Vulnerabilities > Siemens > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-12-14 CVE-2019-19283 Unspecified vulnerability in Siemens XHQ 6.0.0.0/6.0.0.2
A vulnerability has been identified in XHQ (All Versions < 6.1).
network
low complexity
siemens
5.3
2020-12-08 CVE-2020-1971 NULL Pointer Dereference vulnerability in multiple products
The X.509 GeneralName type is a generic type for representing different types of names.
5.9
2020-11-12 CVE-2020-8745 Insufficient control flow management in subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25 , Intel(R) TXE versions before 3.1.80 and 4.0.30 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
low complexity
intel siemens
6.8
2020-11-12 CVE-2020-8698 Exposure of Resource to Wrong Sphere vulnerability in multiple products
Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
5.5
2020-11-12 CVE-2020-0591 Improper buffer restrictions in BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
local
low complexity
intel siemens
6.7
2020-11-06 CVE-2020-28168 Server-Side Request Forgery (SSRF) vulnerability in multiple products
Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.
network
high complexity
axios siemens CWE-918
5.9
2020-10-22 CVE-2018-18508 NULL Pointer Dereference vulnerability in multiple products
In Network Security Services (NSS) before 3.36.7 and before 3.41.1, a malformed signature can cause a crash due to a null dereference, resulting in a Denial of Service.
network
low complexity
mozilla siemens CWE-476
6.5
2020-10-15 CVE-2020-15794 Information Exposure Through an Error Message vulnerability in Siemens Desigo Insight 4.0/5.0/6.0
A vulnerability has been identified in Desigo Insight (All versions).
network
low complexity
siemens CWE-209
4.3
2020-10-15 CVE-2020-15793 Unspecified vulnerability in Siemens Desigo Insight 4.0/5.0/6.0
A vulnerability has been identified in Desigo Insight (All versions).
network
low complexity
siemens
5.4
2020-10-15 CVE-2020-15792 Unspecified vulnerability in Siemens Desigo Insight 4.0/5.0/6.0
A vulnerability has been identified in Desigo Insight (All versions).
network
low complexity
siemens
4.3