Skip to main content

Vendor archive

siemens CVEs

Beta · best-effort

2,146 CVEs tagged to vendor siemens257 Critical, 1,223 High, 589 Medium, 77 Low, 0 Unrated.

CVE-2016-4955

Published Jul 5, 2016

ntpd in NTP 4.x before 4.2.8p8, when autokey is enabled, allows remote attackers to cause a denial of service (peer-variable clearing and association outage) by sending (1) a spoo…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2016-4954

Published Jul 5, 2016

The process_packet function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (peer-variable modification) by sending spoofed p…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2016-4953

Published Jul 5, 2016

ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (ephemeral-association demobilization) by sending a spoofed crypto-NAK packet with incorrect au…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2016-5849

Published Jul 4, 2016

Siemens SICAM PAS through 8.07 allows local users to obtain sensitive configuration information by leveraging database stoppage.

CVSS 2.5 · Low
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2016-5848

Published Jul 4, 2016

Siemens SICAM PAS before 8.07 does not properly restrict password data in the database, which makes it easier for local users to calculate passwords by leveraging unspecified data…

CVSS 6.7 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2016-3949

Published Jun 27, 2016

Siemens SIMATIC S7-300 Profinet-enabled CPU devices with firmware before 3.2.12 and SIMATIC S7-300 Profinet-disabled CPU devices with firmware before 3.3.12 allow remote attackers…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2016-4785

Published May 31, 2016

A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP for EN100 Ethernet module : Al…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2016-4784

Published May 31, 2016

A vulnerability has been identified in firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP for EN100 Ethernet module : Al…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2016-3963

Published Apr 8, 2016

Siemens SCALANCE S613 allows remote attackers to cause a denial of service (web-server outage) via traffic to TCP port 443.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-3155

Published Mar 18, 2016

Siemens APOGEE Insight uses weak permissions for the application folder, which allows local users to obtain sensitive information or modify data via unspecified vectors.

CVSS 3.4 · Low
Vendor/product tagsBeta · best-effort

CVE-2015-8214

Published Nov 27, 2015

A vulnerability has been identified in SIMATIC NET CP 342-5 (incl. SIPLUS variants) (All versions), SIMATIC NET CP 343-1 Advanced (incl. SIPLUS variants) (All versions < V3.0.44),…

CVSS 9.7 · Critical

CVE-2015-7836

Published Oct 28, 2015

Siemens RUGGEDCOM ROS before 4.2.1 allows remote attackers to obtain sensitive information by sniffing the network for VLAN data within the padding section of an Ethernet frame.

CVSS 3.3 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-6675

Published Sep 11, 2015

Siemens RUGGEDCOM ROS 3.8.0 through 4.1.x permanently enables the IP forwarding feature, which allows remote attackers to bypass a VLAN isolation protection mechanism via IP traff…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-5717

Published Aug 31, 2015

The Siemens COMPAS Mobile application before 1.6 for Android does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof server…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5386

Published Jul 16, 2015

Siemens SICAM MIC devices with firmware before 2404 allow remote attackers to bypass authentication and obtain administrative access via unspecified HTTP requests.

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-4174

Published Jun 28, 2015

Cross-site scripting (XSS) vulnerability in the integrated web server on the Siemens Climatix BACnet/IP communication module with firmware before 10.34 allows remote attackers to…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1,951-1,975 of 2,146 CVEsPage 79 of 86