Vulnerabilidades em Siemens

1.679 resultados
Análise Vexday

O portfólio da Siemens acumula 1.633 CVEs catalogadas, volume expressivo que reflete a amplitude e a longevidade de seu ecossistema de produtos industriais e de automação. Nenhuma dessas vulnerabilidades consta atualmente no catálogo CISA KEV, taxa abaixo da média geral do catálogo, o que sugere menor pressão de exploração ativa no momento — embora 113 vulnerabilidades de severidade crítica e 31 surgidas nos últimos 90 dias indiquem um fluxo contínuo de exposição que requer monitoramento constante. O CVE mais relevante em termos de probabilidade de exploração é o CVE-2023-33919, com EPSS de 0,4772, valor que merece atenção em processos de priorização de correções. A falha mais frequente é do tipo CWE-125 (leitura fora dos limites de memória), padrão recorrente em componentes de software embarcado e de controle industrial que tende a viabilizar negação de serviço ou vazamento de informações sensíveis.

CVE-2023-44120HIGHA vulnerability has been identified in Spectrum Power 7 (All versions < V23Q4). The affected product's sudo configuration permits the local EPSS 0.1%CVE-2023-50236HIGHA vulnerability has been identified in Polarion ALM (All versions < V2404.0). The affected product is vulnerable due to weak file and folderEPSS 0.1%CVE-2024-35208MEDIUMA vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server stored theEPSS 0.1%CVE-2023-38533MEDIUMA vulnerability has been identified in TIA Administrator (All versions < V3 SP2). The affected component creates temporary download files inEPSS 0.1%CVE-2024-29119HIGHA vulnerability has been identified in Spectrum Power 7 (All versions < V24Q3). The affected product contains several root-owned SUID binariEPSS 0.1%CVE-2023-45793MEDIUMA vulnerability has been identified in Siveillance Control (All versions >= V2.8 < V3.1.1). The affected product does not properly check theEPSS 0.1%CVE-2024-47783HIGHA vulnerability has been identified in SIPORT (All versions < V3.4.0). The affected application improperly assigns file permissions to instaEPSS 0.1%CVE-2022-46141MEDIUMA vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) (All versions < V19). An information disclosure vulnerability could allowEPSS 0.1%CVE-2025-27769LOWA vulnerability has been identified in Heliox Flex 180 kW EV Charging Station (All versions < F4.11.1), Heliox Mobile DC 40 kW EV Charging SEPSS 0.1%CVE-2026-23718HIGHA vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512). The affected applicEPSS 0.1%CVE-2025-40768HIGHA vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V3.0). The affected application exposes aEPSS 0.1%CVE-2025-30000MEDIUMA vulnerability has been identified in Siemens License Server (SLS) (All versions < V4.3). The affected application does not properly restriEPSS 0.1%CVE-2024-41171CRITICALA vulnerability has been identified in SINUMERIK 828D V4 (All versions), SINUMERIK 828D V5 (All versions < V5.24), SINUMERIK 840D sl V4 (AllEPSS 0.1%CVE-2024-37999HIGHA vulnerability has been identified in Medicalis Workflow Orchestrator (All versions). The affected application executes as a trusted accounEPSS 0.1%CVE-2026-22923HIGHA vulnerability has been identified in NX (All versions < V2512), NX (Managed Mode) (All versions < V2512). The affected application containEPSS 0.1%CVE-2025-40811HIGHA vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 14), Solid Edge SE2025 (All versions < V225.0 Update EPSS 0.1%CVE-2025-40739HIGHA vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 5). The affected applications contain an out of boundEPSS 0.1%CVE-2025-40812HIGHA vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 14), Solid Edge SE2025 (All versions < V225.0 Update EPSS 0.1%CVE-2025-40763HIGHA vulnerability has been identified in Altair Grid Engine (All versions < V2026.0.0). Affected products do not properly validate environmentEPSS 0.1%CVE-2025-40809HIGHA vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 14), Solid Edge SE2025 (All versions < V225.0 Update EPSS 0.1%