Vulnerabilities > Siemens

DATE CVE VULNERABILITY TITLE RISK
2013-03-21 CVE-2011-4515 Credentials Management vulnerability in Siemens Wincc TIA Portal 11.0
Siemens WinCC (TIA Portal) 11 uses a reversible algorithm for storing HMI web-application passwords in world-readable and world-writable files, which allows local users to obtain sensitive information by leveraging (1) physical access or (2) Sm@rt Server access.
local
low complexity
siemens CWE-255
4.6
2013-01-21 CVE-2013-0656 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Siemens Simatic Rf-Manager and Simatic Rf-Manager 2008
Buffer overflow in a third-party ActiveX component in Siemens SIMATIC RF-MANAGER 2008, and RF-MANAGER Basic 3.0 and earlier, allows remote attackers to execute arbitrary code via a crafted web site.
network
siemens CWE-119
6.8
2012-12-23 CVE-2012-4698 Information Exposure vulnerability in Siemens products
Siemens RuggedCom Rugged Operating System (ROS) before 3.12, ROX I OS through 1.14.5, ROX II OS through 2.3.0, and RuggedMax OS through 4.2.1.4621.22 use hardcoded private keys for SSL and SSH communication, which makes it easier for man-in-the-middle attackers to spoof servers and decrypt network traffic by leveraging the availability of these keys within ROS files at all customer installations.
network
siemens CWE-200
4.3
2012-12-18 CVE-2012-4693 Cryptographic Issues vulnerability in multiple products
Invensys Wonderware InTouch 2012 R2 and earlier and Siemens ProcessSuite use a weak encryption algorithm for data in Ps_security.ini, which makes it easier for local users to discover passwords by reading this file.
1.9
2012-12-18 CVE-2012-4691 Resource Management Errors vulnerability in Siemens Automation License Manager 4.0/5.0/5.1
Memory leak in Siemens Automation License Manager (ALM) 4.x and 5.x before 5.2 allows remote attackers to cause a denial of service (memory consumption) via crafted packets.
low complexity
siemens CWE-399
3.3
2012-11-01 CVE-2012-5409 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Siemens Sipass Integrated
AscoServer.exe in the server in Siemens SiPass integrated MP2.6 and earlier does not properly handle IOCP RPC messages received over an Ethernet network, which allows remote attackers to write data to any memory location and consequently execute arbitrary code via crafted messages, as demonstrated by an arbitrary pointer dereference attack or a buffer overflow attack.
network
low complexity
siemens CWE-119
critical
10.0
2012-10-10 CVE-2012-3040 Cross-site Scripting vulnerability in Siemens products
Cross-site scripting (XSS) vulnerability in the web server on Siemens SIMATIC S7-1200 PLCs 2.x through 3.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URI.
network
siemens CWE-79
4.3
2012-09-25 CVE-2012-3037 Improper Certificate Validation vulnerability in Siemens products
The Siemens SIMATIC S7-1200 2.x PLC does not properly protect the private key of the SIMATIC CONTROLLER Certification Authority certificate, which allows remote attackers to spoof the S7-1200 web server by using this key to create a forged certificate.
network
siemens CWE-295
4.3
2012-09-18 CVE-2012-3034 Information Exposure vulnerability in Siemens Simatic Pcs7 and Wincc
WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers to discover a username and password via crafted parameters to unspecified methods in ActiveX controls.
network
siemens CWE-200
4.3
2012-09-18 CVE-2012-3032 SQL Injection vulnerability in Siemens Simatic Pcs7 and Wincc
SQL injection vulnerability in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers to execute arbitrary SQL commands via a crafted SOAP message.
network
low complexity
siemens CWE-89
7.5