Vulnerabilities > Siemens > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-12-12 CVE-2019-18288 Unrestricted Upload of File with Dangerous Type vulnerability in Siemens Sppa-T3000 Application Server R8.2
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2).
network
low complexity
siemens CWE-434
6.5
2019-12-12 CVE-2019-18287 Information Exposure vulnerability in Siemens Sppa-T3000 Application Server R8.2
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2).
network
low complexity
siemens CWE-200
5.0
2019-12-12 CVE-2019-18286 Information Exposure vulnerability in Siemens Sppa-T3000 Application Server R8.2
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2).
network
low complexity
siemens CWE-200
5.0
2019-12-12 CVE-2019-18285 Cleartext Transmission of Sensitive Information vulnerability in Siemens Sppa-T3000 Application Server R8.2
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2).
network
siemens CWE-319
4.3
2019-12-12 CVE-2019-18284 Missing Authentication for Critical Function vulnerability in Siemens Sppa-T3000 Application Server R8.2
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2).
network
low complexity
siemens CWE-306
5.0
2019-12-12 CVE-2019-13947 Cleartext Storage of Sensitive Information in GUI vulnerability in Siemens products
A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0).
network
low complexity
siemens CWE-317
4.9
2019-12-12 CVE-2019-13944 Path Traversal vulnerability in Siemens products
A vulnerability has been identified in EN100 Ethernet module DNP3 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.37), EN100 Ethernet module IEC104 variant (All versions), EN100 Ethernet module Modbus TCP variant (All versions), EN100 Ethernet module PROFINET IO variant (All versions).
network
low complexity
siemens CWE-22
5.3
2019-12-12 CVE-2019-13943 Cross-site Scripting vulnerability in Siemens products
A vulnerability has been identified in EN100 Ethernet module DNP3 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.37), EN100 Ethernet module IEC104 variant (All versions), EN100 Ethernet module Modbus TCP variant (All versions), EN100 Ethernet module PROFINET IO variant (All versions).
network
low complexity
siemens CWE-79
6.1
2019-12-12 CVE-2019-13932 Improper Input Validation vulnerability in Siemens XHQ 6.0.0.0
A vulnerability has been identified in XHQ (All versions < V6.0.0.2).
network
low complexity
siemens CWE-20
6.4
2019-12-12 CVE-2019-13930 Cross-Site Request Forgery (CSRF) vulnerability in Siemens XHQ 6.0.0.0
A vulnerability has been identified in XHQ (All versions < V6.0.0.2).
network
siemens CWE-352
5.8