Vulnerabilities in siemens

1,679 results
Vexday analysis

Siemens apresenta footprint reduzido com apenas 2 CVEs na base, nenhuma sob ataque ativo confirmado. Uma vulnerabilidade foi publicada nos últimos 90 dias, identificada como validação inadequada de entrada (CWE-20), o que sugere risco moderado em cenários de interação com dados não confiáveis, mas sem indicadores de exploração em massa no momento.

CVE-2022-23312—A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP9 Security Patch 1). The integrated web application "Online EPSS 0.6%CVE-2021-41541—A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.44), Climatix POL909 (AWM module) (All versions < V1EPSS 0.6%CVE-2024-43647HIGHA vulnerability has been identified in SIMATIC S7-200 SMART CPU CR40 (6ES7288-1CR40-0AA0) (All versions), SIMATIC S7-200 SMART CPU CR60 (6ESEPSS 0.6%CVE-2025-23363MEDIUMA vulnerability has been identified in Teamcenter V14.1 (All versions), Teamcenter V14.2 (All versions), Teamcenter V14.3 (All versions < V1EPSS 0.6%CVE-2024-41940CRITICALA vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application does not properly validate user input to a EPSS 0.6%CVE-2024-46887MEDIUMThe web server of affected devices do not properly authenticate user request to the '/ClientArea/RuntimeInfoData.mwsl' endpoint. This could EPSS 0.6%CVE-2024-45386HIGHA vulnerability has been identified in SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Update 2), SIMATIC PCSEPSS 0.6%CVE-2023-27410LOWA vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). A heap-based buffer overflow vulnerability was found in the `EPSS 0.6%CVE-2024-23815HIGHA vulnerability has been identified in Desigo CC (All versions if access from Installed Clients to Desigo CC server is allowed from networksEPSS 0.6%CVE-2023-29105MEDIUMA vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC712 (All versiEPSS 0.6%CVE-2025-24812HIGHA vulnerability has been identified in SIMATIC S7-1200 CPU 1211C AC/DC/Rly (6ES7211-1BE40-0XB0) (All versions < V4.7), SIMATIC S7-1200 CPU 1EPSS 0.5%CVE-2023-40731MEDIUMA vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application allows users to upload arbitrary filEPSS 0.5%CVE-2022-44731MEDIUMA vulnerability has been identified in SIMATIC WinCC OA V3.15 (All versions < V3.15 P038), SIMATIC WinCC OA V3.16 (All versions < V3.16 P035EPSS 0.5%CVE-2024-47563MEDIUMA vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate aEPSS 0.5%CVE-2023-42797MEDIUMA vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05.20), CP-8050 MASTER MODULE (All versions < CPCI85 V0EPSS 0.5%CVE-2018-4843MEDIUMA vulnerability has been identified in SIMATIC S7-400 CPU 414-3 PN/DP V7 (All versions < V7.0.3), SIMATIC S7-400 CPU 414F-3 PN/DP V7 (All EPSS 0.5%CVE-2024-51444HIGHA vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.4). The application insufficientlEPSS 0.5%CVE-2024-41793HIGHA vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices provides an enEPSS 0.5%CVE-2024-41798CRITICALA vulnerability has been identified in SENTRON 7KM PAC3200 (All versions). Affected devices only provide a 4-digit PIN to protect from adminEPSS 0.5%CVE-2023-37373MEDIUMA vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.4). The affected applications accept unauthenticated file writeEPSS 0.5%