Vulnerabilities > Siemens

DATE CVE VULNERABILITY TITLE RISK
2021-11-14 CVE-2021-41057 Link Following vulnerability in multiple products
In WIBU CodeMeter Runtime before 7.30a, creating a crafted CmDongles symbolic link will overwrite the linked file without checking permissions.
local
low complexity
wibu siemens CWE-59
7.1
2021-11-14 CVE-2021-43336 Out-of-bounds Write vulnerability in multiple products
An Out-of-Bounds Write vulnerability exists when reading a DXF or DWG file using Open Design Alliance Drawings SDK before 2022.11.
local
low complexity
opendesign siemens CWE-787
7.8
2021-11-11 CVE-2002-20001 Resource Exhaustion vulnerability in multiple products
The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack.
network
low complexity
balasys siemens suse f5 hpe stormshield CWE-400
7.5
2021-11-09 CVE-2020-10052 Unspecified vulnerability in Siemens Simatic Rtls Locating Manager 2.10/2.10.2/2.9.3
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.12).
local
low complexity
siemens
5.5
2021-11-09 CVE-2020-10053 Unspecified vulnerability in Siemens Simatic Rtls Locating Manager 2.10/2.10.2/2.9.3
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.12).
local
low complexity
siemens
5.5
2021-11-09 CVE-2020-10054 Unspecified vulnerability in Siemens Simatic Rtls Locating Manager 2.10/2.10.2/2.9.3
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.12).
local
low complexity
siemens
5.5
2021-11-09 CVE-2021-31344 Unspecified vulnerability in Siemens products
A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303), PLUSCONTROL 1st Gen (All versions), SIMOTICS CONNECT 400 (All versions < V0.5.0.0), SIMOTICS CONNECT 400 (All versions < V1.0.0.0).
network
low complexity
siemens
5.3
2021-11-09 CVE-2021-31345 Unspecified vulnerability in Siemens products
A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303), PLUSCONTROL 1st Gen (All versions).
network
low complexity
siemens
critical
9.1
2021-11-09 CVE-2021-31346 Unspecified vulnerability in Siemens products
A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303), PLUSCONTROL 1st Gen (All versions), SIMOTICS CONNECT 400 (All versions < V0.5.0.0), SIMOTICS CONNECT 400 (All versions < V1.0.0.0).
network
low complexity
siemens
critical
9.1
2021-11-09 CVE-2021-31881 Unspecified vulnerability in Siemens products
A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303).
network
low complexity
siemens
7.5