Siemens / Simatic S7-1500 Software Controller
21 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-46156 | Affected devices improperly handle specially crafted packets sent to port 102/tcp. This could allow an attacker to create a denial of service condition. A rest… | HIGH | 7.5 | Dec 12, 2023 |
| CVE-2022-30694 | The login endpoint /FormLogin in affected web services does not apply proper origin checking. This could allow authenticated remote attackers to track the acti… | MEDIUM | 6.5 | Nov 8, 2022 |
| CVE-2022-38465 | A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS va… | CRITICAL | 9.3 | Oct 11, 2022 |
| CVE-2021-37205 | A vulnerability has been identified in SIMATIC Drive Controller family (All versions >= V2.9.2 < V2.9.4), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl… | HIGH | 7.5 | Feb 9, 2022 |
| CVE-2021-37204 | A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC Drive Controller family (All versions >= V2.9.2 < V2.9.… | HIGH | 7.5 | Feb 9, 2022 |
| CVE-2021-37185 | A vulnerability has been identified in SIMATIC Drive Controller family (All versions >= V2.9.2 < V2.9.4), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl… | HIGH | 7.5 | Feb 9, 2022 |
| CVE-2020-28397 | A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS v… | MEDIUM | 5.3 | Aug 10, 2021 |
| CVE-2020-15782 | A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS va… | CRITICAL | 9.8 | May 28, 2021 |
| CVE-2020-15796 | A vulnerability has been identified in SIMATIC ET 200SP Open Controller (incl. SIPLUS variants) (V20.8), SIMATIC S7-1500 Software Controller (V20.8). The web s… | HIGH | 7.5 | Dec 14, 2020 |
| CVE-2020-7580 | A vulnerability has been identified in SIMATIC Automation Tool (All versions < V4 SP2), SIMATIC NET PC Software V14 (All versions < V14 SP1 Update 14), SIMATIC… | MEDIUM | 6.7 | Jun 10, 2020 |
| CVE-2019-19300 | A vulnerability has been identified in Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200, Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200P, K… | HIGH | 7.5 | Apr 14, 2020 |
| CVE-2019-19281 | A vulnerability has been identified in SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions >= V2.5 and < V20.8), SIMATIC S7-1… | HIGH | 7.5 | Mar 10, 2020 |
| CVE-2019-10936 | Affected devices improperly handle large amounts of specially crafted UDP packets. This could allow an unauthenticated remote attacker to trigger a denial of s… | HIGH | 7.5 | Oct 10, 2019 |
| CVE-2019-10943 | A vulnerability has been identified in SIMATIC Drive Controller family (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants) (… | HIGH | 7.5 | Aug 13, 2019 |
| CVE-2019-10929 | A vulnerability has been identified in SIMATIC CP 1626 (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants) (All versions), S… | MEDIUM | 5.9 | Aug 13, 2019 |
| CVE-2019-6575 | A vulnerability has been identified in SIMATIC CP 443-1 OPC UA (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All ver… | HIGH | 7.5 | Apr 17, 2019 |
| CVE-2019-6568 | The webserver of the affected devices contains a vulnerability that may lead to a denial of service condition. An attacker may cause a denial of service situat… | HIGH | 7.5 | Apr 17, 2019 |
| CVE-2018-13805 | A vulnerability has been identified in SIMATIC ET 200SP Open Controller (All versions >= V2.0 and < V2.1.6), SIMATIC S7-1500 Software Controller (All versions… | HIGH | 7.5 | Oct 10, 2018 |
| CVE-2018-4843 | A vulnerability has been identified in SIMATIC S7-400 CPU 414-3 PN/DP V7 (All versions < V7.0.3), SIMATIC S7-400 CPU 414F-3 PN/DP V7 (All versions < V7.0.3), S… | MEDIUM | 6.5 | Mar 20, 2018 |
| CVE-2017-12741 | Specially crafted packets sent to port 161/udp could cause a denial of service condition. The affected devices must be restarted manually. | HIGH | 8.7 | Dec 26, 2017 |
| CVE-2017-2681 | Specially crafted PROFINET DCP packets sent on a local Ethernet segment (Layer 2) to an affected product could cause a denial of service condition of that prod… | HIGH | 7.1 | May 11, 2017 |
| CVE-2017-2680 | Specially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affected products on a local Ethernet segment (Layer 2). Human in… | HIGH | 7.1 | May 11, 2017 |
Showing 1 to 21 of 21 CVEs