← Back

Simatic Ipc477e Pro Firmware

simatic_ipc477e_pro_firmware

Vendor: Siemens • 12 CVEs

CVEs (12)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Insyde
NetappSiemens
18Fas/aff Bios
Insydeh2oRuggedcom Ape1808 Firmware+15 more
Jun 17, 2026
Feb 3, 2022
N/A· v4
7.5 HIGH· v3
6.9 MEDIUM· v2
An issue was discovered in Kernel 5.x in Insyde InsydeH2O, affecting HddPassword. Software SMI services that use the Communicate() function of the EFI_SMM_COMMUNICATION_PROTOCOL do not check whether the address of the bu...Show more
An issue was discovered in Kernel 5.x in Insyde InsydeH2O, affecting HddPassword. Software SMI services that use the Communicate() function of the EFI_SMM_COMMUNICATION_PROTOCOL do not check whether the address of the buffer is valid, which allows use of SMRAM, MMIO, or OS kernel addresses.Show less
2Insyde
Siemens
17Insydeh2o
Ruggedcom Ape1808 FirmwareSimatic Field Pg M5 Firmware+14 more
Jun 17, 2026
Feb 3, 2022
N/A· v4
7.5 HIGH· v3
6.9 MEDIUM· v2
A vulnerability exists in System Management Interrupt (SWSMI) handler of InsydeH2O UEFI Firmware code located in SWSMI handler that dereferences gRT (EFI_RUNTIME_SERVICES) pointer to call a GetVariable service, which is...Show more
A vulnerability exists in System Management Interrupt (SWSMI) handler of InsydeH2O UEFI Firmware code located in SWSMI handler that dereferences gRT (EFI_RUNTIME_SERVICES) pointer to call a GetVariable service, which is located outside of SMRAM. This can result in code execution in SMM (escalating privilege from ring 0 to ring -2).Show less
2Insyde
Siemens
17Insydeh2o
Ruggedcom Apr1808 FirmwareSimatic Field Pg M5 Firmware+14 more
Jun 17, 2026
Oct 1, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A vulnerability exists in SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently check or validate the allocated buffer pointer(QWORD values for CommBuffer). This can be used by an...Show more
A vulnerability exists in SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently check or validate the allocated buffer pointer(QWORD values for CommBuffer). This can be used by an attacker to corrupt data in SMRAM memory and even lead to arbitrary code execution.Show less
2Insyde
Siemens
17Insydeh2o
Ruggedcom Apr1808 FirmwareSimatic Field Pg M5 Firmware+14 more
Jun 17, 2026
Jun 16, 2021
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
In the kernel in Insyde InsydeH2O 5.x, certain SMM drivers did not correctly validate the CommBuffer and CommBufferSize parameters, allowing callers to corrupt either the firmware or the OS memory. The fixed versions for...Show more
In the kernel in Insyde InsydeH2O 5.x, certain SMM drivers did not correctly validate the CommBuffer and CommBufferSize parameters, allowing callers to corrupt either the firmware or the OS memory. The fixed versions for this issue in the AhciBusDxe, IdeBusDxe, NvmExpressDxe, SdHostDriverDxe, and SdMmcDeviceDxe drivers are 05.16.25, 05.26.25, 05.35.25, 05.43.25, and 05.51.25 (for Kernel 5.1 through 5.5).Show less
2Intel
Siemens
13Local Manageability Service
Simatic Field Pg M5 FirmwareSimatic Field Pg M6 Firmware+10 more
Jun 17, 2026
Jun 9, 2021
N/A· v4
6.4 MEDIUM· v3
4.4 MEDIUM· v2
Race condition in a subsystem in the Intel(R) LMS versions before 2039.1.0.0 may allow a privileged user to potentially enable escalation of privilege via local access.
3Intel
NetappSiemens
14Cloud Backup
Converged Security And Manageability EngineSimatic Field Pg M5 Firmware+11 more
Jun 17, 2026
Jun 9, 2021
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Improper buffer restrictions in a subsystem in the Intel(R) CSME versions before 11.8.86, 11.12.86, 11.22.86, 12.0.81, 13.0.47, 13.30.17, 14.1.53, 14.5.32 and 15.0.22 may allow a privileged user to potentially enable esc...Show more
Improper buffer restrictions in a subsystem in the Intel(R) CSME versions before 11.8.86, 11.12.86, 11.22.86, 12.0.81, 13.0.47, 13.30.17, 14.1.53, 14.5.32 and 15.0.22 may allow a privileged user to potentially enable escalation of privilege via local access.Show less
3Intel
NetappSiemens
18Aff Bios
BiosCloud Backup+15 more
Jun 17, 2026
Jun 9, 2021
N/A· v4
6.4 MEDIUM· v3
4.4 MEDIUM· v2
Race condition in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
2Intel
Siemens
13Converged Security And Manageability Engine
Simatic Field Pg M5 FirmwareSimatic Field Pg M6 Firmware+10 more
Jun 17, 2026
Jun 9, 2021
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
Improper initialization in a subsystem in the Intel(R) CSME versions before 11.8.86, 11.12.86, 11.22.86, 12.0.81, 13.0.47, 13.30.17, 14.1.53, 14.5.32, 13.50.11 and 15.0.22 may allow a privileged user to potentially enabl...Show more
Improper initialization in a subsystem in the Intel(R) CSME versions before 11.8.86, 11.12.86, 11.22.86, 12.0.81, 13.0.47, 13.30.17, 14.1.53, 14.5.32, 13.50.11 and 15.0.22 may allow a privileged user to potentially enable information disclosure via local access.Show less
3Intel
NetappSiemens
19Aff Bios
BiosCloud Backup+16 more
Jun 17, 2026
Jun 9, 2021
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
5Debian
FedoraprojectIntel+2 more
17Clustered Data Ontap
Debian LinuxFedora+14 more
Jun 17, 2026
Nov 12, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
6Canonical
FedoraprojectIntel+3 more
694Celeron 1000m
Celeron 1005mCeleron 1007u+691 more
Jun 17, 2026
Jun 15, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Incomplete cleanup from specific special register read operations in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
12Arm
CanonicalDebian+9 more
282Atom C
Atom EAtom X5 E3930+279 more
May 29, 2026
May 22, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an atta...Show more
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4.Show less