← Back

Simatic Itp1000 Firmware

simatic_itp1000_firmware

Vendor: Siemens • 24 CVEs

CVEs (24)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Insyde
Siemens
16Insydeh2o
Ruggedcom Ape1808 FirmwareSimatic Field Pg M5 Firmware+13 more
Nov 4, 2025
Feb 3, 2022
N/A· v4
8.2 HIGH· v3
7.2 HIGH· v2
An issue was discovered in Insyde InsydeH2O with Kernel 5.0 before 05.08.42, Kernel 5.1 before 05.16.42, Kernel 5.2 before 05.26.42, Kernel 5.3 before 05.35.42, Kernel 5.4 before 05.42.51, and Kernel 5.5 before 05.50.51....Show more
An issue was discovered in Insyde InsydeH2O with Kernel 5.0 before 05.08.42, Kernel 5.1 before 05.16.42, Kernel 5.2 before 05.26.42, Kernel 5.3 before 05.35.42, Kernel 5.4 before 05.42.51, and Kernel 5.5 before 05.50.51. An SMM memory corruption vulnerability in FvbServicesRuntimeDxe allows a possible attacker to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM.Show less
2Insyde
Siemens
15Insydeh2o
Simatic Field Pg M5 FirmwareSimatic Field Pg M6 Firmware+12 more
Nov 4, 2025
Feb 3, 2022
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
An issue was discovered in Insyde InsydeH2O Kernel 5.0 before 05.08.41, Kernel 5.1 before 05.16.41, Kernel 5.2 before 05.26.41, Kernel 5.3 before 05.35.41, and Kernel 5.4 before 05.42.20. A stack-based buffer overflow le...Show more
An issue was discovered in Insyde InsydeH2O Kernel 5.0 before 05.08.41, Kernel 5.1 before 05.16.41, Kernel 5.2 before 05.26.41, Kernel 5.3 before 05.35.41, and Kernel 5.4 before 05.42.20. A stack-based buffer overflow leads toarbitrary code execution in UEFI DisplayTypeDxe DXE driver.Show less
2Insyde
Siemens
15Insydeh2o
Simatic Field Pg M5 FirmwareSimatic Field Pg M6 Firmware+12 more
Nov 4, 2025
Feb 3, 2022
N/A· v4
8.2 HIGH· v3
7.2 HIGH· v2
An issue was discovered in SdHostDriver in the kernel 5.0 through 5.5 in Insyde InsydeH2O. There is an SMM callout that allows an attacker to access the System Management Mode and execute arbitrary code. This occurs beca...Show more
An issue was discovered in SdHostDriver in the kernel 5.0 through 5.5 in Insyde InsydeH2O. There is an SMM callout that allows an attacker to access the System Management Mode and execute arbitrary code. This occurs because of a Numeric Range Comparison Without a Minimum Check.Show less
2Insyde
Siemens
15Insydeh2o
Simatic Field Pg M5 FirmwareSimatic Field Pg M6 Firmware+12 more
Nov 4, 2025
Feb 3, 2022
N/A· v4
8.2 HIGH· v3
7.2 HIGH· v2
An issue was discovered in AhciBusDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. Because of an Untrusted Pointer Dereference that causes SMM memory corruption, an attacker may be able to write fixed or predictabl...Show more
An issue was discovered in AhciBusDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. Because of an Untrusted Pointer Dereference that causes SMM memory corruption, an attacker may be able to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM.Show less
2Insyde
Siemens
15Insydeh2o
Simatic Field Pg M5 FirmwareSimatic Field Pg M6 Firmware+12 more
Nov 4, 2025
Feb 3, 2022
N/A· v4
8.2 HIGH· v3
7.2 HIGH· v2
An issue was discovered in Insyde InsydeH2O Kernel 5.0 before 05.09.11, 5.1 before 05.17.11, 5.2 before 05.27.11, 5.3 before 05.36.11, 5.4 before 05.44.11, and 5.5 before 05.52.11 affecting FwBlockServiceSmm. Software SM...Show more
An issue was discovered in Insyde InsydeH2O Kernel 5.0 before 05.09.11, 5.1 before 05.17.11, 5.2 before 05.27.11, 5.3 before 05.36.11, 5.4 before 05.44.11, and 5.5 before 05.52.11 affecting FwBlockServiceSmm. Software SMI services that use the Communicate() function of the EFI_SMM_COMMUNICATION_PROTOCOL do not check whether the address of the buffer is valid, which allows use of SMRAM, MMIO, or OS kernel addresses.Show less
3Insyde
NetappSiemens
18Fas/aff Bios
Insydeh2oRuggedcom Ape1808 Firmware+15 more
Nov 4, 2025
Feb 3, 2022
N/A· v4
7.5 HIGH· v3
6.9 MEDIUM· v2
An issue was discovered in Kernel 5.x in Insyde InsydeH2O, affecting HddPassword. Software SMI services that use the Communicate() function of the EFI_SMM_COMMUNICATION_PROTOCOL do not check whether the address of the bu...Show more
An issue was discovered in Kernel 5.x in Insyde InsydeH2O, affecting HddPassword. Software SMI services that use the Communicate() function of the EFI_SMM_COMMUNICATION_PROTOCOL do not check whether the address of the buffer is valid, which allows use of SMRAM, MMIO, or OS kernel addresses.Show less
2Insyde
Siemens
17Insydeh2o
Ruggedcom Ape1808 FirmwareSimatic Field Pg M5 Firmware+14 more
Nov 4, 2025
Feb 3, 2022
N/A· v4
7.5 HIGH· v3
6.9 MEDIUM· v2
A vulnerability exists in System Management Interrupt (SWSMI) handler of InsydeH2O UEFI Firmware code located in SWSMI handler that dereferences gRT (EFI_RUNTIME_SERVICES) pointer to call a GetVariable service, which is...Show more
A vulnerability exists in System Management Interrupt (SWSMI) handler of InsydeH2O UEFI Firmware code located in SWSMI handler that dereferences gRT (EFI_RUNTIME_SERVICES) pointer to call a GetVariable service, which is located outside of SMRAM. This can result in code execution in SMM (escalating privilege from ring 0 to ring -2).Show less
2Insyde
Siemens
17Insydeh2o
Ruggedcom Apr1808 FirmwareSimatic Field Pg M5 Firmware+14 more
Nov 4, 2025
Oct 1, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A vulnerability exists in SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently check or validate the allocated buffer pointer(QWORD values for CommBuffer). This can be used by an...Show more
A vulnerability exists in SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently check or validate the allocated buffer pointer(QWORD values for CommBuffer). This can be used by an attacker to corrupt data in SMRAM memory and even lead to arbitrary code execution.Show less
2Insyde
Siemens
17Insydeh2o
Ruggedcom Apr1808 FirmwareSimatic Field Pg M5 Firmware+14 more
Nov 4, 2025
Jun 16, 2021
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
In the kernel in Insyde InsydeH2O 5.x, certain SMM drivers did not correctly validate the CommBuffer and CommBufferSize parameters, allowing callers to corrupt either the firmware or the OS memory. The fixed versions for...Show more
In the kernel in Insyde InsydeH2O 5.x, certain SMM drivers did not correctly validate the CommBuffer and CommBufferSize parameters, allowing callers to corrupt either the firmware or the OS memory. The fixed versions for this issue in the AhciBusDxe, IdeBusDxe, NvmExpressDxe, SdHostDriverDxe, and SdMmcDeviceDxe drivers are 05.16.25, 05.26.25, 05.35.25, 05.43.25, and 05.51.25 (for Kernel 5.1 through 5.5).Show less
2Intel
Siemens
13Local Manageability Service
Simatic Field Pg M5 FirmwareSimatic Field Pg M6 Firmware+10 more
Nov 21, 2024
Jun 9, 2021
N/A· v4
6.4 MEDIUM· v3
4.4 MEDIUM· v2
Race condition in a subsystem in the Intel(R) LMS versions before 2039.1.0.0 may allow a privileged user to potentially enable escalation of privilege via local access.
3Intel
NetappSiemens
14Cloud Backup
Converged Security And Manageability EngineSimatic Field Pg M5 Firmware+11 more
Nov 21, 2024
Jun 9, 2021
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Improper buffer restrictions in a subsystem in the Intel(R) CSME versions before 11.8.86, 11.12.86, 11.22.86, 12.0.81, 13.0.47, 13.30.17, 14.1.53, 14.5.32 and 15.0.22 may allow a privileged user to potentially enable esc...Show more
Improper buffer restrictions in a subsystem in the Intel(R) CSME versions before 11.8.86, 11.12.86, 11.22.86, 12.0.81, 13.0.47, 13.30.17, 14.1.53, 14.5.32 and 15.0.22 may allow a privileged user to potentially enable escalation of privilege via local access.Show less
3Intel
NetappSiemens
18Aff Bios
BiosCloud Backup+15 more
Nov 21, 2024
Jun 9, 2021
N/A· v4
6.4 MEDIUM· v3
4.4 MEDIUM· v2
Race condition in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
2Intel
Siemens
13Converged Security And Manageability Engine
Simatic Field Pg M5 FirmwareSimatic Field Pg M6 Firmware+10 more
Nov 21, 2024
Jun 9, 2021
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
Improper initialization in a subsystem in the Intel(R) CSME versions before 11.8.86, 11.12.86, 11.22.86, 12.0.81, 13.0.47, 13.30.17, 14.1.53, 14.5.32, 13.50.11 and 15.0.22 may allow a privileged user to potentially enabl...Show more
Improper initialization in a subsystem in the Intel(R) CSME versions before 11.8.86, 11.12.86, 11.22.86, 12.0.81, 13.0.47, 13.30.17, 14.1.53, 14.5.32, 13.50.11 and 15.0.22 may allow a privileged user to potentially enable information disclosure via local access.Show less
3Intel
NetappSiemens
19Aff Bios
BiosCloud Backup+16 more
Nov 21, 2024
Jun 9, 2021
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
2Intel
Siemens
22Converged Security And Manageability Engine
Simatic Drive Controller FirmwareSimatic Et200sp 1515sp Pc2 Firmware+19 more
Mar 28, 2025
Nov 12, 2020
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
Insufficient control flow management in subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25 , Intel(R) TXE versions before 3.1.80 and 4.0.30 may allow...Show more
Insufficient control flow management in subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25 , Intel(R) TXE versions before 3.1.80 and 4.0.30 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.Show less
5Debian
FedoraprojectIntel+2 more
17Clustered Data Ontap
Debian LinuxFedora+14 more
Nov 21, 2024
Nov 12, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
6Canonical
FedoraprojectIntel+3 more
694Celeron 1000m
Celeron 1005mCeleron 1007u+691 more
Nov 21, 2024
Jun 15, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Incomplete cleanup from specific special register read operations in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
2Intel
Siemens
14Active Management Technology Firmware
Converged Security Management Engine FirmwareManageability Engine Firmware+11 more
Nov 21, 2024
Sep 12, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Multiple memory leaks in Intel AMT in Intel CSME firmware versions before 12.0.5 may allow an unauthenticated user with Intel AMT provisioned to potentially cause a partial denial of service via network access.
2Intel
Siemens
14Active Management Technology Firmware
Converged Security Management Engine FirmwareManageability Engine Firmware+11 more
Nov 21, 2024
Sep 12, 2018
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
Multiple buffer overflows in Intel AMT in Intel CSME firmware versions before version 12.0.5 may allow a privileged user to potentially execute arbitrary code with Intel AMT execution privilege via local access.
2Intel
Siemens
14Active Management Technology Firmware
Converged Security Management Engine FirmwareManageability Engine Firmware+11 more
Nov 21, 2024
Sep 12, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Bleichenbacher-style side channel vulnerability in TLS implementation in Intel Active Management Technology before 12.0.5 may allow an unauthenticated user to potentially obtain the TLS session key via the network.