Vulnerabilities > Siemens > Scalance Lpe9403 Firmware

DATE CVE VULNERABILITY TITLE RISK
2023-05-09 CVE-2023-27407 OS Command Injection vulnerability in Siemens Scalance Lpe9403 Firmware 2.0
A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1).
network
low complexity
siemens CWE-78
critical
9.9
2023-05-09 CVE-2023-27408 Creation of Temporary File With Insecure Permissions vulnerability in Siemens Scalance Lpe9403 Firmware 2.0
A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1).
local
low complexity
siemens CWE-378
3.3
2023-05-09 CVE-2023-27409 Path Traversal vulnerability in Siemens Scalance Lpe9403 Firmware 2.0
A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1).
local
low complexity
siemens CWE-22
3.3
2023-05-09 CVE-2023-27410 Heap-based Buffer Overflow vulnerability in Siemens Scalance Lpe9403 Firmware 2.0
A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1).
network
low complexity
siemens CWE-122
2.7
2022-03-10 CVE-2022-0847 Improper Initialization vulnerability in multiple products
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values.
7.8
2022-01-28 CVE-2021-4034 Out-of-bounds Write vulnerability in multiple products
A local privilege escalation vulnerability was found on polkit's pkexec utility.
7.8
2021-08-08 CVE-2021-36221 Race Condition vulnerability in multiple products
Go before 1.15.15 and 1.16.x before 1.16.7 has a race condition that can lead to a net/http/httputil ReverseProxy panic upon an ErrAbortHandler abort.
network
high complexity
golang fedoraproject debian oracle siemens CWE-362
5.9
2021-03-25 CVE-2021-3449 NULL Pointer Dereference vulnerability in multiple products
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client.
5.9