CVE-2018-16563 is a Denial-of-Service vulnerability affecting Siemens EN100 Ethernet modules and SIPROTEC 5 relays with specific CPU variants and firmware versions. An attacker with network access can send specially crafted packets to port 102/tcp, causing the device's network functionality to become unavailable and requiring a manual restart. This vulnerability has a CVSS score of 5.9 (Medium), indicating a network-based attack with high impact on availability, but requiring high attack complexity due to the precondition of activated IEC 61850-MMS communication. At the time of advisory publication, there was no known public exploitation, and no exploit intelligence or community discussion has been identified.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.82CPE matchmatch criteria | cpe:2.3:o:siemens:siprotec_5_with_cpu_variant_cp100:*:*:*:*:*:*:*:* | ||
< 7.58CPE matchmatch criteria | cpe:2.3:o:siemens:siprotec_5_with_cpu_variant_cp200:*:*:*:*:*:*:*:* | ||
< 7.82CPE matchmatch criteria | cpe:2.3:o:siemens:siprotec_5_with_cpu_variant_cp300:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:siemens:en100_ethernet_module_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:siemens:en100_ethernet_module_with_firmware_variant_dnp3_tcp:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.