Vulnerabilities > Siemens > Simatic S7 1500 Firmware

DATE CVE VULNERABILITY TITLE RISK
2020-11-12 CVE-2020-8744 Improper Initialization vulnerability in multiple products
Improper initialization in subsystem for Intel(R) CSME versions before12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE versions before 4.0.30 Intel(R) SPS versions before E3_05.01.04.200 may allow a privileged user to potentially enable escalation of privilege via local access.
local
low complexity
intel siemens CWE-665
7.8
2019-04-17 CVE-2019-6575 Uncaught Exception vulnerability in Siemens products
A vulnerability has been identified in SIMATIC CP 443-1 OPC UA (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl.
network
low complexity
siemens CWE-248
7.5
2019-04-17 CVE-2019-6568 Out-of-bounds Read vulnerability in Siemens products
The webserver of the affected devices contains a vulnerability that may lead to a denial of service condition.
network
low complexity
siemens CWE-125
7.5
2019-04-17 CVE-2018-16559 Improper Input Validation vulnerability in Siemens Simatic S7-1500 Firmware
A vulnerability has been identified in SIMATIC S7-1500 CPU (All versions >= V2.0 and < V2.5), SIMATIC S7-1500 CPU (All versions <= V1.8.5).
network
low complexity
siemens CWE-20
7.5
2019-04-17 CVE-2018-16558 Improper Input Validation vulnerability in Siemens Simatic S7-1500 Firmware
A vulnerability has been identified in SIMATIC S7-1500 CPU (All versions >= V2.0 and < V2.5), SIMATIC S7-1500 CPU (All versions <= V1.8.5).
network
low complexity
siemens CWE-20
7.5
2018-12-13 CVE-2018-13815 Resource Exhaustion vulnerability in Siemens Simatic S7-1200 Firmware and Simatic S7-1500 Firmware
A vulnerability has been identified in SIMATIC S7-1200 (All versions), SIMATIC S7-1500 (All Versions < V2.6).
network
low complexity
siemens CWE-400
7.5
2018-10-10 CVE-2018-13805 Resource Exhaustion vulnerability in Siemens products
A vulnerability has been identified in SIMATIC ET 200SP Open Controller (All versions >= V2.0 and < V2.1.6), SIMATIC S7-1500 Software Controller (All versions >= V2.0 and < V2.5), SIMATIC S7-1500 incl.
network
low complexity
siemens CWE-400
7.5
2018-05-22 CVE-2018-3639 Information Exposure Through Discrepancy vulnerability in multiple products
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4.
5.5
2018-03-20 CVE-2018-4843 Improper Input Validation vulnerability in Siemens products
A vulnerability has been identified in SIMATIC S7-400 CPU 414-3 PN/DP V7 (All versions < V7.0.3), SIMATIC S7-400 CPU 414F-3 PN/DP V7 (All versions < V7.0.3), SIMATIC S7-400 CPU 416-3 PN/DP V7 (All versions < V7.0.3), SIMATIC S7-400 CPU 416F-3 PN/DP V7 (All versions < V7.0.3), SIMATIC CP 343-1 (incl.
low complexity
siemens CWE-20
6.5
2017-12-26 CVE-2017-12741 Resource Exhaustion vulnerability in Siemens products
Specially crafted packets sent to port 161/udp could cause a denial of service condition.
network
low complexity
siemens CWE-400
7.5