Vulnerabilities > Siemens

DATE CVE VULNERABILITY TITLE RISK
2019-04-17 CVE-2018-16559 Improper Input Validation vulnerability in Siemens Simatic S7-1500 Firmware
A vulnerability has been identified in SIMATIC S7-1500 CPU (All versions >= V2.0 and < V2.5), SIMATIC S7-1500 CPU (All versions <= V1.8.5).
network
low complexity
siemens CWE-20
7.8
2019-04-17 CVE-2018-16558 Improper Input Validation vulnerability in Siemens Simatic S7-1500 Firmware
A vulnerability has been identified in SIMATIC S7-1500 CPU (All versions >= V2.0 and < V2.5), SIMATIC S7-1500 CPU (All versions <= V1.8.5).
network
low complexity
siemens CWE-20
7.8
2019-04-17 CVE-2018-13810 Cross-Site Request Forgery (CSRF) vulnerability in Siemens CP 1604 Firmware and CP 1616 Firmware
A vulnerability has been identified in CP 1604 (All versions), CP 1616 (All versions).
network
siemens CWE-352
4.3
2019-04-17 CVE-2018-13809 Cross-site Scripting vulnerability in Siemens CP 1604 Firmware and CP 1616 Firmware
A vulnerability has been identified in CP 1604 (All versions), CP 1616 (All versions).
network
siemens CWE-79
4.3
2019-04-17 CVE-2018-13808 Information Exposure vulnerability in Siemens CP 1604 Firmware and CP 1616 Firmware
A vulnerability has been identified in CP 1604 (All versions), CP 1616 (All versions).
network
low complexity
siemens CWE-200
6.4
2019-03-26 CVE-2019-6569 Expected Behavior Violation vulnerability in Siemens products
The monitor barrier of the affected products insufficiently blocks data from being forwarded over the mirror port into the mirrored network.
network
low complexity
siemens CWE-440
6.4
2019-03-21 CVE-2018-13798 Improper Input Validation vulnerability in Siemens products
A vulnerability has been identified in SICAM A8000 CP-8000 (All versions < V14), SICAM A8000 CP-802X (All versions < V14), SICAM A8000 CP-8050 (All versions < V2.00).
network
low complexity
siemens CWE-20
7.8
2019-03-21 CVE-2018-16563 Unspecified vulnerability in Siemens products
A vulnerability has been identified in Firmware variant IEC 61850 for EN100 Ethernet module (All versions < V4.35), Firmware variant MODBUS TCP for EN100 Ethernet module (All versions), Firmware variant DNP3 TCP for EN100 Ethernet module (All versions), Firmware variant IEC104 for EN100 Ethernet module (All versions), Firmware variant Profinet IO for EN100 Ethernet module (All versions), SIPROTEC 5 relays with CPU variants CP300 and CP100 and the respective Ethernet communication modules (All versions < V7.82), SIPROTEC 5 relays with CPU variants CP200 and the respective Ethernet communication modules (All versions < V7.58).
network
siemens
4.3
2019-03-08 CVE-2019-8277 Improper Initialization vulnerability in multiple products
UltraVNC revision 1211 contains multiple memory leaks (CWE-665) in VNC server code, which allows an attacker to read stack memory and can be abused for information disclosure.
network
low complexity
uvnc siemens CWE-665
5.0
2019-03-08 CVE-2019-8276 Out-of-bounds Write vulnerability in multiple products
UltraVNC revision 1211 has a stack buffer overflow vulnerability in VNC server code inside file transfer request handler, which can result in Denial of Service (DoS).
network
low complexity
uvnc siemens CWE-787
5.0