← Back

Siemens

siemens

2,161 CVEs • 4,155 products

Products (4,155)

Click to collapse
Toggle
Jt2go
jt2go
Parasolid
parasolid
Solid Edge
solid_edge
Wincc
wincc
Sinec Nms
sinec-nms
Sinec Ins
sinec_ins
Jt Utilities
jt_utilities
Comos
comos
Simatic Wincc
simatic_wincc
Simatic Pcs 7
simatic_pcs_7
Simatic Pcs7
simatic_pcs7
Nucleus Net
nucleus_net
Pads Viewer
pads_viewer
Tecnomatix
tecnomatix
Sinema Server
sinema_server
Capital Vstar
capital_vstar

CVEs (2,161)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Siemens
1Simatic Step 7
May 6, 2026
Apr 6, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Siemens SIMATIC STEP 7 (TIA Portal) 12 and 13 before 13 SP1 Upd1 allows man-in-the-middle attackers to obtain sensitive information or modify transmitted data via unspecified vectors.
1Siemens
2Simatic S7 300 Cpu
Simatic S7 300 Cpu Firmware
Jun 2, 2026
Mar 7, 2015
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Siemens SIMATIC S7-300 CPU devices allow remote attackers to cause a denial of service (defect-mode transition) via crafted packets on (1) TCP port 102 or (2) Profibus.
1Siemens
1Spcanywhere
May 6, 2026
Mar 7, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
The Siemens SPCanywhere application for iOS allows physically proximate attackers to bypass intended access restrictions by leveraging a filesystem architectural error.
1Siemens
1Spcanywhere
May 6, 2026
Mar 7, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
The Siemens SPCanywhere application for Android does not properly store application passwords, which allows physically proximate attackers to obtain sensitive information by examining the device filesystem.
1Siemens
1Spcanywhere
May 6, 2026
Mar 7, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The Siemens SPCanywhere application for Android does not use encryption during the loading of code, which allows man-in-the-middle attackers to execute arbitrary code by modifying the client-server data stream.
1Siemens
1Spcanywhere
May 6, 2026
Mar 7, 2015
N/A· v4
N/A· v3
5.8 MEDIUM· v2
The Siemens SPCanywhere application for Android and iOS does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a craft...Show more
The Siemens SPCanywhere application for Android and iOS does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.Show less
1Siemens
1Spcanywhere
May 6, 2026
Mar 7, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The Siemens SPCanywhere application for Android and iOS does not use encryption during lookups of system ID to IP address mappings, which allows man-in-the-middle attackers to discover alarm IP addresses and spoof server...Show more
The Siemens SPCanywhere application for Android and iOS does not use encryption during lookups of system ID to IP address mappings, which allows man-in-the-middle attackers to discover alarm IP addresses and spoof servers by intercepting the client-server data stream.Show less
1Siemens
5Simatic Cfc
Simatic ProsaveSimatic Step 7+2 more
May 6, 2026
Mar 7, 2015
N/A· v4
N/A· v3
6.9 MEDIUM· v2
Untrusted search path vulnerability in Siemens SIMATIC ProSave before 13 SP1; SIMATIC CFC before 8.0 SP4 Upd9 and 8.1 before Upd1; SIMATIC STEP 7 before 5.5 SP1 HF2, 5.5 SP2 before HF7, 5.5 SP3, and 5.5 SP4 before HF4; S...Show more
Untrusted search path vulnerability in Siemens SIMATIC ProSave before 13 SP1; SIMATIC CFC before 8.0 SP4 Upd9 and 8.1 before Upd1; SIMATIC STEP 7 before 5.5 SP1 HF2, 5.5 SP2 before HF7, 5.5 SP3, and 5.5 SP4 before HF4; SIMOTION Scout before 4.4; and STARTER before 4.4 HF3 allows local users to gain privileges via a Trojan horse application file.Show less
1Siemens
3Spc4000 Firmware
Spc5000 FirmwareSpc6000 Firmware
May 6, 2026
Mar 7, 2015
N/A· v4
N/A· v3
7.8 HIGH· v2
Siemens SPC controllers SPC4000, SPC5000, and SPC6000 before 3.6.0 allow remote attackers to cause a denial of service (device restart) via crafted packets.
1Siemens
1Wincc
May 6, 2026
Feb 18, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The remote-management module in the (1) Multi Panels, (2) Comfort Panels, and (3) RT Advanced functionality in Siemens SIMATIC WinCC (TIA Portal) before 13 SP1 and in the (4) panels and (5) runtime functionality in SIMAT...Show more
The remote-management module in the (1) Multi Panels, (2) Comfort Panels, and (3) RT Advanced functionality in Siemens SIMATIC WinCC (TIA Portal) before 13 SP1 and in the (4) panels and (5) runtime functionality in SIMATIC WinCC flexible before 2008 SP3 Up7 does not properly encrypt credentials in transit, which makes it easier for remote attackers to determine cleartext credentials by sniffing the network and conducting a decryption attack.Show less
1Siemens
1Simatic Step 7
May 6, 2026
Feb 18, 2015
N/A· v4
N/A· v3
4.4 MEDIUM· v2
Siemens SIMATIC STEP 7 (TIA Portal) before 13 SP1 determines a user's privileges on the basis of project-file fields that lack integrity protection, which allows remote attackers to establish arbitrary authorization data...Show more
Siemens SIMATIC STEP 7 (TIA Portal) before 13 SP1 determines a user's privileges on the basis of project-file fields that lack integrity protection, which allows remote attackers to establish arbitrary authorization data via a modified file.Show less
1Siemens
1Simatic Step 7
May 6, 2026
Feb 18, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
Siemens SIMATIC STEP 7 (TIA Portal) before 13 SP1 uses a weak password-hash algorithm, which makes it easier for local users to determine cleartext passwords by reading a project file and conducting a brute-force attack.
1Siemens
1Ruggedcom Firmware
May 6, 2026
Feb 2, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in the integrated web server on Siemens Ruggedcom WIN51xx devices with firmware before SS4.4.4624.35, WIN52xx devices with firmware before SS4.4.4624.35, WIN70xx devices with firmware before BS4.4.4621.32...Show more
Buffer overflow in the integrated web server on Siemens Ruggedcom WIN51xx devices with firmware before SS4.4.4624.35, WIN52xx devices with firmware before SS4.4.4624.35, WIN70xx devices with firmware before BS4.4.4621.32, and WIN72xx devices with firmware before BS4.4.4621.32 allows remote attackers to execute arbitrary code via unspecified vectors.Show less
1Siemens
1Ruggedcom Firmware
May 6, 2026
Feb 2, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
The integrated management service on Siemens Ruggedcom WIN51xx devices with firmware before SS4.4.4624.35, WIN52xx devices with firmware before SS4.4.4624.35, WIN70xx devices with firmware before BS4.4.4621.32, and WIN72...Show more
The integrated management service on Siemens Ruggedcom WIN51xx devices with firmware before SS4.4.4624.35, WIN52xx devices with firmware before SS4.4.4624.35, WIN70xx devices with firmware before BS4.4.4621.32, and WIN72xx devices with firmware before BS4.4.4621.32 allows remote attackers to bypass authentication and perform administrative actions via unspecified vectors.Show less
1Siemens
1Ruggedcom Firmware
May 6, 2026
Feb 2, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Siemens Ruggedcom WIN51xx devices with firmware before SS4.4.4624.35, WIN52xx devices with firmware before SS4.4.4624.35, WIN70xx devices with firmware before BS4.4.4621.32, and WIN72xx devices with firmware before BS4.4...Show more
Siemens Ruggedcom WIN51xx devices with firmware before SS4.4.4624.35, WIN52xx devices with firmware before SS4.4.4624.35, WIN70xx devices with firmware before BS4.4.4621.32, and WIN72xx devices with firmware before BS4.4.4621.32 allow context-dependent attackers to discover password hashes by reading (1) files or (2) security logs.Show less
1Siemens
1Scalance X 200 Series Firmware
May 6, 2026
Feb 2, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The web server on Siemens SCALANCE X-200IRT switches with firmware before 5.2.0 allows remote attackers to hijack sessions via unspecified vectors.
1Siemens
1Simatic S7 1200 Cpu Firmware
May 6, 2026
Jan 21, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Open redirect vulnerability in the integrated web server on Siemens SIMATIC S7-1200 CPU devices with firmware before 4.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via u...Show more
Open redirect vulnerability in the integrated web server on Siemens SIMATIC S7-1200 CPU devices with firmware before 4.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.Show less
1Siemens
2Scalance X 300 Series Firmware
Scalance X 408 Firmware
May 6, 2026
Jan 21, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The FTP server on Siemens SCALANCE X-300 switches with firmware before 4.0 and SCALANCE X 408 switches with firmware before 4.0 allows remote authenticated users to cause a denial of service (reboot) via crafted FTP pack...Show more
The FTP server on Siemens SCALANCE X-300 switches with firmware before 4.0 and SCALANCE X 408 switches with firmware before 4.0 allows remote authenticated users to cause a denial of service (reboot) via crafted FTP packets.Show less
1Siemens
2Scalance X 300 Series Firmware
Scalance X 408 Firmware
May 6, 2026
Jan 21, 2015
N/A· v4
N/A· v3
7.8 HIGH· v2
The web server on Siemens SCALANCE X-300 switches with firmware before 4.0 and SCALANCE X 408 switches with firmware before 4.0 allows remote attackers to cause a denial of service (reboot) via malformed HTTP requests.
1Siemens
1Simatic Wincc Sm@rtclient
May 6, 2026
Jan 14, 2015
N/A· v4
N/A· v3
1.9 LOW· v2
The Siemens SIMATIC WinCC Sm@rtClient app before 1.0.2 for iOS allows physically proximate attackers to discover Sm@rtServer credentials by leveraging an error in the credential-processing mechanism.