Vulnerabilities > Siemens > Automation License Manager

DATE CVE VULNERABILITY TITLE RISK
2012-01-08 CVE-2011-4532 Path Traversal vulnerability in Siemens Automation License Manager 5.1
Absolute path traversal vulnerability in the ALMListView.ALMListCtrl ActiveX control in almaxcx.dll in the graphical user interface in Siemens Automation License Manager (ALM) 2.0 through 5.1+SP1+Upd2 allows remote attackers to overwrite arbitrary files via the Save method.
network
low complexity
siemens CWE-22
5.0
2012-01-08 CVE-2011-4531 Improper Input Validation vulnerability in Siemens Automation License Manager 5.1
Siemens Automation License Manager (ALM) 4.0 through 5.1+SP1+Upd1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via crafted content in a (1) get_target_ocx_param or (2) send_target_ocx_param command.
network
low complexity
siemens CWE-20
5.0
2012-01-08 CVE-2011-4530 Improper Input Validation vulnerability in Siemens Automation License Manager 5.1
Siemens Automation License Manager (ALM) 4.0 through 5.1+SP1+Upd1 does not properly copy fields obtained from clients, which allows remote attackers to cause a denial of service (exception and daemon crash) via long fields, as demonstrated by fields to the (1) open_session->workstation->NAME or (2) grant->VERSION function.
network
low complexity
siemens CWE-20
5.0
2012-01-08 CVE-2011-4529 Buffer Errors vulnerability in Siemens Automation License Manager 5.1
Multiple buffer overflows in Siemens Automation License Manager (ALM) 4.0 through 5.1+SP1+Upd1 allow remote attackers to execute arbitrary code via a long serialid field in an _licensekey command, as demonstrated by the (1) check_licensekey or (2) read_licensekey command.
network
low complexity
siemens CWE-119
7.5