Skip to main content

Vendor archive

siemens CVEs

Beta · best-effort

2,146 CVEs tagged to vendor siemens257 Critical, 1,223 High, 589 Medium, 77 Low, 0 Unrated.

CVE-2016-9157

Published Dec 5, 2016

A vulnerability in Siemens SICAM PAS (all versions before V8.09) could allow a remote attacker to cause a Denial of Service condition and potentially lead to unauthenticated remot…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-9156

Published Dec 5, 2016

A vulnerability in Siemens SICAM PAS (all versions before V8.09) could allow a remote attacker to upload, download, or delete files in certain parts of the file system by sending…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2016-8673

Published Nov 23, 2016

A vulnerability has been identified in SIMATIC CP 343-1 Advanced (incl. SIPLUS NET variant) (All versions < V3.0.53), SIMATIC CP 443-1 Advanced (incl. SIPLUS NET variant) (All ver…

CVSS 8.8 · High

CVE-2016-8672

Published Nov 23, 2016

A vulnerability has been identified in SIMATIC CP 343-1 Advanced (incl. SIPLUS NET variant) (All versions < V3.0.53), SIMATIC CP 443-1 Advanced (incl. SIPLUS NET variant) (All ver…

CVSS 5.3 · Medium

CVE-2016-8565

Published Oct 13, 2016

Siemens Automation License Manager (ALM) before 5.3 SP3 allows remote attackers to write to files, rename files, create directories, or delete directories via crafted packets.

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-8564

Published Oct 13, 2016

SQL injection vulnerability in Siemens Automation License Manager (ALM) before 5.3 SP3 Update 1 allows remote attackers to execute arbitrary SQL commands via crafted traffic to TC…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-8563

Published Oct 13, 2016

Siemens Automation License Manager (ALM) before 5.3 SP3 Update 1 allows remote attackers to cause a denial of service (ALM service outage) via crafted packets to TCP port 4410.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-7960

Published Oct 13, 2016

Siemens SIMATIC STEP 7 (TIA Portal) before 14 uses an improper format for managing TIA project files during version updates, which makes it easier for local users to obtain sensit…

CVSS 2.5 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-7959

Published Oct 13, 2016

Siemens SIMATIC STEP 7 (TIA Portal) before 14 improperly stores pre-shared key data in TIA project files, which makes it easier for local users to obtain sensitive information by…

CVSS 4.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-6486

Published Aug 8, 2016

Siemens SINEMA Server uses weak permissions for the application folder, which allows local users to gain privileges via unspecified vectors.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6204

Published Jul 22, 2016

Cross-site scripting (XSS) vulnerability in the integrated web server in Siemens SINEMA Remote Connect Server before 1.2 allows remote attackers to inject arbitrary web script or…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-5874

Published Jul 22, 2016

Siemens SIMATIC NET PC-Software before 13 SP2 allows remote attackers to cause a denial of service (OPC UA service outage) via crafted TCP packets.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-5744

Published Jul 22, 2016

Siemens SIMATIC WinCC 7.0 through SP3 and 7.2 allows remote attackers to read arbitrary WinCC station files via crafted packets.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-4956

Published Jul 5, 2016

ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (interleaved-mode transition and time change) via a spoofed broadcast packet. NOTE: this vulne…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Showing 1,926-1,950 of 2,146 CVEsPage 78 of 86