Security readout for executives and security teams
Plain-English summary
This Siemens SIPROTEC 5 and DIGSI 5 issue could let a remote attacker manipulate files on affected systems through traffic to TCP port 443. In power and industrial environments, unauthorized file upload, download, or deletion can create operational and integrity risk even though the source bundle gives no CVSS score.
Executive priority
Treat as high priority for environments using Siemens SIPROTEC 5 in operational technology. The urgency comes from remote file manipulation against protection and engineering assets, not from confirmed exploitation. Prioritize exposure reduction and vendor-guided remediation during controlled maintenance windows.
Technical view
CVE-2019-10930 is a CWE-552 exposure issue affecting multiple Siemens SIPROTEC 5 device types, CPU variants CP100/CP200/CP300 with Ethernet modules, and DIGSI 5 versions below V7.90. Specially crafted packets sent to 443/TCP may allow file upload, download, or deletion in certain filesystem areas.
Likely exposure
Most relevant exposure is OT networks using listed SIPROTEC 5 protection devices or DIGSI 5 engineering software, especially where device HTTPS or management access on TCP 443 is reachable from broader enterprise, vendor, or remote-access networks.
Exploitation context
The bundle does not show CISA KEV listing, active exploitation, exploit publication, or CVSS details. The described attack is remote over TCP 443, but the available evidence does not establish real-world exploitation or the exact authentication and network prerequisites.
Researcher notes
Evidence is limited to the CVE description, affected product list, CWE-552, KEV false status, and Siemens advisory URL. Do not assume affected subcomponents beyond the named CPU variants, Ethernet modules, DIGSI 5, and listed SIPROTEC 5 device families.
Mitigation direction
- Review Siemens SSA-899560 before changing production protection devices.
- Upgrade DIGSI 5 where versions are below V7.90.
- For listed SIPROTEC models below V7.90 or V8.01, follow Siemens product-specific update guidance.
- For products marked all versions affected, request current Siemens remediation or compensating-control guidance.
- Restrict TCP 443 management access to trusted engineering networks only.
- Monitor affected assets for unexpected file changes or management activity.
Validation and detection
- Inventory SIPROTEC 5 device types, CPU variants, Ethernet modules, and DIGSI 5 versions.
- Map which affected assets expose TCP 443 and to which network segments.
- Confirm whether models fall under below-V7.90, below-V8.01, or all-versions-affected categories.
- Check change records for unauthorized file upload, download, or deletion indicators.
- Document any assets that cannot be patched and their compensating controls.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CWE-552: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Open ATT&CK lookupCVE-2019-10930 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://cert-portal.siemens.com/productcert/pdf/ssa-899560.pdfCVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
Files or Directories Accessible to External Parties
Files or Directories Accessible to External Parties represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.
