← Vulnerability feed

Vulnerability record · CVE-2015-5374 · published 18 July 2015

CVE-2015-5374: Siemens EN100 Ethernet Module UDP Packet Denial of Service

Siemens · Siprotec Firmware

Specially crafted UDP packets sent to port 50000 can cause a denial-of-service condition on Siemens EN100 Ethernet modules across multiple firmware variants (PROFINET IO, Modbus TCP, DNP3 TCP, IEC 104) and the SIPROTEC Merging Unit 6MU80. The device may require a manual reboot to restore service, disrupting industrial control communications.

7.8 CVSS 2.0 High EPSS 74% · top 0.5% CWE-19 · CWE-19
7.8CVSS 2.0 base score
74%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References
17 Jun 2026Last modified by NVD

Description

A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP for EN100 Ethernet module : All versions < V1.11.00; Firmware variant DNP3 TCP for EN100 Ethernet module : All versions < V1.03; Firmware variant IEC 104 for EN100 Ethernet module : All versions < V1.21; EN100 Ethernet module included in SIPROTEC Merging Unit 6MU80 : All versions < 1.02.02. Specially crafted packets sent to port 50000/UDP could cause a denial-of-service of the affected device. A manual reboot may be required to recover the service of the device.

AV:N/AC:L/Au:N/C:N/I:N/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityThe vulnerability is remotely exploitable without authentication, causes complete loss of availability, affects critical industrial control equipment, and has a public exploit with very high EPSS probability.

What it is

Specially crafted UDP packets sent to port 50000 can cause a denial-of-service condition on Siemens EN100 Ethernet modules across multiple firmware variants (PROFINET IO, Modbus TCP, DNP3 TCP, IEC 104) and the SIPROTEC Merging Unit 6MU80. The device may require a manual reboot to restore service, disrupting industrial control communications.

Impact

An attacker can render the affected EN100 module unresponsive, interrupting PROFINET, Modbus TCP, DNP3, or IEC 104 communications and potentially requiring physical intervention to recover.

Attack surface

The flaw is reachable over the network via UDP port 50000 with no authentication required, as indicated by the CVSS vector AV:N/AC:L/Au:N. No user interaction is needed.

Exploitation

No CISA KEV listing is present, but EPSS is very high (0.74497, 99.469th percentile) and a public Exploit-DB entry (44103) exists, indicating exploit code is available.

What to do

  • Apply the firmware updates specified in Siemens security advisory SSA-732541 (and related advisories) for each affected EN100 firmware variant.
  • Restrict network access to UDP port 50000 on affected devices using firewalls or ACLs, allowing only trusted control-system hosts.
  • Segment industrial control networks so EN100 modules are not reachable from untrusted networks or the internet.
  • Monitor Siemens and ICS-CERT advisories for updated firmware and mitigation guidance.
  • If patching is not immediately possible, consider disabling unused protocols or placing affected devices behind compensating network controls.

Detection

  • Monitor network traffic for anomalous or high-volume UDP packets directed to port 50000 on EN100 devices.
  • Alert on loss of communication or heartbeat failures from affected EN100 modules or SIPROTEC Merging Unit 6MU80.
  • Review device logs for unexpected reboots or service restarts that may indicate a denial-of-service event.
  • Use IDS/IPS signatures or custom rules to detect known exploit patterns targeting UDP port 50000.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-5374 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

5.3CVE-2016-4785Siemens siprotec firmware information exposure vulnerabilityA vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP …EPSS 2.7%5.3CVE-2016-4784Siemens siprotec firmware information exposure vulnerabilityA vulnerability has been identified in firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP …EPSS 2.7%8.4CVE-2025-48595Android Framework integer overflow enables local code executionAn integer overflow in multiple locations of the Android Framework can be turned into code execution. It allows a local attacker to escalate privileg…KEVEPSS 1.7%analysed7.8CVE-2021-30952Apple WebKit integer overflow allows code execution via crafted web contentAn integer overflow in Apple's WebKit engine was fixed by improved input validation across tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS/iPadOS 15…KEVEPSS 7.0%analysed7.8CVE-2026-21385Qualcomm chipset firmware memory corruption via alignment integer overflowA memory corruption flaw in Qualcomm chipset firmware arises from an integer overflow when alignments are used for memory allocation (CWE-190). It af…KEVEPSS 1.2%analysed7.8CVE-2018-14634Linux kernel create_elf_tables() integer overflow privilege escalationAn integer overflow in the Linux kernel's create_elf_tables() function lets an unprivileged local user escalate privileges when a SUID or otherwise p…KEVEPSS 15%analysed7.8CVE-2025-24985Windows Fast FAT Driver integer overflow enables local code executionThe Windows Fast FAT driver contains an integer overflow that leads to a heap-based buffer overflow. A crafted FAT filesystem operation can corrupt h…KEVEPSS 3.8%analysed9.8CVE-2014-0497Adobe Flash Player integer underflow allows remote code executionAdobe Flash Player contains an integer underflow (CWE-191) that allows remote attackers to execute arbitrary code via unspecified vectors. The flaw a…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2015-5374), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.