Siemens
siemens
2,161 CVEs • 4,155 products
Products (4,155)
Click to collapseToggle
Products (4,155)
Click to collapse
CVEs (2,161)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Siemens 9Simatic S7 1200 Cpu 1211c Firmware Simatic S7 1200 Cpu 1212c FirmwareSimatic S7 1200 Cpu 1212fc Firmware+6 moreApr 29, 2026 Sep 25, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The Siemens SIMATIC S7-1200 2.x PLC does not properly protect the private key of the SIMATIC CONTROLLER Certification Authority certificate, which allows remote attackers to spoof the S7-1200 web server by using this key...Show more |
WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers to discover a username and password via crafted parameters to unspecified methods in ActiveX controls...Show more |
SQL injection vulnerability in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers to execute arbitrary SQL commands via a crafted SOAP message. |
Multiple cross-site scripting (XSS) vulnerabilities in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allow remote attackers to inject arbitrary web script or HTML via a (1...Show more |
WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, stores sensitive information under the web root with insufficient access control, which allows remote attackers to read a (1)...Show more |
Cross-site request forgery (CSRF) vulnerability in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers to hijack the authentication of arbitrary users fo...Show more |
Siemens COMOS before 9.1 Patch 413, 9.2 before Update 03 Patch 023, and 10.0 before Patch 005 allows remote authenticated users to obtain database administrative access via unspecified method calls. |
1Siemens 2Synco Ozw Web Server Synco Ozw Web Server FirmwareApr 29, 2026 Aug 6, 2012 N/A· v4 N/A· v3 7.5 HIGH· v2 The Siemens Synco OZW Web Server devices OZW672.*, OZW772.*, and OZW775 with firmware before 4 have an unspecified default password, which makes it easier for remote attackers to obtain administrative access via a networ...Show more |
1Siemens 4Simatic S7 400 Cpu 414 3 Pn/dp Simatic S7 400 Cpu 416 3 Pn/dpSimatic S7 400 Cpu 416f 3 Pn/dp+1 moreApr 29, 2026 Jul 31, 2012 N/A· v4 N/A· v3 7.8 HIGH· v2 Siemens SIMATIC S7-400 PN CPU devices with firmware 5.x allow remote attackers to cause a denial of service (defect-mode transition and service outage) via (1) malformed HTTP traffic or (2) malformed IP packets. |
1Siemens 6Simatic S7 400 Cpu 412 2 Pn Simatic S7 400 Cpu 414 3 Pn/dpSimatic S7 400 Cpu 414f 3 Pn/dp+3 moreApr 29, 2026 Jul 31, 2012 N/A· v4 N/A· v3 7.8 HIGH· v2 Siemens SIMATIC S7-400 PN CPU devices with firmware 6 before 6.0.3 allow remote attackers to cause a denial of service (defect-mode transition and service outage) via crafted ICMP packets. |
1Siemens 2Simatic Pcs7 Simatic Step 7Apr 29, 2026 Jul 26, 2012 N/A· v4 N/A· v3 6.9 MEDIUM· v2 Untrusted search path vulnerability in Siemens SIMATIC STEP7 before 5.5 SP1, as used in SIMATIC PCS7 7.1 SP3 and earlier and other products, allows local users to gain privileges via a Trojan horse DLL in a STEP7 project...Show more |
Open redirect vulnerability in an unspecified web application in Siemens WinCC 7.0 SP3 before Update 2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in a GET requ...Show more |
Buffer overflow in the DiagAgent web server in Siemens WinCC 7.0 SP3 through Update 2 allows remote attackers to cause a denial of service (agent outage) via crafted input. |
Multiple directory traversal vulnerabilities in Siemens WinCC 7.0 SP3 before Update 2 allow remote authenticated users to read arbitrary files via a crafted parameter in a URL. |
The XPath functionality in unspecified web applications in Siemens WinCC 7.0 SP3 before Update 2 does not properly handle special characters in parameters, which allows remote authenticated users to read or modify settin...Show more |
Multiple cross-site scripting (XSS) vulnerabilities in unspecified web applications in Siemens WinCC 7.0 SP3 before Update 2 allow remote attackers to inject arbitrary web script or HTML via vectors involving special cha...Show more |
1Siemens 1Ruggedcom Rugged Operating System Apr 29, 2026 Apr 28, 2012 N/A· v4 N/A· v3 8.5 HIGH· v2 RuggedCom Rugged Operating System (ROS) before 3.3 has a factory account with a password derived from the MAC Address field in a banner, which makes it easier for remote attackers to obtain access by performing a calcula...Show more |
1Siemens 1Ruggedcom Rugged Operating System Apr 29, 2026 Apr 28, 2012 N/A· v4 N/A· v3 8.5 HIGH· v2 RuggedCom Rugged Operating System (ROS) 3.10.x and earlier has a factory account with a password derived from the MAC Address field in the banner, which makes it easier for remote attackers to obtain access by performing...Show more |
1Siemens 10Scalance X 300 Scalance X 300 FirmwareScalance X 300eec+7 moreApr 29, 2026 Apr 18, 2012 N/A· v4 N/A· v3 7.8 HIGH· v2 Buffer overflow in the embedded web server on the Siemens Scalance X Industrial Ethernet switch X414-3E before 3.7.1, X308-2M before 3.7.2, X-300EEC before 3.7.2, XR-300 before 3.7.2, and X-300 before 3.7.2 allows remote...Show more |
1Siemens 4Scalance S602 Scalance S612Scalance S613+1 moreApr 29, 2026 Apr 18, 2012 N/A· v4 N/A· v3 6.1 MEDIUM· v2 Stack-based buffer overflow in the Profinet DCP protocol implementation on the Siemens Scalance S Security Module firewall S602 V2, S612 V2, and S613 V2 with firmware before 2.3.0.3 allows remote attackers to cause a den...Show more |