Vulnerabilities > Siemens

DATE CVE VULNERABILITY TITLE RISK
2021-09-28 CVE-2021-41538 Access of Uninitialized Pointer vulnerability in Siemens products
A vulnerability has been identified in NX 1953 Series (All versions < V1973.3700), NX 1980 Series (All versions < V1988), Solid Edge SE2021 (All versions < SE2021MP8).
network
siemens CWE-824
4.3
2021-09-28 CVE-2021-41539 Use After Free vulnerability in Siemens Solid Edge Se2021
A vulnerability has been identified in Solid Edge SE2021 (All versions < SE2021MP8).
network
siemens CWE-416
6.8
2021-09-28 CVE-2021-41540 Use After Free vulnerability in Siemens Solid Edge Se2021
A vulnerability has been identified in Solid Edge SE2021 (All versions < SE2021MP8).
network
siemens CWE-416
6.8
2021-09-23 CVE-2021-22945 Double Free vulnerability in multiple products
When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call to send data and also free it *again*.
network
low complexity
haxx fedoraproject netapp oracle apple siemens debian splunk CWE-415
critical
9.1
2021-09-16 CVE-2021-34798 NULL Pointer Dereference vulnerability in multiple products
Malformed requests may cause the server to dereference a NULL pointer.
7.5
2021-09-16 CVE-2021-39275 Out-of-bounds Write vulnerability in multiple products
ap_escape_quotes() may write beyond the end of a buffer when given malicious input.
network
low complexity
apache fedoraproject debian netapp oracle siemens CWE-787
critical
9.8
2021-09-16 CVE-2021-40438 Server-Side Request Forgery (SSRF) vulnerability in multiple products
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.
9.0
2021-09-14 CVE-2019-10941 Missing Authentication for Critical Function vulnerability in Siemens Sinema Server 12.0/13.0/14.0
A vulnerability has been identified in SINEMA Server (All versions < V14 SP3).
network
low complexity
siemens CWE-306
5.0
2021-09-14 CVE-2021-25665 Out-of-bounds Write vulnerability in Siemens Simcenter Star-Ccm+
A vulnerability has been identified in Simcenter STAR-CCM+ Viewer (All versions < V2021.2.1).
network
siemens CWE-787
6.8
2021-09-14 CVE-2021-27391 Classic Buffer Overflow vulnerability in Siemens products
A vulnerability has been identified in APOGEE MBC (PPC) (P2 Ethernet) (All versions >= V2.6.3), APOGEE MEC (PPC) (P2 Ethernet) (All versions >= V2.6.3), APOGEE PXC Compact (BACnet) (All versions < V3.5.3), APOGEE PXC Compact (P2 Ethernet) (All versions >= V2.8), APOGEE PXC Modular (BACnet) (All versions < V3.5.3), APOGEE PXC Modular (P2 Ethernet) (All versions >= V2.8), TALON TC Compact (BACnet) (All versions < V3.5.3), TALON TC Modular (BACnet) (All versions < V3.5.3).
network
low complexity
siemens CWE-120
critical
10.0