{"$ref":"https://www.cert.ssi.gouv.fr/openapi.json","affected_systems":[{"description":"SIPROTEC 5 7SL87 (CP300) versions sup\u00e9rieures ou \u00e9gales \u00e0V7.80 pour la vuln\u00e9rabilit\u00e9 CVE-2024-3596","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"SIPROTEC 5 7SL86 (CP300) versions sup\u00e9rieures ou \u00e9gales \u00e0V7.80 pour la vuln\u00e9rabilit\u00e9 CVE-2024-3596","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"SIPROTEC 5 7SD86 (CP300) versions sup\u00e9rieures ou \u00e9gales \u00e0V7.80 pour la vuln\u00e9rabilit\u00e9 CVE-2024-3596","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"SIPROTEC 5 7SX85 (CP300) toutes versions pour la vuln\u00e9rabilit\u00e9 CVE-2024-3596","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"SIPROTEC 5 6MD85 (CP300) versions sup\u00e9rieures ou \u00e9gales \u00e0V7.80 pour la vuln\u00e9rabilit\u00e9 CVE-2024-3596","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"POWER METER SICAM Q100 family versions ant\u00e9rieures \u00e0 V2.70","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"SIPROTEC 5 6MD89 (CP300) versions sup\u00e9rieures ou \u00e9gales \u00e0V7.80 pour la vuln\u00e9rabilit\u00e9 CVE-2024-3596","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"SIPROTEC 5 7UT87 (CP300) versions sup\u00e9rieures ou \u00e9gales \u00e0V7.80 pour la vuln\u00e9rabilit\u00e9 CVE-2024-3596","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"SIPROTEC 5 7VK87 (CP300) versions sup\u00e9rieures ou \u00e9gales \u00e0V7.80 pour la vuln\u00e9rabilit\u00e9 CVE-2024-3596","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"Totally Integrated Automation Portal (TIA Portal) V17 toutes versions","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"SIPROTEC 5 7ST85 (CP300) versions ant\u00e9rieures \u00e0 V9.68","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"SIPROTEC 5 6MD84 (CP300) toutes versions pour la vuln\u00e9rabilit\u00e9 CVE-2024-3596","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"Totally Integrated Automation Portal (TIA Portal) V18 toutes versions","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"SIMATIC PCS neo versions ant\u00e9rieures \u00e0 V5.0 Update 1","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"SIPROTEC 5 7SJ86 (CP300) versions sup\u00e9rieures ou \u00e9gales \u00e0V7.80 pour la vuln\u00e9rabilit\u00e9 CVE-2024-3596","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"SIPROTEC 5 7SD87 (CP300) versions sup\u00e9rieures ou \u00e9gales \u00e0V7.80 pour la vuln\u00e9rabilit\u00e9 CVE-2024-3596","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"POWER METER SICAM Q200 family toutes versions pour la vuln\u00e9rabilit\u00e9 CVE-2024-3596","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"SIPROTEC 5 7SK85 (CP300) versions sup\u00e9rieures ou \u00e9gales \u00e0V7.80 pour la vuln\u00e9rabilit\u00e9 CVE-2024-3596","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"SIPROTEC 5 7UT85 (CP300) versions sup\u00e9rieures ou \u00e9gales \u00e0V7.80 pour la vuln\u00e9rabilit\u00e9 CVE-2024-3596","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"SIPROTEC 5 7VU85 (CP300) toutes versions pour la vuln\u00e9rabilit\u00e9 CVE-2024-3596","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"Totally Integrated Automation Portal (TIA Portal) V19 toutes versions","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"SIMATIC PCS neo V4.1 toutes versions. L'\u00e9diteur indique que le produit ne b\u00e9n\u00e9ficiera pas de correctif de s\u00e9curit\u00e9 pour les vuln\u00e9rabilit\u00e9s CVE-2025-30174, CVE-2025-30175 et CVE-2025-30176.","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"SIMATIC PCS neo versions ant\u00e9rieures \u00e0 V4.1 Update 3","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"SIMATIC IPC RS-828A toutes versions pour la vuln\u00e9rabilit\u00e9 CVE-2024-54085","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"SIPROTEC 5 7SJ85 (CP300) versions sup\u00e9rieures ou \u00e9gales \u00e0V7.80 pour la vuln\u00e9rabilit\u00e9 CVE-2024-3596","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"SCALANCE LPE9403 toutes versions pour les vuln\u00e9rabilit\u00e9s CVE-2025-40581, CVE-2025-40582 et CVE-2025-40583.","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"Desigo CC toutes versions","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"SIMATIC PCS neo V5.0 toutes versions pour les vuln\u00e9rabilit\u00e9s CVE-2025-30174, CVE-2025-30175 et CVE-2025-30176.","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"SIPROTEC 5 7ST86 (CP300) versions ant\u00e9rieures \u00e0 V9.83","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"SCALANCE LPE9403 toutes versions pour les vuln\u00e9rabilit\u00e9s CVE-2025-40572, CVE-2025-40573, CVE-2025-40574, CVE-2025-40575, CVE-2025-40576, CVE-2025-40577, CVE-2025-40578, CVE-2025-40579 et CVE-2025-40580.","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"SIPROTEC 5 7SA87 (CP300) versions sup\u00e9rieures ou \u00e9gales \u00e0V7.80 pour la vuln\u00e9rabilit\u00e9 CVE-2024-3596","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"SIPROTEC 5 6MU85 (CP300) toutes versions pour la vuln\u00e9rabilit\u00e9 CVE-2024-3596","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"SIPROTEC 5 7UM85 (CP300) versions sup\u00e9rieures ou \u00e9gales \u00e0V7.80 pour la vuln\u00e9rabilit\u00e9 CVE-2024-3596","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"SIPROTEC 5 7SA86 (CP300) versions sup\u00e9rieures ou \u00e9gales \u00e0V7.80 pour la vuln\u00e9rabilit\u00e9 CVE-2024-3596","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"SIPROTEC 5 7VE85 (CP300) versions sup\u00e9rieures ou \u00e9gales \u00e0V7.80 pour la vuln\u00e9rabilit\u00e9 CVE-2024-3596","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"SIPROTEC 5 7KE85 (CP300) versions sup\u00e9rieures ou \u00e9gales \u00e0V7.80 pour la vuln\u00e9rabilit\u00e9 CVE-2024-3596","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"Totally Integrated Automation Portal (TIA Portal) V20 toutes versions","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"SIPROTEC 5 7UT86 (CP300) versions sup\u00e9rieures ou \u00e9gales \u00e0V7.80 pour la vuln\u00e9rabilit\u00e9 CVE-2024-3596","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"SIPROTEC 5 7SS85 (CP300) versions sup\u00e9rieures ou \u00e9gales \u00e0V7.80 pour la vuln\u00e9rabilit\u00e9 CVE-2024-3596","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"SICORE Base system toutes versions pour la vuln\u00e9rabilit\u00e9 CVE-2024-3596","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"SICAM GridPass versions ant\u00e9rieures \u00e0 V2.50","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"SIPROTEC 5 6MD89 (CP300) V9.6 versions ant\u00e9rieures \u00e0 V9.68","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"SIPROTEC 5 6MD86 (CP300) versions sup\u00e9rieures ou \u00e9gales \u00e0V7.80 pour la vuln\u00e9rabilit\u00e9 CVE-2024-3596","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}},{"description":"CPCI85 Central Processing/Communication toutes versions pour la vuln\u00e9rabilit\u00e9 CVE-2024-3596","product":{"name":"N/A","vendor":{"name":"Siemens","scada":true}}}],"affected_systems_content":"","content":"## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l'\u00e9diteur pour l'obtention des correctifs (cf. section Documentation).","cves":[{"name":"CVE-2025-40572","url":"https://www.cve.org/CVERecord?id=CVE-2025-40572"},{"name":"CVE-2025-40577","url":"https://www.cve.org/CVERecord?id=CVE-2025-40577"},{"name":"CVE-2025-30175","url":"https://www.cve.org/CVERecord?id=CVE-2025-30175"},{"name":"CVE-2025-40582","url":"https://www.cve.org/CVERecord?id=CVE-2025-40582"},{"name":"CVE-2025-30176","url":"https://www.cve.org/CVERecord?id=CVE-2025-30176"},{"name":"CVE-2025-40574","url":"https://www.cve.org/CVERecord?id=CVE-2025-40574"},{"name":"CVE-2024-3596","url":"https://www.cve.org/CVERecord?id=CVE-2024-3596"},{"name":"CVE-2025-40581","url":"https://www.cve.org/CVERecord?id=CVE-2025-40581"},{"name":"CVE-2025-30174","url":"https://www.cve.org/CVERecord?id=CVE-2025-30174"},{"name":"CVE-2024-23815","url":"https://www.cve.org/CVERecord?id=CVE-2024-23815"},{"name":"CVE-2025-40576","url":"https://www.cve.org/CVERecord?id=CVE-2025-40576"},{"name":"CVE-2025-40578","url":"https://www.cve.org/CVERecord?id=CVE-2025-40578"},{"name":"CVE-2024-54085","url":"https://www.cve.org/CVERecord?id=CVE-2024-54085"},{"name":"CVE-2025-40575","url":"https://www.cve.org/CVERecord?id=CVE-2025-40575"},{"name":"CVE-2025-40566","url":"https://www.cve.org/CVERecord?id=CVE-2025-40566"},{"name":"CVE-2025-40580","url":"https://www.cve.org/CVERecord?id=CVE-2025-40580"},{"name":"CVE-2025-40573","url":"https://www.cve.org/CVERecord?id=CVE-2025-40573"},{"name":"CVE-2025-40579","url":"https://www.cve.org/CVERecord?id=CVE-2025-40579"},{"name":"CVE-2025-40583","url":"https://www.cve.org/CVERecord?id=CVE-2025-40583"}],"links":[],"reference":"CERTFR-2025-AVI-0397","revisions":[{"description":"Version initiale","revision_date":"2025-05-13T00:00:00.000000"}],"risks":[{"description":"D\u00e9ni de service \u00e0 distance"},{"description":"Ex\u00e9cution de code arbitraire"},{"description":"Injection SQL (SQLi)"},{"description":"Non sp\u00e9cifi\u00e9 par l'\u00e9diteur"},{"description":"Contournement de la politique de s\u00e9curit\u00e9"},{"description":"Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"}],"summary":"De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits Siemens. Certaines d'entre elles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire, un d\u00e9ni de service \u00e0 distance et une atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es.","title":"Multiples vuln\u00e9rabilit\u00e9s dans les produits Siemens","vendor_advisories":[{"published_at":"2025-05-13","title":"Bulletin de s\u00e9curit\u00e9 Siemens SSA-523418","url":"https://cert-portal.siemens.com/productcert/html/ssa-523418.html"},{"published_at":"2025-05-13","title":"Bulletin de s\u00e9curit\u00e9 Siemens SSA-446307","url":"https://cert-portal.siemens.com/productcert/html/ssa-446307.html"},{"published_at":"2025-05-13","title":"Bulletin de s\u00e9curit\u00e9 Siemens SSA-339086","url":"https://cert-portal.siemens.com/productcert/html/ssa-339086.html"},{"published_at":"2025-05-13","title":"Bulletin de s\u00e9curit\u00e9 Siemens SSA-614723","url":"https://cert-portal.siemens.com/productcert/html/ssa-614723.html"},{"published_at":"2025-05-13","title":"Bulletin de s\u00e9curit\u00e9 Siemens SSA-794185","url":"https://cert-portal.siemens.com/productcert/html/ssa-794185.html"},{"published_at":"2025-05-13","title":"Bulletin de s\u00e9curit\u00e9 Siemens SSA-327438","url":"https://cert-portal.siemens.com/productcert/html/ssa-327438.html"}]}
