Vulnerabilities > Siemens

DATE CVE VULNERABILITY TITLE RISK
2022-03-08 CVE-2021-41543 Information Exposure Through Log Files vulnerability in Siemens Climatix Pol909 Firmware 11.34/11.42
A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.44), Climatix POL909 (AWM module) (All versions < V11.36).
network
low complexity
siemens CWE-532
6.5
2022-03-08 CVE-2021-44478 Cross-site Scripting vulnerability in Siemens Polarion ALM and Polarion Subversion Webclient
A vulnerability has been identified in Polarion ALM (All versions < V21 R2 P2), Polarion WebClient for SVN (All versions).
network
low complexity
siemens CWE-79
6.1
2022-03-08 CVE-2022-24408 Improper Privilege Management vulnerability in Siemens Sinumerik MC Firmware and Sinumerik ONE Firmware
A vulnerability has been identified in SINUMERIK MC (All versions < V1.15 SP1), SINUMERIK ONE (All versions < V6.15 SP1).
local
low complexity
siemens CWE-269
7.8
2022-03-08 CVE-2022-24661 Out-of-bounds Write vulnerability in Siemens Simcenter Star-Ccm+ Viewer 2021.2.1/2021.3.1
A vulnerability has been identified in Simcenter STAR-CCM+ Viewer (All versions < V2022.1).
local
low complexity
siemens CWE-787
7.8
2022-02-22 CVE-2021-46162 Out-of-bounds Write vulnerability in Siemens Simcenter Femap 2020.2/2021.1/2022.1.0
A vulnerability has been identified in Simcenter Femap (All versions < V2022.1.1).
local
low complexity
siemens CWE-787
7.8
2022-02-22 CVE-2021-46699 Out-of-bounds Write vulnerability in Siemens Simcenter Femap 2020.2/2021.1/2022.1.0
A vulnerability has been identified in Simcenter Femap (All versions < V2022.1.1).
local
low complexity
siemens CWE-787
7.8
2022-02-18 CVE-2022-25313 Uncontrolled Recursion vulnerability in multiple products
In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.
6.5
2022-02-18 CVE-2022-25314 Integer Overflow or Wraparound vulnerability in multiple products
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.
7.5
2022-02-18 CVE-2022-25315 Integer Overflow or Wraparound vulnerability in multiple products
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.
network
low complexity
libexpat-project debian fedoraproject oracle siemens CWE-190
critical
9.8
2022-02-16 CVE-2022-25235 Improper Encoding or Escaping of Output vulnerability in multiple products
xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.
network
low complexity
libexpat-project debian fedoraproject oracle siemens CWE-116
critical
9.8