# Siemens SIPROTEC 5 file upload flaw risks DoS

Published: 2026-06-23 · Severity: high · Sectors: energy, manufacturing, transportation, healthcare, financial-services, government-national
Canonical: https://vorant.io/reports/f9614d67-a6c4-5468-a748-5041ee99aa78/siemens-siprotec-5-file-upload-flaw-risks-dos

> Authenticated attackers can upload malicious configuration files to Siemens SIPROTEC 5 relays via DIGSI 5 protocol, potentially causing permanent denial of service in power grid protection systems.

Siemens has disclosed CVE-2025-40808, an arbitrary file upload vulnerability affecting all versions of SIPROTEC 5 relay protection devices when accessed via the DIGSI 5 protocol. Authenticated users can exploit this flaw to upload malicious configuration files that could cause a permanent denial of service condition and potentially lead to code execution. The vulnerability affects over 60 device models across the SIPROTEC 5 product line, which are widely deployed in critical infrastructure for power grid protection worldwide.

Siemens is preparing patches and recommends immediate upgrades where available. CP050 and CP150 models should upgrade to version 9.90 or later, while CP300 models 7ST85 and 7ST86 require version 10.00 or later. These patched versions introduce allow-list functionality that restricts arbitrary file uploads. For devices without fixes, Siemens recommends enabling role-based access control (RBAC) in firmware V7.80+, implementing password protection on all DIGSI connections, and using customer PKI-signed certificates.

The vulnerability is particularly concerning given SIPROTEC 5's deployment in critical manufacturing, energy, transportation, healthcare, financial services, and government infrastructure globally. CISA emphasizes that operators of critical power systems should verify their multi-level redundant protection schemes remain intact and follow network segmentation best practices to minimize exploitation risk.

## Mentioned in this report

- Vulnerabilities: CVE-2025-40808

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-02

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/f9614d67-a6c4-5468-a748-5041ee99aa78/siemens-siprotec-5-file-upload-flaw-risks-dos.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
