Vulnerabilities > Siemens

DATE CVE VULNERABILITY TITLE RISK
2018-02-19 CVE-2018-5381 Infinite Loop vulnerability in multiple products
The Quagga BGP daemon (bgpd) prior to version 1.2.3 has a bug in its parsing of "Capabilities" in BGP OPEN messages, in the bgp_packet.c:bgp_capability_msg_parse function.
network
low complexity
quagga canonical debian siemens CWE-835
7.5
2018-02-19 CVE-2018-5380 Out-of-bounds Read vulnerability in multiple products
The Quagga BGP daemon (bgpd) prior to version 1.2.3 can overrun internal BGP code-to-string conversion tables used for debug by 1 pointer value, based on input.
network
low complexity
quagga debian canonical siemens CWE-125
4.3
2018-02-19 CVE-2018-5379 Double Free vulnerability in multiple products
The Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free memory when processing certain forms of UPDATE message, containing cluster-list and/or unknown attributes.
network
low complexity
quagga debian canonical redhat siemens CWE-415
critical
9.8
2018-01-25 CVE-2018-4837 Unspecified vulnerability in Siemens Telecontrol Server Basic 3.0
A vulnerability has been identified in TeleControl Server Basic < V3.1.
network
low complexity
siemens
7.5
2018-01-25 CVE-2018-4836 Unspecified vulnerability in Siemens Telecontrol Server Basic 3.0
A vulnerability has been identified in TeleControl Server Basic < V3.1.
network
low complexity
siemens
8.8
2018-01-25 CVE-2018-4835 Information Exposure vulnerability in Siemens Telecontrol Server Basic 3.0
A vulnerability has been identified in TeleControl Server Basic < V3.1.
network
low complexity
siemens CWE-200
5.3
2018-01-04 CVE-2017-5753 Information Exposure Through Discrepancy vulnerability in multiple products
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
5.6
2018-01-04 CVE-2017-5715 Information Exposure Through Discrepancy vulnerability in multiple products
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
5.6
2017-12-27 CVE-2017-9944 Improper Privilege Management vulnerability in Siemens 7KT Pac1200 Data Manager Firmware
A vulnerability has been identified in Siemens 7KT PAC1200 data manager (7KT1260) in all versions < V2.03.
network
low complexity
siemens CWE-269
critical
9.8
2017-12-26 CVE-2017-12741 Unspecified vulnerability in Siemens products
Specially crafted packets sent to port 161/udp could cause a denial of service condition.
network
low complexity
siemens
7.5