Siemens / Simatic S7-Plcsim Advanced
24 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-54429 | A vulnerability has been identified in SIMATIC S7-PLCSIM Advanced (All versions). Affected devices do not properly handle high-volume multicast network traffic… | MEDIUM | 6.0 | Jul 14, 2026 |
| CVE-2026-25789 | Affected devices do not properly validate and sanitize filenames on the Firmware Update page. This could allow a remote attacker to social engineer the user in… | HIGH | 7.2 | May 12, 2026 |
| CVE-2026-25787 | Affected devices do not properly validate and sanitize Technology Object (TO) name rendered on the "Motion Control Diagnostics" page of the web interface. This… | CRITICAL | 9.3 | May 12, 2026 |
| CVE-2026-25786 | Affected devices do not properly validate and sanitize PLC/station name rendered on the "communication" parameters page of the web interface. This could allow… | CRITICAL | 9.3 | May 12, 2026 |
| CVE-2025-40943 | Affected devices do not properly sanitize contents of trace files. This could allow an attacker to inject code through social engineering an authorized user, w… | CRITICAL | 9.4 | Mar 10, 2026 |
| CVE-2025-30033 | The affected setup component is vulnerable to DLL hijacking. This could allow an attacker to execute arbitrary code when a legitimate user installs an applicat… | HIGH | 8.5 | Aug 12, 2025 |
| CVE-2023-37482 | The login functionality of the web server in affected devices does not normalize the response times of login attempts. An unauthenticated remote attacker could… | MEDIUM | 6.9 | Feb 11, 2025 |
| CVE-2024-46887 | The web server of affected devices do not properly authenticate user request to the '/ClientArea/RuntimeInfoData.mwsl' endpoint. This could allow an unauthenti… | MEDIUM | 6.9 | Oct 8, 2024 |
| CVE-2024-46886 | The web server of affected devices does not properly validate input that is used for a user redirection. This could allow an attacker to make the server redire… | MEDIUM | 5.1 | Oct 8, 2024 |
| CVE-2023-46156 | Affected devices improperly handle specially crafted packets sent to port 102/tcp. This could allow an attacker to create a denial of service condition. A rest… | HIGH | 7.5 | Dec 12, 2023 |
| CVE-2023-28831 | The OPC UA implementations (ANSI C and C++) in affected products contain an integer overflow vulnerability that could cause the application to run into an infi… | HIGH | 8.7 | Sep 12, 2023 |
| CVE-2021-44695 | Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in th… | HIGH | 7.5 | Dec 13, 2022 |
| CVE-2021-44694 | Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in th… | HIGH | 7.5 | Dec 13, 2022 |
| CVE-2021-44693 | Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in th… | HIGH | 7.5 | Dec 13, 2022 |
| CVE-2021-40365 | Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in th… | HIGH | 7.5 | Dec 13, 2022 |
| CVE-2022-30694 | The login endpoint /FormLogin in affected web services does not apply proper origin checking. This could allow authenticated remote attackers to track the acti… | MEDIUM | 6.5 | Nov 8, 2022 |
| CVE-2022-38465 | A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS va… | CRITICAL | 9.3 | Oct 11, 2022 |
| CVE-2021-37205 | A vulnerability has been identified in SIMATIC Drive Controller family (All versions >= V2.9.2 < V2.9.4), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl… | HIGH | 7.5 | Feb 9, 2022 |
| CVE-2021-37204 | A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC Drive Controller family (All versions >= V2.9.2 < V2.9.… | HIGH | 7.5 | Feb 9, 2022 |
| CVE-2021-37185 | A vulnerability has been identified in SIMATIC Drive Controller family (All versions >= V2.9.2 < V2.9.4), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl… | HIGH | 7.5 | Feb 9, 2022 |
| CVE-2020-15782 | A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS va… | CRITICAL | 9.8 | May 28, 2021 |
| CVE-2019-10943 | A vulnerability has been identified in SIMATIC Drive Controller family (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants) (… | HIGH | 7.5 | Aug 13, 2019 |
| CVE-2019-10929 | A vulnerability has been identified in SIMATIC CP 1626 (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants) (All versions), S… | MEDIUM | 5.9 | Aug 13, 2019 |
| CVE-2019-6568 | The webserver of the affected devices contains a vulnerability that may lead to a denial of service condition. An attacker may cause a denial of service situat… | HIGH | 7.5 | Apr 17, 2019 |
Showing 1 to 24 of 24 CVEs