Vulnerabilities > Siemens

DATE CVE VULNERABILITY TITLE RISK
2021-09-28 CVE-2021-41539 Unspecified vulnerability in Siemens Solid Edge Se2020/Se2021
A vulnerability has been identified in Solid Edge SE2021 (All versions < SE2021MP8).
local
low complexity
siemens
7.8
2021-09-28 CVE-2021-41540 Unspecified vulnerability in Siemens Solid Edge Se2020/Se2021
A vulnerability has been identified in Solid Edge SE2021 (All versions < SE2021MP8).
local
low complexity
siemens
7.8
2021-09-23 CVE-2021-22945 Double Free vulnerability in multiple products
When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call to send data and also free it *again*.
network
low complexity
haxx fedoraproject netapp oracle apple siemens debian splunk CWE-415
critical
9.1
2021-09-16 CVE-2021-34798 NULL Pointer Dereference vulnerability in multiple products
Malformed requests may cause the server to dereference a NULL pointer.
7.5
2021-09-16 CVE-2021-39275 Out-of-bounds Write vulnerability in multiple products
ap_escape_quotes() may write beyond the end of a buffer when given malicious input.
network
low complexity
apache fedoraproject debian netapp oracle siemens CWE-787
critical
9.8
2021-09-16 CVE-2021-40438 Server-Side Request Forgery (SSRF) vulnerability in multiple products
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.
9.0
2021-09-14 CVE-2019-10941 Missing Authentication for Critical Function vulnerability in Siemens Sinema Server 12.0/13.0/14.0
A vulnerability has been identified in SINEMA Server (All versions < V14 SP3).
network
low complexity
siemens CWE-306
5.3
2021-09-14 CVE-2021-25665 Unspecified vulnerability in Siemens Simcenter Star-Ccm+
A vulnerability has been identified in Simcenter STAR-CCM+ Viewer (All versions < V2021.2.1).
local
low complexity
siemens
7.8
2021-09-14 CVE-2021-27391 Unspecified vulnerability in Siemens products
A vulnerability has been identified in APOGEE MBC (PPC) (P2 Ethernet) (All versions >= V2.6.3), APOGEE MEC (PPC) (P2 Ethernet) (All versions >= V2.6.3), APOGEE PXC Compact (BACnet) (All versions < V3.5.3), APOGEE PXC Compact (P2 Ethernet) (All versions >= V2.8), APOGEE PXC Modular (BACnet) (All versions < V3.5.3), APOGEE PXC Modular (P2 Ethernet) (All versions >= V2.8), TALON TC Compact (BACnet) (All versions < V3.5.3), TALON TC Modular (BACnet) (All versions < V3.5.3).
network
low complexity
siemens
critical
9.8
2021-09-14 CVE-2021-31891 Unspecified vulnerability in Siemens products
A vulnerability has been identified in Desigo CC (All versions with OIS Extension Module), GMA-Manager (All versions with OIS running on Debian 9 or earlier), Operation Scheduler (All versions with OIS running on Debian 9 or earlier), Siveillance Control (All versions with OIS running on Debian 9 or earlier), Siveillance Control Pro (All versions).
network
low complexity
siemens
critical
10.0