← Back

Sinumerik One Firmware

sinumerik_one_firmware

Vendor: Siemens • 5 CVEs

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Siemens
73Simatic Drive Controller Cpu 1504d Tf Firmware
Simatic Drive Controller Cpu 1507d Tf FirmwareSimatic Et 200sp Open Control 1515sp Pc2 Firmware+70 more
Jun 17, 2026
Dec 12, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Affected devices improperly handle specially crafted packets sent to port 102/tcp. This could allow an attacker to create a denial of service condition. A restart is needed to restore normal operations.
1Siemens
1136ag1151 8ab01 7ab0 Firmware
6ag1151 8fb01 2ab0 Firmware6ag1314 6eh04 7ab0 Firmware+110 more
Jun 17, 2026
Nov 8, 2022
N/A· v4
3.5 LOW· v3
N/A· v2
The login endpoint /FormLogin in affected web services does not apply proper origin checking. This could allow authenticated remote attackers to track the activities of other users via a login cross-site request forge...Show more
The login endpoint /FormLogin in affected web services does not apply proper origin checking. This could allow authenticated remote attackers to track the activities of other users via a login cross-site request forgery attack.Show less
1Siemens
2Sinumerik Mc Firmware
Sinumerik One Firmware
Jun 17, 2026
Mar 8, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A vulnerability has been identified in SINUMERIK MC (All versions < V1.15 SP1), SINUMERIK ONE (All versions < V6.15 SP1). The sc SUID binary on affected devices provides several commands that are used to execute system c...Show more
A vulnerability has been identified in SINUMERIK MC (All versions < V1.15 SP1), SINUMERIK ONE (All versions < V6.15 SP1). The sc SUID binary on affected devices provides several commands that are used to execute system commands or modify system files. A specific set of operations using sc could allow local attackers to escalate their privileges to root.Show less
5Fedoraproject
Lldpd ProjectOpenvswitch+2 more
17Enterprise Linux
FedoraLldpd+14 more
Jun 17, 2026
Mar 18, 2021
N/A· v4
7.5 HIGH· v3
7.1 HIGH· v2
A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest...Show more
A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.Show less
2Intel
Siemens
22Converged Security And Manageability Engine
Simatic Drive Controller FirmwareSimatic Et200sp 1515sp Pc2 Firmware+19 more
Jun 17, 2026
Nov 12, 2020
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
Insufficient control flow management in subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25 , Intel(R) TXE versions before 3.1.80 and 4.0.30 may allow...Show more
Insufficient control flow management in subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25 , Intel(R) TXE versions before 3.1.80 and 4.0.30 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.Show less