Vulnerabilities > Siemens > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-04-12 CVE-2022-28662 Out-of-bounds Write vulnerability in Siemens Simcenter Femap
A vulnerability has been identified in Simcenter Femap (All versions < V2022.1.2).
network
low complexity
siemens CWE-787
6.5
2022-03-23 CVE-2022-0396 Improper Resource Shutdown or Release vulnerability in multiple products
BIND 9.16.11 -> 9.16.26, 9.17.0 -> 9.18.0 and versions 9.16.11-S1 -> 9.16.26-S1 of the BIND Supported Preview Edition.
network
low complexity
isc fedoraproject netapp siemens CWE-404
5.3
2022-03-21 CVE-2021-45117 NULL Pointer Dereference vulnerability in multiple products
The OPC autogenerated ANSI C stack stubs (in the NodeSets) do not handle all error cases.
network
low complexity
opcfoundation siemens CWE-476
6.5
2022-03-08 CVE-2021-41541 Cross-site Scripting vulnerability in Siemens Climatix Pol909 Firmware 11.34/11.42
A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.44), Climatix POL909 (AWM module) (All versions < V11.36).
network
low complexity
siemens CWE-79
6.1
2022-03-08 CVE-2021-41542 Cross-site Scripting vulnerability in Siemens Climatix Pol909 Firmware 11.34/11.42
A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.44), Climatix POL909 (AWM module) (All versions < V11.36).
network
low complexity
siemens CWE-79
6.1
2022-03-08 CVE-2021-41543 Information Exposure Through Log Files vulnerability in Siemens Climatix Pol909 Firmware 11.34/11.42
A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.44), Climatix POL909 (AWM module) (All versions < V11.36).
network
low complexity
siemens CWE-532
6.5
2022-03-08 CVE-2021-44478 Cross-site Scripting vulnerability in Siemens Polarion ALM and Polarion Subversion Webclient
A vulnerability has been identified in Polarion ALM (All versions < V21 R2 P2), Polarion WebClient for SVN (All versions).
network
low complexity
siemens CWE-79
6.1
2022-02-18 CVE-2022-25313 Uncontrolled Recursion vulnerability in multiple products
In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.
6.5
2022-02-09 CVE-2021-45106 Use of Hard-coded Credentials vulnerability in Siemens Sicam Toolbox II
A vulnerability has been identified in SICAM TOOLBOX II (All versions).
network
low complexity
siemens CWE-798
6.5
2022-02-09 CVE-2022-23102 Open Redirect vulnerability in Siemens Sinema Remote Connect Server
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0).
network
low complexity
siemens CWE-601
6.1