PatchSiren cyber security CVE debrief
CVE-2024-38867 Siemens CVE debrief
Siemens SIPROTEC 5 devices support weak TLS ciphers on ports 443/tcp (web), 4443/tcp (DIGSI 5), and configurable syslog-over-TLS ports. An attacker in a man-in-the-middle position could exploit this to decrypt traffic. The vulnerability was published on 2024-07-09 and last modified on 2025-11-11, when fixes were added for additional product variants (SIPROTEC 5 7SA82, 7SD82, 7SL82, and 7UT82 with CP100). CVSS 3.1 score is 5.9 (Medium).
- Vendor
- Siemens
- Product
- SIPROTEC 5 6MD84 (CP300)
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-07-09
- Original CVE updated
- 2025-11-11
- Advisory published
- 2024-07-09
- Advisory updated
- 2025-11-11
Who should care
Operators of Siemens SIPROTEC 5 protection and control devices in electrical substations and industrial environments; OT security teams responsible for securing IEC 61850 and protection relay communications; compliance officers managing NERC CIP or similar critical infrastructure security requirements.
Technical summary
Affected SIPROTEC 5 devices accept weak TLS cipher suites on web (443/tcp), DIGSI 5 (4443/tcp), and syslog-over-TLS ports. This cryptographic weakness allows network-positioned attackers to downgrade connections and decrypt traffic. The vulnerability affects 69 product variants across multiple device families and communication modules. Siemens has released firmware updates for many variants; however, 22 products have no planned fix. Network access restrictions serve as the primary compensating control for unpatched devices.
Defensive priority
medium
Recommended defensive actions
- Apply vendor firmware updates where available: V8.89+ or V8.90+ for V8.xx variants; V9.62+, V9.64+, or V9.65+ for V9.xx variants per Siemens guidance.
- Restrict network access to affected ports (443/tcp, 4443/tcp, and configurable syslog-over-TLS ports) to trusted IP addresses only as a compensating control.
- Monitor for products marked 'no fix planned' and plan replacement or additional network segmentation for these variants.
- Review TLS configuration on affected devices to ensure only strong cipher suites are enabled after patching.
Evidence notes
CISA CSAF advisory ICSA-24-193-14 documents weak cipher support on multiple ports. Siemens SSA-750499 provides vendor remediation guidance. The 2025-11-11 revision added fixes for four additional CP100-based product variants.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-38867 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-38867
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-38867 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-38867
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-193-14.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-750499.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-750499.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-193-14
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.