siemens

2,341 tracked vulnerabilities.

CVE-2024-32008 HIGH
Spectrum Power 4 <V4.70 SP12 Update 2 - Privilege Escalation
Nov 11, 2025
CVSS 7.8
EPSS 0.00
CVE-2024-54678 HIGH
SIMATIC PCS neo V4.1-V6.0, S7-PLCSIM V17, STEP 7 V17<V19, WinCC V17...
Aug 12, 2025
CVSS 8.2
EPSS 0.00
CVE-2024-52504 HIGH
SIPROTEC 4 - Unauthenticated Denial of Service via File Transfer Interruption
Aug 12, 2025
CVSS 7.5
EPSS 0.00
CVE-2024-41986 MEDIUM
Siemens Opcenter Quality SmartClient Modules - Use of Broken Cryptographic Algorithm via TLS 1.0 and 1.1
Aug 12, 2025
CVSS 6.4
EPSS 0.00
CVE-2024-41985 LOW
Siemens Opcenter Quality SmartClient Modules - Insufficient Session Expiration
Aug 12, 2025
CVSS 2.6
EPSS 0.00
CVE-2024-41984 LOW
Siemens Opcenter Quality SmartClient Modules - Information Disclosure via Error Message
Aug 12, 2025
CVSS 2.6
EPSS 0.00
CVE-2024-41983 LOW
Siemens Opcenter Quality SmartClient - SQL Error Message Information Disclosure
Aug 12, 2025
CVSS 3.5
EPSS 0.00
CVE-2024-41982 MEDIUM
Siemens Opcenter Quality SmartClient Modules - Missing Encryption of Sensitive Data
Aug 12, 2025
CVSS 4.8
EPSS 0.00
CVE-2024-41980 LOW
Siemens Opcenter Quality SmartClient Modules >= V13.2 < V2506 - Unencrypted LDAP Communication
Aug 12, 2025
CVSS 3.1
EPSS 0.00
CVE-2024-41979 HIGH
Siemens Opcenter Quality - Incorrect Authorization
Aug 12, 2025
CVSS 7.1
EPSS 0.00
CVE-2024-31854 HIGH
SICAM TOOLBOX II < V07.11 - Man-in-the-Middle
Jul 08, 2025
CVSS 8.1
EPSS 0.00
CVE-2024-31853 HIGH
SICAM TOOLBOX II < V07.11 - Man-in-the-Middle
Jul 08, 2025
CVSS 8.1
EPSS 0.00
CVE-2024-41797 MEDIUM
RUGGEDCOM RST2428P,SCALANCE XC316-8,SCALANCE XC324-4,SCALANCE XC324...
Jun 10, 2025
CVSS 4.3
EPSS 0.01
CVE-2024-51447 MEDIUM
Polarion ALM V2310 and V2404 < V2404.2 - Unauthenticated Observable Response Discrepancy in Username Validation
May 13, 2025
CVSS 5.3
EPSS 0.00
CVE-2024-51446 MEDIUM
Polarion ALM V2310 and V2404 < V2404.4 - Authenticated Stored Cross-Site Scripting via XML File Upload
May 13, 2025
CVSS 6.5
EPSS 0.00
CVE-2024-51445 MEDIUM
Polarion ALM V2310 and V2404 < V2404.4 - Authenticated XML External Entity Injection in Docx Import Feature
May 13, 2025
CVSS 6.5
EPSS 0.00
CVE-2024-51444 MEDIUM
Polarion ALM V2310 and V2404 < V2404.4 - Authenticated SQL Injection
May 13, 2025
CVSS 6.5
EPSS 0.00
CVE-2024-23815 HIGH
Siemens Desigo CC - Unauthenticated SQL Query Execution via Event Port
May 13, 2025
CVSS 7.5
EPSS 0.00
CVE-2024-54092 CRITICAL
Industrial Edge Device Kit - arm64/x86-64 <1.20.2-1/<1.21.1-1 - Inf...
Apr 08, 2025
CVSS 9.8
EPSS 0.01
CVE-2024-41796 MEDIUM
SENTRON 7KT PAC1260 Data Manager - Unauthenticated Password Change via Web Interface
Apr 08, 2025
CVSS 6.5
EPSS 0.00
CVE-2024-41795 MEDIUM
SENTRON 7KT PAC1260 Data Manager - Cross-Site Request Forgery
Apr 08, 2025
CVSS 6.5
EPSS 0.00
CVE-2024-41794 CRITICAL
SENTRON 7KT PAC1260 Data Manager - Use of Hard-coded Credentials
Apr 08, 2025
CVSS 10.0
EPSS 0.01
CVE-2024-41793 HIGH
SENTRON 7KT PAC1260 Data Manager - Unauthenticated SSH Service Enablement via Web Interface
Apr 08, 2025
CVSS 8.6
EPSS 0.00
CVE-2024-41792 HIGH
SENTRON 7KT PAC1260 Data Manager - Unauthenticated Path Traversal via Web Interface
Apr 08, 2025
CVSS 8.6
EPSS 0.01
CVE-2024-41791 HIGH
SENTRON 7KT PAC1260 Data Manager - Unauthenticated Critical Function Access via Web Interface
Apr 08, 2025
CVSS 7.3
EPSS 0.00