aug 12, 2025, 12:56 PM
Updated: Aug 12, 2025, 3:17 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
2.5
exploitability
7.8
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.