AID
Automation
Information Directory
HomeCVE FeedBrands
AID
Automation Information Directory
CVE data sourced from NIST NVD · Documentation links from official sources
Home›Brands›Siemens
SI
Platform

Siemens

Leading provider of industrial automation, digitalization, and smart infrastructure. Products include SIMATIC PLCs, SINAMICS drives, TIA Portal, and WinCC SCADA.

https://www.siemens.com/global/en/markets/machinebuilding/automation.html →
259
Total CVEs
12
Resources
13
CRIT
112
HIGH
115
MED
19
LOW
CVEsCVEsSpecsTech SpecsDocsTech DocsImplImplementationsExamplesExamples
259 entries
CVE-2019-10938CRITICAL

A vulnerability has been identified in SIPROTEC 5 devices with CPU variants CP200 (All versions < V7.59), SIPROTEC 5 devices with CPU variants CP300 and CP100 (All versions < V8.01), Siemens Power Meters Series 9410 (All versions < V2.2.1), Siemens Power Meters Series 9810 (All versions). An unauthenticated attacker with network access to the device could potentially insert arbitrary code which is executed before firmware verification in the device. At the time of advisory publication no public exploitation of this security vulnerability was known.

Aug 2, 2019
9.8
CVE-2018-4846CRITICAL

A vulnerability has been identified in RAPIDLab 1200 systems / RAPIDPoint 400 systems / RAPIDPoint 500 systems (All versions_without_ use of Siemens Healthineers Informatics products), RAPIDLab 1200 Series (All versions < V3.3 _with_ Siemens Healthineers Informatics products), RAPIDPoint 500 systems (All versions >= V3.0 _with_ Siemens Healthineers Informatics products), RAPIDPoint 500 systems (V2.4.X_with_ Siemens Healthineers Informatics products), RAPIDPoint 500 systems (All versions =< V2.3 _with_ Siemens Healthineers Informatics products), RAPIDPoint 400 systems (All versions _with_ Siemens Healthineers Informatics products). A factory account with hardcoded password might allow attackers access to the device over port 5900/tcp. Successful exploitation requires no user interaction or privileges and impacts the confidentiality, integrity, and availability of the affected device. At the time of advisory publication, no public exploitation of this security vulnerability is known. Siemens Healthineers confirms the security vulnerability and provides mitigations to resolve the security issue.

Jun 26, 2018
9.8
CVE-2018-4841CRITICAL

A vulnerability has been identified in TIM 1531 IRC (All versions < V1.1). A remote attacker with network access to port 80/tcp or port 443/tcp could perform administrative operations on the device without prior authentication. Successful exploitation could allow to cause a denial-of-service, or read and manipulate data as well as configuration settings of the affected device. At the stage of publishing this security advisory no public exploitation is known. Siemens provides mitigations to resolve it.

Mar 29, 2018
9.8
CVE-2017-9944CRITICAL

A vulnerability has been identified in Siemens 7KT PAC1200 data manager (7KT1260) in all versions < V2.03. The integrated web server (port 80/tcp) of the affected devices could allow an unauthenticated remote attacker to perform administrative operations over the network.

Dec 27, 2017
9.8
CVE-2017-12739CRITICAL

An issue was discovered on Siemens SICAM RTUs SM-2556 COM Modules with the firmware variants ENOS00, ERAC00, ETA2, ETLS00, MODi00, and DNPi00. The integrated web server (port 80/tcp) of the affected devices could allow unauthenticated remote attackers to execute arbitrary code on the affected device.

Nov 15, 2017
9.8
CVE-2017-9939CRITICAL

A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with network access to the SiPass integrated server to bypass the authentication mechanism and perform administrative operations.

Aug 8, 2017
9.8
CVE-2017-6869CRITICAL

A vulnerability was discovered in Siemens ViewPort for Web Office Portal before revision number 1453 that could allow an unauthenticated remote user to upload arbitrary code and execute it with the permissions of the operating-system user running the web server by sending specially crafted network packets to port 443/TCP or port 80/TCP.

Aug 8, 2017
9.8
CVE-2016-8567CRITICAL

An issue was discovered in Siemens SICAM PAS before 8.00. A factory account with hard-coded passwords is present in the SICAM PAS installations. Attackers might gain privileged access to the database over Port 2638/TCP.

Feb 13, 2017
9.8
CVE-2016-9157CRITICAL

A vulnerability in Siemens SICAM PAS (all versions before V8.09) could allow a remote attacker to cause a Denial of Service condition and potentially lead to unauthenticated remote code execution by sending specially crafted packets to port 19234/TCP.

Dec 5, 2016
9.8
CVE-2016-9155CRITICAL

The following SIEMENS branded IP Camera Models CCMW3025, CVMW3025-IR, CFMW3025 prior to version 1.41_SP18_S1; CCPW3025, CCPW5025 prior to version 0.1.73_S1; CCMD3025-DN18 prior to version v1.394_S1; CCID1445-DN18, CCID1445-DN28, CCID1145-DN36, CFIS1425, CCIS1425, CFMS2025, CCMS2025, CVMS2025-IR, CFMW1025, CCMW1025 prior to version v2635_SP1 could allow an attacker with network access to the web server to obtain administrative credentials under certain circumstances.

Nov 22, 2016
9.8
CVE-2016-5743CRITICAL

Siemens SIMATIC WinCC before 7.3 Update 10 and 7.4 before Update 1, SIMATIC BATCH before 8.1 SP1 Update 9 as distributed in SIMATIC PCS 7 through 8.1 SP1, SIMATIC OpenPCS 7 before 8.1 Update 3 as distributed in SIMATIC PCS 7 through 8.1 SP1, SIMATIC OpenPCS 7 before 8.2 Update 1 as distributed in SIMATIC PCS 7 8.2, and SIMATIC WinCC Runtime Professional before 13 SP1 Update 9 allow remote attackers to execute arbitrary code via crafted packets.

Jul 22, 2016
9.8
CVE-2016-8565CRITICAL

Siemens Automation License Manager (ALM) before 5.3 SP3 allows remote attackers to write to files, rename files, create directories, or delete directories via crafted packets.

Oct 13, 2016
9.1
CVE-2017-2684CRITICAL

Siemens SIMATIC Logon prior to V1.5 SP3 Update 2 could allow an attacker with knowledge of a valid user name, and physical or network access to the affected system, to bypass the application-level authentication.

Feb 22, 2017
9.0
CVE-2015-1449HIGH

Buffer overflow in the integrated web server on Siemens Ruggedcom WIN51xx devices with firmware before SS4.4.4624.35, WIN52xx devices with firmware before SS4.4.4624.35, WIN70xx devices with firmware before BS4.4.4621.32, and WIN72xx devices with firmware before BS4.4.4621.32 allows remote attackers to execute arbitrary code via unspecified vectors.

Feb 2, 2015
10.0
CVE-2015-1448HIGH

The integrated management service on Siemens Ruggedcom WIN51xx devices with firmware before SS4.4.4624.35, WIN52xx devices with firmware before SS4.4.4624.35, WIN70xx devices with firmware before BS4.4.4621.32, and WIN72xx devices with firmware before BS4.4.4621.32 allows remote attackers to bypass authentication and perform administrative actions via unspecified vectors.

Feb 2, 2015
10.0
CVE-2014-8551HIGH

The WinCC server in Siemens SIMATIC WinCC 7.0 through SP3, 7.2 before Update 9, and 7.3 before Update 2; SIMATIC PCS 7 7.1 through SP4, 8.0 through SP2, and 8.1; and TIA Portal 13 before Update 6 allows remote attackers to execute arbitrary code via crafted packets.

Nov 26, 2014
10.0
CVE-2013-6920HIGH

Siemens SINAMICS S/G controllers with firmware before 4.6.11 do not require authentication for FTP and TELNET sessions, which allows remote attackers to bypass intended access restrictions via TCP traffic to port (1) 21 or (2) 23.

Dec 7, 2013
10.0
CVE-2013-5944HIGH

The integrated web server on Siemens SCALANCE X-200 switches with firmware before 4.5.0 and X-200IRT switches with firmware before 5.1.0 does not properly enforce authentication requirements, which allows remote attackers to perform administrative actions via requests to the management interface.

Oct 3, 2013
10.0
CVE-2013-4652HIGH

Unspecified vulnerability in the command-line management interface on Siemens Scalance W7xx devices with firmware before 4.5.4 allows remote attackers to bypass authentication and execute arbitrary code via a (1) SSH or (2) TELNET connection.

Aug 1, 2013
10.0
CVE-2013-4781HIGH

core/getLog.php on the Siemens Enterprise OpenScape Branch appliance and OpenScape Session Border Controller (SBC) before 2 R0.32.0, and 7 before 7 R1.7.0, allows remote attackers to execute arbitrary commands via unspecified vectors.

Jul 18, 2013
10.0
CVE-2013-0659HIGH

The debugging feature on the Siemens CP 1604 and CP 1616 interface cards with firmware before 2.5.2 allows remote attackers to execute arbitrary code via a crafted packet to UDP port 17185.

Apr 1, 2013
10.0
CVE-2012-5409HIGH

AscoServer.exe in the server in Siemens SiPass integrated MP2.6 and earlier does not properly handle IOCP RPC messages received over an Ethernet network, which allows remote attackers to write data to any memory location and consequently execute arbitrary code via crafted messages, as demonstrated by an arbitrary pointer dereference attack or a buffer overflow attack.

Nov 1, 2012
10.0
CVE-2012-1799HIGH

The web server on the Siemens Scalance S Security Module firewall S602 V2, S612 V2, and S613 V2 with firmware before 2.3.0.3 does not limit the rate of authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack on the administrative password.

Apr 18, 2012
10.0
CVE-2011-4514HIGH

The TELNET daemon in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime does not perform authentication, which makes it easier for remote attackers to obtain access via a TCP session.

Feb 3, 2012
10.0
CVE-2011-4513HIGH

Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime allow user-assisted remote attackers to execute arbitrary code via a crafted project file, related to the HMI web server and runtime loader.

Feb 3, 2012
10.0
CVE-2011-4509HIGH

The HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime has an improperly selected default password for the administrator account, which makes it easier for remote attackers to obtain access via a brute-force approach involving many HTTP requests.

Feb 3, 2012
10.0
CVE-2008-6993HIGH

Siemens Gigaset WLAN Camera 1.27 has an insecure default password, which allows remote attackers to conduct unauthorized activities. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Aug 19, 2009
10.0
CVE-2008-6916HIGH

Siemens SpeedStream 5200 with NetPort Software 1.1 allows remote attackers to bypass authentication via an invalid Host header, possibly involving a trailing dot in the hostname.

Aug 7, 2009
10.0
CVE-2015-5386HIGH

Siemens SICAM MIC devices with firmware before 2404 allow remote attackers to bypass authentication and obtain administrative access via unspecified HTTP requests.

Jul 16, 2015
9.3
CVE-2014-2731HIGH

Multiple unspecified vulnerabilities in the integrated web server in Siemens SINEMA Server before 12 SP1 allow remote attackers to execute arbitrary code via HTTP traffic to port (1) 4999 or (2) 80.

Apr 19, 2014
9.3
CVE-2011-4876HIGH

Directory traversal vulnerability in HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime, when Transfer Mode is enabled, allows remote attackers to execute, read, create, modify, or delete arbitrary files via a .. (dot dot) in a string.

Feb 3, 2012
9.3
CVE-2011-4875HIGH

Stack-based buffer overflow in HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime, when Transfer Mode is enabled, allows remote attackers to execute arbitrary code via vectors related to Unicode strings.

Feb 3, 2012
9.3
CVE-2011-4508HIGH

The HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before SP2 Update 1; the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime generates predictable authentication tokens for cookies, which makes it easier for remote attackers to bypass authentication via a crafted cookie.

Feb 3, 2012
9.3
CVE-2011-4055HIGH

Buffer overflow in the WebClient ActiveX control in Siemens Tecnomatix FactoryLink 6.6.1 (aka 6.6 SP1), 7.5.217 (aka 7.5 SP2), and 8.0.2.54 allows remote attackers to execute arbitrary code via a long string in a parameter associated with the location URL.

Jan 8, 2012
9.3
CVE-2011-3321HIGH

Heap-based buffer overflow in the Siemens WinCC Runtime Advanced Loader, as used in SIMATIC WinCC flexible Runtime and SIMATIC WinCC (TIA Portal) Runtime Advanced, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted packet to TCP port 2308.

Sep 16, 2011
9.3
CVE-2019-6584HIGH

A vulnerability has been identified in SIEMENS LOGO!8 (6ED1052-xyyxx-0BA8 FS:01 to FS:06 / Firmware version V1.80.xx and V1.81.xx), SIEMENS LOGO!8 (6ED1052-xyy08-0BA0 FS:01 / Firmware version < V1.82.02). The integrated webserver does not invalidate the Session ID upon user logout. An attacker that successfully extracted a valid Session ID is able to use it even after the user logs out. The security vulnerability could be exploited by an attacker in a privileged network position who is able to read the communication between the affected device and the user or by an attacker who is able to obtain valid Session IDs through other means. The user must invoke a session to the affected device. At the time of advisory publication no public exploitation of this security vulnerability was known.

Jun 12, 2019
8.8
CVE-2018-4845HIGH

A vulnerability has been identified in RAPIDLab 1200 systems / RAPIDPoint 400 systems / RAPIDPoint 500 systems (All versions_without_ use of Siemens Healthineers Informatics products), RAPIDLab 1200 Series (All versions < V3.3 _with_ Siemens Healthineers Informatics products), RAPIDPoint 500 systems (All versions >= V3.0 _with_ Siemens Healthineers Informatics products), RAPIDPoint 500 systems (V2.4.X_with_ Siemens Healthineers Informatics products), RAPIDPoint 500 systems (All versions =< V2.3 _with_ Siemens Healthineers Informatics products), RAPIDPoint 400 systems (All versions _with_ Siemens Healthineers Informatics products). Remote attackers with either local or remote credentialed access to the "Remote View" feature might be able to elevate their privileges, compromising confidentiality, integrity, and availability of the system. No special skills or user interaction are required to perform this attack. At the time of advisory publication, no public exploitation of this security vulnerability is known. Siemens Healthineers confirms the security vulnerability and provides mitigations to resolve the security issue.

Jun 26, 2018
8.8
CVE-2017-2689HIGH

Siemens RUGGEDCOM ROX I (all versions) allow an authenticated user to bypass access restrictions in the web interface at port 10000/TCP to obtain privileged file system access or change configuration settings.

Mar 29, 2017
8.8
CVE-2017-2688HIGH

The integrated web server in Siemens RUGGEDCOM ROX I (all versions) at port 10000/TCP could allow remote attackers to perform actions with the privileges of an authenticated user, provided the targeted user has an active session and is induced into clicking on a malicious link or into visiting a malicious website, aka CSRF.

Mar 29, 2017
8.8
CVE-2017-2682HIGH

The Siemens web application RUGGEDCOM NMS < V1.2 on port 8080/TCP and 8081/TCP could allow a remote attacker to perform a Cross-Site Request Forgery (CSRF) attack, potentially allowing an attacker to execute administrative operations, provided the targeted user has an active session and is induced to trigger a malicious request.

Feb 27, 2017
8.8
CVE-2012-3009HIGH

Siemens COMOS before 9.1 Patch 413, 9.2 before Update 03 Patch 023, and 10.0 before Patch 005 allows remote authenticated users to obtain database administrative access via unspecified method calls.

Aug 16, 2012
8.5
CVE-2011-4879HIGH

miniweb.exe in the HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before SP2 Update 1; the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime does not properly handle URIs beginning with a 0xfa character, which allows remote attackers to read data from arbitrary memory locations or cause a denial of service (application crash) via a crafted POST request.

Feb 3, 2012
8.5
CVE-2014-2250HIGH

The random-number generator on Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 does not have sufficient entropy, which makes it easier for remote attackers to defeat cryptographic protection mechanisms and hijack sessions via unspecified vectors, a different vulnerability than CVE-2014-2251.

Mar 24, 2014
8.3
CVE-2014-2251HIGH

The random-number generator on Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 does not have sufficient entropy, which makes it easier for remote attackers to defeat cryptographic protection mechanisms and hijack sessions via unspecified vectors.

Mar 16, 2014
8.3
CVE-2013-6925HIGH

The integrated HTTPS server in Siemens RuggedCom ROS before 3.12.2 allows remote attackers to hijack web sessions by predicting a session id value.

Dec 17, 2013
8.3
CVE-2013-5709HIGH

The authentication implementation in the web server on Siemens SCALANCE X-200 switches with firmware before 5.0.0 does not use a sufficient source of entropy for generating values of random numbers, which makes it easier for remote attackers to hijack sessions by predicting a value.

Sep 17, 2013
8.3
CVE-2017-12069HIGH

An XXE vulnerability has been identified in OPC Foundation UA .NET Sample Code before 2017-03-21 and Local Discovery Server (LDS) before 1.03.367. Among the affected products are Siemens SIMATIC PCS7 (All versions V8.1 and earlier), SIMATIC WinCC (All versions < V7.4 SP1), SIMATIC WinCC Runtime Professional (All versions < V14 SP1), SIMATIC NET PC Software, and SIMATIC IT Production Suite. By sending specially crafted packets to the OPC Discovery Server at port 4840/tcp, an attacker might cause the system to access various resources chosen by the attacker.

Aug 30, 2017
8.2
CVE-2017-2683HIGH

A non-privileged user of the Siemens web application RUGGEDCOM NMS < V1.2 on port 8080/TCP and 8081/TCP could perform a persistent Cross-Site Scripting (XSS) attack, potentially resulting in obtaining administrative permissions.

Feb 27, 2017
8.2
CVE-2014-8422HIGH

The web-based management (WBM) interface in Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 generates session cookies with insufficient entropy, which makes it easier for remote attackers to hijack sessions via a brute-force attack.

Apr 12, 2018
8.1
CVE-2017-9940HIGH

A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with access to a low-privileged user account to read or write files on the file system of the SiPass integrated server over the network.

Aug 8, 2017
8.1
CVE-2017-6868HIGH

An Improper Authentication issue was discovered in Siemens SIMATIC CP 44x-1 RNA, all versions prior to 1.4.1. An unauthenticated remote attacker may be able to perform administrative actions on the Communication Process (CP) of the RNA series module, if network access to Port 102/TCP is available and the configuration file for the CP is stored on the RNA's CPU.

Jul 7, 2017
8.1
CVE-2016-9160HIGH

A vulnerability in SIEMENS SIMATIC WinCC (All versions < SIMATIC WinCC V7.2) and SIEMENS SIMATIC PCS 7 (All versions < SIMATIC PCS 7 V8.0 SP1) could allow a remote attacker to crash an ActiveX component or leak parts of the application memory if a user is tricked into clicking on a malicious link under certain conditions.

Dec 17, 2016
8.1
CVE-2013-6926HIGH

The integrated HTTPS server in Siemens RuggedCom ROS before 3.12.2 allows remote authenticated users to bypass intended restrictions on administrative actions by leveraging access to a (1) guest or (2) operator account.

Dec 17, 2013
8.0
CVE-2025-40827HIGH

A vulnerability has been identified in Siemens Software Center (All versions < V3.5), Solid Edge SE2025 (All versions < V225.0 Update 10). The affected application is vulnerable to DLL hijacking. This could allow an attacker to execute arbitrary code via placing a crafted DLL file on the system.

Nov 11, 2025
7.8
CVE-2021-47302HIGH

In the Linux kernel, the following vulnerability has been resolved: igc: Fix use-after-free error during reset Cleans the next descriptor to watch (next_to_watch) when cleaning the TX ring. Failure to do so can cause invalid memory accesses. If igc_poll() runs while the controller is being reset this can lead to the driver try to free a skb that was already freed. Log message: [ 101.525242] refcount_t: underflow; use-after-free. [ 101.525251] WARNING: CPU: 1 PID: 646 at lib/refcount.c:28 refcount_warn_saturate+0xab/0xf0 [ 101.525259] Modules linked in: sch_etf(E) sch_mqprio(E) rfkill(E) intel_rapl_msr(E) intel_rapl_common(E) x86_pkg_temp_thermal(E) intel_powerclamp(E) coretemp(E) binfmt_misc(E) kvm_intel(E) kvm(E) irqbypass(E) crc32_pclmul(E) ghash_clmulni_intel(E) aesni_intel(E) mei_wdt(E) libaes(E) crypto_simd(E) cryptd(E) glue_helper(E) snd_hda_codec_hdmi(E) rapl(E) intel_cstate(E) snd_hda_intel(E) snd_intel_dspcfg(E) sg(E) soundwire_intel(E) intel_uncore(E) at24(E) soundwire_generic_allocation(E) iTCO_wdt(E) soundwire_cadence(E) intel_pmc_bxt(E) serio_raw(E) snd_hda_codec(E) iTCO_vendor_support(E) watchdog(E) snd_hda_core(E) snd_hwdep(E) snd_soc_core(E) snd_compress(E) snd_pcsp(E) soundwire_bus(E) snd_pcm(E) evdev(E) snd_timer(E) mei_me(E) snd(E) soundcore(E) mei(E) configfs(E) ip_tables(E) x_tables(E) autofs4(E) ext4(E) crc32c_generic(E) crc16(E) mbcache(E) jbd2(E) sd_mod(E) t10_pi(E) crc_t10dif(E) crct10dif_generic(E) i915(E) ahci(E) libahci(E) ehci_pci(E) igb(E) xhci_pci(E) ehci_hcd(E) [ 101.525303] drm_kms_helper(E) dca(E) xhci_hcd(E) libata(E) crct10dif_pclmul(E) cec(E) crct10dif_common(E) tsn(E) igc(E) e1000e(E) ptp(E) i2c_i801(E) crc32c_intel(E) psmouse(E) i2c_algo_bit(E) i2c_smbus(E) scsi_mod(E) lpc_ich(E) pps_core(E) usbcore(E) drm(E) button(E) video(E) [ 101.525318] CPU: 1 PID: 646 Comm: irq/37-enp7s0-T Tainted: G E 5.10.30-rt37-tsn1-rt-ipipe #ipipe [ 101.525320] Hardware name: SIEMENS AG SIMATIC IPC427D/A5E31233588, BIOS V17.02.09 03/31/2017 [ 101.525322] RIP: 0010:refcount_warn_saturate+0xab/0xf0 [ 101.525325] Code: 05 31 48 44 01 01 e8 f0 c6 42 00 0f 0b c3 80 3d 1f 48 44 01 00 75 90 48 c7 c7 78 a8 f3 a6 c6 05 0f 48 44 01 01 e8 d1 c6 42 00 <0f> 0b c3 80 3d fe 47 44 01 00 0f 85 6d ff ff ff 48 c7 c7 d0 a8 f3 [ 101.525327] RSP: 0018:ffffbdedc0917cb8 EFLAGS: 00010286 [ 101.525329] RAX: 0000000000000000 RBX: ffff98fd6becbf40 RCX: 0000000000000001 [ 101.525330] RDX: 0000000000000001 RSI: ffffffffa6f2700c RDI: 00000000ffffffff [ 101.525332] RBP: ffff98fd6becc14c R08: ffffffffa7463d00 R09: ffffbdedc0917c50 [ 101.525333] R10: ffffffffa74c3578 R11: 0000000000000034 R12: 00000000ffffff00 [ 101.525335] R13: ffff98fd6b0b1000 R14: 0000000000000039 R15: ffff98fd6be35c40 [ 101.525337] FS: 0000000000000000(0000) GS:ffff98fd6e240000(0000) knlGS:0000000000000000 [ 101.525339] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 101.525341] CR2: 00007f34135a3a70 CR3: 0000000150210003 CR4: 00000000001706e0 [ 101.525343] Call Trace: [ 101.525346] sock_wfree+0x9c/0xa0 [ 101.525353] unix_destruct_scm+0x7b/0xa0 [ 101.525358] skb_release_head_state+0x40/0x90 [ 101.525362] skb_release_all+0xe/0x30 [ 101.525364] napi_consume_skb+0x57/0x160 [ 101.525367] igc_poll+0xb7/0xc80 [igc] [ 101.525376] ? sched_clock+0x5/0x10 [ 101.525381] ? sched_clock_cpu+0xe/0x100 [ 101.525385] net_rx_action+0x14c/0x410 [ 101.525388] __do_softirq+0xe9/0x2f4 [ 101.525391] __local_bh_enable_ip+0xe3/0x110 [ 101.525395] ? irq_finalize_oneshot.part.47+0xe0/0xe0 [ 101.525398] irq_forced_thread_fn+0x6a/0x80 [ 101.525401] irq_thread+0xe8/0x180 [ 101.525403] ? wake_threads_waitq+0x30/0x30 [ 101.525406] ? irq_thread_check_affinity+0xd0/0xd0 [ 101.525408] kthread+0x183/0x1a0 [ 101.525412] ? kthread_park+0x80/0x80 [ 101.525415] ret_from_fork+0x22/0x30

May 21, 2024
7.8
CVE-2021-41544HIGH

A vulnerability has been identified in Siemens Software Center (All versions < V3.0). A DLL Hijacking vulnerability could allow a local attacker to execute code with elevated privileges by placing a malicious DLL in one of the directories on the DLL search path.

Aug 8, 2023
7.8
CVE-2022-2069HIGH

The APDFL.dll in Siemens JT2Go prior to V13.3.0.5 and Siemens Teamcenter Visualization prior to V14.0.0.2 contains an out of bounds write past the fixed-length heap-based buffer while parsing specially crafted PDF files. This could allow an attacker to execute code in the context of the current process.

Oct 20, 2022
7.8
CVE-2018-13806HIGH

A vulnerability has been identified in SIEMENS TD Keypad Designer (All versions). A DLL hijacking vulnerability exists in all versions of SIEMENS TD Keypad Designer which could allow an attacker to execute code with the permission of the user running TD Designer. The attacker must have write access to the directory containing the TD project file in order to exploit the vulnerability. A legitimate user with higher privileges than the attacker must open the TD project in order for this vulnerability to be exploited. At the time of advisory publication no public exploitation of this security vulnerability was known.

Sep 12, 2018
7.8
CVE-2018-4858HIGH

A vulnerability has been identified in IEC 61850 system configurator (All versions < V5.80), DIGSI 5 (affected as IEC 61850 system configurator is incorporated) (All versions < V7.80), DIGSI 4 (All versions < V4.93), SICAM PAS/PQS (All versions < V8.11), SICAM PQ Analyzer (All versions < V3.11), SICAM SCC (All versions < V9.02 HF3). A service of the affected products listening on all of the host's network interfaces on either port 4884/TCP, 5885/TCP, or port 5886/TCP could allow an attacker to either exfiltrate limited data from the system or to execute code with Microsoft Windows user permissions. Successful exploitation requires an attacker to be able to send a specially crafted network request to the vulnerable service and a user interacting with the service's client application on the host. In order to execute arbitrary code with Microsoft Windows user permissions, an attacker must be able to plant the code in advance on the host by other means. The vulnerability has limited impact to confidentiality and integrity of the affected system. At the time of advisory publication no public exploitation of this security vulnerability was known. Siemens confirms the security vulnerability and provides mitigations to resolve the security issue.

Jul 9, 2018
7.8
CVE-2017-9942HIGH

A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with local access to the SiPass integrated server or SiPass integrated client to potentially obtain credentials from the systems.

Aug 8, 2017
7.8
CVE-2016-8566HIGH

An issue was discovered in Siemens SICAM PAS before 8.00. Because of Storing Passwords in a Recoverable Format, an authenticated local attacker with certain privileges could possibly reconstruct the passwords of users for accessing the database.

Feb 13, 2017
7.8
CVE-2016-6486HIGH

Siemens SINEMA Server uses weak permissions for the application folder, which allows local users to gain privileges via unspecified vectors.

Aug 8, 2016
7.8
CVE-2015-2177HIGH

Siemens SIMATIC S7-300 CPU devices allow remote attackers to cause a denial of service (defect-mode transition) via crafted packets on (1) TCP port 102 or (2) Profibus.

Mar 7, 2015
7.8
CVE-2014-9369HIGH

Siemens SPC controllers SPC4000, SPC5000, and SPC6000 before 3.6.0 allow remote attackers to cause a denial of service (device restart) via crafted packets.

Mar 7, 2015
7.8
CVE-2014-8478HIGH

The web server on Siemens SCALANCE X-300 switches with firmware before 4.0 and SCALANCE X 408 switches with firmware before 4.0 allows remote attackers to cause a denial of service (reboot) via malformed HTTP requests.

Jan 21, 2015
7.8
CVE-2014-2258HIGH

Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 allow remote attackers to cause a denial of service (defect-mode transition) via crafted HTTPS packets, a different vulnerability than CVE-2014-2259.

Mar 24, 2014
7.8
CVE-2014-2254HIGH

Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 allow remote attackers to cause a denial of service (defect-mode transition) via crafted HTTP packets, a different vulnerability than CVE-2014-2255.

Mar 24, 2014
7.8
CVE-2014-2256HIGH

Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 allow remote attackers to cause a denial of service (defect-mode transition) via crafted ISO-TSAP packets, a different vulnerability than CVE-2014-2257.

Mar 24, 2014
7.8
CVE-2014-2259HIGH

Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allow remote attackers to cause a denial of service (defect-mode transition) via crafted HTTPS packets.

Mar 16, 2014
7.8
CVE-2014-2257HIGH

Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allow remote attackers to cause a denial of service (defect-mode transition) via crafted ISO-TSAP packets.

Mar 16, 2014
7.8
CVE-2014-2255HIGH

Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allow remote attackers to cause a denial of service (defect-mode transition) via crafted HTTP packets.

Mar 16, 2014
7.8
CVE-2014-1966HIGH

The SNMP implementation in Siemens RuggedCom ROS before 3.11, ROS 3.11 for RS950G, ROS 3.12 before 3.12.4, and ROS 4.0 for RSG2488 allows remote attackers to cause a denial of service (device outage) via crafted packets.

Feb 24, 2014
7.8
CVE-2013-4780HIGH

core/getLog.php on the Siemens Enterprise OpenScape Branch appliance and OpenScape Session Border Controller (SBC) before 2 R0.32.0, and 7 before 7 R1.7.0, allows remote attackers to read arbitrary files via unspecified vectors.

Jul 18, 2013
7.8
CVE-2013-4778HIGH

core/getLog.php on the Siemens Enterprise OpenScape Branch appliance and OpenScape Session Border Controller (SBC) before 2 R0.32.0, and 7 before 7 R1.7.0, allows remote attackers to obtain sensitive server and statistics information via unspecified vectors.

Jul 18, 2013
7.8
CVE-2013-2780HIGH

Siemens SIMATIC S7-1200 PLCs 2.x and 3.x allow remote attackers to cause a denial of service (defect-mode transition and control outage) via crafted packets to UDP port 161 (aka the SNMP port).

Apr 22, 2013
7.8
CVE-2013-0700HIGH

Siemens SIMATIC S7-1200 PLCs 2.x and 3.x allow remote attackers to cause a denial of service (defect-mode transition and control outage) via crafted packets to TCP port 102 (aka the ISO-TSAP port).

Apr 22, 2013
7.8
CVE-2012-3017HIGH

Siemens SIMATIC S7-400 PN CPU devices with firmware 5.x allow remote attackers to cause a denial of service (defect-mode transition and service outage) via (1) malformed HTTP traffic or (2) malformed IP packets.

Jul 31, 2012
7.8
CVE-2012-3016HIGH

Siemens SIMATIC S7-400 PN CPU devices with firmware 6 before 6.0.3 allow remote attackers to cause a denial of service (defect-mode transition and service outage) via crafted ICMP packets.

Jul 31, 2012
7.8
CVE-2012-1802HIGH

Buffer overflow in the embedded web server on the Siemens Scalance X Industrial Ethernet switch X414-3E before 3.7.1, X308-2M before 3.7.2, X-300EEC before 3.7.2, XR-300 before 3.7.2, and X-300 before 3.7.2 allows remote attackers to cause a denial of service (device reboot) or possibly execute arbitrary code via a malformed URL.

Apr 18, 2012
7.8
CVE-2011-4878HIGH

Directory traversal vulnerability in miniweb.exe in the HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before SP2 Update 1; the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime allows remote attackers to read arbitrary files via a ..%5c (dot dot backslash) in a URI.

Feb 3, 2012
7.8
CVE-2010-2772HIGH

Siemens Simatic WinCC and PCS 7 SCADA system uses a hard-coded password, which allows local users to access a back-end database and gain privileges, as demonstrated in the wild in July 2010 by the Stuxnet worm, a different vulnerability than CVE-2010-2568.

Jul 22, 2010
7.8
CVE-2010-2568HIGH

Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote attackers to execute arbitrary code via a crafted (1) .LNK or (2) .PIF shortcut file, which is not properly handled during icon display in Windows Explorer, as demonstrated in the wild in July 2010, and originally reported for malware that leverages CVE-2010-2772 in Siemens WinCC SCADA systems.

Jul 22, 2010
7.8
CVE-2009-3322HIGH

The Siemens Gigaset SE361 WLAN router allows remote attackers to cause a denial of service (device reboot) via a flood of crafted TCP packets to port 1723.

Sep 23, 2009
7.8
CVE-2008-7065HIGH

Siemens C450 IP and C475 IP VoIP devices allow remote attackers to cause a denial of service (disconnected calls and device reboot) via a crafted SIP packet to UDP port 5060.

Aug 25, 2009
7.8
CVE-2008-1267HIGH

The Siemens SpeedStream 6520 router allows remote attackers to cause a denial of service (web interface crash) via an HTTP request to basehelp_English.htm with a large integer in the Content-Length field.

Mar 10, 2008
7.8
CVE-2003-1464HIGH

Buffer overflow in Siemens 45 series mobile phones allows remote attackers to cause a denial of service (disconnect and unavailable inbox) via a Short Message Service (SMS) message with a long image name.

Dec 31, 2003
7.8
CVE-2023-27336HIGH

Softing edgeConnector Siemens OPC UA Server Null Pointer Dereference Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Softing edgeConnector Siemens. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of OPC client certificates. The issue results from dereferencing a NULL pointer. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-20508.

May 3, 2024
7.5
CVE-2023-27334HIGH

Softing edgeConnector Siemens ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Softing edgeConnector Siemens. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of OPC UA ConditionRefresh requests. By sending a large number of requests, an attacker can consume all available resources on the server. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-20498.

May 3, 2024
7.5
CVE-2023-46590HIGH

A vulnerability has been identified in Siemens OPC UA Modelling Editor (SiOME) (All versions < V2.8). Affected products suffer from a XML external entity (XXE) injection vulnerability. This vulnerability could allow an attacker to interfere with an application's processing of XML data and read arbitrary files in the system.

Nov 14, 2023
7.5
CVE-2019-19279HIGH

A vulnerability has been identified in SIPROTEC 4 and SIPROTEC Compact relays equipped with EN100 Ethernet communication modules (All versions). Specially crafted packets sent to port 50000/UDP of the EN100 Ethernet communication modules could cause a Denial-of-Service of the affected device. A manual reboot is required to recover the service of the device. At the time of advisory publication no public exploitation of this security vulnerability was known to Siemens.

Mar 10, 2020
7.5
CVE-2019-6571HIGH

A vulnerability has been identified in SIEMENS LOGO!8 (6ED1052-xyyxx-0BA8 FS:01 to FS:06 / Firmware version V1.80.xx and V1.81.xx), SIEMENS LOGO!8 (6ED1052-xyy08-0BA0 FS:01 / Firmware version < V1.82.02). An attacker with network access to port 10005/tcp of the LOGO! device could cause a Denial-of-Service condition by sending specially crafted packets. The security vulnerability could be exploited by an unauthenticated attacker with network access to the affected service. No user interaction is required to exploit this security vulnerability. Successful exploitation of the security vulnerability compromises availability of the targeted system. At the time of advisory publication no public exploitation of this security vulnerability was known.

Jun 12, 2019
7.5
CVE-2019-10953HIGH

ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple versions. Researchers have found some controllers are susceptible to a denial-of-service attack due to a flood of network packets.

Apr 17, 2019
7.5
CVE-2018-16561HIGH

A vulnerability has been identified in SIMATIC S7-300 CPUs (All versions < V3.X.16). The affected CPUs improperly validate S7 communication packets which could cause a Denial-of-Service condition of the CPU. The CPU will remain in DEFECT mode until manual restart. Successful exploitation requires an attacker to be able to send a specially crafted S7 communication packet to a communication interface of the CPU. This includes Ethernet, PROFIBUS, and Multi Point Interfaces (MPI). No user interaction or privileges are required to exploit the security vulnerability. The vulnerability could allow causing a Denial-of-Service condition of the core functionality of the CPU, compromising the availability of the system. At the time of advisory publication no public exploitation of this security vulnerability was known. Siemens confirms the security vulnerability and provides mitigations to resolve the security issue.

Apr 17, 2019
7.5
CVE-2014-8421HIGH

Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 allow remote attackers to gain super-user privileges by leveraging SSH access and incorrect ownership of (1) ConfigureCoreFile.sh, (2) Traceroute.sh, (3) apps.sh, (4) conversion_java2native.sh, (5) coreCompression.sh, (6) deletePasswd.sh, (7) findHealthSvcFDs.sh, (8) fw_printenv.sh, (9) fw_setenv.sh, (10) hw_wd_kicker.sh, (11) new_rootfs.sh, (12) opera_killSnmpd.sh, (13) opera_startSnmpd.sh, (14) rebootOperaSoftware.sh, (15) removeLogFiles.sh, (16) runOperaServices.sh, (17) setPasswd.sh, (18) startAccTestSvcs.sh, (19) usbNotification.sh, or (20) appWeb in /Opera_Deploy.

Apr 12, 2018
7.5
CVE-2017-9946HIGH

A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions <V3.5. An attacker with network access to the integrated web server (80/tcp and 443/tcp) could bypass the authentication and download sensitive information from the device.

Oct 23, 2017
7.5
CVE-2017-12734HIGH

A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V1.81.2). An attacker with network access to the integrated web server on port 80/tcp could obtain the session ID of an active user session. A user must be logged in to the web interface. Siemens recommends to use the integrated webserver on port 80/tcp only in trusted networks.

Aug 30, 2017
7.5
CVE-2017-9938HIGH

A vulnerability was discovered in Siemens SIMATIC Logon (All versions before V1.6) that could allow specially crafted packets sent to the SIMATIC Logon Remote Access service on port 16389/tcp to cause a Denial-of-Service condition. The service restarts automatically.

Aug 8, 2017
7.5
CVE-2016-7987HIGH

An issue was discovered in Siemens ETA4 firmware (all versions prior to Revision 08) of the SM-2558 extension module for: SICAM AK, SICAM TM 1703, SICAM BC 1703, and SICAM AK 3. Specially crafted packets sent to Port 2404/TCP could cause the affected device to go into defect mode. A cold start might be required to recover the system, a Denial-of-Service Vulnerability.

Feb 13, 2017
7.5
CVE-2016-9154HIGH

Siemens Desigo PX Web modules PXA40-W0, PXA40-W1, PXA40-W2 for Desigo PX automation controllers PXC00-E.D, PXC50-E.D, PXC100-E.D, PXC200-E.D (All firmware versions < V6.00.046) and Desigo PX Web modules PXA30-W0, PXA30-W1, PXA30-W2 for Desigo PX automation controllers PXC00-U, PXC64-U, PXC128-U (All firmware versions < V6.00.046) use a pseudo random number generator with insufficient entropy to generate certificates for HTTPS, potentially allowing remote attackers to reconstruct the corresponding private key.

Dec 23, 2016
7.5
CVE-2016-8563HIGH

Siemens Automation License Manager (ALM) before 5.3 SP3 Update 1 allows remote attackers to cause a denial of service (ALM service outage) via crafted packets to TCP port 4410.

Oct 13, 2016
7.5
CVE-2016-5874HIGH

Siemens SIMATIC NET PC-Software before 13 SP2 allows remote attackers to cause a denial of service (OPC UA service outage) via crafted TCP packets.

Jul 22, 2016
7.5
CVE-2016-5744HIGH

Siemens SIMATIC WinCC 7.0 through SP3 and 7.2 allows remote attackers to read arbitrary WinCC station files via crafted packets.

Jul 22, 2016
7.5
CVE-2016-3949HIGH

Siemens SIMATIC S7-300 Profinet-enabled CPU devices with firmware before 3.2.12 and SIMATIC S7-300 Profinet-disabled CPU devices with firmware before 3.3.12 allow remote attackers to cause a denial of service (defect-mode transition) via crafted (1) ISO-TSAP or (2) Profibus packets.

Jun 27, 2016
7.5
CVE-2016-2200HIGH

Siemens SIMATIC S7-1500 CPU devices before 1.8.3 allow remote attackers to cause a denial of service (STOP mode transition) via crafted packets on TCP port 102.

Feb 8, 2016
7.5
CVE-2015-5698HIGH

Cross-site request forgery (CSRF) vulnerability in the web server on Siemens SIMATIC S7-1200 CPU devices with firmware before 4.1.3 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

Aug 30, 2015
7.5
CVE-2014-1697HIGH

The integrated web server in Siemens SIMATIC WinCC OA before 3.12 P002 January allows remote attackers to execute arbitrary code via crafted packets to TCP port 4999.

Feb 7, 2014
7.5
CVE-2013-3958HIGH

The login implementation in the Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMATIC PCS7 8.0 SP1 and earlier and other products, has a hardcoded account, which makes it easier for remote attackers to obtain access via an unspecified request.

Jun 14, 2013
7.5
CVE-2013-3957HIGH

SQL injection vulnerability in the login screen in the Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMATIC PCS7 8.0 SP1 and earlier and other products, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Jun 14, 2013
7.5
CVE-2012-3032HIGH

SQL injection vulnerability in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers to execute arbitrary SQL commands via a crafted SOAP message.

Sep 18, 2012
7.5
CVE-2012-3020HIGH

The Siemens Synco OZW Web Server devices OZW672.*, OZW772.*, and OZW775 with firmware before 4 have an unspecified default password, which makes it easier for remote attackers to obtain administrative access via a network session.

Aug 6, 2012
7.5
CVE-2011-4529HIGH

Multiple buffer overflows in Siemens Automation License Manager (ALM) 4.0 through 5.1+SP1+Upd1 allow remote attackers to execute arbitrary code via a long serialid field in an _licensekey command, as demonstrated by the (1) check_licensekey or (2) read_licensekey command.

Jan 8, 2012
7.5
CVE-2006-3344HIGH

Siemens Speedstream Wireless Router 2624 allows local users to bypass authentication and access protected files by using the Universal Plug and Play UPnP/1.0 component.

Jul 3, 2006
7.5
CVE-2005-2424HIGH

The management interface for Siemens SANTIS 50 running firmware 4.2.8.0, and possibly other products including Ericsson HN294dp and Dynalink RTA300W, allows remote attackers to access the Telnet port without authentication via certain packets to the web interface that cause the interface to freeze.

Aug 3, 2005
7.5
CVE-2018-4849HIGH

A vulnerability has been identified in Siveillance VMS Video for Android (All versions < V12.1a (2018 R1)), Siveillance VMS Video for iOS (All versions < V12.1a (2018 R1)). Improper certificate validation could allow an attacker in a privileged network position to read data from and write data to the encrypted communication channel between the app and a server. The security vulnerability could be exploited by an attacker in a privileged network position which allows intercepting the communication channel between the affected app and a server (such as Man-in-the-Middle). Furthermore, an attacker must be able to generate a certificate that results for the validation algorithm in a checksum identical to a trusted certificate. Successful exploitation requires no user interaction. The vulnerability could allow reading data from and writing data to the encrypted communication channel between the app and a server, impacting the communication's confidentiality and integrity. At the time of advisory publication no public exploitation of this security vulnerability was known. Siemens confirms the security vulnerability and provides mitigations to resolve the security issue.

May 3, 2018
7.4
CVE-2017-9941HIGH

A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker in a Man-in-the-Middle position between the SiPass integrated server and SiPass integrated clients to read or modify the network communication.

Aug 8, 2017
7.4
CVE-2017-6873HIGH

A vulnerability was discovered in Siemens OZW672 (all versions) and OZW772 (all versions) that could allow an attacker to read and manipulate data in TLS sessions while performing a man-in-the-middle (MITM) attack on the integrated web server on port 443/tcp.

Aug 8, 2017
7.4
CVE-2017-6870HIGH

A vulnerability was discovered in Siemens SIMATIC WinCC Sm@rtClient for Android (All versions before V1.0.2.2). The existing TLS protocol implementation could allow an attacker to read and modify data within a TLS session while performing a Man-in-the-Middle (MitM) attack.

Aug 8, 2017
7.4
CVE-2017-2685HIGH

Siemens SINUMERIK Integrate Operate Clients between 2.0.3.00.016 (including) and 2.0.6 (excluding) and between 3.0.4.00.032 (including) and 3.0.6 (excluding) contain a vulnerability that could allow an attacker to read and manipulate data in TLS sessions while performing a man-in-the-middle (MITM) attack.

Mar 1, 2017
7.4
CVE-2016-9156HIGH

A vulnerability in Siemens SICAM PAS (all versions before V8.09) could allow a remote attacker to upload, download, or delete files in certain parts of the file system by sending specially crafted packets to port 19235/TCP.

Dec 5, 2016
7.3
CVE-2009-1152HIGH

Siemens Gigaset SE461 WiMAX router 1.5-BL024.9.6401, and possibly other versions, allows remote attackers to cause a denial of service (device restart and loss of configuration) by connecting to TCP port 53, then closing the connection.

Mar 26, 2009
7.3
CVE-2013-4943HIGH

The client application in Siemens COMOS before 9.1 Update 458, 9.2 before 9.2.0.6.37, and 10.0 before 10.0.3.0.19 allows local users to gain privileges and bypass intended database-operation restrictions by leveraging COMOS project access.

Aug 9, 2013
7.2
CVE-2003-1528HIGH

nsr_shutdown in Fujitsu Siemens NetWorker 6.0 allows local users to overwrite arbitrary files via a symlink attack on the nsrsh[PID] temporary file.

Dec 31, 2003
7.2
CVE-2014-5074HIGH

Siemens SIMATIC S7-1500 CPU devices with firmware before 1.6 allow remote attackers to cause a denial of service (device restart and STOP transition) via crafted TCP packets.

Aug 17, 2014
7.1
CVE-2011-4877HIGH

HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime, when Transfer Mode is enabled, allows remote attackers to cause a denial of service (application crash) by sending crafted data over TCP.

Feb 3, 2012
7.1
CVE-2019-11486HIGH

The Siemens R3964 line discipline driver in drivers/tty/n_r3964.c in the Linux kernel before 5.0.8 has multiple race conditions.

Apr 23, 2019
7.0
CVE-2015-1594MEDIUM

Untrusted search path vulnerability in Siemens SIMATIC ProSave before 13 SP1; SIMATIC CFC before 8.0 SP4 Upd9 and 8.1 before Upd1; SIMATIC STEP 7 before 5.5 SP1 HF2, 5.5 SP2 before HF7, 5.5 SP3, and 5.5 SP4 before HF4; SIMOTION Scout before 4.4; and STARTER before 4.4 HF3 allows local users to gain privileges via a Trojan horse application file.

Mar 7, 2015
6.9
CVE-2013-6840MEDIUM

Siemens COMOS before 9.2.0.8.1, 10.0 before 10.0.3.1.40, and 10.1 before 10.1.0.0.2 allows local users to gain database privileges via unspecified vectors.

Dec 10, 2013
6.9
CVE-2012-3015MEDIUM

Untrusted search path vulnerability in Siemens SIMATIC STEP7 before 5.5 SP1, as used in SIMATIC PCS7 7.1 SP3 and earlier and other products, allows local users to gain privileges via a Trojan horse DLL in a STEP7 project folder.

Jul 26, 2012
6.9
CVE-2015-2823MEDIUM

Siemens SIMATIC HMI Basic Panels 2nd Generation before WinCC (TIA Portal) 13 SP1 Upd2, SIMATIC HMI Comfort Panels before WinCC (TIA Portal) 13 SP1 Upd2, SIMATIC WinCC Runtime Advanced before WinCC (TIA Portal) 13 SP1 Upd2, SIMATIC WinCC Runtime Professional before WinCC (TIA Portal) 13 SP1 Upd2, SIMATIC HMI Basic Panels 1st Generation (WinCC TIA Portal), SIMATIC HMI Mobile Panel 277 (WinCC TIA Portal), SIMATIC HMI Multi Panels (WinCC TIA Portal), and SIMATIC WinCC 7.x before 7.3 Upd4 allow remote attackers to complete authentication by leveraging knowledge of a password hash without knowledge of the associated password.

Apr 8, 2015
6.8
CVE-2015-1601MEDIUM

Siemens SIMATIC STEP 7 (TIA Portal) 12 and 13 before 13 SP1 Upd1 allows man-in-the-middle attackers to obtain sensitive information or modify transmitted data via unspecified vectors.

Apr 6, 2015
6.8
CVE-2015-1597MEDIUM

The Siemens SPCanywhere application for Android does not use encryption during the loading of code, which allows man-in-the-middle attackers to execute arbitrary code by modifying the client-server data stream.

Mar 7, 2015
6.8
CVE-2015-1049MEDIUM

The web server on Siemens SCALANCE X-200IRT switches with firmware before 5.2.0 allows remote attackers to hijack sessions via unspecified vectors.

Feb 2, 2015
6.8
CVE-2014-8479MEDIUM

The FTP server on Siemens SCALANCE X-300 switches with firmware before 4.0 and SCALANCE X 408 switches with firmware before 4.0 allows remote authenticated users to cause a denial of service (reboot) via crafted FTP packets.

Jan 21, 2015
6.8
CVE-2014-4686MEDIUM

The Project administration application in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, has a hardcoded encryption key, which allows remote attackers to obtain sensitive information by extracting this key from another product installation and then employing this key during the sniffing of network traffic on TCP port 1030.

Jul 24, 2014
6.8
CVE-2013-4911MEDIUM

Cross-site request forgery (CSRF) vulnerability in Siemens WinCC (TIA Portal) 11 and 12 before 12 SP1 allows remote attackers to hijack the authentication of unspecified victims by leveraging improper configuration of SIMATIC HMI panels by the WinCC product.

Aug 1, 2013
6.8
CVE-2013-0674MEDIUM

Buffer overflow in the RegReader ActiveX control in Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, allows remote attackers to execute arbitrary code via a long parameter.

Mar 21, 2013
6.8
CVE-2013-0656MEDIUM

Buffer overflow in a third-party ActiveX component in Siemens SIMATIC RF-MANAGER 2008, and RF-MANAGER Basic 3.0 and earlier, allows remote attackers to execute arbitrary code via a crafted web site.

Jan 21, 2013
6.8
CVE-2012-3028MEDIUM

Cross-site request forgery (CSRF) vulnerability in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers to hijack the authentication of arbitrary users for requests that modify data or cause a denial of service.

Sep 18, 2012
6.8
CVE-2025-30000MEDIUM

A vulnerability has been identified in Siemens License Server (SLS) (All versions < V4.3). The affected application does not properly restrict permissions of the users. This could allow a lowly-privileged attacker to escalate their privileges.

Apr 8, 2025
6.7
CVE-2025-29999MEDIUM

A vulnerability has been identified in Siemens License Server (SLS) (All versions < V4.3). The affected application searches for executable files in the application folder without proper validation. This could allow an attacker to execute arbitrary code with administrative privileges by placing a malicious executable in the same directory.

Apr 8, 2025
6.7
CVE-2018-4844MEDIUM

A vulnerability has been identified in SIMATIC WinCC OA UI for Android (All versions < V3.15.10), SIMATIC WinCC OA UI for iOS (All versions < V3.15.10). Insufficient limitation of CONTROL script capabilities could allow read and write access from one HMI project cache folder to other HMI project cache folders within the app's sandbox on the same mobile device. This includes HMI project cache folders of other configured WinCC OA servers. The security vulnerability could be exploited by an attacker who tricks an app user to connect to an attacker-controlled WinCC OA server. Successful exploitation requires user interaction and read/write access to the app's folder on a mobile device. The vulnerability could allow reading data from and writing data to the app's folder. At the time of advisory publication no public exploitation of this security vulnerability was known. Siemens confirms the security vulnerability and provides mitigations to resolve the security issue.

Mar 20, 2018
6.7
CVE-2016-5848MEDIUM

Siemens SICAM PAS before 8.07 does not properly restrict password data in the database, which makes it easier for local users to calculate passwords by leveraging unspecified database privileges.

Jul 4, 2016
6.7
CVE-2013-4651MEDIUM

Siemens Scalance W7xx devices with firmware before 4.5.4 use the same hardcoded X.509 certificate across different customers' installations, which makes it easier for remote attackers to conduct man-in-the-middle attacks against SSL sessions by leveraging the certificate's trust relationship.

Aug 1, 2013
6.6
CVE-2017-9945MEDIUM

In the Siemens 7KM PAC Switched Ethernet PROFINET expansion module (All versions < V2.1.3), a Denial-of-Service condition could be induced by a specially crafted PROFINET DCP packet sent as a local Ethernet (Layer 2) broadcast. The affected component requires a manual restart via the main device to recover.

Aug 30, 2017
6.5
CVE-2017-6872MEDIUM

A vulnerability was discovered in Siemens OZW672 (all versions) and OZW772 (all versions) that could allow an attacker with access to port 21/tcp to access or alter historical measurement data stored on the device.

Aug 8, 2017
6.5
CVE-2017-6866MEDIUM

A vulnerability was discovered in Siemens XHQ server 4 and 5 (4 before V4.7.1.3 and 5 before V5.0.0.2) that could allow an authenticated low-privileged remote user to gain read access to data in the XHQ solution exceeding his configured permission level.

Aug 7, 2017
6.5
CVE-2017-2686MEDIUM

Siemens RUGGEDCOM ROX I (all versions) contain a vulnerability that could allow an authenticated user to read arbitrary files through the web interface at port 10000/TCP and access sensitive information.

Mar 29, 2017
6.5
CVE-2016-8564MEDIUM

SQL injection vulnerability in Siemens Automation License Manager (ALM) before 5.3 SP3 Update 1 allows remote attackers to execute arbitrary SQL commands via crafted traffic to TCP port 4410.

Oct 13, 2016
6.5
CVE-2016-2846MEDIUM

Siemens SIMATIC S7-1200 CPU devices before 4.0 allow remote attackers to bypass a "user program block" protection mechanism via unspecified vectors.

Mar 16, 2016
6.5
CVE-2008-3126MEDIUM

Multiple stack-based buffer overflows in the ServerView web interface (SnmpGetMibValues.exe) in Fujitsu Siemens Computers ServerView 04.60.07 and earlier allow remote authenticated users to execute arbitrary code via a crafted URL.

Jul 10, 2008
6.5
CVE-2020-7579MEDIUM

A vulnerability has been identified in Spectrum Power™ 5 (All versions < v5.50 HF02). The web server could allow Cross-Site Scripting (XSS) attacks if unsuspecting users are tricked into accessing a malicious link. User interaction is required for a successful exploitation. If deployed according to recommended system configuration, Siemens consideres the environmental vector as CR:L/IR:M/AR:H/MAV:A (4.1).

Mar 10, 2020
6.1
CVE-2018-11450MEDIUM

A reflected Cross-Site-Scripting (XSS) vulnerability has been identified in Siemens PLM Software TEAMCENTER (V9.1.2.5). If a user visits the login portal through the URL crafted by the attacker, the attacker can insert html/javascript and thus alter/rewrite the login portal page. Siemens PLM Software TEAMCENTER V9.1.3 and newer are not affected.

Jul 9, 2018
6.1
CVE-2017-12738MEDIUM

An issue was discovered on Siemens SICAM RTUs SM-2556 COM Modules with the firmware variants ENOS00, ERAC00, ETA2, ETLS00, MODi00, and DNPi00. The integrated web server (port 80/tcp) of the affected devices could allow Cross-Site Scripting (XSS) attacks if unsuspecting users are tricked into clicking on a malicious link.

Nov 15, 2017
6.1
CVE-2017-2687MEDIUM

Siemens RUGGEDCOM ROX I (all versions) contain a vulnerability in the integrated web server at port 10000/TCP which is prone to reflected Cross-Site Scripting attacks if an unsuspecting user is induced to click on a malicious link.

Mar 29, 2017
6.1
CVE-2016-6204MEDIUM

Cross-site scripting (XSS) vulnerability in the integrated web server in Siemens SINEMA Remote Connect Server before 1.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

Jul 22, 2016
6.1
CVE-2016-1488MEDIUM

Cross-site scripting (XSS) vulnerability in the login form in the integrated web server on Siemens OZW OZW672 devices before 6.00 and OZW772 devices before 6.00 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

Jan 30, 2016
6.1
CVE-2014-2252MEDIUM

Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 allow remote attackers to cause a denial of service (defect-mode transition) via crafted PROFINET packets, a different vulnerability than CVE-2014-2253.

Mar 24, 2014
6.1
CVE-2014-2253MEDIUM

Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allow remote attackers to cause a denial of service (defect-mode transition) via crafted Profinet packets.

Mar 16, 2014
6.1
CVE-2013-0675MEDIUM

Buffer overflow in CCEServer (aka the central communications component) in Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, allows remote attackers to cause a denial of service via a crafted packet.

Mar 21, 2013
6.1
CVE-2012-1800MEDIUM

Stack-based buffer overflow in the Profinet DCP protocol implementation on the Siemens Scalance S Security Module firewall S602 V2, S612 V2, and S613 V2 with firmware before 2.3.0.3 allows remote attackers to cause a denial of service (device outage) or possibly execute arbitrary code via a crafted DCP frame.

Apr 18, 2012
6.1
CVE-2014-4684MEDIUM

The database server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote authenticated users to gain privileges via a request to TCP port 1433.

Jul 24, 2014
6.0
CVE-2017-12740MEDIUM

Siemens LOGO! Soft Comfort (All versions before V8.2) lacks integrity verification of software packages downloaded via an unprotected communication channel. This could allow a remote attacker to manipulate the software package while performing a Man-in-the-Middle (MitM) attack.

Dec 26, 2017
5.9
CVE-2015-5717MEDIUM

The Siemens COMPAS Mobile application before 1.6 for Android does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

Aug 31, 2015
5.8
CVE-2015-1596MEDIUM

The Siemens SPCanywhere application for Android and iOS does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

Mar 7, 2015
5.8
CVE-2014-2909MEDIUM

CRLF injection vulnerability in the integrated web server on Siemens SIMATIC S7-1200 CPU devices 2.x and 3.x allows remote attackers to inject arbitrary HTTP headers via unspecified vectors.

Apr 25, 2014
5.8
CVE-2014-2249MEDIUM

Cross-site request forgery (CSRF) vulnerability on Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 and SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

Mar 16, 2014
5.8
CVE-2014-2247MEDIUM

The integrated web server on Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allows remote attackers to inject headers via unspecified vectors.

Mar 16, 2014
5.8
CVE-2013-4912MEDIUM

Open redirect vulnerability in Siemens WinCC (TIA Portal) 11 and 12 before 12 SP1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks by leveraging improper configuration of SIMATIC HMI panels by the WinCC product.

Aug 1, 2013
5.8
CVE-2013-0677MEDIUM

The web server in Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, allows remote attackers to obtain sensitive information or cause a denial of service via a crafted project file.

Mar 21, 2013
5.8
CVE-2012-3003MEDIUM

Open redirect vulnerability in an unspecified web application in Siemens WinCC 7.0 SP3 before Update 2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in a GET request.

Jun 8, 2012
5.8
CVE-2011-4056MEDIUM

An unspecified ActiveX control in ActBar.ocx in Siemens Tecnomatix FactoryLink 6.6.1 (aka 6.6 SP1), 7.5.217 (aka 7.5 SP2), and 8.0.2.54 allows remote attackers to create or overwrite arbitrary files via the save method.

Jan 8, 2012
5.8
CVE-2012-2596MEDIUM

The XPath functionality in unspecified web applications in Siemens WinCC 7.0 SP3 before Update 2 does not properly handle special characters in parameters, which allows remote authenticated users to read or modify settings via a crafted URL, related to an "XML injection" attack.

Jun 8, 2012
5.5
CVE-2017-6871MEDIUM

A vulnerability was discovered in Siemens SIMATIC WinCC Sm@rtClient for Android (All versions before V1.0.2.2) and SIMATIC WinCC Sm@rtClient for Android Lite (All versions before V1.0.2.2). An attacker with physical access to an unlocked mobile device, that has the affected app running, could bypass the app's authentication mechanism under certain conditions.

Aug 8, 2017
5.4
CVE-2017-6864MEDIUM

The integrated web server in Siemens RUGGEDCOM ROX I (all versions) at port 10000/TCP could allow an authenticated user to perform stored Cross-Site Scripting attacks.

Mar 29, 2017
5.4
CVE-2015-3610MEDIUM

The Siemens HomeControl for Room Automation application before 2.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information or modify data via a crafted certificate.

May 7, 2015
5.4
CVE-2023-52891MEDIUM

A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.5), SIMATIC Energy Manager PRO (All versions < V7.5), SIMATIC IPC DiagBase (All versions), SIMATIC IPC DiagMonitor (All versions), SIMIT V10 (All versions), SIMIT V11 (All versions < V11.1). Unified Automation .NET based OPC UA Server SDK before 3.2.2 used in Siemens products are affected by a similar vulnerability as documented in CVE-2023-27321 for the OPC Foundation UA .NET Standard implementation. A successful attack may lead to high load situation and memory exhaustion, and may block the server.

Jul 9, 2024
5.3
CVE-2017-12737MEDIUM

An issue was discovered on Siemens SICAM RTUs SM-2556 COM Modules with the firmware variants ENOS00, ERAC00, ETA2, ETLS00, MODi00, and DNPi00. The integrated web server (port 80/tcp) of the affected devices could allow unauthenticated remote attackers to obtain sensitive device information over the network.

Nov 15, 2017
5.3
CVE-2017-9947MEDIUM

A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions <V3.5. A directory traversal vulnerability could allow a remote attacker with network access to the integrated web server (80/tcp and 443/tcp) to obtain information on the structure of the file system of the affected devices.

Oct 23, 2017
5.3
CVE-2016-3963MEDIUM

Siemens SCALANCE S613 allows remote attackers to cause a denial of service (web-server outage) via traffic to TCP port 443.

Apr 8, 2016
5.3
CVE-2016-2201MEDIUM

Siemens SIMATIC S7-1500 CPU devices before 1.8.3 allow remote attackers to bypass a replay protection mechanism via packets on TCP port 102.

Feb 8, 2016
5.3
CVE-2015-1358MEDIUM

The remote-management module in the (1) Multi Panels, (2) Comfort Panels, and (3) RT Advanced functionality in Siemens SIMATIC WinCC (TIA Portal) before 13 SP1 and in the (4) panels and (5) runtime functionality in SIMATIC WinCC flexible before 2008 SP3 Up7 does not properly encrypt credentials in transit, which makes it easier for remote attackers to determine cleartext credentials by sniffing the network and conducting a decryption attack.

Feb 18, 2015
5.0
CVE-2015-1357MEDIUM

Siemens Ruggedcom WIN51xx devices with firmware before SS4.4.4624.35, WIN52xx devices with firmware before SS4.4.4624.35, WIN70xx devices with firmware before BS4.4.4621.32, and WIN72xx devices with firmware before BS4.4.4621.32 allow context-dependent attackers to discover password hashes by reading (1) files or (2) security logs.

Feb 2, 2015
5.0
CVE-2014-8552MEDIUM

The WinCC server in Siemens SIMATIC WinCC 7.0 through SP3, 7.2 before Update 9, and 7.3 before Update 2; SIMATIC PCS 7 7.1 through SP4, 8.0 through SP2, and 8.1; and TIA Portal 13 before Update 6 allows remote attackers to read arbitrary files via crafted packets.

Nov 26, 2014
5.0
CVE-2014-4682MEDIUM

The WebNavigator server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote attackers to obtain sensitive information via an HTTP request.

Jul 24, 2014
5.0
CVE-2014-2733MEDIUM

Siemens SINEMA Server before 12 SP1 allows remote attackers to cause a denial of service (web-interface outage) via crafted HTTP requests to port (1) 4999 or (2) 80.

Apr 19, 2014
5.0
CVE-2014-2732MEDIUM

Multiple directory traversal vulnerabilities in the integrated web server in Siemens SINEMA Server before 12 SP1 allow remote attackers to access arbitrary files via HTTP traffic to port (1) 4999 or (2) 80.

Apr 19, 2014
5.0
CVE-2014-2590MEDIUM

The web management interface in Siemens RuggedCom ROS before 3.11, ROS 3.11 before 3.11.5 for RS950G, ROS 3.12, and ROS 4.0 for RSG2488 allows remote attackers to cause a denial of service (interface outage) via crafted HTTP packets.

Apr 1, 2014
5.0
CVE-2014-1699MEDIUM

Siemens SIMATIC WinCC OA before 3.12 P002 January allows remote attackers to cause a denial of service (monitoring-service outage) via malformed HTTP requests to port 4999.

Feb 7, 2014
5.0
CVE-2014-1698MEDIUM

Directory traversal vulnerability in Siemens SIMATIC WinCC OA before 3.12 P002 January allows remote attackers to read arbitrary files via crafted packets to TCP port 4999.

Feb 7, 2014
5.0
CVE-2014-1696MEDIUM

Siemens SIMATIC WinCC OA before 3.12 P002 January uses a weak hash algorithm for passwords, which makes it easier for remote attackers to obtain access via a brute-force attack.

Feb 7, 2014
5.0
CVE-2012-3030MEDIUM

WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, stores sensitive information under the web root with insufficient access control, which allows remote attackers to read a (1) log file or (2) configuration file via a direct request.

Sep 18, 2012
5.0
CVE-2011-4512MEDIUM

CRLF injection vulnerability in the HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before SP2 Update 1; the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

Feb 3, 2012
5.0
CVE-2011-4532MEDIUM

Absolute path traversal vulnerability in the ALMListView.ALMListCtrl ActiveX control in almaxcx.dll in the graphical user interface in Siemens Automation License Manager (ALM) 2.0 through 5.1+SP1+Upd2 allows remote attackers to overwrite arbitrary files via the Save method.

Jan 8, 2012
5.0
CVE-2011-4531MEDIUM

Siemens Automation License Manager (ALM) 4.0 through 5.1+SP1+Upd1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via crafted content in a (1) get_target_ocx_param or (2) send_target_ocx_param command.

Jan 8, 2012
5.0
CVE-2011-4530MEDIUM

Siemens Automation License Manager (ALM) 4.0 through 5.1+SP1+Upd1 does not properly copy fields obtained from clients, which allows remote attackers to cause a denial of service (exception and daemon crash) via long fields, as demonstrated by fields to the (1) open_session->workstation->NAME or (2) grant->VERSION function.

Jan 8, 2012
5.0
CVE-2006-3907MEDIUM

Siemens SpeedStream 2624 allows remote attackers to cause a denial of service (device hang) by sending a crafted packet to the web administrative interface.

Jul 27, 2006
5.0
CVE-2002-0122MEDIUM

Siemens 3568i WAP mobile phones allows remote attackers to cause a denial of service (crash) via an SMS message containing unusual characters.

Mar 25, 2002
5.0
CVE-2014-9563MEDIUM

CRLF injection vulnerability in the web-based management (WBM) interface in Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 allows remote authenticated users to modify the root password and consequently access the debug port using the serial interface via the ssh-password parameter to page.cmd.

Apr 12, 2018
4.9
CVE-2017-14023MEDIUM

An Improper Input Validation issue was discovered in Siemens SIMATIC PCS 7 V8.1 prior to V8.1 SP1 with WinCC V7.3 Upd 13, and V8.2 all versions. The improper input validation vulnerability has been identified, which may allow an authenticated remote attacker who is a member of the administrators group to crash services by sending specially crafted messages to the DCOM interface.

Nov 6, 2017
4.9
CVE-2017-6867MEDIUM

A vulnerability was discovered in Siemens SIMATIC WinCC (V7.3 before Upd 11 and V7.4 before SP1), SIMATIC WinCC Runtime Professional (V13 before SP2 and V14 before SP1), SIMATIC WinCC (TIA Portal) Professional (V13 before SP2 and V14 before SP1) that could allow an authenticated, remote attacker who is member of the "administrators" group to crash services by sending specially crafted messages to the DCOM interface.

May 11, 2017
4.9
CVE-2014-4683MEDIUM

The WebNavigator server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote authenticated users to gain privileges via a (1) HTTP or (2) HTTPS request.

Jul 24, 2014
4.9
CVE-2008-2235MEDIUM

OpenSC before 0.11.5 uses weak permissions (ADMIN file control information of 00) for the 5015 directory on smart cards and USB crypto tokens running Siemens CardOS M4, which allows physically proximate attackers to change the PIN.

Aug 1, 2008
4.9
CVE-2016-7959MEDIUM

Siemens SIMATIC STEP 7 (TIA Portal) before 14 improperly stores pre-shared key data in TIA project files, which makes it easier for local users to obtain sensitive information by leveraging access to a file and conducting a brute-force attack.

Oct 13, 2016
4.7
CVE-2018-4847MEDIUM

A vulnerability has been identified in SIMATIC WinCC OA Operator iOS App (All versions < V1.4). Insufficient protection of sensitive information (e.g. session key for accessing server) in Siemens WinCC OA Operator iOS app could allow an attacker with physical access to the mobile device to read unencrypted data from the app's directory. Siemens provides mitigations to resolve the security issue.

Apr 23, 2018
4.6
CVE-2014-4685MEDIUM

Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows local users to gain privileges by leveraging weak system-object access control.

Jul 24, 2014
4.6
CVE-2013-3927MEDIUM

Unspecified vulnerability in the client library in Siemens COMOS 9.2 before 9.2.0.6.10 and 10.0 before 10.0.3.0.4 allows local users to obtain unintended write access to the database by leveraging read access.

Jun 18, 2013
4.6
CVE-2011-4515MEDIUM

Siemens WinCC (TIA Portal) 11 uses a reversible algorithm for storing HMI web-application passwords in world-readable and world-writable files, which allows local users to obtain sensitive information by leveraging (1) physical access or (2) Sm@rt Server access.

Mar 21, 2013
4.6
CVE-2015-1356MEDIUM

Siemens SIMATIC STEP 7 (TIA Portal) before 13 SP1 determines a user's privileges on the basis of project-file fields that lack integrity protection, which allows remote attackers to establish arbitrary authorization data via a modified file.

Feb 18, 2015
4.4
CVE-2015-6929MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in Nokia Networks (formerly Nokia Solutions and Networks and Nokia Siemens Networks) @vantage Commander allow remote attackers to inject arbitrary web script or HTML via the (1) idFilter or (2) nameFilter parameter to cftraces/filter/fl_copy.jsp; the (3) flName parameter to cftraces/filter/fl_crea1.jsp; the (4) serchStatus, (5) refreshTime, or (6) serchNode parameter to cftraces/process/pr_show_process.jsp; the (7) MaxActivationTime, (8) NumberOfBytes, (9) NumberOfTracefiles, (10) SessionName, or (11) serchSessionkind parameter to cftraces/session/se_crea.jsp; the (12) serchSessionDescription parameter to cftraces/session/se_show.jsp; the (13) serchApplication or (14) serchApplicationkind parameter to cftraces/session/tr_crea_filter.jsp; the (15) columKeyUnique, (16) columParameter, (17) componentName, (18) criteria1, (19) criteria2, (20) criteria3, (21) description, (22) filter, (23) id, (24) pathName, (25) tableName, or (26) component parameter to cftraces/session/tr_create_tagg_para.jsp; or the (27) userid parameter to home/certificate_association.jsp.

Sep 16, 2015
4.3
CVE-2015-6675MEDIUM

Siemens RUGGEDCOM ROS 3.8.0 through 4.1.x permanently enables the IP forwarding feature, which allows remote attackers to bypass a VLAN isolation protection mechanism via IP traffic.

Sep 11, 2015
4.3
CVE-2015-5537MEDIUM

The SSL layer of the HTTPS service in Siemens RuggedCom ROS before 4.2.0 and ROX II does not properly implement CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a different vulnerability than CVE-2014-3566.

Aug 3, 2015
4.3
CVE-2015-4174MEDIUM

Cross-site scripting (XSS) vulnerability in the integrated web server on the Siemens Climatix BACnet/IP communication module with firmware before 10.34 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

Jun 28, 2015
4.3
CVE-2015-2822MEDIUM

Siemens SIMATIC HMI Comfort Panels before WinCC (TIA Portal) 13 SP1 Upd2 and SIMATIC WinCC Runtime Advanced before WinCC (TIA Portal) 13 SP1 Upd2 allow man-in-the-middle attackers to cause a denial of service via crafted packets on TCP port 102.

Apr 8, 2015
4.3
CVE-2015-1595MEDIUM

The Siemens SPCanywhere application for Android and iOS does not use encryption during lookups of system ID to IP address mappings, which allows man-in-the-middle attackers to discover alarm IP addresses and spoof servers by intercepting the client-server data stream.

Mar 7, 2015
4.3
CVE-2015-1048MEDIUM

Open redirect vulnerability in the integrated web server on Siemens SIMATIC S7-1200 CPU devices with firmware before 4.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

Jan 21, 2015
4.3
CVE-2014-2908MEDIUM

Cross-site scripting (XSS) vulnerability in the integrated web server on Siemens SIMATIC S7-1200 CPU devices 2.x and 3.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Apr 25, 2014
4.3
CVE-2014-2248MEDIUM

Open redirect vulnerability in the integrated web server on Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

Mar 16, 2014
4.3
CVE-2014-2246MEDIUM

Cross-site scripting (XSS) vulnerability in the integrated web server on Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Mar 16, 2014
4.3
CVE-2013-4779MEDIUM

Cross-site scripting (XSS) vulnerability in core/handleTw.php on the Siemens Enterprise OpenScape Branch appliance and OpenScape Session Border Controller (SBC) before 2 R0.32.0, and 7 before 7 R1.7.0, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Jul 18, 2013
4.3
CVE-2013-0670MEDIUM

CRLF injection vulnerability in the HMI web application in Siemens WinCC (TIA Portal) 11 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.

Mar 21, 2013
4.3
CVE-2013-0668MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in the HMI web application in Siemens WinCC (TIA Portal) 11 allow remote attackers to inject arbitrary web script or HTML via a crafted URL.

Mar 21, 2013
4.3
CVE-2013-0667MEDIUM

Cross-site scripting (XSS) vulnerability in the HMI web application in Siemens WinCC (TIA Portal) 11 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

Mar 21, 2013
4.3
CVE-2012-4698MEDIUM

Siemens RuggedCom Rugged Operating System (ROS) before 3.12, ROX I OS through 1.14.5, ROX II OS through 2.3.0, and RuggedMax OS through 4.2.1.4621.22 use hardcoded private keys for SSL and SSH communication, which makes it easier for man-in-the-middle attackers to spoof servers and decrypt network traffic by leveraging the availability of these keys within ROS files at all customer installations.

Dec 23, 2012
4.3
CVE-2012-3040MEDIUM

Cross-site scripting (XSS) vulnerability in the web server on Siemens SIMATIC S7-1200 PLCs 2.x through 3.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URI.

Oct 10, 2012
4.3
CVE-2012-3037MEDIUM

The Siemens SIMATIC S7-1200 2.x PLC does not properly protect the private key of the SIMATIC CONTROLLER Certification Authority certificate, which allows remote attackers to spoof the S7-1200 web server by using this key to create a forged certificate.

Sep 25, 2012
4.3
CVE-2012-3034MEDIUM

WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers to discover a username and password via crafted parameters to unspecified methods in ActiveX controls.

Sep 18, 2012
4.3
CVE-2012-3031MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allow remote attackers to inject arbitrary web script or HTML via a (1) GET parameter, (2) POST parameter, or (3) Referer HTTP header.

Sep 18, 2012
4.3
CVE-2012-2598MEDIUM

Buffer overflow in the DiagAgent web server in Siemens WinCC 7.0 SP3 through Update 2 allows remote attackers to cause a denial of service (agent outage) via crafted input.

Jun 8, 2012
4.3
CVE-2012-2595MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in unspecified web applications in Siemens WinCC 7.0 SP3 before Update 2 allow remote attackers to inject arbitrary web script or HTML via vectors involving special characters in parameters.

Jun 8, 2012
4.3
CVE-2011-4511MEDIUM

Cross-site scripting (XSS) vulnerability in the HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before SP2 Update 1; the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2011-4510.

Feb 3, 2012
4.3
CVE-2011-4510MEDIUM

Cross-site scripting (XSS) vulnerability in the HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before SP2 Update 1; the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2011-4511.

Feb 3, 2012
4.3
CVE-2007-4488MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in the Siemens Gigaset SE361 WLAN router with firmware 1.00.0 allow remote attackers to inject arbitrary web script or HTML via the portion of the URI immediately following the filename for (1) a GIF filename, which triggers display of the GIF file in text format and an unspecified denial of service (crash); or (2) the login.tri filename, which triggers a continuous loop of the browser attempting to visit the login page.

Aug 22, 2007
4.3
CVE-2016-7090MEDIUM

The integrated web server on Siemens SCALANCE M-800 and S615 modules with firmware before 4.02 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

Sep 29, 2016
4.0
CVE-2013-3959MEDIUM

The Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMATIC PCS7 8.0 SP1 and earlier and other products, exhibits different behavior for NetBIOS user names depending on whether the user account exists, which allows remote authenticated users to enumerate account names via crafted URL parameters.

Jun 14, 2013
4.0
CVE-2013-0679MEDIUM

Directory traversal vulnerability in the web server in Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, allows remote authenticated users to read arbitrary files via vectors involving a query for a pathname.

Mar 21, 2013
4.0
CVE-2013-0678MEDIUM

Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, does not properly represent WebNavigator credentials in a database, which makes it easier for remote authenticated users to obtain sensitive information via a SQL query.

Mar 21, 2013
4.0
CVE-2013-0676MEDIUM

Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, does not properly assign privileges for the database containing WebNavigator credentials, which allows remote authenticated users to obtain sensitive information via a SQL query.

Mar 21, 2013
4.0
CVE-2013-0671MEDIUM

Directory traversal vulnerability in Siemens WinCC (TIA Portal) 11 allows remote authenticated users to read HMI web-application source code and user-defined scripts via a crafted URL.

Mar 21, 2013
4.0
CVE-2013-0669MEDIUM

The HMI web application in Siemens WinCC (TIA Portal) 11 allows remote authenticated users to cause a denial of service (daemon crash) via a crafted HTTP request.

Mar 21, 2013
4.0
CVE-2012-2597MEDIUM

Multiple directory traversal vulnerabilities in Siemens WinCC 7.0 SP3 before Update 2 allow remote authenticated users to read arbitrary files via a crafted parameter in a URL.

Jun 8, 2012
4.0
CVE-2004-2626LOW

GUI overlay vulnerability in the Java API in Siemens S55 cellular phones allows remote attackers to send unauthorized SMS messages by overlaying a confirmation message with a malicious message.

Dec 31, 2004
3.7
CVE-2019-13936LOW

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webclient of Siemens AG Polarion could allow an attacker to exploit a persistent XSS vulnerability. This issue affects: Siemens AG Polarion All versions < 19.2.

Nov 27, 2019
3.5
CVE-2019-13935LOW

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webclient of Siemens AG Polarion could allow an attacker to exploit a reflected XSS vulnerability. This issue affects: Siemens AG Polarion All versions < 19.2.

Nov 27, 2019
3.5
CVE-2019-13934LOW

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webclient of Siemens AG Polarion could allow an attacker to exploit a reflected XSS vulnerability. This issue affects: Siemens AG Polarion All versions < 19.2.

Nov 27, 2019
3.5
CVE-2013-0672LOW

Cross-site scripting (XSS) vulnerability in the HMI web application in Siemens WinCC (TIA Portal) 11 allows remote authenticated users to inject arbitrary web script or HTML via unspecified data.

Mar 21, 2013
3.5
CVE-2016-3155LOW

Siemens APOGEE Insight uses weak permissions for the application folder, which allows local users to obtain sensitive information or modify data via unspecified vectors.

Mar 18, 2016
3.4
CVE-2015-7836LOW

Siemens RUGGEDCOM ROS before 4.2.1 allows remote attackers to obtain sensitive information by sniffing the network for VLAN data within the padding section of an Ethernet frame.

Oct 28, 2015
3.3
CVE-2012-4691LOW

Memory leak in Siemens Automation License Manager (ALM) 4.x and 5.x before 5.2 allows remote attackers to cause a denial of service (memory consumption) via crafted packets.

Dec 18, 2012
3.3
CVE-2016-7960LOW

Siemens SIMATIC STEP 7 (TIA Portal) before 14 uses an improper format for managing TIA project files during version updates, which makes it easier for local users to obtain sensitive configuration information via unspecified vectors.

Oct 13, 2016
2.5
CVE-2016-5849LOW

Siemens SICAM PAS through 8.07 allows local users to obtain sensitive configuration information by leveraging database stoppage.

Jul 4, 2016
2.5
CVE-2015-5084LOW

The Siemens SIMATIC WinCC Sm@rtClient and Sm@rtClient Lite applications before 01.00.01.00 for Android do not properly store passwords, which allows physically proximate attackers to obtain sensitive information via unspecified vectors.

Aug 3, 2015
2.1
CVE-2015-1602LOW

Siemens SIMATIC STEP 7 (TIA Portal) 12 and 13 before 13 SP1 Upd1 improperly stores password data within project files, which makes it easier for local users to determine cleartext (1) protection-level passwords or (2) web-server passwords by leveraging the ability to read these files.

Apr 6, 2015
2.1
CVE-2015-1599LOW

The Siemens SPCanywhere application for iOS allows physically proximate attackers to bypass intended access restrictions by leveraging a filesystem architectural error.

Mar 7, 2015
2.1
CVE-2015-1598LOW

The Siemens SPCanywhere application for Android does not properly store application passwords, which allows physically proximate attackers to obtain sensitive information by examining the device filesystem.

Mar 7, 2015
2.1
CVE-2015-1355LOW

Siemens SIMATIC STEP 7 (TIA Portal) before 13 SP1 uses a weak password-hash algorithm, which makes it easier for local users to determine cleartext passwords by reading a project file and conducting a brute-force attack.

Feb 18, 2015
2.1
CVE-2014-5231LOW

The Siemens SIMATIC WinCC Sm@rtClient app before 1.0.2 for iOS allows physically proximate attackers to extract the password from storage via unspecified vectors.

Jan 14, 2015
2.1
CVE-2014-5233LOW

The Siemens SIMATIC WinCC Sm@rtClient app before 1.0.2 for iOS allows physically proximate attackers to discover Sm@rtServer credentials by leveraging an error in the credential-processing mechanism.

Jan 14, 2015
1.9
CVE-2014-5232LOW

The Siemens SIMATIC WinCC Sm@rtClient app before 1.0.2 for iOS allows local users to bypass an intended application-password requirement by leveraging the running of the app in the background state.

Jan 14, 2015
1.9
CVE-2012-4693LOW

Invensys Wonderware InTouch 2012 R2 and earlier and Siemens ProcessSuite use a weak encryption algorithm for data in Ps_security.ini, which makes it easier for local users to discover passwords by reading this file.

Dec 18, 2012
1.9
CVE ID ⇅Severity ↓CVSS ⇅DescriptionPublished ⇅
CVE-2019-10938CRITICAL
9.8
A vulnerability has been identified in SIPROTEC 5 devices with CPU variants CP200 (All versions < V7…Aug 2, 2019›
CVE-2018-4846CRITICAL
9.8
A vulnerability has been identified in RAPIDLab 1200 systems / RAPIDPoint 400 systems / RAPIDPoint 5…Jun 26, 2018›
CVE-2018-4841CRITICAL
9.8
A vulnerability has been identified in TIM 1531 IRC (All versions < V1.1). A remote attacker with ne…Mar 29, 2018›
CVE-2017-9944CRITICAL
9.8
A vulnerability has been identified in Siemens 7KT PAC1200 data manager (7KT1260) in all versions < …Dec 27, 2017›
CVE-2017-12739CRITICAL
9.8
An issue was discovered on Siemens SICAM RTUs SM-2556 COM Modules with the firmware variants ENOS00,…Nov 15, 2017›
CVE-2017-9939CRITICAL
9.8
A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could a…Aug 8, 2017›
CVE-2017-6869CRITICAL
9.8
A vulnerability was discovered in Siemens ViewPort for Web Office Portal before revision number 1453…Aug 8, 2017›
CVE-2016-8567CRITICAL
9.8
An issue was discovered in Siemens SICAM PAS before 8.00. A factory account with hard-coded password…Feb 13, 2017›
CVE-2016-9157CRITICAL
9.8
A vulnerability in Siemens SICAM PAS (all versions before V8.09) could allow a remote attacker to ca…Dec 5, 2016›
CVE-2016-9155CRITICAL
9.8
The following SIEMENS branded IP Camera Models CCMW3025, CVMW3025-IR, CFMW3025 prior to version 1.41…Nov 22, 2016›
CVE-2016-5743CRITICAL
9.8
Siemens SIMATIC WinCC before 7.3 Update 10 and 7.4 before Update 1, SIMATIC BATCH before 8.1 SP1 Upd…Jul 22, 2016›
CVE-2016-8565CRITICAL
9.1
Siemens Automation License Manager (ALM) before 5.3 SP3 allows remote attackers to write to files, r…Oct 13, 2016›
CVE-2017-2684CRITICAL
9.0
Siemens SIMATIC Logon prior to V1.5 SP3 Update 2 could allow an attacker with knowledge of a valid u…Feb 22, 2017›
CVE-2015-1449HIGH
10.0
Buffer overflow in the integrated web server on Siemens Ruggedcom WIN51xx devices with firmware befo…Feb 2, 2015›
CVE-2015-1448HIGH
10.0
The integrated management service on Siemens Ruggedcom WIN51xx devices with firmware before SS4.4.46…Feb 2, 2015›
CVE-2014-8551HIGH
10.0
The WinCC server in Siemens SIMATIC WinCC 7.0 through SP3, 7.2 before Update 9, and 7.3 before Updat…Nov 26, 2014›
CVE-2013-6920HIGH
10.0
Siemens SINAMICS S/G controllers with firmware before 4.6.11 do not require authentication for FTP a…Dec 7, 2013›
CVE-2013-5944HIGH
10.0
The integrated web server on Siemens SCALANCE X-200 switches with firmware before 4.5.0 and X-200IRT…Oct 3, 2013›
CVE-2013-4652HIGH
10.0
Unspecified vulnerability in the command-line management interface on Siemens Scalance W7xx devices …Aug 1, 2013›
CVE-2013-4781HIGH
10.0
core/getLog.php on the Siemens Enterprise OpenScape Branch appliance and OpenScape Session Border Co…Jul 18, 2013›
CVE-2013-0659HIGH
10.0
The debugging feature on the Siemens CP 1604 and CP 1616 interface cards with firmware before 2.5.2 …Apr 1, 2013›
CVE-2012-5409HIGH
10.0
AscoServer.exe in the server in Siemens SiPass integrated MP2.6 and earlier does not properly handle…Nov 1, 2012›
CVE-2012-1799HIGH
10.0
The web server on the Siemens Scalance S Security Module firewall S602 V2, S612 V2, and S613 V2 with…Apr 18, 2012›
CVE-2011-4514HIGH
10.0
The TELNET daemon in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); …Feb 3, 2012›
CVE-2011-4513HIGH
10.0
Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfo…Feb 3, 2012›
CVE-2011-4509HIGH
10.0
The HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal);…Feb 3, 2012›
CVE-2008-6993HIGH
10.0
Siemens Gigaset WLAN Camera 1.27 has an insecure default password, which allows remote attackers to …Aug 19, 2009›
CVE-2008-6916HIGH
10.0
Siemens SpeedStream 5200 with NetPort Software 1.1 allows remote attackers to bypass authentication …Aug 7, 2009›
CVE-2015-5386HIGH
9.3
Siemens SICAM MIC devices with firmware before 2404 allow remote attackers to bypass authentication …Jul 16, 2015›
CVE-2014-2731HIGH
9.3
Multiple unspecified vulnerabilities in the integrated web server in Siemens SINEMA Server before 12…Apr 19, 2014›
CVE-2011-4876HIGH
9.3
Directory traversal vulnerability in HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2…Feb 3, 2012›
CVE-2011-4875HIGH
9.3
Stack-based buffer overflow in HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2…Feb 3, 2012›
CVE-2011-4508HIGH
9.3
The HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka T…Feb 3, 2012›
CVE-2011-4055HIGH
9.3
Buffer overflow in the WebClient ActiveX control in Siemens Tecnomatix FactoryLink 6.6.1 (aka 6.6 SP…Jan 8, 2012›
CVE-2011-3321HIGH
9.3
Heap-based buffer overflow in the Siemens WinCC Runtime Advanced Loader, as used in SIMATIC WinCC fl…Sep 16, 2011›
CVE-2019-6584HIGH
8.8
A vulnerability has been identified in SIEMENS LOGO!8 (6ED1052-xyyxx-0BA8 FS:01 to FS:06 / Firmware …Jun 12, 2019›
CVE-2018-4845HIGH
8.8
A vulnerability has been identified in RAPIDLab 1200 systems / RAPIDPoint 400 systems / RAPIDPoint 5…Jun 26, 2018›
CVE-2017-2689HIGH
8.8
Siemens RUGGEDCOM ROX I (all versions) allow an authenticated user to bypass access restrictions in …Mar 29, 2017›
CVE-2017-2688HIGH
8.8
The integrated web server in Siemens RUGGEDCOM ROX I (all versions) at port 10000/TCP could allow re…Mar 29, 2017›
CVE-2017-2682HIGH
8.8
The Siemens web application RUGGEDCOM NMS < V1.2 on port 8080/TCP and 8081/TCP could allow a remote …Feb 27, 2017›
CVE-2012-3009HIGH
8.5
Siemens COMOS before 9.1 Patch 413, 9.2 before Update 03 Patch 023, and 10.0 before Patch 005 allows…Aug 16, 2012›
CVE-2011-4879HIGH
8.5
miniweb.exe in the HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; W…Feb 3, 2012›
CVE-2014-2250HIGH
8.3
The random-number generator on Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 does…Mar 24, 2014›
CVE-2014-2251HIGH
8.3
The random-number generator on Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 do…Mar 16, 2014›
CVE-2013-6925HIGH
8.3
The integrated HTTPS server in Siemens RuggedCom ROS before 3.12.2 allows remote attackers to hijack…Dec 17, 2013›
CVE-2013-5709HIGH
8.3
The authentication implementation in the web server on Siemens SCALANCE X-200 switches with firmware…Sep 17, 2013›
CVE-2017-12069HIGH
8.2
An XXE vulnerability has been identified in OPC Foundation UA .NET Sample Code before 2017-03-21 and…Aug 30, 2017›
CVE-2017-2683HIGH
8.2
A non-privileged user of the Siemens web application RUGGEDCOM NMS < V1.2 on port 8080/TCP and 8081/…Feb 27, 2017›
CVE-2014-8422HIGH
8.1
The web-based management (WBM) interface in Unify (former Siemens) OpenStage SIP and OpenScape Desk …Apr 12, 2018›
CVE-2017-9940HIGH
8.1
A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could a…Aug 8, 2017›
CVE-2017-6868HIGH
8.1
An Improper Authentication issue was discovered in Siemens SIMATIC CP 44x-1 RNA, all versions prior …Jul 7, 2017›
CVE-2016-9160HIGH
8.1
A vulnerability in SIEMENS SIMATIC WinCC (All versions < SIMATIC WinCC V7.2) and SIEMENS SIMATIC PCS…Dec 17, 2016›
CVE-2013-6926HIGH
8.0
The integrated HTTPS server in Siemens RuggedCom ROS before 3.12.2 allows remote authenticated users…Dec 17, 2013›
CVE-2025-40827HIGH
7.8
A vulnerability has been identified in Siemens Software Center (All versions < V3.5), Solid Edge SE2…Nov 11, 2025›
CVE-2021-47302HIGH
7.8
In the Linux kernel, the following vulnerability has been resolved: igc: Fix use-after-free error d…May 21, 2024›
CVE-2021-41544HIGH
7.8
A vulnerability has been identified in Siemens Software Center (All versions < V3.0). A DLL Hijackin…Aug 8, 2023›
CVE-2022-2069HIGH
7.8
The APDFL.dll in Siemens JT2Go prior to V13.3.0.5 and Siemens Teamcenter Visualization prior to V14.…Oct 20, 2022›
CVE-2018-13806HIGH
7.8
A vulnerability has been identified in SIEMENS TD Keypad Designer (All versions). A DLL hijacking vu…Sep 12, 2018›
CVE-2018-4858HIGH
7.8
A vulnerability has been identified in IEC 61850 system configurator (All versions < V5.80), DIGSI 5…Jul 9, 2018›
CVE-2017-9942HIGH
7.8
A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could a…Aug 8, 2017›
CVE-2016-8566HIGH
7.8
An issue was discovered in Siemens SICAM PAS before 8.00. Because of Storing Passwords in a Recovera…Feb 13, 2017›
CVE-2016-6486HIGH
7.8
Siemens SINEMA Server uses weak permissions for the application folder, which allows local users to …Aug 8, 2016›
CVE-2015-2177HIGH
7.8
Siemens SIMATIC S7-300 CPU devices allow remote attackers to cause a denial of service (defect-mode …Mar 7, 2015›
CVE-2014-9369HIGH
7.8
Siemens SPC controllers SPC4000, SPC5000, and SPC6000 before 3.6.0 allow remote attackers to cause a…Mar 7, 2015›
CVE-2014-8478HIGH
7.8
The web server on Siemens SCALANCE X-300 switches with firmware before 4.0 and SCALANCE X 408 switch…Jan 21, 2015›
CVE-2014-2258HIGH
7.8
Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 allow remote attackers to cause a d…Mar 24, 2014›
CVE-2014-2254HIGH
7.8
Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 allow remote attackers to cause a d…Mar 24, 2014›
CVE-2014-2256HIGH
7.8
Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 allow remote attackers to cause a d…Mar 24, 2014›
CVE-2014-2259HIGH
7.8
Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allow remote attackers to cause a…Mar 16, 2014›
CVE-2014-2257HIGH
7.8
Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allow remote attackers to cause a…Mar 16, 2014›
CVE-2014-2255HIGH
7.8
Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allow remote attackers to cause a…Mar 16, 2014›
CVE-2014-1966HIGH
7.8
The SNMP implementation in Siemens RuggedCom ROS before 3.11, ROS 3.11 for RS950G, ROS 3.12 before 3…Feb 24, 2014›
CVE-2013-4780HIGH
7.8
core/getLog.php on the Siemens Enterprise OpenScape Branch appliance and OpenScape Session Border Co…Jul 18, 2013›
CVE-2013-4778HIGH
7.8
core/getLog.php on the Siemens Enterprise OpenScape Branch appliance and OpenScape Session Border Co…Jul 18, 2013›
CVE-2013-2780HIGH
7.8
Siemens SIMATIC S7-1200 PLCs 2.x and 3.x allow remote attackers to cause a denial of service (defect…Apr 22, 2013›
CVE-2013-0700HIGH
7.8
Siemens SIMATIC S7-1200 PLCs 2.x and 3.x allow remote attackers to cause a denial of service (defect…Apr 22, 2013›
CVE-2012-3017HIGH
7.8
Siemens SIMATIC S7-400 PN CPU devices with firmware 5.x allow remote attackers to cause a denial of …Jul 31, 2012›
CVE-2012-3016HIGH
7.8
Siemens SIMATIC S7-400 PN CPU devices with firmware 6 before 6.0.3 allow remote attackers to cause a…Jul 31, 2012›
CVE-2012-1802HIGH
7.8
Buffer overflow in the embedded web server on the Siemens Scalance X Industrial Ethernet switch X414…Apr 18, 2012›
CVE-2011-4878HIGH
7.8
Directory traversal vulnerability in miniweb.exe in the HMI web server in Siemens WinCC flexible 200…Feb 3, 2012›
CVE-2010-2772HIGH
7.8
Siemens Simatic WinCC and PCS 7 SCADA system uses a hard-coded password, which allows local users to…Jul 22, 2010›
CVE-2010-2568HIGH
7.8
Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R…Jul 22, 2010›
CVE-2009-3322HIGH
7.8
The Siemens Gigaset SE361 WLAN router allows remote attackers to cause a denial of service (device r…Sep 23, 2009›
CVE-2008-7065HIGH
7.8
Siemens C450 IP and C475 IP VoIP devices allow remote attackers to cause a denial of service (discon…Aug 25, 2009›
CVE-2008-1267HIGH
7.8
The Siemens SpeedStream 6520 router allows remote attackers to cause a denial of service (web interf…Mar 10, 2008›
CVE-2003-1464HIGH
7.8
Buffer overflow in Siemens 45 series mobile phones allows remote attackers to cause a denial of serv…Dec 31, 2003›
CVE-2023-27336HIGH
7.5
Softing edgeConnector Siemens OPC UA Server Null Pointer Dereference Denial-of-Service Vulnerability…May 3, 2024›
CVE-2023-27334HIGH
7.5
Softing edgeConnector Siemens ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability. …May 3, 2024›
CVE-2023-46590HIGH
7.5
A vulnerability has been identified in Siemens OPC UA Modelling Editor (SiOME) (All versions < V2.8)…Nov 14, 2023›
CVE-2019-19279HIGH
7.5
A vulnerability has been identified in SIPROTEC 4 and SIPROTEC Compact relays equipped with EN100 Et…Mar 10, 2020›
CVE-2019-6571HIGH
7.5
A vulnerability has been identified in SIEMENS LOGO!8 (6ED1052-xyyxx-0BA8 FS:01 to FS:06 / Firmware …Jun 12, 2019›
CVE-2019-10953HIGH
7.5
ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple v…Apr 17, 2019›
CVE-2018-16561HIGH
7.5
A vulnerability has been identified in SIMATIC S7-300 CPUs (All versions < V3.X.16). The affected CP…Apr 17, 2019›
CVE-2014-8421HIGH
7.5
Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 allow rem…Apr 12, 2018›
CVE-2017-9946HIGH
7.5
A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers…Oct 23, 2017›
CVE-2017-12734HIGH
7.5
A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V1.81.2). …Aug 30, 2017›
CVE-2017-9938HIGH
7.5
A vulnerability was discovered in Siemens SIMATIC Logon (All versions before V1.6) that could allow …Aug 8, 2017›
CVE-2016-7987HIGH
7.5
An issue was discovered in Siemens ETA4 firmware (all versions prior to Revision 08) of the SM-2558 …Feb 13, 2017›
CVE-2016-9154HIGH
7.5
Siemens Desigo PX Web modules PXA40-W0, PXA40-W1, PXA40-W2 for Desigo PX automation controllers PXC0…Dec 23, 2016›
CVE-2016-8563HIGH
7.5
Siemens Automation License Manager (ALM) before 5.3 SP3 Update 1 allows remote attackers to cause a …Oct 13, 2016›
CVE-2016-5874HIGH
7.5
Siemens SIMATIC NET PC-Software before 13 SP2 allows remote attackers to cause a denial of service (…Jul 22, 2016›
CVE-2016-5744HIGH
7.5
Siemens SIMATIC WinCC 7.0 through SP3 and 7.2 allows remote attackers to read arbitrary WinCC statio…Jul 22, 2016›
CVE-2016-3949HIGH
7.5
Siemens SIMATIC S7-300 Profinet-enabled CPU devices with firmware before 3.2.12 and SIMATIC S7-300 P…Jun 27, 2016›
CVE-2016-2200HIGH
7.5
Siemens SIMATIC S7-1500 CPU devices before 1.8.3 allow remote attackers to cause a denial of service…Feb 8, 2016›
CVE-2015-5698HIGH
7.5
Cross-site request forgery (CSRF) vulnerability in the web server on Siemens SIMATIC S7-1200 CPU dev…Aug 30, 2015›
CVE-2014-1697HIGH
7.5
The integrated web server in Siemens SIMATIC WinCC OA before 3.12 P002 January allows remote attacke…Feb 7, 2014›
CVE-2013-3958HIGH
7.5
The login implementation in the Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMAT…Jun 14, 2013›
CVE-2013-3957HIGH
7.5
SQL injection vulnerability in the login screen in the Web Navigator in Siemens WinCC before 7.2 Upd…Jun 14, 2013›
CVE-2012-3032HIGH
7.5
SQL injection vulnerability in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC…Sep 18, 2012›
CVE-2012-3020HIGH
7.5
The Siemens Synco OZW Web Server devices OZW672.*, OZW772.*, and OZW775 with firmware before 4 have …Aug 6, 2012›
CVE-2011-4529HIGH
7.5
Multiple buffer overflows in Siemens Automation License Manager (ALM) 4.0 through 5.1+SP1+Upd1 allow…Jan 8, 2012›
CVE-2006-3344HIGH
7.5
Siemens Speedstream Wireless Router 2624 allows local users to bypass authentication and access prot…Jul 3, 2006›
CVE-2005-2424HIGH
7.5
The management interface for Siemens SANTIS 50 running firmware 4.2.8.0, and possibly other products…Aug 3, 2005›
CVE-2018-4849HIGH
7.4
A vulnerability has been identified in Siveillance VMS Video for Android (All versions < V12.1a (201…May 3, 2018›
CVE-2017-9941HIGH
7.4
A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could a…Aug 8, 2017›
CVE-2017-6873HIGH
7.4
A vulnerability was discovered in Siemens OZW672 (all versions) and OZW772 (all versions) that could…Aug 8, 2017›
CVE-2017-6870HIGH
7.4
A vulnerability was discovered in Siemens SIMATIC WinCC Sm@rtClient for Android (All versions before…Aug 8, 2017›
CVE-2017-2685HIGH
7.4
Siemens SINUMERIK Integrate Operate Clients between 2.0.3.00.016 (including) and 2.0.6 (excluding) a…Mar 1, 2017›
CVE-2016-9156HIGH
7.3
A vulnerability in Siemens SICAM PAS (all versions before V8.09) could allow a remote attacker to up…Dec 5, 2016›
CVE-2009-1152HIGH
7.3
Siemens Gigaset SE461 WiMAX router 1.5-BL024.9.6401, and possibly other versions, allows remote atta…Mar 26, 2009›
CVE-2013-4943HIGH
7.2
The client application in Siemens COMOS before 9.1 Update 458, 9.2 before 9.2.0.6.37, and 10.0 befor…Aug 9, 2013›
CVE-2003-1528HIGH
7.2
nsr_shutdown in Fujitsu Siemens NetWorker 6.0 allows local users to overwrite arbitrary files via a …Dec 31, 2003›
CVE-2014-5074HIGH
7.1
Siemens SIMATIC S7-1500 CPU devices with firmware before 1.6 allow remote attackers to cause a denia…Aug 17, 2014›
CVE-2011-4877HIGH
7.1
HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka T…Feb 3, 2012›
CVE-2019-11486HIGH
7.0
The Siemens R3964 line discipline driver in drivers/tty/n_r3964.c in the Linux kernel before 5.0.8 h…Apr 23, 2019›
CVE-2015-1594MEDIUM
6.9
Untrusted search path vulnerability in Siemens SIMATIC ProSave before 13 SP1; SIMATIC CFC before 8.0…Mar 7, 2015›
CVE-2013-6840MEDIUM
6.9
Siemens COMOS before 9.2.0.8.1, 10.0 before 10.0.3.1.40, and 10.1 before 10.1.0.0.2 allows local use…Dec 10, 2013›
CVE-2012-3015MEDIUM
6.9
Untrusted search path vulnerability in Siemens SIMATIC STEP7 before 5.5 SP1, as used in SIMATIC PCS7…Jul 26, 2012›
CVE-2015-2823MEDIUM
6.8
Siemens SIMATIC HMI Basic Panels 2nd Generation before WinCC (TIA Portal) 13 SP1 Upd2, SIMATIC HMI C…Apr 8, 2015›
CVE-2015-1601MEDIUM
6.8
Siemens SIMATIC STEP 7 (TIA Portal) 12 and 13 before 13 SP1 Upd1 allows man-in-the-middle attackers …Apr 6, 2015›
CVE-2015-1597MEDIUM
6.8
The Siemens SPCanywhere application for Android does not use encryption during the loading of code, …Mar 7, 2015›
CVE-2015-1049MEDIUM
6.8
The web server on Siemens SCALANCE X-200IRT switches with firmware before 5.2.0 allows remote attack…Feb 2, 2015›
CVE-2014-8479MEDIUM
6.8
The FTP server on Siemens SCALANCE X-300 switches with firmware before 4.0 and SCALANCE X 408 switch…Jan 21, 2015›
CVE-2014-4686MEDIUM
6.8
The Project administration application in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and othe…Jul 24, 2014›
CVE-2013-4911MEDIUM
6.8
Cross-site request forgery (CSRF) vulnerability in Siemens WinCC (TIA Portal) 11 and 12 before 12 SP…Aug 1, 2013›
CVE-2013-0674MEDIUM
6.8
Buffer overflow in the RegReader ActiveX control in Siemens WinCC before 7.2, as used in SIMATIC PCS…Mar 21, 2013›
CVE-2013-0656MEDIUM
6.8
Buffer overflow in a third-party ActiveX component in Siemens SIMATIC RF-MANAGER 2008, and RF-MANAGE…Jan 21, 2013›
CVE-2012-3028MEDIUM
6.8
Cross-site request forgery (CSRF) vulnerability in WebNavigator in Siemens WinCC 7.0 SP3 and earlier…Sep 18, 2012›
CVE-2025-30000MEDIUM
6.7
A vulnerability has been identified in Siemens License Server (SLS) (All versions < V4.3). The affec…Apr 8, 2025›
CVE-2025-29999MEDIUM
6.7
A vulnerability has been identified in Siemens License Server (SLS) (All versions < V4.3). The affec…Apr 8, 2025›
CVE-2018-4844MEDIUM
6.7
A vulnerability has been identified in SIMATIC WinCC OA UI for Android (All versions < V3.15.10), SI…Mar 20, 2018›
CVE-2016-5848MEDIUM
6.7
Siemens SICAM PAS before 8.07 does not properly restrict password data in the database, which makes …Jul 4, 2016›
CVE-2013-4651MEDIUM
6.6
Siemens Scalance W7xx devices with firmware before 4.5.4 use the same hardcoded X.509 certificate ac…Aug 1, 2013›
CVE-2017-9945MEDIUM
6.5
In the Siemens 7KM PAC Switched Ethernet PROFINET expansion module (All versions < V2.1.3), a Denial…Aug 30, 2017›
CVE-2017-6872MEDIUM
6.5
A vulnerability was discovered in Siemens OZW672 (all versions) and OZW772 (all versions) that could…Aug 8, 2017›
CVE-2017-6866MEDIUM
6.5
A vulnerability was discovered in Siemens XHQ server 4 and 5 (4 before V4.7.1.3 and 5 before V5.0.0.…Aug 7, 2017›
CVE-2017-2686MEDIUM
6.5
Siemens RUGGEDCOM ROX I (all versions) contain a vulnerability that could allow an authenticated use…Mar 29, 2017›
CVE-2016-8564MEDIUM
6.5
SQL injection vulnerability in Siemens Automation License Manager (ALM) before 5.3 SP3 Update 1 allo…Oct 13, 2016›
CVE-2016-2846MEDIUM
6.5
Siemens SIMATIC S7-1200 CPU devices before 4.0 allow remote attackers to bypass a "user program bloc…Mar 16, 2016›
CVE-2008-3126MEDIUM
6.5
Multiple stack-based buffer overflows in the ServerView web interface (SnmpGetMibValues.exe) in Fuji…Jul 10, 2008›
CVE-2020-7579MEDIUM
6.1
A vulnerability has been identified in Spectrum Power™ 5 (All versions < v5.50 HF02). The web server…Mar 10, 2020›
CVE-2018-11450MEDIUM
6.1
A reflected Cross-Site-Scripting (XSS) vulnerability has been identified in Siemens PLM Software TEA…Jul 9, 2018›
CVE-2017-12738MEDIUM
6.1
An issue was discovered on Siemens SICAM RTUs SM-2556 COM Modules with the firmware variants ENOS00,…Nov 15, 2017›
CVE-2017-2687MEDIUM
6.1
Siemens RUGGEDCOM ROX I (all versions) contain a vulnerability in the integrated web server at port …Mar 29, 2017›
CVE-2016-6204MEDIUM
6.1
Cross-site scripting (XSS) vulnerability in the integrated web server in Siemens SINEMA Remote Conne…Jul 22, 2016›
CVE-2016-1488MEDIUM
6.1
Cross-site scripting (XSS) vulnerability in the login form in the integrated web server on Siemens O…Jan 30, 2016›
CVE-2014-2252MEDIUM
6.1
Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 allow remote attackers to cause a d…Mar 24, 2014›
CVE-2014-2253MEDIUM
6.1
Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allow remote attackers to cause a…Mar 16, 2014›
CVE-2013-0675MEDIUM
6.1
Buffer overflow in CCEServer (aka the central communications component) in Siemens WinCC before 7.2,…Mar 21, 2013›
CVE-2012-1800MEDIUM
6.1
Stack-based buffer overflow in the Profinet DCP protocol implementation on the Siemens Scalance S Se…Apr 18, 2012›
CVE-2014-4684MEDIUM
6.0
The database server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows …Jul 24, 2014›
CVE-2017-12740MEDIUM
5.9
Siemens LOGO! Soft Comfort (All versions before V8.2) lacks integrity verification of software packa…Dec 26, 2017›
CVE-2015-5717MEDIUM
5.8
The Siemens COMPAS Mobile application before 1.6 for Android does not properly verify X.509 certific…Aug 31, 2015›
CVE-2015-1596MEDIUM
5.8
The Siemens SPCanywhere application for Android and iOS does not properly verify X.509 certificates …Mar 7, 2015›
CVE-2014-2909MEDIUM
5.8
CRLF injection vulnerability in the integrated web server on Siemens SIMATIC S7-1200 CPU devices 2.x…Apr 25, 2014›
CVE-2014-2249MEDIUM
5.8
Cross-site request forgery (CSRF) vulnerability on Siemens SIMATIC S7-1500 CPU PLC devices with firm…Mar 16, 2014›
CVE-2014-2247MEDIUM
5.8
The integrated web server on Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allo…Mar 16, 2014›
CVE-2013-4912MEDIUM
5.8
Open redirect vulnerability in Siemens WinCC (TIA Portal) 11 and 12 before 12 SP1 allows remote atta…Aug 1, 2013›
CVE-2013-0677MEDIUM
5.8
The web server in Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other product…Mar 21, 2013›
CVE-2012-3003MEDIUM
5.8
Open redirect vulnerability in an unspecified web application in Siemens WinCC 7.0 SP3 before Update…Jun 8, 2012›
CVE-2011-4056MEDIUM
5.8
An unspecified ActiveX control in ActBar.ocx in Siemens Tecnomatix FactoryLink 6.6.1 (aka 6.6 SP1), …Jan 8, 2012›
CVE-2012-2596MEDIUM
5.5
The XPath functionality in unspecified web applications in Siemens WinCC 7.0 SP3 before Update 2 doe…Jun 8, 2012›
CVE-2017-6871MEDIUM
5.4
A vulnerability was discovered in Siemens SIMATIC WinCC Sm@rtClient for Android (All versions before…Aug 8, 2017›
CVE-2017-6864MEDIUM
5.4
The integrated web server in Siemens RUGGEDCOM ROX I (all versions) at port 10000/TCP could allow an…Mar 29, 2017›
CVE-2015-3610MEDIUM
5.4
The Siemens HomeControl for Room Automation application before 2.0.1 for Android does not verify X.5…May 7, 2015›
CVE-2023-52891MEDIUM
5.3
A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.5), SIMATIC E…Jul 9, 2024›
CVE-2017-12737MEDIUM
5.3
An issue was discovered on Siemens SICAM RTUs SM-2556 COM Modules with the firmware variants ENOS00,…Nov 15, 2017›
CVE-2017-9947MEDIUM
5.3
A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers…Oct 23, 2017›
CVE-2016-3963MEDIUM
5.3
Siemens SCALANCE S613 allows remote attackers to cause a denial of service (web-server outage) via t…Apr 8, 2016›
CVE-2016-2201MEDIUM
5.3
Siemens SIMATIC S7-1500 CPU devices before 1.8.3 allow remote attackers to bypass a replay protectio…Feb 8, 2016›
CVE-2015-1358MEDIUM
5.0
The remote-management module in the (1) Multi Panels, (2) Comfort Panels, and (3) RT Advanced functi…Feb 18, 2015›
CVE-2015-1357MEDIUM
5.0
Siemens Ruggedcom WIN51xx devices with firmware before SS4.4.4624.35, WIN52xx devices with firmware …Feb 2, 2015›
CVE-2014-8552MEDIUM
5.0
The WinCC server in Siemens SIMATIC WinCC 7.0 through SP3, 7.2 before Update 9, and 7.3 before Updat…Nov 26, 2014›
CVE-2014-4682MEDIUM
5.0
The WebNavigator server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, all…Jul 24, 2014›
CVE-2014-2733MEDIUM
5.0
Siemens SINEMA Server before 12 SP1 allows remote attackers to cause a denial of service (web-interf…Apr 19, 2014›
CVE-2014-2732MEDIUM
5.0
Multiple directory traversal vulnerabilities in the integrated web server in Siemens SINEMA Server b…Apr 19, 2014›
CVE-2014-2590MEDIUM
5.0
The web management interface in Siemens RuggedCom ROS before 3.11, ROS 3.11 before 3.11.5 for RS950G…Apr 1, 2014›
CVE-2014-1699MEDIUM
5.0
Siemens SIMATIC WinCC OA before 3.12 P002 January allows remote attackers to cause a denial of servi…Feb 7, 2014›
CVE-2014-1698MEDIUM
5.0
Directory traversal vulnerability in Siemens SIMATIC WinCC OA before 3.12 P002 January allows remote…Feb 7, 2014›
CVE-2014-1696MEDIUM
5.0
Siemens SIMATIC WinCC OA before 3.12 P002 January uses a weak hash algorithm for passwords, which ma…Feb 7, 2014›
CVE-2012-3030MEDIUM
5.0
WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, store…Sep 18, 2012›
CVE-2011-4512MEDIUM
5.0
CRLF injection vulnerability in the HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2…Feb 3, 2012›
CVE-2011-4532MEDIUM
5.0
Absolute path traversal vulnerability in the ALMListView.ALMListCtrl ActiveX control in almaxcx.dll …Jan 8, 2012›
CVE-2011-4531MEDIUM
5.0
Siemens Automation License Manager (ALM) 4.0 through 5.1+SP1+Upd1 allows remote attackers to cause a…Jan 8, 2012›
CVE-2011-4530MEDIUM
5.0
Siemens Automation License Manager (ALM) 4.0 through 5.1+SP1+Upd1 does not properly copy fields obta…Jan 8, 2012›
CVE-2006-3907MEDIUM
5.0
Siemens SpeedStream 2624 allows remote attackers to cause a denial of service (device hang) by sendi…Jul 27, 2006›
CVE-2002-0122MEDIUM
5.0
Siemens 3568i WAP mobile phones allows remote attackers to cause a denial of service (crash) via an …Mar 25, 2002›
CVE-2014-9563MEDIUM
4.9
CRLF injection vulnerability in the web-based management (WBM) interface in Unify (former Siemens) O…Apr 12, 2018›
CVE-2017-14023MEDIUM
4.9
An Improper Input Validation issue was discovered in Siemens SIMATIC PCS 7 V8.1 prior to V8.1 SP1 wi…Nov 6, 2017›
CVE-2017-6867MEDIUM
4.9
A vulnerability was discovered in Siemens SIMATIC WinCC (V7.3 before Upd 11 and V7.4 before SP1), SI…May 11, 2017›
CVE-2014-4683MEDIUM
4.9
The WebNavigator server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, all…Jul 24, 2014›
CVE-2008-2235MEDIUM
4.9
OpenSC before 0.11.5 uses weak permissions (ADMIN file control information of 00) for the 5015 direc…Aug 1, 2008›
CVE-2016-7959MEDIUM
4.7
Siemens SIMATIC STEP 7 (TIA Portal) before 14 improperly stores pre-shared key data in TIA project f…Oct 13, 2016›
CVE-2018-4847MEDIUM
4.6
A vulnerability has been identified in SIMATIC WinCC OA Operator iOS App (All versions < V1.4). Insu…Apr 23, 2018›
CVE-2014-4685MEDIUM
4.6
Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows local users to gain pri…Jul 24, 2014›
CVE-2013-3927MEDIUM
4.6
Unspecified vulnerability in the client library in Siemens COMOS 9.2 before 9.2.0.6.10 and 10.0 befo…Jun 18, 2013›
CVE-2011-4515MEDIUM
4.6
Siemens WinCC (TIA Portal) 11 uses a reversible algorithm for storing HMI web-application passwords …Mar 21, 2013›
CVE-2015-1356MEDIUM
4.4
Siemens SIMATIC STEP 7 (TIA Portal) before 13 SP1 determines a user's privileges on the basis of pro…Feb 18, 2015›
CVE-2015-6929MEDIUM
4.3
Multiple cross-site scripting (XSS) vulnerabilities in Nokia Networks (formerly Nokia Solutions and …Sep 16, 2015›
CVE-2015-6675MEDIUM
4.3
Siemens RUGGEDCOM ROS 3.8.0 through 4.1.x permanently enables the IP forwarding feature, which allow…Sep 11, 2015›
CVE-2015-5537MEDIUM
4.3
The SSL layer of the HTTPS service in Siemens RuggedCom ROS before 4.2.0 and ROX II does not properl…Aug 3, 2015›
CVE-2015-4174MEDIUM
4.3
Cross-site scripting (XSS) vulnerability in the integrated web server on the Siemens Climatix BACnet…Jun 28, 2015›
CVE-2015-2822MEDIUM
4.3
Siemens SIMATIC HMI Comfort Panels before WinCC (TIA Portal) 13 SP1 Upd2 and SIMATIC WinCC Runtime A…Apr 8, 2015›
CVE-2015-1595MEDIUM
4.3
The Siemens SPCanywhere application for Android and iOS does not use encryption during lookups of sy…Mar 7, 2015›
CVE-2015-1048MEDIUM
4.3
Open redirect vulnerability in the integrated web server on Siemens SIMATIC S7-1200 CPU devices with…Jan 21, 2015›
CVE-2014-2908MEDIUM
4.3
Cross-site scripting (XSS) vulnerability in the integrated web server on Siemens SIMATIC S7-1200 CPU…Apr 25, 2014›
CVE-2014-2248MEDIUM
4.3
Open redirect vulnerability in the integrated web server on Siemens SIMATIC S7-1500 CPU PLC devices …Mar 16, 2014›
CVE-2014-2246MEDIUM
4.3
Cross-site scripting (XSS) vulnerability in the integrated web server on Siemens SIMATIC S7-1500 CPU…Mar 16, 2014›
CVE-2013-4779MEDIUM
4.3
Cross-site scripting (XSS) vulnerability in core/handleTw.php on the Siemens Enterprise OpenScape Br…Jul 18, 2013›
CVE-2013-0670MEDIUM
4.3
CRLF injection vulnerability in the HMI web application in Siemens WinCC (TIA Portal) 11 allows remo…Mar 21, 2013›
CVE-2013-0668MEDIUM
4.3
Multiple cross-site scripting (XSS) vulnerabilities in the HMI web application in Siemens WinCC (TIA…Mar 21, 2013›
CVE-2013-0667MEDIUM
4.3
Cross-site scripting (XSS) vulnerability in the HMI web application in Siemens WinCC (TIA Portal) 11…Mar 21, 2013›
CVE-2012-4698MEDIUM
4.3
Siemens RuggedCom Rugged Operating System (ROS) before 3.12, ROX I OS through 1.14.5, ROX II OS thro…Dec 23, 2012›
CVE-2012-3040MEDIUM
4.3
Cross-site scripting (XSS) vulnerability in the web server on Siemens SIMATIC S7-1200 PLCs 2.x throu…Oct 10, 2012›
CVE-2012-3037MEDIUM
4.3
The Siemens SIMATIC S7-1200 2.x PLC does not properly protect the private key of the SIMATIC CONTROL…Sep 25, 2012›
CVE-2012-3034MEDIUM
4.3
WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allow…Sep 18, 2012›
CVE-2012-3031MEDIUM
4.3
Multiple cross-site scripting (XSS) vulnerabilities in WebNavigator in Siemens WinCC 7.0 SP3 and ear…Sep 18, 2012›
CVE-2012-2598MEDIUM
4.3
Buffer overflow in the DiagAgent web server in Siemens WinCC 7.0 SP3 through Update 2 allows remote …Jun 8, 2012›
CVE-2012-2595MEDIUM
4.3
Multiple cross-site scripting (XSS) vulnerabilities in unspecified web applications in Siemens WinCC…Jun 8, 2012›
CVE-2011-4511MEDIUM
4.3
Cross-site scripting (XSS) vulnerability in the HMI web server in Siemens WinCC flexible 2004, 2005,…Feb 3, 2012›
CVE-2011-4510MEDIUM
4.3
Cross-site scripting (XSS) vulnerability in the HMI web server in Siemens WinCC flexible 2004, 2005,…Feb 3, 2012›
CVE-2007-4488MEDIUM
4.3
Multiple cross-site scripting (XSS) vulnerabilities in the Siemens Gigaset SE361 WLAN router with fi…Aug 22, 2007›
CVE-2016-7090MEDIUM
4.0
The integrated web server on Siemens SCALANCE M-800 and S615 modules with firmware before 4.02 does …Sep 29, 2016›
CVE-2013-3959MEDIUM
4.0
The Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMATIC PCS7 8.0 SP1 and earlier …Jun 14, 2013›
CVE-2013-0679MEDIUM
4.0
Directory traversal vulnerability in the web server in Siemens WinCC before 7.2, as used in SIMATIC …Mar 21, 2013›
CVE-2013-0678MEDIUM
4.0
Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, does not proper…Mar 21, 2013›
CVE-2013-0676MEDIUM
4.0
Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, does not proper…Mar 21, 2013›
CVE-2013-0671MEDIUM
4.0
Directory traversal vulnerability in Siemens WinCC (TIA Portal) 11 allows remote authenticated users…Mar 21, 2013›
CVE-2013-0669MEDIUM
4.0
The HMI web application in Siemens WinCC (TIA Portal) 11 allows remote authenticated users to cause …Mar 21, 2013›
CVE-2012-2597MEDIUM
4.0
Multiple directory traversal vulnerabilities in Siemens WinCC 7.0 SP3 before Update 2 allow remote a…Jun 8, 2012›
CVE-2004-2626LOW
3.7
GUI overlay vulnerability in the Java API in Siemens S55 cellular phones allows remote attackers to …Dec 31, 2004›
CVE-2019-13936LOW
3.5
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i…Nov 27, 2019›
CVE-2019-13935LOW
3.5
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i…Nov 27, 2019›
CVE-2019-13934LOW
3.5
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i…Nov 27, 2019›
CVE-2013-0672LOW
3.5
Cross-site scripting (XSS) vulnerability in the HMI web application in Siemens WinCC (TIA Portal) 11…Mar 21, 2013›
CVE-2016-3155LOW
3.4
Siemens APOGEE Insight uses weak permissions for the application folder, which allows local users to…Mar 18, 2016›
CVE-2015-7836LOW
3.3
Siemens RUGGEDCOM ROS before 4.2.1 allows remote attackers to obtain sensitive information by sniffi…Oct 28, 2015›
CVE-2012-4691LOW
3.3
Memory leak in Siemens Automation License Manager (ALM) 4.x and 5.x before 5.2 allows remote attacke…Dec 18, 2012›
CVE-2016-7960LOW
2.5
Siemens SIMATIC STEP 7 (TIA Portal) before 14 uses an improper format for managing TIA project files…Oct 13, 2016›
CVE-2016-5849LOW
2.5
Siemens SICAM PAS through 8.07 allows local users to obtain sensitive configuration information by l…Jul 4, 2016›
CVE-2015-5084LOW
2.1
The Siemens SIMATIC WinCC Sm@rtClient and Sm@rtClient Lite applications before 01.00.01.00 for Andro…Aug 3, 2015›
CVE-2015-1602LOW
2.1
Siemens SIMATIC STEP 7 (TIA Portal) 12 and 13 before 13 SP1 Upd1 improperly stores password data wit…Apr 6, 2015›
CVE-2015-1599LOW
2.1
The Siemens SPCanywhere application for iOS allows physically proximate attackers to bypass intended…Mar 7, 2015›
CVE-2015-1598LOW
2.1
The Siemens SPCanywhere application for Android does not properly store application passwords, which…Mar 7, 2015›
CVE-2015-1355LOW
2.1
Siemens SIMATIC STEP 7 (TIA Portal) before 13 SP1 uses a weak password-hash algorithm, which makes i…Feb 18, 2015›
CVE-2014-5231LOW
2.1
The Siemens SIMATIC WinCC Sm@rtClient app before 1.0.2 for iOS allows physically proximate attackers…Jan 14, 2015›
CVE-2014-5233LOW
1.9
The Siemens SIMATIC WinCC Sm@rtClient app before 1.0.2 for iOS allows physically proximate attackers…Jan 14, 2015›
CVE-2014-5232LOW
1.9
The Siemens SIMATIC WinCC Sm@rtClient app before 1.0.2 for iOS allows local users to bypass an inten…Jan 14, 2015›
CVE-2012-4693LOW
1.9
Invensys Wonderware InTouch 2012 R2 and earlier and Siemens ProcessSuite use a weak encryption algor…Dec 18, 2012›