📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global vulnerability Information Technology CRITICAL 2h Global vulnerability Information Technology CRITICAL 3h Global vulnerability Software and Technology HIGH 4h Global vulnerability Software and Cloud Services CRITICAL 4h Global phishing Artificial Intelligence and Email Security HIGH 4h Global phishing Email and Communications CRITICAL 5h Global vulnerability Enterprise Software / E-commerce CRITICAL 6h Global supply_chain Software Development and Technology CRITICAL 6h Global vulnerability Information Technology HIGH 7h Global vulnerability Information Technology HIGH 7h Global vulnerability Information Technology CRITICAL 2h Global vulnerability Information Technology CRITICAL 3h Global vulnerability Software and Technology HIGH 4h Global vulnerability Software and Cloud Services CRITICAL 4h Global phishing Artificial Intelligence and Email Security HIGH 4h Global phishing Email and Communications CRITICAL 5h Global vulnerability Enterprise Software / E-commerce CRITICAL 6h Global supply_chain Software Development and Technology CRITICAL 6h Global vulnerability Information Technology HIGH 7h Global vulnerability Information Technology HIGH 7h Global vulnerability Information Technology CRITICAL 2h Global vulnerability Information Technology CRITICAL 3h Global vulnerability Software and Technology HIGH 4h Global vulnerability Software and Cloud Services CRITICAL 4h Global phishing Artificial Intelligence and Email Security HIGH 4h Global phishing Email and Communications CRITICAL 5h Global vulnerability Enterprise Software / E-commerce CRITICAL 6h Global supply_chain Software Development and Technology CRITICAL 6h Global vulnerability Information Technology HIGH 7h Global vulnerability Information Technology HIGH 7h
Vulnerabilities

CVE-2025-40808

Medium
CWE-434 — Weakness Type
Published: Jun 9, 2026  ·  Modified: Jun 10, 2026  ·  Source: NVD
CVSS v3
6.1
🔗 NVD Official
📄 Description (English)

A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP300) (All versions), SIPROTEC 5 6MD86 (CP200) (All versions), SIPROTEC 5 6MD86 (CP300) (All versions), SIPROTEC 5 6MD89 (CP300) (All versions), SIPROTEC 5 6MU85 (CP300) (All versions), SIPROTEC 5 7KE85 (CP200) (All versions), SIPROTEC 5 7KE85 (CP300) (All versions), SIPROTEC 5 7SA82 (CP100) (All versions), SIPROTEC 5 7SA82 (CP150) (All versions), SIPROTEC 5 7SA86 (CP200) (All versions), SIPROTEC 5 7SA86 (CP300) (All versions), SIPROTEC 5 7SA87 (CP200) (All versions), SIPROTEC 5 7SA87 (CP300) (All versions), SIPROTEC 5 7SD82 (CP100) (All versions), SIPROTEC 5 7SD82 (CP150) (All versions), SIPROTEC 5 7SD86 (CP200) (All versions), SIPROTEC 5 7SD86 (CP300) (All versions), SIPROTEC 5 7SD87 (CP200) (All versions), SIPROTEC 5 7SD87 (CP300) (All versions), SIPROTEC 5 7SJ81 (CP100) (All versions), SIPROTEC 5 7SJ81 (CP150) (All versions), SIPROTEC 5 7SJ82 (CP100) (All versions), SIPROTEC 5 7SJ82 (CP150) (All versions), SIPROTEC 5 7SJ85 (CP200) (All versions), SIPROTEC 5 7SJ85 (CP300) (All versions), SIPROTEC 5 7SJ86 (CP200) (All versions), SIPROTEC 5 7SJ86 (CP300) (All versions), SIPROTEC 5 7SK82 (CP100) (All versions), SIPROTEC 5 7SK82 (CP150) (All versions), SIPROTEC 5 7SK85 (CP200) (All versions), SIPROTEC 5 7SK85 (CP300) (All versions), SIPROTEC 5 7SL82 (CP100) (All versions), SIPROTEC 5 7SL82 (CP150) (All versions), SIPROTEC 5 7SL86 (CP200) (All versions), SIPROTEC 5 7SL86 (CP300) (All versions), SIPROTEC 5 7SL87 (CP200) (All versions), SIPROTEC 5 7SL87 (CP300) (All versions), SIPROTEC 5 7SS85 (CP200) (All versions), SIPROTEC 5 7SS85 (CP300) (All versions), SIPROTEC 5 7ST85 (CP200) (All versions), SIPROTEC 5 7ST85 (CP300) (All versions), SIPROTEC 5 7ST86 (CP300) (All versions), SIPROTEC 5 7SX82 (CP150) (All versions), SIPROTEC 5 7SX85 (CP300) (All versions), SIPROTEC 5 7SY82 (CP150) (All versions), SIPROTEC 5 7UM85 (CP300) (All versions), SIPROTEC 5 7UT82 (CP100) (All versions), SIPROTEC 5 7UT82 (CP150) (All versions), SIPROTEC 5 7UT85 (CP200) (All versions), SIPROTEC 5 7UT85 (CP300) (All versions), SIPROTEC 5 7UT86 (CP200) (All versions), SIPROTEC 5 7UT86 (CP300) (All versions), SIPROTEC 5 7UT87 (CP200) (All versions), SIPROTEC 5 7UT87 (CP300) (All versions), SIPROTEC 5 7VE85 (CP300) (All versions), SIPROTEC 5 7VK87 (CP200) (All versions), SIPROTEC 5 7VK87 (CP300) (All versions), SIPROTEC 5 7VU85 (CP300) (All versions), SIPROTEC 5 Compact 7SX800 (CP050) (All versions). The affected application allows authenticated users to upload arbitrary files using DIGSI 5 protocol. This could allow an attacker to upload malicious configuration files, that could cause denial of service condition and potentially lead to code execution.

🤖 AI Executive Summary

CVE-2025-40808 affects Siemens SIPROTEC 5 protection relays across 60+ device models, allowing authenticated users to upload arbitrary files via DIGSI 5 protocol. This CWE-434 vulnerability could enable denial of service or code execution through malicious configuration files. With no patch currently available and widespread deployment in critical infrastructure, this poses significant risk to Saudi energy and industrial sectors.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: Jun 9, 2026 14:03
🇸🇦 Saudi Arabia Impact Assessment
Critical impact on Saudi energy sector (Saudi Aramco, SEC, regional utilities) relying on SIPROTEC 5 relays for grid protection and asset management. High risk to government critical infrastructure (NCA oversight), water/desalination facilities, and industrial manufacturing. Banking sector exposure through SWIFT-connected data centers using these relays. Telecom operators (STC, Mobily) using SIPROTEC 5 in network infrastructure. Attack surface expanded by insider threats and compromised maintenance accounts with DIGSI 5 access.
🏢 Affected Saudi Sectors
Energy (Saudi Aramco, SEC, regional utilities) Government (Critical Infrastructure - NCA oversight) Water & Desalination Industrial Manufacturing Banking & Financial Services Telecommunications (STC, Mobily) Healthcare (Hospital power systems)
⚖️ Saudi Risk Score (AI)
7.8
/ 10.0
🔧 Remediation Steps (English)
Immediate Actions:
1. Inventory all SIPROTEC 5 devices across organization (all 60+ affected models)
2. Restrict DIGSI 5 protocol access to authorized maintenance personnel only
3. Implement network segmentation isolating protection relay networks from general IT
4. Enable detailed logging of all DIGSI 5 upload activities
5. Require multi-factor authentication for DIGSI 5 access

Compensating Controls (until patch available):
6. Deploy file integrity monitoring on relay configuration files
7. Implement strict change management requiring approval before any configuration uploads
8. Use air-gapped maintenance networks for DIGSI 5 operations
9. Validate all configuration files against known-good checksums before deployment
10. Monitor relay CPU/memory usage for anomalous behavior indicating code execution

Detection Rules:
- Alert on DIGSI 5 upload commands from non-standard source IPs
- Flag configuration files with unexpected file extensions or sizes
- Monitor relay event logs for unauthorized configuration changes
- Detect relay reboots following configuration uploads
- Alert on relay process execution anomalies post-upload
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. حصر جميع أجهزة SIPROTEC 5 في المنظمة (جميع الموديلات الـ 60+ المتأثرة)
2. تقييد وصول بروتوكول DIGSI 5 للموظفين المصرحين فقط
3. تطبيق تقسيم الشبكة لعزل شبكات أجهزة الحماية عن تكنولوجيا المعلومات العامة
4. تفعيل تسجيل مفصل لجميع أنشطة تحميل DIGSI 5
5. فرض المصادقة متعددة العوامل لوصول DIGSI 5

الضوابط التعويضية (حتى توفر التصحيح):
6. نشر مراقبة سلامة الملفات على ملفات إعدادات الجهاز
7. تطبيق إدارة تغيير صارمة تتطلب موافقة قبل أي تحميل إعدادات
8. استخدام شبكات صيانة معزولة لعمليات DIGSI 5
9. التحقق من جميع ملفات الإعدادات مقابل بصمات معروفة قبل النشر
10. مراقبة استخدام CPU والذاكرة للجهاز للكشف عن السلوك الشاذ

قواعد الكشف:
- تنبيهات على أوامر تحميل DIGSI 5 من عناوين IP غير قياسية
- وضع علامة على ملفات الإعدادات بامتدادات أو أحجام غير متوقعة
- مراقبة سجلات أحداث الجهاز للتغييرات غير المصرحة
- الكشف عن إعادة تشغيل الجهاز بعد تحميل الإعدادات
- تنبيهات على شذوذ تنفيذ العمليات بعد التحميل
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
A.5.1.1 - Information security policies and procedures A.6.1.1 - Access control to information and other assets A.8.1.1 - Asset management and inventory A.12.2.1 - Change management procedures A.12.6.1 - Management of technical vulnerabilities
🔵 SAMA CSF
ID.AM-2 - Software platforms and applications are inventoried PR.AC-1 - Identities and credentials are issued and managed PR.AC-4 - Access is managed based on the principle of least privilege PR.IP-1 - Security policies and procedures are maintained DE.CM-3 - Personnel activity is monitored to detect anomalous behavior
🟡 ISO 27001:2022
A.5.1 - Management direction for information security A.6.1 - Screening and access control A.8.1 - Asset responsibility and inventory A.12.2 - Change management A.12.6 - Management of technical vulnerabilities and exposures
🟣 PCI DSS v4.0.1
Requirement 1.1 - Firewall configuration standards Requirement 2.1 - Default security parameters Requirement 6.2 - Security patches and updates Requirement 8.1 - User identification and authentication
📊 CVSS Score
6.1
/ 10.0 — Medium
📊 CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Attack VectorA — Adjacent
Attack ComplexityL — Low / Local
Privileges RequiredH — High
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityN — None / Network
IntegrityH — High
AvailabilityH — High
📋 Quick Facts
Severity Medium
CVSS Score6.1
CWECWE-434
Exploit No
Patch ✗ No
Published 2026-06-09
Source Feed nvd
🇸🇦 Saudi Risk Score
7.8
/ 10.0 — Saudi Risk
Priority: CRITICAL
🏷️ Tags
CWE-434
Share this CVE
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.