Vulnerability index

Browse CVEs

1,648 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Siprotec Firmware HIGH 7.8
CVE-2015-5374EPSS 74%

A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP …

Patch available
Fix from $1,950 2015-07-18
Sicam Mic Firmware HIGH 9.3
CVE-2015-5386

Siemens SICAM MIC devices with firmware before 2404 allow remote attackers to bypass authentication and obtain administrative access via unspecified …

Fix: after 2403
Fix from $1,950 2015-07-16
Homecontrol For Room Automation MEDIUM 5.4
CVE-2015-3610

The Siemens HomeControl for Room Automation application before 2.0.1 for Android does not verify X.509 certificates from SSL servers, which allows ma…

Fix: after 2.0.0
Fix from $1,600 2015-05-07
Wincc MEDIUM 6.8
CVE-2015-2823

Siemens SIMATIC HMI Basic Panels 2nd Generation before WinCC (TIA Portal) 13 SP1 Upd2, SIMATIC HMI Comfort Panels before WinCC (TIA Portal) 13 SP1 Up…

Fix: after 13.0
Fix from $1,600 2015-04-08
Simatic Step 7 MEDIUM 6.8
CVE-2015-1601

Siemens SIMATIC STEP 7 (TIA Portal) 12 and 13 before 13 SP1 Upd1 allows man-in-the-middle attackers to obtain sensitive information or modify transmi…

Fix: after 13
Fix from $1,600 2015-04-06
Simatic S7 300 Cpu Firmware HIGH 7.5
CVE-2015-2177EPSS 35%

Siemens SIMATIC S7-300 CPU devices allow remote attackers to cause a denial of service (defect-mode transition) via crafted packets on (1) TCP port 1…

No fix yet
Fix from $1,950 2015-03-07
Spcanywhere MEDIUM 6.8
CVE-2015-1597

The Siemens SPCanywhere application for Android does not use encryption during the loading of code, which allows man-in-the-middle attackers to execu…

Fix: after 1.4.1
Fix from $1,600 2015-03-07
Spcanywhere MEDIUM 5.8
CVE-2015-1596

The Siemens SPCanywhere application for Android and iOS does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle …

Fix: after 1.4.1
Fix from $1,600 2015-03-07
Starter MEDIUM 6.9
CVE-2015-1594

Untrusted search path vulnerability in Siemens SIMATIC ProSave before 13 SP1; SIMATIC CFC before 8.0 SP4 Upd9 and 8.1 before Upd1; SIMATIC STEP 7 bef…

Fix: after 8.0
Fix from $1,600 2015-03-07
Spc5000 Firmware HIGH 7.8
CVE-2014-9369

Siemens SPC controllers SPC4000, SPC5000, and SPC6000 before 3.6.0 allow remote attackers to cause a denial of service (device restart) via crafted p…

Fix: after 3.5.9
Fix from $1,950 2015-03-07
Wincc MEDIUM 5.0
CVE-2015-1358

The remote-management module in the (1) Multi Panels, (2) Comfort Panels, and (3) RT Advanced functionality in Siemens SIMATIC WinCC (TIA Portal) bef…

Mitigation only
Fix from $1,600 2015-02-18
Ruggedcom Firmware HIGH 10.0
CVE-2015-1449

Buffer overflow in the integrated web server on Siemens Ruggedcom WIN51xx devices with firmware before SS4.4.4624.35, WIN52xx devices with firmware b…

Mitigation only
Fix from $1,950 2015-02-02
Ruggedcom Firmware HIGH 10.0
CVE-2015-1448

The integrated management service on Siemens Ruggedcom WIN51xx devices with firmware before SS4.4.4624.35, WIN52xx devices with firmware before SS4.4…

Mitigation only
Fix from $1,950 2015-02-02
Ruggedcom Firmware MEDIUM 5.0
CVE-2015-1357

Siemens Ruggedcom WIN51xx devices with firmware before SS4.4.4624.35, WIN52xx devices with firmware before SS4.4.4624.35, WIN70xx devices with firmwa…

Mitigation only
Fix from $1,600 2015-02-02
Scalance X 200 Series Firmware MEDIUM 6.8
CVE-2015-1049

The web server on Siemens SCALANCE X-200IRT switches with firmware before 5.2.0 allows remote attackers to hijack sessions via unspecified vectors.

Fix: after 5.1.1
Fix from $1,600 2015-02-02
Scalance X 408 Firmware MEDIUM 6.8
CVE-2014-8479

The FTP server on Siemens SCALANCE X-300 switches with firmware before 4.0 and SCALANCE X 408 switches with firmware before 4.0 allows remote authent…

Fix: after 3.9.3
Fix from $1,600 2015-01-21
Scalance X 300 Series Firmware HIGH 7.8
CVE-2014-8478

The web server on Siemens SCALANCE X-300 switches with firmware before 4.0 and SCALANCE X 408 switches with firmware before 4.0 allows remote attacke…

Fix: after 3.9.3
Fix from $1,950 2015-01-21
Simatic Pcs 7 MEDIUM 5.0
CVE-2014-8552

The WinCC server in Siemens SIMATIC WinCC 7.0 through SP3, 7.2 before Update 9, and 7.3 before Update 2; SIMATIC PCS 7 7.1 through SP4, 8.0 through S…

Mitigation only
Fix from $1,600 2014-11-26
Simatic Pcs 7 HIGH 10.0
CVE-2014-8551EPSS 5%

The WinCC server in Siemens SIMATIC WinCC 7.0 through SP3, 7.2 before Update 9, and 7.3 before Update 2; SIMATIC PCS 7 7.1 through SP4, 8.0 through S…

Mitigation only
Fix from $1,950 2014-11-26
Simatic S7 1500 Cpu Firmware HIGH 7.1
CVE-2014-5074EPSS 10%

Siemens SIMATIC S7-1500 CPU devices with firmware before 1.6 allow remote attackers to cause a denial of service (device restart and STOP transition)…

Fix: after 1.5.1
Fix from $1,950 2014-08-17
Simatic Pcs7 MEDIUM 6.8
CVE-2014-4686

The Project administration application in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, has a hardcoded encryption key, which…

Fix: after 8.0
Fix from $1,600 2014-07-24
Simatic Pcs7 MEDIUM 6.0
CVE-2014-4684

The database server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote authenticated users to gain privileges via…

Fix: after 8.0
Fix from $1,600 2014-07-24
Simatic Pcs7 MEDIUM 5.0
CVE-2014-4682

The WebNavigator server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote attackers to obtain sensitive informat…

Fix: after 8.0
Fix from $1,600 2014-07-24
Simatic S7 Cpu 1200 Firmware MEDIUM 5.8
CVE-2014-2909

CRLF injection vulnerability in the integrated web server on Siemens SIMATIC S7-1200 CPU devices 2.x and 3.x allows remote attackers to inject arbitr…

Mitigation only
Fix from $1,600 2014-04-25
Sinema Server HIGH 9.3
CVE-2014-2731

Multiple unspecified vulnerabilities in the integrated web server in Siemens SINEMA Server before 12 SP1 allow remote attackers to execute arbitrary …

Fix: after 12.0
Fix from $1,950 2014-04-19
Sinema Server MEDIUM 5.0
CVE-2014-2732

Multiple directory traversal vulnerabilities in the integrated web server in Siemens SINEMA Server before 12 SP1 allow remote attackers to access arb…

Fix: after 12.0
Fix from $1,600 2014-04-19
Sinema Server MEDIUM 5.0
CVE-2014-2733

Siemens SINEMA Server before 12 SP1 allows remote attackers to cause a denial of service (web-interface outage) via crafted HTTP requests to port (1)…

Fix: after 12.0
Fix from $1,600 2014-04-19
Ruggedcom Rugged Operating System MEDIUM 5.0
CVE-2014-2590

The web management interface in Siemens RuggedCom ROS before 3.11, ROS 3.11 before 3.11.5 for RS950G, ROS 3.12, and ROS 4.0 for RSG2488 allows remote…

Fix: 3.11.0 / 3.11.5+
Fix from $1,600 2014-04-01
Simatic S7 Cpu 1200 Firmware HIGH 8.3
CVE-2014-2250

The random-number generator on Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 does not have sufficient entropy, which makes it easi…

Fix: after 3.0.2
Fix from $1,950 2014-03-24
Simatic S7 Cpu 1200 Firmware HIGH 7.8
CVE-2014-2254

Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 allow remote attackers to cause a denial of service (defect-mode transition) via cra…

Fix: after 3.0.2
Fix from $1,950 2014-03-24