Vulnerabilities > Siemens > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2013-03-21 | CVE-2013-0674 | Buffer Errors vulnerability in Siemens Simatic Pcs7 and Wincc Buffer overflow in the RegReader ActiveX control in Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, allows remote attackers to execute arbitrary code via a long parameter. | 6.8 |
2013-03-21 | CVE-2013-0671 | Path Traversal vulnerability in Siemens Wincc TIA Portal 11.0 Directory traversal vulnerability in Siemens WinCC (TIA Portal) 11 allows remote authenticated users to read HMI web-application source code and user-defined scripts via a crafted URL. | 4.0 |
2013-03-21 | CVE-2013-0670 | Improper Input Validation vulnerability in Siemens Wincc TIA Portal 11.0 CRLF injection vulnerability in the HMI web application in Siemens WinCC (TIA Portal) 11 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL. | 4.3 |
2013-03-21 | CVE-2013-0669 | Improper Input Validation vulnerability in Siemens Wincc TIA Portal 11.0 The HMI web application in Siemens WinCC (TIA Portal) 11 allows remote authenticated users to cause a denial of service (daemon crash) via a crafted HTTP request. | 4.0 |
2013-03-21 | CVE-2013-0668 | Cross-Site Scripting vulnerability in Siemens Wincc TIA Portal 11.0 Multiple cross-site scripting (XSS) vulnerabilities in the HMI web application in Siemens WinCC (TIA Portal) 11 allow remote attackers to inject arbitrary web script or HTML via a crafted URL. | 4.3 |
2013-03-21 | CVE-2013-0667 | Cross-Site Scripting vulnerability in Siemens Wincc TIA Portal 11.0 Cross-site scripting (XSS) vulnerability in the HMI web application in Siemens WinCC (TIA Portal) 11 allows remote attackers to inject arbitrary web script or HTML via a crafted URL. | 4.3 |
2013-03-21 | CVE-2011-4515 | Credentials Management vulnerability in Siemens Wincc TIA Portal 11.0 Siemens WinCC (TIA Portal) 11 uses a reversible algorithm for storing HMI web-application passwords in world-readable and world-writable files, which allows local users to obtain sensitive information by leveraging (1) physical access or (2) Sm@rt Server access. | 4.6 |
2013-01-21 | CVE-2013-0656 | Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Siemens Simatic Rf-Manager and Simatic Rf-Manager 2008 Buffer overflow in a third-party ActiveX component in Siemens SIMATIC RF-MANAGER 2008, and RF-MANAGER Basic 3.0 and earlier, allows remote attackers to execute arbitrary code via a crafted web site. | 6.8 |
2012-12-23 | CVE-2012-4698 | Information Exposure vulnerability in Siemens products Siemens RuggedCom Rugged Operating System (ROS) before 3.12, ROX I OS through 1.14.5, ROX II OS through 2.3.0, and RuggedMax OS through 4.2.1.4621.22 use hardcoded private keys for SSL and SSH communication, which makes it easier for man-in-the-middle attackers to spoof servers and decrypt network traffic by leveraging the availability of these keys within ROS files at all customer installations. | 4.3 |
2012-10-10 | CVE-2012-3040 | Cross-site Scripting vulnerability in Siemens products Cross-site scripting (XSS) vulnerability in the web server on Siemens SIMATIC S7-1200 PLCs 2.x through 3.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URI. | 4.3 |