๐ ๐ฉ๐๐น๐ป๐ฒ๐ฟ๐ฎ๐ฏ๐ถ๐น๐ถ๐๐ ๐ถ๐ป ๐ฆ๐ถ๐ฒ๐บ๐ฒ๐ป๐ ๐ฆ๐๐ฃ๐ฅ๐ข๐ง๐๐ ๐ฑ ๐๐ฑ๐ฒ๐ป๐๐ถ๐ณ๐ถ๐ฒ๐ฑ
Our Technical Security Audit team has identified a vulnerability in ๐ฆ๐ถ๐ฒ๐บ๐ฒ๐ป๐ ๐ฆ๐๐ฃ๐ฅ๐ข๐ง๐๐ ๐ฑ ๐ฑ๐ฒ๐๐ถ๐ฐ๐ฒ๐:
โ ๏ธ The USB port may allow attacks due to improper bandwidth limitation.
๐ Description:
Affected SIPROTEC 5 devices do not properly limit the bandwidth for incoming network packets over their local USB port. This could allow an attacker with physical access to send specially crafted packets with high bandwidth to the affected devices thus forcing them to exhaust their memory and stop responding to any network traffic via the local USB port. Affected devices reset themselves automatically after a successful attack. During this restart the protection function is not available.
๐ The full advisory is available here: https://www.gai-netconsult.de/wp-content/uploads/2025/09/Advisory-GAINC-2025-001-1.0.pdf
โ ๏ธ Please follow the manufacturerโs guidance and updates.
๐ An overview of further advisories can be found on our website: www.gai-netconsult.de/advisories
๐ Congratulations to our colleagues ๐ ๐ฎ๐ฟ๐ฐ ๐๐๐ป๐ and ๐ง๐ผ๐ฟ๐ฎ๐น๐ณ ๐๐ถ๐บ๐ฝ๐ฒ๐น for this discovery.
#CyberSecurity #SecurityAdvisory #Vulnerability #ITSecurity #GAINetConsult #SecurityNotice

