Back to all lessons
Awareness Lessons
4 months ago

Siemens SIPROTEC 5 Vulnerable to Malicious File Uploads via DIGSI 5 Protocol

Siemens SIPROTEC 5 devices contain a critical vulnerability that allows authenticated attackers to upload arbitrary, potentially malicious configuration files through the DIGSI 5 protocol, which could result in denial of service or remote code execution. The root cause is an insufficient file validation mechanism — the protocol lacked an allow-list to restrict what types of configuration files could be uploaded. This is especially concerning in operational technology (OT) and industrial control system (ICS) environments, where availability and integrity are mission-critical. Even authenticated users should not have unconstrained ability to upload arbitrary files to safety-critical devices, illustrating why least-privilege and input validation must be enforced at the protocol level.

Tactical Insight

Immediate actions

  • Apply Siemens' updated firmware versions that include the allow-list feature to all affected SIPROTEC 5 devices as soon as possible.
  • Implement Siemens' recommended countermeasures (e.g., network access restrictions) for devices where the patch cannot yet be applied.
  • Restrict DIGSI 5 protocol access to only authorized engineering workstations using firewall rules or network ACLs.

Long-term improvements

  • Enforce strict network segmentation between corporate IT networks and OT/ICS environments to limit lateral movement opportunities.
  • Adopt a formal OT asset inventory and vulnerability management program to track exposure of industrial devices in real time.
  • Require cryptographic signing and validation of all configuration files uploaded to industrial control devices.

Detection measures

  • Deploy OT-aware intrusion detection systems (IDS) capable of monitoring DIGSI 5 and similar industrial protocol traffic for anomalous file upload activity.
  • Enable centralized logging of all configuration changes on SIPROTEC 5 devices and alert on unexpected or unauthorized upload events.
  • Conduct regular configuration integrity checks to detect unauthorized modifications to device settings.