Vulnerabilities > Siemens

DATE CVE VULNERABILITY TITLE RISK
2022-02-16 CVE-2022-25236 Exposure of Resource to Wrong Sphere vulnerability in multiple products
xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.
network
low complexity
libexpat-project debian oracle siemens CWE-668
critical
9.8
2022-02-09 CVE-2021-37194 Unrestricted Upload of File with Dangerous Type vulnerability in Siemens Comos
A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web components are used), COMOS V10.4 (All versions < V10.4.1 only if web components are used).
network
low complexity
siemens CWE-434
7.5
2022-02-09 CVE-2021-40360 Insufficiently Protected Credentials vulnerability in Siemens Simatic PCS 7 and Simatic Wincc
A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP1), SIMATIC WinCC V15 and earlier (All versions < V15 SP1 Update 7), SIMATIC WinCC V16 (All versions < V16 Update 5), SIMATIC WinCC V17 (All versions < V17 Update 2), SIMATIC WinCC V7.4 (All versions < V7.4 SP1 Update 19), SIMATIC WinCC V7.5 (All versions < V7.5 SP2 Update 6).
network
low complexity
siemens CWE-522
8.8
2022-02-09 CVE-2021-40363 Unspecified vulnerability in Siemens Simatic PCS 7 and Simatic Wincc
A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP1), SIMATIC WinCC V15 and earlier (All versions < V15 SP1 Update 7), SIMATIC WinCC V16 (All versions < V16 Update 5), SIMATIC WinCC V17 (All versions < V17 Update 2), SIMATIC WinCC V17 (All versions <= V17 Update 4), SIMATIC WinCC V7.4 (All versions < V7.4 SP1 Update 19), SIMATIC WinCC V7.5 (All versions < V7.5 SP2 Update 6).
local
low complexity
siemens
7.8
2022-02-09 CVE-2021-44000 Out-of-bounds Write vulnerability in Siemens Jt2Go, Solid Edge and Teamcenter Visualization
A vulnerability has been identified in JT2Go (All versions < V13.2.0.7), Solid Edge SE2021 (All versions < SE2021MP9), Solid Edge SE2022 (All versions < SE2022MP1), Teamcenter Visualization V13.1 (All versions < V13.1.0.9), Teamcenter Visualization V13.2 (All versions < V13.2.0.7), Teamcenter Visualization V13.3 (All versions < V13.3.0.1).
local
low complexity
siemens CWE-787
7.8
2022-02-09 CVE-2021-44016 Out-of-bounds Write vulnerability in Siemens Jt2Go, Solid Edge and Teamcenter Visualization
A vulnerability has been identified in JT2Go (All versions < V13.2.0.7), Solid Edge SE2021 (All versions < SE2021MP9), Solid Edge SE2022 (All versions < SE2022MP1), Teamcenter Visualization V13.1 (All versions < V13.1.0.9), Teamcenter Visualization V13.2 (All versions < V13.2.0.7), Teamcenter Visualization V13.3 (All versions < V13.3.0.1).
local
low complexity
siemens CWE-787
7.8
2022-02-09 CVE-2021-44018 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Siemens Jt2Go, Solid Edge and Teamcenter Visualization
A vulnerability has been identified in JT2Go (All versions < V13.2.0.7), Solid Edge SE2021 (All versions < SE2021MP9), Solid Edge SE2022 (All versions < SE2022MP1), Teamcenter Visualization V13.1 (All versions < V13.1.0.9), Teamcenter Visualization V13.2 (All versions < V13.2.0.7), Teamcenter Visualization V13.3 (All versions < V13.3.0.1).
local
low complexity
siemens CWE-119
7.8
2022-02-09 CVE-2021-45106 Use of Hard-coded Credentials vulnerability in Siemens Sicam Toolbox II
A vulnerability has been identified in SICAM TOOLBOX II (All versions).
network
low complexity
siemens CWE-798
6.5
2022-02-09 CVE-2021-46151 Out-of-bounds Write vulnerability in Siemens Simcenter Femap 2020.2/2021.1
A vulnerability has been identified in Simcenter Femap V2020.2 (All versions), Simcenter Femap V2021.1 (All versions).
local
low complexity
siemens CWE-787
7.8
2022-02-09 CVE-2021-46152 Type Confusion vulnerability in Siemens Simcenter Femap 2020.2/2021.1
A vulnerability has been identified in Simcenter Femap V2020.2 (All versions), Simcenter Femap V2021.1 (All versions).
local
low complexity
siemens CWE-843
7.8