Vulnerabilities > Siemens > Simatic S7 1200 CPU Firmware

DATE CVE VULNERABILITY TITLE RISK
2023-09-12 CVE-2023-28831 Integer Overflow or Wraparound vulnerability in Siemens products
The OPC UA implementations (ANSI C and C++) in affected products contain an integer overflow vulnerability that could cause the application to run into an infinite loop during certificate validation. This could allow an unauthenticated remote attacker to create a denial of service condition by sending a specially crafted certificate.
network
low complexity
siemens CWE-190
7.5
2021-08-10 CVE-2021-37172 Improper Authentication vulnerability in Siemens products
A vulnerability has been identified in SIMATIC S7-1200 CPU family (incl.
network
low complexity
siemens CWE-287
5.0
2019-10-10 CVE-2019-10936 Resource Exhaustion vulnerability in Siemens products
A vulnerability has been identified in SIMATIC S7-400 CPU 414-3 PN/DP V7, SIMATIC S7-400 CPU 414F-3 PN/DP V7, SIMATIC S7-400 CPU 416-3 PN/DP V7, SIMATIC S7-400 CPU 416F-3 PN/DP V7, Development/Evaluation Kits for PROFINET IO: DK Standard Ethernet Controller, Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200, Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200P, SIMATIC CFU PA, SIMATIC ET 200pro IM154-8 PN/DP CPU, SIMATIC ET 200pro IM154-8F PN/DP CPU, SIMATIC ET 200pro IM154-8FX PN/DP CPU, SIMATIC ET 200S IM151-8 PN/DP CPU, SIMATIC ET 200S IM151-8F PN/DP CPU, SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl.
network
low complexity
siemens CWE-400
7.5
2015-01-21 CVE-2015-1048 Open Redirection vulnerability in Siemens Simatic S7 1200 CPU Firmware 4.0
Open redirect vulnerability in the integrated web server on Siemens SIMATIC S7-1200 CPU devices with firmware before 4.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
network
siemens
4.3