PatchSiren cyber security CVE debrief
CVE-2024-53649 Siemens CVE debrief
CVE-2024-53649 is a path traversal vulnerability in Siemens SIPROTEC 5 protective relay devices that allows authenticated remote attackers to read arbitrary files from the device filesystem. The vulnerability stems from improper path limitation in the embedded web server. Published on January 14, 2025, this vulnerability affects 43 distinct SIPROTEC 5 product variants across multiple device families including 6MD, 6MU, 7KE, 7SA, 7SD, 7SJ, 7SK, 7SL, 7SS, 7ST, 7SX, 7SY, 7UM, 7UT, 7VE, 7VK, and 7VU series with various CPU modules (CP050, CP100, CP150, CP300). The CVSS 3.1 score of 6.5 (Medium severity) reflects network accessibility, low attack complexity, and required authentication, with high confidentiality impact but no integrity or availability impact. CISA issued advisory ICSA-25-016-04 on the publication date. Siemens has released multiple firmware updates between February and November 2025 to address affected products, with fix versions varying by product line (V8.90, V9.68, or V9.80 depending on the specific device).
- Vendor
- Siemens
- Product
- SIPROTEC 5 6MD84 (CP300)
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-01-14
- Original CVE updated
- 2025-11-11
- Advisory published
- 2025-01-14
- Advisory updated
- 2025-11-11
Who should care
Organizations operating Siemens SIPROTEC 5 protective relays in electrical power systems, including electric utilities, industrial facilities with on-site generation, substation operators, and critical infrastructure providers. Security teams responsible for OT/ICS environments, power system protection engineers, and asset owners with SIPROTEC 5 deployments should prioritize assessment and patching. The authenticated nature of this vulnerability means organizations with strong access controls may have reduced immediate risk, but the high confidentiality impact and ease of exploitation once authenticated warrant prompt attention.
Technical summary
CVE-2024-53649 is a path traversal vulnerability (CWE-22) in the embedded web server of Siemens SIPROTEC 5 protective relay devices. The web server fails to properly validate and restrict file system paths, allowing an authenticated attacker to traverse the directory structure and read arbitrary files from the device filesystem. This vulnerability requires network access to the device's web interface and valid credentials. The attack complexity is low with no user interaction required. The confidentiality impact is rated high as sensitive configuration files, credentials, or operational data may be exposed, while integrity and availability impacts are none. The vulnerability affects 43 product variants across the SIPROTEC 5 family with different CPU modules (CP050, CP100, CP150, CP300). Siemens has released firmware updates with varying fix versions: V8.90 for older CP100-based devices, V9.68 for 6MD89 and 7ST85, and V9.80 for most other affected products. A mitigation of disabling the web server is available for all affected devices if patching is not immediately feasible.
Defensive priority
high
Recommended defensive actions
- Apply vendor-supplied firmware updates: update SIPROTEC 5 6MD89 and 7ST85 to V9.68 or later; update SIPROTEC 5 6MD84, 7SA82 (CP150), 7SD82 (CP150), 7SJ81 (CP150), 7SJ82 (CP150), 7SK82 (CP150), 7SL82 (CP150), 7ST86, 7SX82
- 7SY82
- 7UT82 (CP150)
- 7SX800 to V9.80 or later; update SIPROTEC 5 6MD85
- 6MD86
- 6MU85
- 7KE85
- 7SA86 (CP300), 7SA87 (CP300), 7SD86 (CP300), 7SD87 (CP300), 7SJ85 (CP300), 7SJ86 (CP300), 7SK85 (CP300), 7SL86 (CP300), 7SL87 (CP300), 7SS85 (CP300), 7SX85 (CP300), 7UM85 (CP300), 7UT85 (CP300), 7UT86 (CP300), 7UT87 (CP3
Evidence notes
Vulnerability description and affected products confirmed through CISA CSAF advisory ICSA-25-016-04 and Siemens security advisory SSA-194557. CVSS vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N sourced from CISA CSAF document. Remediation timeline shows fixes released across multiple dates: February 11, 2025 (6MD89), March 11, 2025 (7ST85 and mitigation added), and November 11, 2025 (multiple CP100-based devices including 7SA82, 7SD82, 7SJ81, 7SJ82, 7SK82, 7SL82, 7UT82).
Sources and references
Verified primary and authoritative sources
-
CVE-2024-53649 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-53649
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-53649 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-53649
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-016-04.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-194557.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-194557.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-016-04
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.