Vulnerabilities > Siemens > High

DATE CVE VULNERABILITY TITLE RISK
2018-07-03 CVE-2018-4851 Improper Input Validation vulnerability in Siemens Siclock Tc100 Firmware and Siclock Tc400 Firmware
A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions).
network
low complexity
siemens CWE-20
8.2
2018-06-26 CVE-2018-4860 OS Command Injection vulnerability in Siemens Scalance M875 Firmware
A vulnerability has been identified in SCALANCE M875 (All versions).
network
low complexity
siemens CWE-78
7.2
2018-06-26 CVE-2018-4859 OS Command Injection vulnerability in Siemens Scalance M875 Firmware
A vulnerability has been identified in SCALANCE M875 (All versions).
network
low complexity
siemens CWE-78
7.2
2018-06-26 CVE-2018-4845 Improper Privilege Management vulnerability in Siemens products
A vulnerability has been identified in RAPIDLab 1200 systems / RAPIDPoint 400 systems / RAPIDPoint 500 systems (All versions_without_ use of Siemens Healthineers Informatics products), RAPIDLab 1200 Series (All versions < V3.3 _with_ Siemens Healthineers Informatics products), RAPIDPoint 500 systems (All versions >= V3.0 _with_ Siemens Healthineers Informatics products), RAPIDPoint 500 systems (V2.4.X_with_ Siemens Healthineers Informatics products), RAPIDPoint 500 systems (All versions =< V2.3 _with_ Siemens Healthineers Informatics products), RAPIDPoint 400 systems (All versions _with_ Siemens Healthineers Informatics products).
network
low complexity
siemens CWE-269
8.8
2018-06-26 CVE-2018-11449 Unspecified vulnerability in Siemens Scalance M875 Firmware
A vulnerability has been identified in SCALANCE M875 (All versions).
local
low complexity
siemens
7.8
2018-06-26 CVE-2018-11447 Cross-Site Request Forgery (CSRF) vulnerability in Siemens Scalance M875 Firmware
A vulnerability has been identified in SCALANCE M875 (All versions).
network
low complexity
siemens CWE-352
8.8
2018-06-14 CVE-2018-4833 Heap-based Buffer Overflow vulnerability in Siemens products
A vulnerability has been identified in RFID 181EIP (All versions), RUGGEDCOM Win (V4.4, V4.5, V5.0, and V5.1), SCALANCE X-200 switch family (incl.
low complexity
siemens CWE-122
8.8
2018-05-16 CVE-2018-4850 Unspecified vulnerability in Siemens Simatic S7-400 Firmware and Simatic S7-400H Firmware
A vulnerability has been identified in SIMATIC S7-400 (incl.
network
low complexity
siemens
7.5
2018-05-03 CVE-2018-4849 Improper Certificate Validation vulnerability in Siemens Siveillance VMS Video
A vulnerability has been identified in Siveillance VMS Video for Android (All versions < V12.1a (2018 R1)), Siveillance VMS Video for iOS (All versions < V12.1a (2018 R1)).
network
high complexity
siemens CWE-295
7.4
2018-04-30 CVE-2018-7891 Deserialization of Untrusted Data vulnerability in multiple products
The Milestone XProtect Video Management Software (Corporate, Expert, Professional+, Express+, Essential+) 2016 R1 (10.0.a) to 2018 R1 (12.1a) contains .NET Remoting endpoints that are vulnerable to deserialization attacks resulting in remote code execution.
network
high complexity
milestonesys siemens CWE-502
8.1