INTEL_REPORT
CISA Cybersecurity Advisories · published 6/23/2026, 12:00:00 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Siemens SIPROTEC 5 Using DIGSI5 Protocol View CSAF Summary SIPROTEC 5 is vulnerable to arbitrary file uploads by authenticated users using the DIGSI 5 protocol. This could allow an attacker to upload malicious configuration files, potentially causing a permanent denial of service condition. As a mitigation measure, users of the CP050 and CP150 device models are advised to upgrade to version 9.90 or later. For CP300 device models, devices 7ST85 and 7ST86 are advised to upgrad…
https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-02
sha256:19b35992a978179f49c69e0f708bac3d26d65a4ea2dbf7330e27b512ed0e81f0
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| url |
| https://www.siemens.com/productcert/terms-of-use |
| Open → |
| domain | support.industry.siemens.com | Open → |
| url | https://www.siemens.com/gridsecurity | Open → |
| url | https://support.industry.siemens.com/cs/document/109768375 | Open → |
| cve | CVE-2025-40808 | Open → |