Vulnerabilities > Siemens > High

DATE CVE VULNERABILITY TITLE RISK
2021-11-09 CVE-2021-40366 Cleartext Transmission of Sensitive Information vulnerability in Siemens Climatix Pol909 Firmware
A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.42), Climatix POL909 (AWM module) (All versions < V11.34).
network
high complexity
siemens CWE-319
7.4
2021-11-09 CVE-2021-42021 Path Traversal vulnerability in Siemens products
A vulnerability has been identified in Siveillance Video DLNA Server (2019 R1), Siveillance Video DLNA Server (2019 R2), Siveillance Video DLNA Server (2019 R3), Siveillance Video DLNA Server (2020 R1), Siveillance Video DLNA Server (2020 R2), Siveillance Video DLNA Server (2020 R3), Siveillance Video DLNA Server (2021 R1).
network
low complexity
siemens CWE-22
7.5
2021-10-18 CVE-2021-41990 Integer Overflow or Wraparound vulnerability in multiple products
The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature.
network
low complexity
strongswan debian fedoraproject siemens CWE-190
7.5
2021-10-18 CVE-2021-41991 Integer Overflow or Wraparound vulnerability in multiple products
The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries.
network
low complexity
strongswan debian fedoraproject siemens CWE-190
7.5
2021-10-12 CVE-2021-37732 OS Command Injection vulnerability in multiple products
A remote arbitrary command execution vulnerability was discovered in HPE Aruba Instant (IAP) version(s): Aruba Instant 6.4.x.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x.x: 6.5.4.18 and below; Aruba Instant 8.5.x.x: 8.5.0.11 and below; Aruba Instant 8.6.x.x: 8.6.0.6 and below; Aruba Instant 8.7.x.x: 8.7.1.0 and below.
network
low complexity
arubanetworks siemens CWE-78
7.2
2021-10-12 CVE-2021-37727 OS Command Injection vulnerability in multiple products
A remote arbitrary command execution vulnerability was discovered in HPE Aruba Instant (IAP) version(s): 6.4.x.x: 6.4.4.8-4.2.4.18 and below; Aruba Instant 6.5.x.x: 6.5.4.20 and below; Aruba Instant 8.5.x.x: 8.5.0.12 and below; Aruba Instant 8.6.x.x: 8.6.0.11 and below; Aruba Instant 8.7.x.x: 8.7.1.3 and below.
network
low complexity
arubanetworks siemens CWE-78
7.2
2021-10-12 CVE-2021-37730 OS Command Injection vulnerability in multiple products
A remote arbitrary command execution vulnerability was discovered in HPE Aruba Instant (IAP) version(s): Aruba Instant 6.4.x.x: 6.4.4.8-4.2.4.18 and below; Aruba Instant 6.5.x.x: 6.5.4.20 and below; Aruba Instant 8.5.x.x: 8.5.0.12 and below; Aruba Instant 8.6.x.x: 8.6.0.11 and below; Aruba Instant 8.7.x.x: 8.7.1.3 and below.
network
low complexity
arubanetworks siemens CWE-78
7.2
2021-10-12 CVE-2021-27395 Missing Authentication for Critical Function vulnerability in Siemens products
A vulnerability has been identified in SIMATIC Process Historian 2013 and earlier (All versions), SIMATIC Process Historian 2014 (All versions < SP3 Update 6), SIMATIC Process Historian 2019 (All versions), SIMATIC Process Historian 2020 (All versions).
network
low complexity
siemens CWE-306
8.1
2021-10-12 CVE-2021-33726 Path Traversal vulnerability in Siemens Sinec NMS 1.0
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1).
network
low complexity
siemens CWE-22
7.5
2021-10-12 CVE-2021-33728 Deserialization of Untrusted Data vulnerability in Siemens Sinec NMS 1.0
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1).
network
low complexity
siemens CWE-502
7.2