Vulnerabilities > Siemens > Simatic CP 1604 Firmware

DATE CVE VULNERABILITY TITLE RISK
2023-10-10 CVE-2023-37194 Improper Access Control vulnerability in Siemens products
A vulnerability has been identified in SIMATIC CP 1604 (All versions), SIMATIC CP 1616 (All versions), SIMATIC CP 1623 (All versions), SIMATIC CP 1626 (All versions), SIMATIC CP 1628 (All versions).
local
low complexity
siemens CWE-284
6.7
2023-10-10 CVE-2023-37195 Resource Exhaustion vulnerability in Siemens products
A vulnerability has been identified in SIMATIC CP 1604 (All versions), SIMATIC CP 1616 (All versions), SIMATIC CP 1623 (All versions), SIMATIC CP 1626 (All versions), SIMATIC CP 1628 (All versions).
local
low complexity
siemens CWE-400
4.4
2020-02-11 CVE-2019-13946 Resource Exhaustion vulnerability in Siemens products
Profinet-IO (PNIO) stack versions prior V06.00 do not properly limit internal resource allocation when multiple legitimate diagnostic package requests are sent to the DCE-RPC interface. This could lead to a denial of service condition due to lack of memory for devices that include a vulnerable version of the stack. The security vulnerability could be exploited by an attacker with network access to an affected device.
network
low complexity
siemens CWE-400
7.5
2017-05-11 CVE-2017-2681 Resource Exhaustion vulnerability in Siemens products
Specially crafted PROFINET DCP packets sent on a local Ethernet segment (Layer 2) to an affected product could cause a denial of service condition of that product.
low complexity
siemens CWE-400
6.5
2017-05-11 CVE-2017-2680 Resource Exhaustion vulnerability in Siemens products
Specially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affected products on a local Ethernet segment (Layer 2).
low complexity
siemens CWE-400
6.5