Vulnerabilities > Siemens > High

DATE CVE VULNERABILITY TITLE RISK
2018-03-08 CVE-2018-4838 Missing Authentication for Critical Function vulnerability in Siemens products
A vulnerability has been identified in EN100 Ethernet module IEC 61850 variant (All versions < V4.30), EN100 Ethernet module DNP3 variant (All versions < V1.04), EN100 Ethernet module PROFINET IO variant (All versions), EN100 Ethernet module Modbus TCP variant (All versions), EN100 Ethernet module IEC 104 variant (All versions < V1.22).
network
low complexity
siemens CWE-306
7.5
2018-02-19 CVE-2018-5381 Infinite Loop vulnerability in multiple products
The Quagga BGP daemon (bgpd) prior to version 1.2.3 has a bug in its parsing of "Capabilities" in BGP OPEN messages, in the bgp_packet.c:bgp_capability_msg_parse function.
network
low complexity
quagga canonical debian siemens CWE-835
7.5
2018-01-25 CVE-2018-4837 Unspecified vulnerability in Siemens Telecontrol Server Basic 3.0
A vulnerability has been identified in TeleControl Server Basic < V3.1.
network
low complexity
siemens
7.5
2018-01-25 CVE-2018-4836 Unspecified vulnerability in Siemens Telecontrol Server Basic 3.0
A vulnerability has been identified in TeleControl Server Basic < V3.1.
network
low complexity
siemens
8.8
2017-12-26 CVE-2017-12741 Unspecified vulnerability in Siemens products
Specially crafted packets sent to port 161/udp could cause a denial of service condition.
network
low complexity
siemens
7.5
2017-12-26 CVE-2017-12736 Improper Initialization vulnerability in Siemens products
A vulnerability has been identified in RUGGEDCOM ROS for RSL910 devices (All versions < ROS V5.0.1), RUGGEDCOM ROS for all other devices (All versions < ROS V4.3.4), SCALANCE XB-200/XC-200/XP-200/XR300-WG (All versions between V3.0 (including) and V3.0.2 (excluding)), SCALANCE XR-500/XM-400 (All versions between V6.1 (including) and V6.1.1 (excluding)).
low complexity
siemens CWE-665
8.8
2017-11-21 CVE-2017-5712 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Buffer overflow in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allows attacker with remote Admin access to the system to execute arbitrary code with AMT execution privilege.
network
low complexity
intel asus siemens CWE-119
7.2
2017-11-21 CVE-2017-5711 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Multiple buffer overflows in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allow attacker with local access to the system to execute arbitrary code with AMT execution privilege.
local
low complexity
intel asus siemens CWE-119
7.8
2017-10-23 CVE-2017-9946 Improper Authentication vulnerability in Siemens products
A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions <V3.5.
network
low complexity
siemens CWE-287
7.5
2017-08-30 CVE-2017-12735 Unspecified vulnerability in Siemens Logo! 8 BM Firmware
A vulnerability has been identified in LOGO! 8 BM (incl.
network
high complexity
siemens
7.4