AID
Automation
Information Directory
HomeCVE FeedBrands
AID
Automation Information Directory
CVE data sourced from NIST NVD · Documentation links from official sources
Home›Brands›Siemens
SI
Platform

Siemens

Leading provider of industrial automation, digitalization, and smart infrastructure. Products include SIMATIC PLCs, SINAMICS drives, TIA Portal, and WinCC SCADA.

https://www.siemens.com/global/en/markets/machinebuilding/automation.html →
259
Total CVEs
12
Resources
13
CRIT
112
HIGH
115
MED
19
LOW
CVEsCVEsSpecsTech SpecsDocsTech DocsImplImplementationsExamplesExamples
13 / 259
CVE-2019-10938CRITICAL

A vulnerability has been identified in SIPROTEC 5 devices with CPU variants CP200 (All versions < V7.59), SIPROTEC 5 devices with CPU variants CP300 and CP100 (All versions < V8.01), Siemens Power Meters Series 9410 (All versions < V2.2.1), Siemens Power Meters Series 9810 (All versions). An unauthenticated attacker with network access to the device could potentially insert arbitrary code which is executed before firmware verification in the device. At the time of advisory publication no public exploitation of this security vulnerability was known.

Aug 2, 2019
9.8
CVE-2018-4846CRITICAL

A vulnerability has been identified in RAPIDLab 1200 systems / RAPIDPoint 400 systems / RAPIDPoint 500 systems (All versions_without_ use of Siemens Healthineers Informatics products), RAPIDLab 1200 Series (All versions < V3.3 _with_ Siemens Healthineers Informatics products), RAPIDPoint 500 systems (All versions >= V3.0 _with_ Siemens Healthineers Informatics products), RAPIDPoint 500 systems (V2.4.X_with_ Siemens Healthineers Informatics products), RAPIDPoint 500 systems (All versions =< V2.3 _with_ Siemens Healthineers Informatics products), RAPIDPoint 400 systems (All versions _with_ Siemens Healthineers Informatics products). A factory account with hardcoded password might allow attackers access to the device over port 5900/tcp. Successful exploitation requires no user interaction or privileges and impacts the confidentiality, integrity, and availability of the affected device. At the time of advisory publication, no public exploitation of this security vulnerability is known. Siemens Healthineers confirms the security vulnerability and provides mitigations to resolve the security issue.

Jun 26, 2018
9.8
CVE-2018-4841CRITICAL

A vulnerability has been identified in TIM 1531 IRC (All versions < V1.1). A remote attacker with network access to port 80/tcp or port 443/tcp could perform administrative operations on the device without prior authentication. Successful exploitation could allow to cause a denial-of-service, or read and manipulate data as well as configuration settings of the affected device. At the stage of publishing this security advisory no public exploitation is known. Siemens provides mitigations to resolve it.

Mar 29, 2018
9.8
CVE-2017-9944CRITICAL

A vulnerability has been identified in Siemens 7KT PAC1200 data manager (7KT1260) in all versions < V2.03. The integrated web server (port 80/tcp) of the affected devices could allow an unauthenticated remote attacker to perform administrative operations over the network.

Dec 27, 2017
9.8
CVE-2017-12739CRITICAL

An issue was discovered on Siemens SICAM RTUs SM-2556 COM Modules with the firmware variants ENOS00, ERAC00, ETA2, ETLS00, MODi00, and DNPi00. The integrated web server (port 80/tcp) of the affected devices could allow unauthenticated remote attackers to execute arbitrary code on the affected device.

Nov 15, 2017
9.8
CVE-2017-9939CRITICAL

A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with network access to the SiPass integrated server to bypass the authentication mechanism and perform administrative operations.

Aug 8, 2017
9.8
CVE-2017-6869CRITICAL

A vulnerability was discovered in Siemens ViewPort for Web Office Portal before revision number 1453 that could allow an unauthenticated remote user to upload arbitrary code and execute it with the permissions of the operating-system user running the web server by sending specially crafted network packets to port 443/TCP or port 80/TCP.

Aug 8, 2017
9.8
CVE-2016-8567CRITICAL

An issue was discovered in Siemens SICAM PAS before 8.00. A factory account with hard-coded passwords is present in the SICAM PAS installations. Attackers might gain privileged access to the database over Port 2638/TCP.

Feb 13, 2017
9.8
CVE-2016-9157CRITICAL

A vulnerability in Siemens SICAM PAS (all versions before V8.09) could allow a remote attacker to cause a Denial of Service condition and potentially lead to unauthenticated remote code execution by sending specially crafted packets to port 19234/TCP.

Dec 5, 2016
9.8
CVE-2016-9155CRITICAL

The following SIEMENS branded IP Camera Models CCMW3025, CVMW3025-IR, CFMW3025 prior to version 1.41_SP18_S1; CCPW3025, CCPW5025 prior to version 0.1.73_S1; CCMD3025-DN18 prior to version v1.394_S1; CCID1445-DN18, CCID1445-DN28, CCID1145-DN36, CFIS1425, CCIS1425, CFMS2025, CCMS2025, CVMS2025-IR, CFMW1025, CCMW1025 prior to version v2635_SP1 could allow an attacker with network access to the web server to obtain administrative credentials under certain circumstances.

Nov 22, 2016
9.8
CVE-2016-5743CRITICAL

Siemens SIMATIC WinCC before 7.3 Update 10 and 7.4 before Update 1, SIMATIC BATCH before 8.1 SP1 Update 9 as distributed in SIMATIC PCS 7 through 8.1 SP1, SIMATIC OpenPCS 7 before 8.1 Update 3 as distributed in SIMATIC PCS 7 through 8.1 SP1, SIMATIC OpenPCS 7 before 8.2 Update 1 as distributed in SIMATIC PCS 7 8.2, and SIMATIC WinCC Runtime Professional before 13 SP1 Update 9 allow remote attackers to execute arbitrary code via crafted packets.

Jul 22, 2016
9.8
CVE-2016-8565CRITICAL

Siemens Automation License Manager (ALM) before 5.3 SP3 allows remote attackers to write to files, rename files, create directories, or delete directories via crafted packets.

Oct 13, 2016
9.1
CVE-2017-2684CRITICAL

Siemens SIMATIC Logon prior to V1.5 SP3 Update 2 could allow an attacker with knowledge of a valid user name, and physical or network access to the affected system, to bypass the application-level authentication.

Feb 22, 2017
9.0
CVE ID ⇅Severity ↓CVSS ⇅DescriptionPublished ⇅
CVE-2019-10938CRITICAL
9.8
A vulnerability has been identified in SIPROTEC 5 devices with CPU variants CP200 (All versions < V7…Aug 2, 2019›
CVE-2018-4846CRITICAL
9.8
A vulnerability has been identified in RAPIDLab 1200 systems / RAPIDPoint 400 systems / RAPIDPoint 5…Jun 26, 2018›
CVE-2018-4841CRITICAL
9.8
A vulnerability has been identified in TIM 1531 IRC (All versions < V1.1). A remote attacker with ne…Mar 29, 2018›
CVE-2017-9944CRITICAL
9.8
A vulnerability has been identified in Siemens 7KT PAC1200 data manager (7KT1260) in all versions < …Dec 27, 2017›
CVE-2017-12739CRITICAL
9.8
An issue was discovered on Siemens SICAM RTUs SM-2556 COM Modules with the firmware variants ENOS00,…Nov 15, 2017›
CVE-2017-9939CRITICAL
9.8
A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could a…Aug 8, 2017›
CVE-2017-6869CRITICAL
9.8
A vulnerability was discovered in Siemens ViewPort for Web Office Portal before revision number 1453…Aug 8, 2017›
CVE-2016-8567CRITICAL
9.8
An issue was discovered in Siemens SICAM PAS before 8.00. A factory account with hard-coded password…Feb 13, 2017›
CVE-2016-9157CRITICAL
9.8
A vulnerability in Siemens SICAM PAS (all versions before V8.09) could allow a remote attacker to ca…Dec 5, 2016›
CVE-2016-9155CRITICAL
9.8
The following SIEMENS branded IP Camera Models CCMW3025, CVMW3025-IR, CFMW3025 prior to version 1.41…Nov 22, 2016›
CVE-2016-5743CRITICAL
9.8
Siemens SIMATIC WinCC before 7.3 Update 10 and 7.4 before Update 1, SIMATIC BATCH before 8.1 SP1 Upd…Jul 22, 2016›
CVE-2016-8565CRITICAL
9.1
Siemens Automation License Manager (ALM) before 5.3 SP3 allows remote attackers to write to files, r…Oct 13, 2016›
CVE-2017-2684CRITICAL
9.0
Siemens SIMATIC Logon prior to V1.5 SP3 Update 2 could allow an attacker with knowledge of a valid u…Feb 22, 2017›