AID
Automation
Information Directory
HomeCVE FeedBrands
AID
Automation Information Directory
CVE data sourced from NIST NVD · Documentation links from official sources
Home›Brands›Siemens
SI
Platform

Siemens

Leading provider of industrial automation, digitalization, and smart infrastructure. Products include SIMATIC PLCs, SINAMICS drives, TIA Portal, and WinCC SCADA.

https://www.siemens.com/global/en/markets/machinebuilding/automation.html →
259
Total CVEs
12
Resources
13
CRIT
112
HIGH
115
MED
19
LOW
CVEsCVEsSpecsTech SpecsDocsTech DocsImplImplementationsExamplesExamples
19 / 259
CVE-2004-2626LOW

GUI overlay vulnerability in the Java API in Siemens S55 cellular phones allows remote attackers to send unauthorized SMS messages by overlaying a confirmation message with a malicious message.

Dec 31, 2004
3.7
CVE-2019-13936LOW

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webclient of Siemens AG Polarion could allow an attacker to exploit a persistent XSS vulnerability. This issue affects: Siemens AG Polarion All versions < 19.2.

Nov 27, 2019
3.5
CVE-2019-13935LOW

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webclient of Siemens AG Polarion could allow an attacker to exploit a reflected XSS vulnerability. This issue affects: Siemens AG Polarion All versions < 19.2.

Nov 27, 2019
3.5
CVE-2019-13934LOW

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webclient of Siemens AG Polarion could allow an attacker to exploit a reflected XSS vulnerability. This issue affects: Siemens AG Polarion All versions < 19.2.

Nov 27, 2019
3.5
CVE-2013-0672LOW

Cross-site scripting (XSS) vulnerability in the HMI web application in Siemens WinCC (TIA Portal) 11 allows remote authenticated users to inject arbitrary web script or HTML via unspecified data.

Mar 21, 2013
3.5
CVE-2016-3155LOW

Siemens APOGEE Insight uses weak permissions for the application folder, which allows local users to obtain sensitive information or modify data via unspecified vectors.

Mar 18, 2016
3.4
CVE-2015-7836LOW

Siemens RUGGEDCOM ROS before 4.2.1 allows remote attackers to obtain sensitive information by sniffing the network for VLAN data within the padding section of an Ethernet frame.

Oct 28, 2015
3.3
CVE-2012-4691LOW

Memory leak in Siemens Automation License Manager (ALM) 4.x and 5.x before 5.2 allows remote attackers to cause a denial of service (memory consumption) via crafted packets.

Dec 18, 2012
3.3
CVE-2016-7960LOW

Siemens SIMATIC STEP 7 (TIA Portal) before 14 uses an improper format for managing TIA project files during version updates, which makes it easier for local users to obtain sensitive configuration information via unspecified vectors.

Oct 13, 2016
2.5
CVE-2016-5849LOW

Siemens SICAM PAS through 8.07 allows local users to obtain sensitive configuration information by leveraging database stoppage.

Jul 4, 2016
2.5
CVE-2015-5084LOW

The Siemens SIMATIC WinCC Sm@rtClient and Sm@rtClient Lite applications before 01.00.01.00 for Android do not properly store passwords, which allows physically proximate attackers to obtain sensitive information via unspecified vectors.

Aug 3, 2015
2.1
CVE-2015-1602LOW

Siemens SIMATIC STEP 7 (TIA Portal) 12 and 13 before 13 SP1 Upd1 improperly stores password data within project files, which makes it easier for local users to determine cleartext (1) protection-level passwords or (2) web-server passwords by leveraging the ability to read these files.

Apr 6, 2015
2.1
CVE-2015-1599LOW

The Siemens SPCanywhere application for iOS allows physically proximate attackers to bypass intended access restrictions by leveraging a filesystem architectural error.

Mar 7, 2015
2.1
CVE-2015-1598LOW

The Siemens SPCanywhere application for Android does not properly store application passwords, which allows physically proximate attackers to obtain sensitive information by examining the device filesystem.

Mar 7, 2015
2.1
CVE-2015-1355LOW

Siemens SIMATIC STEP 7 (TIA Portal) before 13 SP1 uses a weak password-hash algorithm, which makes it easier for local users to determine cleartext passwords by reading a project file and conducting a brute-force attack.

Feb 18, 2015
2.1
CVE-2014-5231LOW

The Siemens SIMATIC WinCC Sm@rtClient app before 1.0.2 for iOS allows physically proximate attackers to extract the password from storage via unspecified vectors.

Jan 14, 2015
2.1
CVE-2014-5233LOW

The Siemens SIMATIC WinCC Sm@rtClient app before 1.0.2 for iOS allows physically proximate attackers to discover Sm@rtServer credentials by leveraging an error in the credential-processing mechanism.

Jan 14, 2015
1.9
CVE-2014-5232LOW

The Siemens SIMATIC WinCC Sm@rtClient app before 1.0.2 for iOS allows local users to bypass an intended application-password requirement by leveraging the running of the app in the background state.

Jan 14, 2015
1.9
CVE-2012-4693LOW

Invensys Wonderware InTouch 2012 R2 and earlier and Siemens ProcessSuite use a weak encryption algorithm for data in Ps_security.ini, which makes it easier for local users to discover passwords by reading this file.

Dec 18, 2012
1.9
CVE ID ⇅Severity ↓CVSS ⇅DescriptionPublished ⇅
CVE-2004-2626LOW
3.7
GUI overlay vulnerability in the Java API in Siemens S55 cellular phones allows remote attackers to …Dec 31, 2004›
CVE-2019-13936LOW
3.5
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i…Nov 27, 2019›
CVE-2019-13935LOW
3.5
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i…Nov 27, 2019›
CVE-2019-13934LOW
3.5
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i…Nov 27, 2019›
CVE-2013-0672LOW
3.5
Cross-site scripting (XSS) vulnerability in the HMI web application in Siemens WinCC (TIA Portal) 11…Mar 21, 2013›
CVE-2016-3155LOW
3.4
Siemens APOGEE Insight uses weak permissions for the application folder, which allows local users to…Mar 18, 2016›
CVE-2015-7836LOW
3.3
Siemens RUGGEDCOM ROS before 4.2.1 allows remote attackers to obtain sensitive information by sniffi…Oct 28, 2015›
CVE-2012-4691LOW
3.3
Memory leak in Siemens Automation License Manager (ALM) 4.x and 5.x before 5.2 allows remote attacke…Dec 18, 2012›
CVE-2016-7960LOW
2.5
Siemens SIMATIC STEP 7 (TIA Portal) before 14 uses an improper format for managing TIA project files…Oct 13, 2016›
CVE-2016-5849LOW
2.5
Siemens SICAM PAS through 8.07 allows local users to obtain sensitive configuration information by l…Jul 4, 2016›
CVE-2015-5084LOW
2.1
The Siemens SIMATIC WinCC Sm@rtClient and Sm@rtClient Lite applications before 01.00.01.00 for Andro…Aug 3, 2015›
CVE-2015-1602LOW
2.1
Siemens SIMATIC STEP 7 (TIA Portal) 12 and 13 before 13 SP1 Upd1 improperly stores password data wit…Apr 6, 2015›
CVE-2015-1599LOW
2.1
The Siemens SPCanywhere application for iOS allows physically proximate attackers to bypass intended…Mar 7, 2015›
CVE-2015-1598LOW
2.1
The Siemens SPCanywhere application for Android does not properly store application passwords, which…Mar 7, 2015›
CVE-2015-1355LOW
2.1
Siemens SIMATIC STEP 7 (TIA Portal) before 13 SP1 uses a weak password-hash algorithm, which makes i…Feb 18, 2015›
CVE-2014-5231LOW
2.1
The Siemens SIMATIC WinCC Sm@rtClient app before 1.0.2 for iOS allows physically proximate attackers…Jan 14, 2015›
CVE-2014-5233LOW
1.9
The Siemens SIMATIC WinCC Sm@rtClient app before 1.0.2 for iOS allows physically proximate attackers…Jan 14, 2015›
CVE-2014-5232LOW
1.9
The Siemens SIMATIC WinCC Sm@rtClient app before 1.0.2 for iOS allows local users to bypass an inten…Jan 14, 2015›
CVE-2012-4693LOW
1.9
Invensys Wonderware InTouch 2012 R2 and earlier and Siemens ProcessSuite use a weak encryption algor…Dec 18, 2012›