IMPROPER RESTRICTION OF OPERATIONS WITHIN THE BOUNDS OF A MEMORY BUFFER CWE-119
An attacker could exploit a buffer overflow vulnerability in the webserver. Specially crafted packets could cause a denial-of-service condition, and if certain conditions are met, affected devices must be restarted manually to fully recover.
IMPROPER NEUTRALIZATION OF INPUT DURING WEB PAGE GENERATION (‘CROSS-SITE SCRIPTING’) CWE-79
The web interface could allow cross-site scripting (XSS), causing the application to behave in unexpected ways for legitimate users.
RELATIVE PATH TRAVERSAL CWE-23
A vulnerability in the integrated web server of the affected devices could allow unauthorized attackers to obtain sensitive information about the device, including logs and configurations.
The above devices are included in SIPROTEC 4 and SIPROTEC Compact.
https://www.us-cert.gov/ics/advisories/icsa-19-344-07