Vulnerability index

Browse CVEs

1,648 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sipass Integrated HIGH 8.1
CVE-2017-9940

A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with access to a low-privileged …

Fix: after 2.65
Fix from $1,950 2017-08-08
Sipass Integrated HIGH 7.8
CVE-2017-9942

A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with local access to the SiPass …

Fix: after 2.65
Fix from $1,950 2017-08-08
Simatic Logon HIGH 7.5
CVE-2017-9938

A vulnerability was discovered in Siemens SIMATIC Logon (All versions before V1.6) that could allow specially crafted packets sent to the SIMATIC Log…

Fix: after 1.5
Fix from $1,950 2017-08-08
Simatic Wincc Sm\@rtclient HIGH 7.4
CVE-2017-6870

A vulnerability was discovered in Siemens SIMATIC WinCC Sm@rtClient for Android (All versions before V1.0.2.2). The existing TLS protocol implementat…

Fix: after 1.0.2.1
Fix from $1,950 2017-08-08
Ozw772 Firmware HIGH 7.4
CVE-2017-6873

A vulnerability was discovered in Siemens OZW672 (all versions) and OZW772 (all versions) that could allow an attacker to read and manipulate data in…

Mitigation only
Fix from $1,950 2017-08-08
Sipass Integrated HIGH 7.4
CVE-2017-9941

A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker in a Man-in-the-Middle position …

Fix: after 2.65
Fix from $1,950 2017-08-08
Ozw772 Firmware MEDIUM 6.5
CVE-2017-6872

A vulnerability was discovered in Siemens OZW672 (all versions) and OZW772 (all versions) that could allow an attacker with access to port 21/tcp to …

Mitigation only
Fix from $1,600 2017-08-08
Simatic Wincc Sm\@rtclient MEDIUM 5.4
CVE-2017-6871

A vulnerability was discovered in Siemens SIMATIC WinCC Sm@rtClient for Android (All versions before V1.0.2.2) and SIMATIC WinCC Sm@rtClient for Andr…

Fix: after 1.0.2.1
Fix from $1,600 2017-08-08
Xhq Server MEDIUM 6.5
CVE-2017-6866

A vulnerability was discovered in Siemens XHQ server 4 and 5 (4 before V4.7.1.3 and 5 before V5.0.0.2) that could allow an authenticated low-privileg…

Fix: after 5.0.0.1
Fix from $1,600 2017-08-07
Simatic Cp 44x 1 Redundant Network Access Modules HIGH 8.1
CVE-2017-6868

An Improper Authentication issue was discovered in Siemens SIMATIC CP 44x-1 RNA, all versions prior to 1.4.1. An unauthenticated remote attacker may …

Fix: after 1.4.0
Fix from $1,950 2017-07-07
Simatic Cp 343 1 Std Firmware MEDIUM 6.5
CVE-2017-2681

Specially crafted PROFINET DCP packets sent on a local Ethernet segment (Layer 2) to an affected product could cause a denial of service condition of…

Fix: 2.0 / 2.1.82+
Fix from $1,600 2017-05-11
Pcs 7 MEDIUM 6.5
CVE-2017-6865

A vulnerability has been identified in Primary Setup Tool (PST) (All versions < V4.2 HF1), SIMATIC Automation Tool (All versions < V3.0), SIMATIC NET…

Mitigation only
Fix from $1,600 2017-05-11
Simatic Cp 343 1 Std Firmware MEDIUM 6.5
CVE-2017-2680

Specially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affected products on a local Ethernet segment (Layer 2)…

Fix: 2.0 / 2.1.82+
Fix from $1,600 2017-05-11
Ruggedcom Rox I MEDIUM 5.4
CVE-2017-6864

The integrated web server in Siemens RUGGEDCOM ROX I (all versions) at port 10000/TCP could allow an authenticated user to perform stored Cross-Site …

Fix: after 2.9.0
Fix from $1,600 2017-03-29
Ruggedcom Rox I HIGH 8.8
CVE-2017-2688

The integrated web server in Siemens RUGGEDCOM ROX I (all versions) at port 10000/TCP could allow remote attackers to perform actions with the privil…

Fix: after 2.9.0
Fix from $1,950 2017-03-29
Ruggedcom Rox I HIGH 8.8
CVE-2017-2689

Siemens RUGGEDCOM ROX I (all versions) allow an authenticated user to bypass access restrictions in the web interface at port 10000/TCP to obtain pri…

Fix: after 2.9.0
Fix from $1,950 2017-03-29
Ruggedcom Rox I MEDIUM 6.5
CVE-2017-2686

Siemens RUGGEDCOM ROX I (all versions) contain a vulnerability that could allow an authenticated user to read arbitrary files through the web interfa…

Fix: after 2.9.0
Fix from $1,600 2017-03-29
Ruggedcom Rox I MEDIUM 6.1
CVE-2017-2687

Siemens RUGGEDCOM ROX I (all versions) contain a vulnerability in the integrated web server at port 10000/TCP which is prone to reflected Cross-Site …

Fix: after 2.9.0
Fix from $1,600 2017-03-29
Sinumerik Integrate Access Mymachine\/ethernet HIGH 7.4
CVE-2017-2685

Siemens SINUMERIK Integrate Operate Clients between 2.0.3.00.016 (including) and 2.0.6 (excluding) and between 3.0.4.00.032 (including) and 3.0.6 (ex…

Mitigation only
Fix from $1,950 2017-03-01
Ruggedcom Network Management Software HIGH 8.8
CVE-2017-2682

The Siemens web application RUGGEDCOM NMS < V1.2 on port 8080/TCP and 8081/TCP could allow a remote attacker to perform a Cross-Site Request Forgery …

Fix: after 2.0.2
Fix from $1,950 2017-02-27
Ruggedcom Network Management Software HIGH 8.2
CVE-2017-2683

A non-privileged user of the Siemens web application RUGGEDCOM NMS < V1.2 on port 8080/TCP and 8081/TCP could perform a persistent Cross-Site Scripti…

Fix: after 2.0.2
Fix from $1,950 2017-02-27
Simatic Logon CRITICAL 9.0
CVE-2017-2684

Siemens SIMATIC Logon prior to V1.5 SP3 Update 2 could allow an attacker with knowledge of a valid user name, and physical or network access to the a…

Fix: after 1.5
Fix from $2,300 2017-02-22
Sicam Pas\/pqs CRITICAL 9.8
CVE-2016-8567

An issue was discovered in Siemens SICAM PAS before 8.00. A factory account with hard-coded passwords is present in the SICAM PAS installations. Atta…

Fix: 8.00+
Fix from $2,300 2017-02-13
Sicam Pas\/pqs HIGH 7.8
CVE-2016-8566

An issue was discovered in Siemens SICAM PAS before 8.00. Because of Storing Passwords in a Recoverable Format, an authenticated local attacker with …

Fix: 8.00+
Fix from $1,950 2017-02-13
Eta4 Firmware HIGH 7.5
CVE-2016-7987

An issue was discovered in Siemens ETA4 firmware (all versions prior to Revision 08) of the SM-2558 extension module for: SICAM AK, SICAM TM 1703, SI…

Fix: after 11.0
Fix from $1,950 2017-02-13
Desigo Web Module Pxa30 W0 Firmware HIGH 7.5
CVE-2016-9154

Siemens Desigo PX Web modules PXA40-W0, PXA40-W1, PXA40-W2 for Desigo PX automation controllers PXC00-E.D, PXC50-E.D, PXC100-E.D, PXC200-E.D (All fir…

Fix: after 6.00.00
Fix from $1,950 2016-12-23
Simatic Pcs 7 HIGH 8.1
CVE-2016-9160

A vulnerability in SIEMENS SIMATIC WinCC (All versions < SIMATIC WinCC V7.2) and SIEMENS SIMATIC PCS 7 (All versions < SIMATIC PCS 7 V8.0 SP1) could …

Fix: after 8.0
Fix from $1,950 2016-12-17
Simatic S7 300 Cpu Firmware HIGH 7.5
CVE-2016-9158

A vulnerability has been identified in SIMATIC S7-300 CPU family (All versions), SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS varia…

Mitigation only
Fix from $1,950 2016-12-17
Simatic S7 300 Cpu Firmware MEDIUM 5.9
CVE-2016-9159

A vulnerability has been identified in SIMATIC S7-300 CPU family (All versions), SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS varia…

Mitigation only
Fix from $1,600 2016-12-17
Sicam Pas\/pqs CRITICAL 9.8
CVE-2016-9157

A vulnerability in Siemens SICAM PAS (all versions before V8.09) could allow a remote attacker to cause a Denial of Service condition and potentially…

Fix: 8.09+
Fix from $2,300 2016-12-05