Vulnerabilities > Siemens > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2014-07-24 | CVE-2014-4685 | Permissions, Privileges, and Access Controls vulnerability in Siemens Simatic Pcs7 and Wincc Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows local users to gain privileges by leveraging weak system-object access control. | 4.6 |
2014-07-24 | CVE-2014-4684 | Permissions, Privileges, and Access Controls vulnerability in Siemens Simatic Pcs7 and Wincc The database server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote authenticated users to gain privileges via a request to TCP port 1433. | 6.0 |
2014-07-24 | CVE-2014-4683 | Permissions, Privileges, and Access Controls vulnerability in Siemens Simatic Pcs7 and Wincc The WebNavigator server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote authenticated users to gain privileges via a (1) HTTP or (2) HTTPS request. | 4.9 |
2014-07-24 | CVE-2014-4682 | Information Exposure vulnerability in Siemens Simatic Pcs7 and Wincc The WebNavigator server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote attackers to obtain sensitive information via an HTTP request. | 5.0 |
2014-04-25 | CVE-2014-2909 | Code Injection vulnerability in Siemens products CRLF injection vulnerability in the integrated web server on Siemens SIMATIC S7-1200 CPU devices 2.x and 3.x allows remote attackers to inject arbitrary HTTP headers via unspecified vectors. | 5.8 |
2014-04-25 | CVE-2014-2908 | Cross-Site Scripting vulnerability in Siemens products Cross-site scripting (XSS) vulnerability in the integrated web server on Siemens SIMATIC S7-1200 CPU devices 2.x and 3.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 4.3 |
2014-04-19 | CVE-2014-2733 | Improper Input Validation vulnerability in Siemens Sinema Server 12.0 Siemens SINEMA Server before 12 SP1 allows remote attackers to cause a denial of service (web-interface outage) via crafted HTTP requests to port (1) 4999 or (2) 80. | 5.0 |
2014-04-19 | CVE-2014-2732 | Path Traversal vulnerability in Siemens Sinema Server 12.0 Multiple directory traversal vulnerabilities in the integrated web server in Siemens SINEMA Server before 12 SP1 allow remote attackers to access arbitrary files via HTTP traffic to port (1) 4999 or (2) 80. | 5.0 |
2014-04-01 | CVE-2014-2590 | Missing Authentication for Critical Function vulnerability in Siemens Ruggedcom Rugged Operating System The web management interface in Siemens RuggedCom ROS before 3.11, ROS 3.11 before 3.11.5 for RS950G, ROS 3.12, and ROS 4.0 for RSG2488 allows remote attackers to cause a denial of service (interface outage) via crafted HTTP packets. | 5.0 |
2014-03-24 | CVE-2014-2252 | Resource Management Errors vulnerability in Siemens products Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 allow remote attackers to cause a denial of service (defect-mode transition) via crafted PROFINET packets, a different vulnerability than CVE-2014-2253. | 6.1 |