Vulnerability record · CVE-2015-5374 · published 18 July 2015
CVE-2015-5374: Siemens EN100 Ethernet Module UDP Packet Denial of Service
Siemens · Siprotec Firmware
Specially crafted UDP packets sent to port 50000 can cause a denial-of-service condition on Siemens EN100 Ethernet modules across multiple firmware variants (PROFINET IO, Modbus TCP, DNP3 TCP, IEC 104) and the SIPROTEC Merging Unit 6MU80. The device may require a manual reboot to restore service, disrupting industrial control communications.
Description
A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP for EN100 Ethernet module : All versions < V1.11.00; Firmware variant DNP3 TCP for EN100 Ethernet module : All versions < V1.03; Firmware variant IEC 104 for EN100 Ethernet module : All versions < V1.21; EN100 Ethernet module included in SIPROTEC Merging Unit 6MU80 : All versions < 1.02.02. Specially crafted packets sent to port 50000/UDP could cause a denial-of-service of the affected device. A manual reboot may be required to recover the service of the device.
AV:N/AC:L/Au:N/C:N/I:N/A:C
Automated analysis
high priorityThe vulnerability is remotely exploitable without authentication, causes complete loss of availability, affects critical industrial control equipment, and has a public exploit with very high EPSS probability.
What it is
Specially crafted UDP packets sent to port 50000 can cause a denial-of-service condition on Siemens EN100 Ethernet modules across multiple firmware variants (PROFINET IO, Modbus TCP, DNP3 TCP, IEC 104) and the SIPROTEC Merging Unit 6MU80. The device may require a manual reboot to restore service, disrupting industrial control communications.
Impact
An attacker can render the affected EN100 module unresponsive, interrupting PROFINET, Modbus TCP, DNP3, or IEC 104 communications and potentially requiring physical intervention to recover.
Attack surface
The flaw is reachable over the network via UDP port 50000 with no authentication required, as indicated by the CVSS vector AV:N/AC:L/Au:N. No user interaction is needed.
Exploitation
No CISA KEV listing is present, but EPSS is very high (0.74497, 99.469th percentile) and a public Exploit-DB entry (44103) exists, indicating exploit code is available.
What to do
- Apply the firmware updates specified in Siemens security advisory SSA-732541 (and related advisories) for each affected EN100 firmware variant.
- Restrict network access to UDP port 50000 on affected devices using firewalls or ACLs, allowing only trusted control-system hosts.
- Segment industrial control networks so EN100 modules are not reachable from untrusted networks or the internet.
- Monitor Siemens and ICS-CERT advisories for updated firmware and mitigation guidance.
- If patching is not immediately possible, consider disabling unused protocols or placing affected devices behind compensating network controls.
Detection
- Monitor network traffic for anomalous or high-volume UDP packets directed to port 50000 on EN100 devices.
- Alert on loss of communication or heartbeat failures from affected EN100 modules or SIPROTEC Merging Unit 6MU80.
- Review device logs for unexpected reboots or service restarts that may indicate a denial-of-service event.
- Use IDS/IPS signatures or custom rules to detect known exploit patterns targeting UDP port 50000.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-5374 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-5374), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.