Vulnerabilities > Siemens > Sinamics S120 Firmware

DATE CVE VULNERABILITY TITLE RISK
2023-12-12 CVE-2022-47374 Uncontrolled Recursion vulnerability in Siemens products
A vulnerability has been identified in SIMATIC PC-Station Plus (All versions), SIMATIC S7-400 CPU 412-2 PN V7 (All versions), SIMATIC S7-400 CPU 414-3 PN/DP V7 (All versions), SIMATIC S7-400 CPU 414F-3 PN/DP V7 (All versions), SIMATIC S7-400 CPU 416-3 PN/DP V7 (All versions), SIMATIC S7-400 CPU 416F-3 PN/DP V7 (All versions), SINAMICS S120 (incl.
network
low complexity
siemens CWE-674
7.5
2023-12-12 CVE-2022-47375 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Siemens products
A vulnerability has been identified in SIMATIC PC-Station Plus (All versions), SIMATIC S7-400 CPU 412-2 PN V7 (All versions), SIMATIC S7-400 CPU 414-3 PN/DP V7 (All versions), SIMATIC S7-400 CPU 414F-3 PN/DP V7 (All versions), SIMATIC S7-400 CPU 416-3 PN/DP V7 (All versions), SIMATIC S7-400 CPU 416F-3 PN/DP V7 (All versions), SINAMICS S120 (incl.
network
low complexity
siemens CWE-119
7.5
2019-10-10 CVE-2019-10936 Resource Exhaustion vulnerability in Siemens products
Affected devices improperly handle large amounts of specially crafted UDP packets. This could allow an unauthenticated remote attacker to trigger a denial of service condition.
network
low complexity
siemens CWE-400
7.5
2019-10-10 CVE-2019-10923 Resource Exhaustion vulnerability in Siemens products
An attacker with network access to an affected product may cause a denial of service condition by breaking the real-time synchronization (IRT) of the affected installation.
network
low complexity
siemens CWE-400
7.5
2019-04-17 CVE-2019-6568 Out-of-bounds Read vulnerability in Siemens products
The webserver of the affected devices contains a vulnerability that may lead to a denial of service condition.
network
low complexity
siemens CWE-125
7.5
2017-12-26 CVE-2017-12741 Resource Exhaustion vulnerability in Siemens products
Specially crafted packets sent to port 161/udp could cause a denial of service condition.
network
low complexity
siemens CWE-400
7.5
2017-05-11 CVE-2017-2681 Resource Exhaustion vulnerability in Siemens products
Specially crafted PROFINET DCP packets sent on a local Ethernet segment (Layer 2) to an affected product could cause a denial of service condition of that product.
low complexity
siemens CWE-400
6.5
2017-05-11 CVE-2017-2680 Resource Exhaustion vulnerability in Siemens products
Specially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affected products on a local Ethernet segment (Layer 2).
low complexity
siemens CWE-400
6.5