CVE-2015-5374General(siemens / siprotec_4)

LOWCVSS 7.8 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for siemens siprotec_4 systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP for EN100 Ethernet module : All versions < V1.11.00; Firmware variant DNP3 TCP for EN100 Ethernet module : All versions < V1.03; Firmware variant IEC 104 for EN100 Ethernet module : All versions < V1.21; EN100 Ethernet module included in SIPROTEC Merging Unit 6MU80 : All versions < 1.02.02. Specially crafted packets sent to port 50000/UDP could cause a denial-of-service of the affected device. A manual reboot may be required to recover the service of the device.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-19

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • siprotec_4
  • siprotec_compact
  • siprotec_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-01-30); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
siprotec_4siprotec_compactsiprotec_firmware

1 version affected across 3 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-01-30: 1Mentions · 2026-04-15: 1Active Exploitation · 2026-04-15: 1Technical Details · 2026-04-15: 101-3004-15
Signal classification2 categories
General
150.0%
Active Exploitation
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-01-301
General1
2026-04-151
Active Exploitation1
Full discourse2 posts
  • Urja@urjasec
    Active Exploitation

    One year later: Industroyer (Dec 2016). Different target, Ukrenergo's Pivnichna 330kV transmission substation. Higher up the grid. The malware spoke IEC-104 natively to open breakers via RTUs, and used CVE-2015-5374 to disable Siemens SIPROTEC protection relays.

    Post summary

    The Industroyer malware targeted Ukraine’s grid, actively exploiting CVE‑2015‑5374 to disable Siemens SIPROTEC protection relays via IEC‑104 communication, illustrating a real‑world attack.

    1000055
    6 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    General

    IDS deployments across 100+ energy sites reveal critical OT security gaps including unpatched PAC devices (CVE-2015-5374), risky external links, weak segmentation, and incomplete asset inventories. #OTSecurity #EnergyRisk #IndustrialSafety https://ift.tt/GKHewUF

    Post summary

    The tweet notes OT security gaps, citing unpatched PAC devices with CVE‑2015‑5374, but offers no technical, exploit, or patch details.

    00010113
    3.6K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
HWsiemenssiprotec_4---
HWsiemenssiprotec_compact---
OSsiemenssiprotec_firmware4.24--

Explore more