siemens

2,341 tracked vulnerabilities.

CVE-2018-4860 HIGH
SCALANCE M875 - Authenticated OS Command Injection via Web Interface
Jun 26, 2018
CVSS 7.2
EPSS 0.01
CVE-2018-4859 HIGH
SCALANCE M875 Firmware - Authenticated OS Command Injection via Web Interface
Jun 26, 2018
CVSS 7.2
EPSS 0.01
CVE-2018-4846 CRITICAL
Siemens RAPIDPoint 400/500 and RAPIDLab 1200 Firmware - Use of Hard-coded Credentials
Jun 26, 2018
CVSS 9.8
EPSS 0.00
CVE-2018-4845 HIGH
Siemens RAPIDPoint 400/500 and RAPIDLab 1200 Firmware - Authenticated Privilege Escalation via Remote View Feature
Jun 26, 2018
CVSS 8.8
EPSS 0.00
CVE-2018-11449 HIGH
SCALANCE M875 Firmware - Unprotected Administrative Password Exposure via Local File System Access
Jun 26, 2018
CVSS 7.8
EPSS 0.00
CVE-2018-11448 MEDIUM
SCALANCE M875 - Authenticated Stored Cross-Site Scripting via Web Interface
Jun 26, 2018
CVSS 4.8
EPSS 0.00
CVE-2018-11447 HIGH
SCALANCE M875 - Cross-Site Request Forgery via Web Interface
Jun 26, 2018
CVSS 8.8
EPSS 0.00
CVE-2018-4848 MEDIUM
SCALANCE X-200, X-200IRT, X-200RNA, X-300 - Cross-Site Scripting via Malicious Link
Jun 14, 2018
CVSS 6.1
EPSS 0.00
CVE-2018-4842 MEDIUM
SCALANCE X-200IRT, X-200RNA, X-300 - Authenticated Stored Cross-Site Scripting via HRP Redundancy Configuration
Jun 14, 2018
CVSS 4.8
EPSS 0.00
CVE-2018-4833 HIGH
Siemens Rfid 181-eip Firmware < 5.2.3 - Heap Buffer Overflow
Jun 14, 2018
CVSS 8.8
EPSS 0.01
CVE-2018-3639 MEDIUM
Intel Atom C/E/X5/X7/Z - Information Disclosure via Speculative Store Bypass
May 22, 2018
CVSS 5.5
EPSS 0.46
CVE-2018-4850 HIGH
SIMATIC S7-400 and S7-400H Firmware < 4.0, 5.0 < 5.2, < 4.5 - Denial of Service via S7 Communication Packet
May 16, 2018
CVSS 7.5
EPSS 0.01
CVE-2018-4849 HIGH
Siveillance VMS Video < 12.1a - Improper Certificate Validation
May 03, 2018
CVSS 7.4
EPSS 0.00
CVE-2018-7891 HIGH
Milestone XProtect <12.1a - Remote Code Execution
Apr 30, 2018
CVSS 8.1
EPSS 0.03
CVE-2018-4832 HIGH
Siemens OpenPCS 7 < 7.1 and SIMATIC PCS 7 < 7.1 - Denial of Service via RPC Service
Apr 24, 2018
CVSS 7.5
EPSS 0.00
CVE-2018-4847 MEDIUM
SIMATIC WinCC OA Operator iOS App < V1.4 - Info Disclosure
Apr 23, 2018
CVSS 4.6
EPSS 0.00
CVE-2018-4841 CRITICAL
TIM 1531 IRC Firmware < 1.1 - Unauthenticated Remote Code Execution
Mar 29, 2018
CVSS 9.8
EPSS 0.04
CVE-2018-4844 MEDIUM
SIMATIC WinCC OA UI < 3.15.10 - Improper Access Control via HMI Project Cache Folder
Mar 20, 2018
CVSS 6.7
EPSS 0.00
CVE-2018-4843 MEDIUM
SIMATIC S7-400 CPU 414-3 PN/DP V7 < V7.0.3 - Denial of Service via PROFINET DCP Packet
Mar 20, 2018
CVSS 6.5
EPSS 0.00
CVE-2018-4840 HIGH
Siemens DIGSI 4 < 4.92 and EN100 Ethernet Modules - Unauthenticated Device Configuration Upload
Mar 08, 2018
CVSS 7.5
EPSS 0.00
CVE-2018-4839 MEDIUM
Siemens SIPROTEC and DIGSI - Inadequate Encryption Strength
Mar 08, 2018
CVSS 5.3
EPSS 0.00
CVE-2018-4838 HIGH
Siemens EN100 Ethernet Module - Unauthenticated Firmware Upgrade/Downgrade via Web Interface
Mar 08, 2018
CVSS 7.5
EPSS 0.00
CVE-2018-5381 MEDIUM
Quagga < 1.2.3 - Denial of Service via BGP OPEN Message Capability Parsing
Feb 19, 2018
CVSS 6.5
EPSS 0.06
CVE-2018-5380 MEDIUM
Quagga < 1.2.3 - Out-of-bounds Read in BGP Daemon Debug Code-to-String Conversion
Feb 19, 2018
CVSS 4.3
EPSS 0.01
CVE-2018-5379 HIGH
Quagga BGP daemon <1.2.3 - Use After Free
Feb 19, 2018
CVSS 7.5
EPSS 0.07