Vulnerabilities > Siemens > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-01-04 CVE-2017-5715 Information Exposure Through Discrepancy vulnerability in multiple products
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
5.6
2017-12-26 CVE-2017-12740 Insufficient Verification of Data Authenticity vulnerability in Siemens Logo! Soft Comfort
Siemens LOGO! Soft Comfort (All versions before V8.2) lacks integrity verification of software packages downloaded via an unprotected communication channel.
network
high complexity
siemens CWE-345
5.9
2017-12-13 CVE-2017-13099 Information Exposure Through Discrepancy vulnerability in multiple products
wolfSSL prior to version 3.12.2 provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated.
network
high complexity
wolfssl siemens arubanetworks CWE-203
5.9
2017-11-15 CVE-2017-12738 Cross-site Scripting vulnerability in Siemens Sm-2556 Firmware
An issue was discovered on Siemens SICAM RTUs SM-2556 COM Modules with the firmware variants ENOS00, ERAC00, ETA2, ETLS00, MODi00, and DNPi00.
network
low complexity
siemens CWE-79
6.1
2017-11-15 CVE-2017-12737 Information Exposure vulnerability in Siemens Sm-2556 Firmware
An issue was discovered on Siemens SICAM RTUs SM-2556 COM Modules with the firmware variants ENOS00, ERAC00, ETA2, ETLS00, MODi00, and DNPi00.
network
low complexity
siemens CWE-200
5.3
2017-11-06 CVE-2017-14023 Improper Input Validation vulnerability in Siemens Simatic Pcs7 and Simatic Wincc
An Improper Input Validation issue was discovered in Siemens SIMATIC PCS 7 V8.1 prior to V8.1 SP1 with WinCC V7.3 Upd 13, and V8.2 all versions.
network
low complexity
siemens CWE-20
4.9
2017-10-23 CVE-2017-9947 Path Traversal vulnerability in Siemens products
A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions <V3.5.
network
low complexity
siemens CWE-22
5.3
2017-08-30 CVE-2017-9945 Improper Input Validation vulnerability in Siemens 7KM PAC Switched Ethernet Profinet Expansion Module Firmware 2.1.2
In the Siemens 7KM PAC Switched Ethernet PROFINET expansion module (All versions < V2.1.3), a Denial-of-Service condition could be induced by a specially crafted PROFINET DCP packet sent as a local Ethernet (Layer 2) broadcast.
low complexity
siemens CWE-20
6.5
2017-08-08 CVE-2017-6872 Exposure of Resource to Wrong Sphere vulnerability in Siemens Ozw672 Firmware and Ozw772 Firmware
A vulnerability was discovered in Siemens OZW672 (all versions) and OZW772 (all versions) that could allow an attacker with access to port 21/tcp to access or alter historical measurement data stored on the device.
network
low complexity
siemens CWE-668
6.5
2017-08-08 CVE-2017-6871 Improper Authentication vulnerability in Siemens products
A vulnerability was discovered in Siemens SIMATIC WinCC Sm@rtClient for Android (All versions before V1.0.2.2) and SIMATIC WinCC Sm@rtClient for Android Lite (All versions before V1.0.2.2).
low complexity
siemens CWE-287
5.4