Vulnerability index

Browse CVEs

1,648 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Simatic S7 Cpu 1200 Firmware HIGH 7.8
CVE-2014-2256

Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 allow remote attackers to cause a denial of service (defect-mode transition) via cra…

Fix: after 3.0.2
Fix from $1,950 2014-03-24
Simatic S7 Cpu 1200 Firmware HIGH 7.8
CVE-2014-2258

Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 allow remote attackers to cause a denial of service (defect-mode transition) via cra…

Fix: after 3.0.2
Fix from $1,950 2014-03-24
Simatic S7 Cpu 1200 Firmware MEDIUM 6.1
CVE-2014-2252

Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 allow remote attackers to cause a denial of service (defect-mode transition) via cra…

Fix: after 3.0.2
Fix from $1,600 2014-03-24
Simatic S7 1500 Cpu Firmware HIGH 8.3
CVE-2014-2251

The random-number generator on Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 does not have sufficient entropy, which makes it ea…

Fix: after 1.1.2
Fix from $1,950 2014-03-16
Simatic S7 1500 Cpu Firmware HIGH 7.8
CVE-2014-2255

Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allow remote attackers to cause a denial of service (defect-mode transition) via c…

Fix: after 1.1.2
Fix from $1,950 2014-03-16
Simatic S7 1500 Cpu Firmware HIGH 7.8
CVE-2014-2257

Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allow remote attackers to cause a denial of service (defect-mode transition) via c…

Fix: after 1.1.2
Fix from $1,950 2014-03-16
Simatic S7 1500 Cpu Firmware HIGH 7.8
CVE-2014-2259

Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allow remote attackers to cause a denial of service (defect-mode transition) via c…

Fix: after 1.1.2
Fix from $1,950 2014-03-16
Simatic S7 1500 Cpu Firmware MEDIUM 6.1
CVE-2014-2253

Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allow remote attackers to cause a denial of service (defect-mode transition) via c…

Fix: after 1.1.2
Fix from $1,600 2014-03-16
Simatic S7 1500 Cpu Firmware MEDIUM 5.8
CVE-2014-2247

The integrated web server on Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allows remote attackers to inject headers via unspeci…

Fix: after 1.1.2
Fix from $1,600 2014-03-16
Simatic S7 1500 Cpu Firmware MEDIUM 5.8
CVE-2014-2249

Cross-site request forgery (CSRF) vulnerability on Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 and SIMATIC S7-1200 CPU PLC dev…

Fix: after 1.1.2
Fix from $1,600 2014-03-16
Ruggedcom Rugged Operating System HIGH 7.8
CVE-2014-1966

The SNMP implementation in Siemens RuggedCom ROS before 3.11, ROS 3.11 for RS950G, ROS 3.12 before 3.12.4, and ROS 4.0 for RSG2488 allows remote atta…

Fix: 3.11.0 / 3.11.5+
Fix from $1,950 2014-02-24
Simatic Wincc Open Architecture HIGH 7.5
CVE-2014-1697EPSS 5%

The integrated web server in Siemens SIMATIC WinCC OA before 3.12 P002 January allows remote attackers to execute arbitrary code via crafted packets …

Fix: after 3.12
Fix from $1,950 2014-02-07
Simatic Wincc Open Architecture MEDIUM 5.0
CVE-2014-1696

Siemens SIMATIC WinCC OA before 3.12 P002 January uses a weak hash algorithm for passwords, which makes it easier for remote attackers to obtain acce…

Fix: after 3.12
Fix from $1,600 2014-02-07
Simatic Wincc Open Architecture MEDIUM 5.0
CVE-2014-1698

Directory traversal vulnerability in Siemens SIMATIC WinCC OA before 3.12 P002 January allows remote attackers to read arbitrary files via crafted pa…

Fix: after 3.12
Fix from $1,600 2014-02-07
Simatic Wincc Open Architecture MEDIUM 5.0
CVE-2014-1699

Siemens SIMATIC WinCC OA before 3.12 P002 January allows remote attackers to cause a denial of service (monitoring-service outage) via malformed HTTP…

Fix: after 3.12
Fix from $1,600 2014-02-07
Ruggedcom Rugged Operating System HIGH 8.3
CVE-2013-6925

The integrated HTTPS server in Siemens RuggedCom ROS before 3.12.2 allows remote attackers to hijack web sessions by predicting a session id value.

Fix: 3.12.2+
Fix from $1,950 2013-12-17
Ruggedcom Rugged Operating System HIGH 8.0
CVE-2013-6926

The integrated HTTPS server in Siemens RuggedCom ROS before 3.12.2 allows remote authenticated users to bypass intended restrictions on administrativ…

Fix: 3.12.2+
Fix from $1,950 2013-12-17
Comos MEDIUM 6.9
CVE-2013-6840

Siemens COMOS before 9.2.0.8.1, 10.0 before 10.0.3.1.40, and 10.1 before 10.1.0.0.2 allows local users to gain database privileges via unspecified ve…

No fix yet
Fix from $1,600 2013-12-10
Sinamics S\/g Family Firmware HIGH 10.0
CVE-2013-6920

Siemens SINAMICS S/G controllers with firmware before 4.6.11 do not require authentication for FTP and TELNET sessions, which allows remote attackers…

Fix: after 4.6
Fix from $1,950 2013-12-07
Scalance X 200 Series Firmware HIGH 10.0
CVE-2013-5944

The integrated web server on Siemens SCALANCE X-200 switches with firmware before 4.5.0 and X-200IRT switches with firmware before 5.1.0 does not pro…

Fix: after 5.0.1
Fix from $1,950 2013-10-03
Scalance X 200 Series Firmware HIGH 8.3
CVE-2013-5709

The authentication implementation in the web server on Siemens SCALANCE X-200 switches with firmware before 5.0.0 does not use a sufficient source of…

Fix: after 4.4
Fix from $1,950 2013-09-17
Comos HIGH 7.2
CVE-2013-4943

The client application in Siemens COMOS before 9.1 Update 458, 9.2 before 9.2.0.6.37, and 10.0 before 10.0.3.0.19 allows local users to gain privileg…

Mitigation only
Fix from $1,950 2013-08-09
Scalance W700 Series Firmware HIGH 10.0
CVE-2013-4652EPSS 6%

Unspecified vulnerability in the command-line management interface on Siemens Scalance W7xx devices with firmware before 4.5.4 allows remote attacker…

Fix: after 4.4.0
Fix from $1,950 2013-08-01
Wincc MEDIUM 6.8
CVE-2013-4911

Cross-site request forgery (CSRF) vulnerability in Siemens WinCC (TIA Portal) 11 and 12 before 12 SP1 allows remote attackers to hijack the authentic…

Mitigation only
Fix from $1,600 2013-08-01
Scalance W700 Series Firmware MEDIUM 6.6
CVE-2013-4651

Siemens Scalance W7xx devices with firmware before 4.5.4 use the same hardcoded X.509 certificate across different customers' installations, which ma…

Fix: after 4.4.0
Fix from $1,600 2013-08-01
Wincc MEDIUM 5.8
CVE-2013-4912

Open redirect vulnerability in Siemens WinCC (TIA Portal) 11 and 12 before 12 SP1 allows remote attackers to redirect users to arbitrary web sites an…

Mitigation only
Fix from $1,600 2013-08-01
Openscape Session Border Controller HIGH 10.0
CVE-2013-4781

core/getLog.php on the Siemens Enterprise OpenScape Branch appliance and OpenScape Session Border Controller (SBC) before 2 R0.32.0, and 7 before 7 R…

Mitigation only
Fix from $1,950 2013-07-18
Openscape Session Border Controller HIGH 7.8
CVE-2013-4778

core/getLog.php on the Siemens Enterprise OpenScape Branch appliance and OpenScape Session Border Controller (SBC) before 2 R0.32.0, and 7 before 7 R…

Mitigation only
Fix from $1,950 2013-07-18
Openscape Session Border Controller HIGH 7.8
CVE-2013-4780

core/getLog.php on the Siemens Enterprise OpenScape Branch appliance and OpenScape Session Border Controller (SBC) before 2 R0.32.0, and 7 before 7 R…

Mitigation only
Fix from $1,950 2013-07-18
Simatic Pcs7 HIGH 7.5
CVE-2013-3957

SQL injection vulnerability in the login screen in the Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMATIC PCS7 8.0 SP1 and earlie…

Fix: after 8.0
Fix from $1,950 2013-06-14