PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-38867 Siemens CVE debrief

Siemens SIPROTEC 5 devices support weak TLS ciphers on ports 443/tcp (web), 4443/tcp (DIGSI 5), and configurable syslog-over-TLS ports. An attacker in a man-in-the-middle position could exploit this to decrypt traffic. The vulnerability was published on 2024-07-09 and last modified on 2025-11-11, when fixes were added for additional product variants (SIPROTEC 5 7SA82, 7SD82, 7SL82, and 7UT82 with CP100). CVSS 3.1 score is 5.9 (Medium).

Vendor
Siemens
Product
SIPROTEC 5 6MD84 (CP300)
CVSS
MEDIUM 5.9
CISA KEV
Not listed in stored evidence
Original CVE published
2024-07-09
Original CVE updated
2025-11-11
Advisory published
2024-07-09
Advisory updated
2025-11-11

Who should care

Operators of Siemens SIPROTEC 5 protection and control devices in electrical substations and industrial environments; OT security teams responsible for securing IEC 61850 and protection relay communications; compliance officers managing NERC CIP or similar critical infrastructure security requirements.

Technical summary

Affected SIPROTEC 5 devices accept weak TLS cipher suites on web (443/tcp), DIGSI 5 (4443/tcp), and syslog-over-TLS ports. This cryptographic weakness allows network-positioned attackers to downgrade connections and decrypt traffic. The vulnerability affects 69 product variants across multiple device families and communication modules. Siemens has released firmware updates for many variants; however, 22 products have no planned fix. Network access restrictions serve as the primary compensating control for unpatched devices.

Defensive priority

medium

Recommended defensive actions

  • Apply vendor firmware updates where available: V8.89+ or V8.90+ for V8.xx variants; V9.62+, V9.64+, or V9.65+ for V9.xx variants per Siemens guidance.
  • Restrict network access to affected ports (443/tcp, 4443/tcp, and configurable syslog-over-TLS ports) to trusted IP addresses only as a compensating control.
  • Monitor for products marked 'no fix planned' and plan replacement or additional network segmentation for these variants.
  • Review TLS configuration on affected devices to ensure only strong cipher suites are enabled after patching.

Evidence notes

CISA CSAF advisory ICSA-24-193-14 documents weak cipher support on multiple ports. Siemens SSA-750499 provides vendor remediation guidance. The 2025-11-11 revision added fixes for four additional CP100-based product variants.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-38867 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-38867

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-38867 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-38867

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-193-14.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-750499.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-750499.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-193-14

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.