Vulnerabilities > Siemens > Medium

DATE CVE VULNERABILITY TITLE RISK
2016-02-08 CVE-2016-2201 Improper Input Validation vulnerability in Siemens Simatic S7-1500 CPU Firmware 1.8.2
Siemens SIMATIC S7-1500 CPU devices before 1.8.3 allow remote attackers to bypass a replay protection mechanism via packets on TCP port 102.
network
low complexity
siemens CWE-20
5.3
2016-01-30 CVE-2016-1488 Cross-site Scripting vulnerability in Siemens Ozw672 Firmware and Ozw772 Firmware
Cross-site scripting (XSS) vulnerability in the login form in the integrated web server on Siemens OZW OZW672 devices before 6.00 and OZW772 devices before 6.00 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
network
low complexity
siemens CWE-79
6.1