Vulnerability index

Browse CVEs

1,648 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Simatic Pcs7 HIGH 7.5
CVE-2013-3958

The login implementation in the Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMATIC PCS7 8.0 SP1 and earlier and other products, h…

Fix: after 8.0
Fix from $1,950 2013-06-14
Scalance X200irt Firmware HIGH 8.0
CVE-2013-3633

A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (Versions < V5.0.0 for CVE-2013-3633 and versions < V…

Fix: after 5.0.0
Fix from $1,950 2013-05-24
Scalance X200irt Firmware HIGH 7.5
CVE-2013-3634

A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (Versions < V5.0.0 for CVE-2013-3633 and versions < V…

Fix: after 5.0.0
Fix from $1,950 2013-05-24
Simatic S7 1200 Firmware HIGH 7.8
CVE-2013-0700

Siemens SIMATIC S7-1200 PLCs 2.x and 3.x allow remote attackers to cause a denial of service (defect-mode transition and control outage) via crafted …

Fix: 4.0+
Fix from $1,950 2013-04-22
Simatic S7 1200 Firmware HIGH 7.8
CVE-2013-2780

Siemens SIMATIC S7-1200 PLCs 2.x and 3.x allow remote attackers to cause a denial of service (defect-mode transition and control outage) via crafted …

Fix: 4.0+
Fix from $1,950 2013-04-22
Cp 1604 Firmware HIGH 10.0
CVE-2013-0659EPSS 6%

The debugging feature on the Siemens CP 1604 and CP 1616 interface cards with firmware before 2.5.2 allows remote attackers to execute arbitrary code…

Fix: after 2.5.1
Fix from $1,950 2013-04-01
Simatic Pcs7 MEDIUM 6.8
CVE-2013-0674

Buffer overflow in the RegReader ActiveX control in Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, allows remot…

Fix: after 8.0
Fix from $1,600 2013-03-21
Simatic Pcs7 MEDIUM 6.1
CVE-2013-0675

Buffer overflow in CCEServer (aka the central communications component) in Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other…

Fix: after 8.0
Fix from $1,600 2013-03-21
Simatic Pcs7 MEDIUM 5.8
CVE-2013-0677

The web server in Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, allows remote attackers to obtain sensitive in…

Fix: after 8.0
Fix from $1,600 2013-03-21
Simatic Rf Manager MEDIUM 6.8
CVE-2013-0656

Buffer overflow in a third-party ActiveX component in Siemens SIMATIC RF-MANAGER 2008, and RF-MANAGER Basic 3.0 and earlier, allows remote attackers …

Fix: after 3.0
Fix from $1,600 2013-01-21
Sipass Integrated HIGH 10.0
CVE-2012-5409EPSS 16%

AscoServer.exe in the server in Siemens SiPass integrated MP2.6 and earlier does not properly handle IOCP RPC messages received over an Ethernet netw…

Mitigation only
Fix from $1,950 2012-11-01
Simatic Pcs7 HIGH 7.5
CVE-2012-3032

SQL injection vulnerability in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers…

Fix: after 7.0
Fix from $1,950 2012-09-18
Simatic Pcs7 MEDIUM 6.8
CVE-2012-3028

Cross-site request forgery (CSRF) vulnerability in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, all…

Fix: after 7.0
Fix from $1,600 2012-09-18
Simatic Pcs7 MEDIUM 5.0
CVE-2012-3030

WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, stores sensitive information under the web root with i…

Fix: after 7.0
Fix from $1,600 2012-09-18
Comos HIGH 8.5
CVE-2012-3009

Siemens COMOS before 9.1 Patch 413, 9.2 before Update 03 Patch 023, and 10.0 before Patch 005 allows remote authenticated users to obtain database ad…

Fix: after 9.1
Fix from $1,950 2012-08-16
Synco Ozw Web Server HIGH 7.5
CVE-2012-3020

The Siemens Synco OZW Web Server devices OZW672.*, OZW772.*, and OZW775 with firmware before 4 have an unspecified default password, which makes it e…

Fix: after 3.0
Fix from $1,950 2012-08-06
Simatic S7 400 Cpu Firmware HIGH 7.8
CVE-2012-3016

Siemens SIMATIC S7-400 PN CPU devices with firmware 6 before 6.0.3 allow remote attackers to cause a denial of service (defect-mode transition and se…

Patch available
Fix from $1,950 2012-07-31
Simatic S7 400 Cpu Firmware HIGH 7.8
CVE-2012-3017

Siemens SIMATIC S7-400 PN CPU devices with firmware 5.x allow remote attackers to cause a denial of service (defect-mode transition and service outag…

Mitigation only
Fix from $1,950 2012-07-31
Simatic Pcs7 MEDIUM 6.9
CVE-2012-3015

Untrusted search path vulnerability in Siemens SIMATIC STEP7 before 5.5 SP1, as used in SIMATIC PCS7 7.1 SP3 and earlier and other products, allows l…

Fix: after 7.1
Fix from $1,600 2012-07-26
Wincc MEDIUM 5.8
CVE-2012-3003

Open redirect vulnerability in an unspecified web application in Siemens WinCC 7.0 SP3 before Update 2 allows remote attackers to redirect users to a…

Mitigation only
Fix from $1,600 2012-06-08
Wincc MEDIUM 5.5
CVE-2012-2596

The XPath functionality in unspecified web applications in Siemens WinCC 7.0 SP3 before Update 2 does not properly handle special characters in param…

Mitigation only
Fix from $1,600 2012-06-08
Ruggedcom Rugged Operating System HIGH 8.5
CVE-2012-1803EPSS 49%

RuggedCom Rugged Operating System (ROS) 3.10.x and earlier has a factory account with a password derived from the MAC Address field in the banner, wh…

Fix: after 3.10.1
Fix from $1,950 2012-04-28
Ruggedcom Rugged Operating System HIGH 8.5
CVE-2012-2441EPSS 9%

RuggedCom Rugged Operating System (ROS) before 3.3 has a factory account with a password derived from the MAC Address field in a banner, which makes …

Fix: 3.3.0+
Fix from $1,950 2012-04-28
Scalance X414 3e Firmware HIGH 7.8
CVE-2012-1802EPSS 6%

Buffer overflow in the embedded web server on the Siemens Scalance X Industrial Ethernet switch X414-3E before 3.7.1, X308-2M before 3.7.2, X-300EEC …

Fix: after 3.7.0
Fix from $1,950 2012-04-18
Scalance S Firmware HIGH 10.0
CVE-2012-1799EPSS 5%

The web server on the Siemens Scalance S Security Module firewall S602 V2, S612 V2, and S613 V2 with firmware before 2.3.0.3 does not limit the rate …

Fix: after 2.3.0
Fix from $1,950 2012-04-18
Scalance S Firmware MEDIUM 6.1
CVE-2012-1800

Stack-based buffer overflow in the Profinet DCP protocol implementation on the Siemens Scalance S Security Module firewall S602 V2, S612 V2, and S613…

Fix: after 2.3.0
Fix from $1,600 2012-04-18
Wincc Flexible HIGH 8.5
CVE-2011-4879EPSS 13%

miniweb.exe in the HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before SP2 Update 1; th…

No fix yet
Fix from $1,950 2012-02-03
Wincc Flexible HIGH 7.8
CVE-2011-4878EPSS 12%

Directory traversal vulnerability in miniweb.exe in the HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (ak…

No fix yet
Fix from $1,950 2012-02-03
Wincc Flexible HIGH 10.0
CVE-2011-4509

The HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panel…

Mitigation only
Fix from $1,950 2012-02-03
Wincc Flexible HIGH 10.0
CVE-2011-4513

Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; …

Mitigation only
Fix from $1,950 2012-02-03