ClosedMedium impactAI Generated

Siemens SIPROTEC 5 ICS Vulnerability – Session Identifier Brute-Force Risk

Occurred 12 May 2026·Detected 23 May 2026·
🇩🇪 Worldwide deployment of Siemens SIPROTEC 5 devices; vendor headquartered in Germany1 reportEnded 29 May 2026
CyberEnergy

CISA has republished a Siemens ProductCERT advisory identifying a vulnerability (CVE-2024-54017) in Siemens SIPROTEC 5 protective relay devices. The flaw involves insufficiently random session identifiers, enabling unauthenticated remote attackers to brute-force valid session IDs and gain limited read access to web server data. Dozens of device variants across multiple firmware versions are affected. SIPROTEC 5 devices are widely deployed in critical power infrastructure globally. Siemens is preparing patches and recommends network segmentation and VPN mitigations in the interim.

AI-generated from linked source reports. See our correction policy.

Impact verdict

Medium impact. MEDIUM: Second-pass historical recalibration. This cyber advisory or vulnerability item is relevant to Cyber and technology-dependent Property/Casualty books, but it does not evidence confirmed insured loss, claims activity, ransomware/business interruption, critical infrastructure outage, or quantified market impact sufficient for HIGH.

View assessment methodology

Premium discovery tier

Unlock analyst briefs, intelligence depth, and the revision timeline

Public pages show event facts and a short lead-in. Premium accounts unlock analyst briefs, deeper intelligence, loss context, and the full revision history for this event.

Start two-week trial

Affected countries

🇩🇪 Germany🇬🇱 GLOBAL

Lloyd's classifications

Tracking this kind of risk? Get an email when Cyber events escalate.

Get alerts