Vulnerability index

Browse CVEs

1,648 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Wincc Flexible HIGH 10.0
CVE-2011-4514

The TELNET daemon in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels…

Mitigation only
Fix from $1,950 2012-02-03
Wincc Flexible HIGH 9.3
CVE-2011-4508

The HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before SP2 Update 1; the TP, OP, MP, C…

Mitigation only
Fix from $1,950 2012-02-03
Wincc Flexible HIGH 9.3
CVE-2011-4875EPSS 14%

Stack-based buffer overflow in HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP…

No fix yet
Fix from $1,950 2012-02-03
Wincc Flexible HIGH 9.3
CVE-2011-4876EPSS 10%

Directory traversal vulnerability in HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); …

No fix yet
Fix from $1,950 2012-02-03
Wincc Flexible HIGH 7.1
CVE-2011-4877EPSS 8%

HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and M…

No fix yet
Fix from $1,950 2012-02-03
Wincc Flexible MEDIUM 5.0
CVE-2011-4512

CRLF injection vulnerability in the HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before…

Mitigation only
Fix from $1,600 2012-02-03
Automation License Manager HIGH 7.5
CVE-2011-4529EPSS 7%

Multiple buffer overflows in Siemens Automation License Manager (ALM) 4.0 through 5.1+SP1+Upd1 allow remote attackers to execute arbitrary code via a…

Fix: after 5.1
Fix from $1,950 2012-01-08
Automation License Manager MEDIUM 5.0
CVE-2011-4530

Siemens Automation License Manager (ALM) 4.0 through 5.1+SP1+Upd1 does not properly copy fields obtained from clients, which allows remote attackers …

Fix: after 5.1
Fix from $1,600 2012-01-08
Automation License Manager MEDIUM 5.0
CVE-2011-4531EPSS 9%

Siemens Automation License Manager (ALM) 4.0 through 5.1+SP1+Upd1 allows remote attackers to cause a denial of service (NULL pointer dereference and …

Fix: after 5.1
Fix from $1,600 2012-01-08
Automation License Manager MEDIUM 5.0
CVE-2011-4532

Absolute path traversal vulnerability in the ALMListView.ALMListCtrl ActiveX control in almaxcx.dll in the graphical user interface in Siemens Automa…

Fix: after 5.1
Fix from $1,600 2012-01-08
Tecnomatix Factorylink HIGH 9.3
CVE-2011-4055

Buffer overflow in the WebClient ActiveX control in Siemens Tecnomatix FactoryLink 6.6.1 (aka 6.6 SP1), 7.5.217 (aka 7.5 SP2), and 8.0.2.54 allows re…

Patch available
Fix from $1,950 2012-01-08
Tecnomatix Factorylink MEDIUM 5.8
CVE-2011-4056

An unspecified ActiveX control in ActBar.ocx in Siemens Tecnomatix FactoryLink 6.6.1 (aka 6.6 SP1), 7.5.217 (aka 7.5 SP2), and 8.0.2.54 allows remote…

Patch available
Fix from $1,600 2012-01-08
Simatic Wincc Flexible Runtime HIGH 9.3
CVE-2011-3321EPSS 7%

Heap-based buffer overflow in the Siemens WinCC Runtime Advanced Loader, as used in SIMATIC WinCC flexible Runtime and SIMATIC WinCC (TIA Portal) Run…

Mitigation only
Fix from $1,950 2011-09-16
Simatic Wincc HIGH 7.8
CVE-2010-2772

Siemens Simatic WinCC and PCS 7 SCADA system uses a hard-coded password, which allows local users to access a back-end database and gain privileges, …

No fix yet
Fix from $1,950 2010-07-22
Gigaset Se361 Wlan Router HIGH 7.8
CVE-2009-3322

The Siemens Gigaset SE361 WLAN router allows remote attackers to cause a denial of service (device reboot) via a flood of crafted TCP packets to port…

No fix yet
Fix from $1,950 2009-09-23
Gigaset C450 Ip HIGH 7.8
CVE-2008-7065

Siemens C450 IP and C475 IP VoIP devices allow remote attackers to cause a denial of service (disconnected calls and device reboot) via a crafted SIP…

No fix yet
Fix from $1,950 2009-08-25
Gigaset Wlan Camera HIGH 10.0
CVE-2008-6993

Siemens Gigaset WLAN Camera 1.27 has an insecure default password, which allows remote attackers to conduct unauthorized activities. NOTE: the proven…

Mitigation only
Fix from $1,950 2009-08-19
Speedstream 5200 HIGH 10.0
CVE-2008-6916

Siemens SpeedStream 5200 with NetPort Software 1.1 allows remote attackers to bypass authentication via an invalid Host header, possibly involving a …

No fix yet
Fix from $1,950 2009-08-07
Gigaset Se461 Wimax Router HIGH 7.3
CVE-2009-1152

Siemens Gigaset SE461 WiMAX router 1.5-BL024.9.6401, and possibly other versions, allows remote attackers to cause a denial of service (device restar…

No fix yet
Fix from $1,950 2009-03-26
Speedstream 6520 HIGH 7.8
CVE-2008-1267

The Siemens SpeedStream 6520 router allows remote attackers to cause a denial of service (web interface crash) via an HTTP request to basehelp_Englis…

No fix yet
Fix from $1,950 2008-03-10
Speedstream Wireless Router MEDIUM 5.0
CVE-2006-3907

Siemens SpeedStream 2624 allows remote attackers to cause a denial of service (device hang) by sending a crafted packet to the web administrative int…

Mitigation only
Fix from $1,600 2006-07-27
Speedstream Wireless Router HIGH 7.5
CVE-2006-3344

Siemens Speedstream Wireless Router 2624 allows local users to bypass authentication and access protected files by using the Universal Plug and Play …

Mitigation only
Fix from $1,950 2006-07-03
Santis 50 HIGH 7.5
CVE-2005-2424

The management interface for Siemens SANTIS 50 running firmware 4.2.8.0, and possibly other products including Ericsson HN294dp and Dynalink RTA300W,…

No fix yet
Fix from $1,950 2005-08-03
M45 HIGH 7.8
CVE-2003-1464

Buffer overflow in Siemens 45 series mobile phones allows remote attackers to cause a denial of service (disconnect and unavailable inbox) via a Shor…

Mitigation only
Fix from $1,950 2003-12-31
Db4web CRITICAL 9.8
CVE-2002-1484EPSS 14%

DB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a proxy and attempt TCP connections to other s…

Patch available
Fix from $2,300 2003-04-22
3568i Wap MEDIUM 5.0
CVE-2002-0122

Siemens 3568i WAP mobile phones allows remote attackers to cause a denial of service (crash) via an SMS message containing unusual characters.

Patch available
Fix from $1,600 2002-03-25
Reliant Unix MEDIUM 5.0
CVE-2001-0411

Reliant Unix 5.44 and earlier allows remote attackers to cause a denial of service via an ICMP port unreachable packet, which causes Reliant to drop …

Mitigation only
Fix from $1,600 2001-06-18
Hinet Lp HIGH 10.0
CVE-2000-0964

Buffer overflow in the web administration service for the HiNet LP5100 IP-phone allows remote attackers to cause a denial of service and possibly exe…

Mitigation only
Fix from $1,950 2000-12-19