Vulnerabilities > Siemens > High

DATE CVE VULNERABILITY TITLE RISK
2021-08-19 CVE-2020-35683 Out-of-bounds Read vulnerability in multiple products
An issue was discovered in HCC Nichestack 3.0.
network
low complexity
hcc-embedded siemens CWE-125
7.5
2021-08-19 CVE-2020-35684 Improper Input Validation vulnerability in multiple products
An issue was discovered in HCC Nichestack 3.0.
network
low complexity
hcc-embedded siemens CWE-20
7.5
2021-08-19 CVE-2021-31401 Improper Input Validation vulnerability in multiple products
An issue was discovered in tcp_rcv() in nptcp.c in HCC embedded InterNiche 4.0.1.
network
low complexity
hcc-embedded siemens CWE-20
7.5
2021-08-16 CVE-2021-22940 Use After Free vulnerability in multiple products
Node.js before 16.6.1, 14.17.5, and 12.22.5 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior.
network
low complexity
nodejs oracle netapp siemens debian CWE-416
7.5
2021-08-10 CVE-2021-25659 Resource Exhaustion vulnerability in Siemens Automation License Manager
A vulnerability has been identified in Automation License Manager 5 (All versions), Automation License Manager 6 (All versions < V6.0 SP9 Update 2).
network
low complexity
siemens CWE-400
7.5
2021-08-10 CVE-2021-33721 OS Command Injection vulnerability in Siemens Sinec Network Management System 1.0
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2).
network
low complexity
siemens CWE-78
7.2
2021-08-10 CVE-2021-37172 Improper Authentication vulnerability in Siemens products
A vulnerability has been identified in SIMATIC S7-1200 CPU family (incl.
network
low complexity
siemens CWE-287
7.5
2021-08-10 CVE-2021-37179 Use After Free vulnerability in Siemens Solid Edge Se2021 Firmware
A vulnerability has been identified in Solid Edge SE2021 (All Versions < SE2021MP7).
local
low complexity
siemens CWE-416
7.8
2021-08-10 CVE-2021-37180 Access of Uninitialized Pointer vulnerability in Siemens Solid Edge Se2021 Firmware
A vulnerability has been identified in Solid Edge SE2021 (All Versions < SE2021MP7).
local
low complexity
siemens CWE-824
7.8
2021-08-05 CVE-2021-22926 Improper Certificate Validation vulnerability in multiple products
libcurl-using applications can ask for a specific client certificate to be used in a transfer.
network
low complexity
haxx netapp oracle siemens splunk CWE-295
7.5