CVEs (5)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Siemens 90Scalance M 800 Firmware Scalance S615 FirmwareScalance Sc 600 Firmware+87 moreApr 14, 2026 Aug 10, 2022 N/A· v4 4.8 MEDIUM· v3 N/A· v2 Affected devices do not properly sanitize data introduced by an user when rendering the web interface. This could allow an authenticated remote attacker with administrative privileges to inject code and lead to a DOM-bas...Show more |
1Siemens 84Scalance M 800 Firmware Scalance S615 FirmwareScalance W700 Ieee 802.11ac Firmware+81 moreApr 14, 2026 Aug 10, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Affected devices do not properly handle the renegotiation of SSL/TLS parameters. This could allow an unauthenticated remote attacker to bypass the TCP brute force prevention and lead to a denial of service condition for...Show more |
1Siemens 90Scalance M 800 Firmware Scalance S615 FirmwareScalance Sc 600 Firmware+87 moreApr 14, 2026 Aug 10, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with administrative privileges to inject code or spawn a system root shell. |
1Siemens 11Scalance Xm 400 Firmware Scalance Xm408 4c FirmwareScalance Xm408 4c L3 Firmware+8 moreNov 21, 2024 May 12, 2021 N/A· v4 7.5 HIGH· v3 7.1 HIGH· v2 An unauthenticated remote attacker could create a permanent denial-of-service condition by sending specially crafted OSPF packets. Successful exploitation requires OSPF to be enabled on an affected device on the SCALANCE...Show more |
1Siemens 52Dk Standard Ethernet Controller Ek Ertec 200 FirmwareEk Ertec 200p Firmware+49 moreNov 21, 2024 Feb 11, 2020 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Profinet-IO (PNIO) stack versions prior V06.00 do not properly limit internal resource allocation when multiple legitimate diagnostic package requests are sent to the DCE-RPC interface. This could lead to a denial of ser...Show more |