Vulnerabilities > Siemens > Critical

DATE CVE VULNERABILITY TITLE RISK
2017-11-15 CVE-2017-12739 Insecure Default Initialization of Resource vulnerability in Siemens Sm-2556 Firmware
An issue was discovered on Siemens SICAM RTUs SM-2556 COM Modules with the firmware variants ENOS00, ERAC00, ETA2, ETLS00, MODi00, and DNPi00.
network
low complexity
siemens CWE-1188
critical
9.8
2017-10-04 CVE-2017-14491 Out-of-bounds Write vulnerability in multiple products
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.
9.8
2017-08-08 CVE-2017-9939 Improper Authentication vulnerability in Siemens Sipass Integrated 2.65
A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with network access to the SiPass integrated server to bypass the authentication mechanism and perform administrative operations.
network
low complexity
siemens CWE-287
critical
9.8
2017-08-08 CVE-2017-6869 Unspecified vulnerability in Siemens Viewport for web Office Portal
A vulnerability was discovered in Siemens ViewPort for Web Office Portal before revision number 1453 that could allow an unauthenticated remote user to upload arbitrary code and execute it with the permissions of the operating-system user running the web server by sending specially crafted network packets to port 443/TCP or port 80/TCP.
network
low complexity
siemens
critical
9.8
2017-08-07 CVE-2015-7705 Improper Input Validation vulnerability in multiple products
The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to have unspecified impact via a large number of crafted requests.
network
low complexity
ntp netapp citrix siemens CWE-20
critical
9.8
2017-02-22 CVE-2017-2684 Unspecified vulnerability in Siemens Simatic Logon 1.5
Siemens SIMATIC Logon prior to V1.5 SP3 Update 2 could allow an attacker with knowledge of a valid user name, and physical or network access to the affected system, to bypass the application-level authentication.
network
high complexity
siemens
critical
9.0
2017-02-13 CVE-2016-8567 Use of Hard-coded Credentials vulnerability in Siemens Sicam Pas/Pqs 7.0
An issue was discovered in Siemens SICAM PAS before 8.00.
network
low complexity
siemens CWE-798
critical
9.8
2016-12-05 CVE-2016-9157 Improper Access Control vulnerability in Siemens Sicam Pas/Pqs
A vulnerability in Siemens SICAM PAS (all versions before V8.09) could allow a remote attacker to cause a Denial of Service condition and potentially lead to unauthenticated remote code execution by sending specially crafted packets to port 19234/TCP.
network
low complexity
siemens CWE-284
critical
9.8
2016-11-22 CVE-2016-9155 Improper Access Control vulnerability in Siemens products
The following SIEMENS branded IP Camera Models CCMW3025, CVMW3025-IR, CFMW3025 prior to version 1.41_SP18_S1; CCPW3025, CCPW5025 prior to version 0.1.73_S1; CCMD3025-DN18 prior to version v1.394_S1; CCID1445-DN18, CCID1445-DN28, CCID1145-DN36, CFIS1425, CCIS1425, CFMS2025, CCMS2025, CVMS2025-IR, CFMW1025, CCMW1025 prior to version v2635_SP1 could allow an attacker with network access to the web server to obtain administrative credentials under certain circumstances.
network
low complexity
siemens CWE-284
critical
9.8
2016-10-13 CVE-2016-8565 Improper Access Control vulnerability in Siemens Automation License Manager 5.3
Siemens Automation License Manager (ALM) before 5.3 SP3 allows remote attackers to write to files, rename files, create directories, or delete directories via crafted packets.
network
low complexity
siemens CWE-284
critical
9.1