Vulnerabilities > Siemens > Medium

DATE CVE VULNERABILITY TITLE RISK
2014-07-24 CVE-2014-4685 Permissions, Privileges, and Access Controls vulnerability in Siemens Simatic Pcs7 and Wincc
Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows local users to gain privileges by leveraging weak system-object access control.
local
low complexity
siemens CWE-264
4.6
2014-07-24 CVE-2014-4684 Permissions, Privileges, and Access Controls vulnerability in Siemens Simatic Pcs7 and Wincc
The database server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote authenticated users to gain privileges via a request to TCP port 1433.
network
siemens CWE-264
6.0
2014-07-24 CVE-2014-4683 Permissions, Privileges, and Access Controls vulnerability in Siemens Simatic Pcs7 and Wincc
The WebNavigator server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote authenticated users to gain privileges via a (1) HTTP or (2) HTTPS request.
network
siemens CWE-264
4.9
2014-07-24 CVE-2014-4682 Information Exposure vulnerability in Siemens Simatic Pcs7 and Wincc
The WebNavigator server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote attackers to obtain sensitive information via an HTTP request.
network
low complexity
siemens CWE-200
5.0
2014-04-25 CVE-2014-2909 Code Injection vulnerability in Siemens products
CRLF injection vulnerability in the integrated web server on Siemens SIMATIC S7-1200 CPU devices 2.x and 3.x allows remote attackers to inject arbitrary HTTP headers via unspecified vectors.
network
siemens CWE-94
5.8
2014-04-25 CVE-2014-2908 Cross-Site Scripting vulnerability in Siemens products
Cross-site scripting (XSS) vulnerability in the integrated web server on Siemens SIMATIC S7-1200 CPU devices 2.x and 3.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
siemens CWE-79
4.3
2014-04-19 CVE-2014-2733 Improper Input Validation vulnerability in Siemens Sinema Server 12.0
Siemens SINEMA Server before 12 SP1 allows remote attackers to cause a denial of service (web-interface outage) via crafted HTTP requests to port (1) 4999 or (2) 80.
network
low complexity
siemens CWE-20
5.0
2014-04-19 CVE-2014-2732 Path Traversal vulnerability in Siemens Sinema Server 12.0
Multiple directory traversal vulnerabilities in the integrated web server in Siemens SINEMA Server before 12 SP1 allow remote attackers to access arbitrary files via HTTP traffic to port (1) 4999 or (2) 80.
network
low complexity
siemens CWE-22
5.0
2014-04-01 CVE-2014-2590 Missing Authentication for Critical Function vulnerability in Siemens Ruggedcom Rugged Operating System
The web management interface in Siemens RuggedCom ROS before 3.11, ROS 3.11 before 3.11.5 for RS950G, ROS 3.12, and ROS 4.0 for RSG2488 allows remote attackers to cause a denial of service (interface outage) via crafted HTTP packets.
network
low complexity
siemens CWE-306
5.0
2014-03-24 CVE-2014-2252 Resource Management Errors vulnerability in Siemens products
Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 allow remote attackers to cause a denial of service (defect-mode transition) via crafted PROFINET packets, a different vulnerability than CVE-2014-2253.
low complexity
siemens CWE-399
6.1