siemens

2,341 tracked vulnerabilities.

CVE-2020-0590 HIGH
Intel Xeon Bronze/Silver/Gold Firmware - Authenticated Privilege Escalation via BIOS Input Validation
Nov 12, 2020
CVSS 7.8
EPSS 0.00
CVE-2020-28168 MEDIUM
axios 0.19.0-0.20.0 - Server-Side Request Forgery via Redirect Bypass
Nov 06, 2020
CVSS 5.9
EPSS 0.00
CVE-2020-7591 HIGH
SIPORT MP < 3.2.1 - Authenticated User Impersonation via Single Sign-On Feature
Oct 15, 2020
CVSS 8.8
EPSS 0.00
CVE-2020-15794 MEDIUM
Desigo Insight - Authenticated Sensitive Information Exposure via Error Message
Oct 15, 2020
CVSS 4.3
EPSS 0.00
CVE-2020-15793 MEDIUM
Desigo Insight - Clickjacking via Missing X-Frame-Options Header
Oct 15, 2020
CVSS 5.4
EPSS 0.00
CVE-2020-15792 MEDIUM
Desigo Insight - Authenticated SQL Injection via Query Parameter
Oct 15, 2020
CVSS 4.3
EPSS 0.00
CVE-2020-7590 MEDIUM
DCA Vantage Analyzer <4.5 - Info Disclosure
Oct 13, 2020
CVSS 6.8
EPSS 0.00
CVE-2020-15797 MEDIUM
Siemens DCA Vantage Analyzer Firmware < 4.5.0.0 - Unauthenticated Privilege Escalation via Kiosk Mode Escape
Oct 13, 2020
CVSS 6.8
EPSS 0.00
CVE-2020-15791 MEDIUM
SIMATIC S7-300 and S7-400 CPU Families - Insufficiently Protected Credentials via ISO-TSAP Authentication
Sep 09, 2020
CVSS 6.5
EPSS 0.00
CVE-2020-15790 MEDIUM
Spectrum Power 4 < 4.70 SP8 - Directory Listing Exposure via Web Server Misconfiguration
Sep 09, 2020
CVSS 5.3
EPSS 0.00
CVE-2020-15789 HIGH
Polarion Subversion Webclient - Cross-Site Request Forgery
Sep 09, 2020
CVSS 8.1
EPSS 0.00
CVE-2020-15788 MEDIUM
Polarion Subversion Webclient - Cross-Site Scripting via Malicious URL Input
Sep 09, 2020
CVSS 6.1
EPSS 0.00
CVE-2020-15787 CRITICAL
SIMATIC HMI Unified Comfort Panels <= V16 - Info Disclosure
Sep 09, 2020
CVSS 9.8
EPSS 0.00
CVE-2020-15786 CRITICAL
SIMATIC HMI Panels <= V16 - Brute-Force Attack via Sm@rt Server
Sep 09, 2020
CVSS 9.8
EPSS 0.00
CVE-2020-15785 MEDIUM
Siveillance Video Client - Cleartext Transmission of Sensitive Information via NTLM Authentication
Sep 09, 2020
CVSS 5.3
EPSS 0.00
CVE-2020-15784 MEDIUM
Spectrum Power 4 < 4.70 SP8 - Cleartext Storage of Sensitive Information in Configuration Files
Sep 09, 2020
CVSS 5.3
EPSS 0.00
CVE-2020-10056 HIGH
Siemens License Management Utility < 2.4 - Authenticated Privilege Escalation via lmgrd Service Configuration
Sep 09, 2020
CVSS 7.8
EPSS 0.00
CVE-2020-10051 HIGH
SIMATIC RTLS Locating Manager <V2.10.2 - Command Injection
Sep 09, 2020
CVSS 7.8
EPSS 0.00
CVE-2020-10050 HIGH
SIMATIC RTLS Locating Manager < 2.10.2 - Local Privilege Escalation via Service Executable Directory
Sep 09, 2020
CVSS 7.8
EPSS 0.00
CVE-2020-10049 HIGH
SIMATIC RTLS Locating Manager < 2.10.2 - Local Command Injection via Start-Stop Scripts
Sep 09, 2020
CVSS 7.3
EPSS 0.00
CVE-2020-7583 HIGH
Siemens Automation License Manager 5.x and 6.x < 6.0.8 - Improper Authorization
Aug 14, 2020
CVSS 7.8
EPSS 0.00
CVE-2020-15781 CRITICAL
SICAM A8000 Firmware < 05.30 - Stored Cross-Site Scripting via Login Screen Log Messages
Aug 14, 2020
CVSS 9.6
EPSS 0.01
CVE-2020-10055 CRITICAL
Siemens Desigo CC and Desigo CC Compact - Remote Code Execution via BIRT Advanced Reporting Engine
Aug 14, 2020
CVSS 9.8
EPSS 0.03
CVE-2020-7593 CRITICAL
Siemens LOGO! 8 BM Firmware <=1.82.02 - Unauthenticated Remote Code Execution via Web Server
Jul 14, 2020
CVSS 9.8
EPSS 0.17
CVE-2020-7592 MEDIUM
SIMATIC HMI Panels and WinCC Runtime Advanced - Cleartext Transmission of Sensitive Information
Jul 14, 2020
CVSS 6.5
EPSS 0.00