Siemens / Wincc
43 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-30897 | A vulnerability has been identified in SIMATIC WinCC (All versions < V7.5.2.13). Affected applications fail to set proper access rights for their installation… | HIGH | 7.8 | Jun 13, 2023 |
| CVE-2017-12069 | An XXE vulnerability has been identified in OPC Foundation UA .NET Sample Code before 2017-03-21 and Local Discovery Server (LDS) before 1.03.367. Among the af… | HIGH | 8.2 | Aug 30, 2017 |
| CVE-2015-2823 | Siemens SIMATIC HMI Basic Panels 2nd Generation before WinCC (TIA Portal) 13 SP1 Upd2, SIMATIC HMI Comfort Panels before WinCC (TIA Portal) 13 SP1 Upd2, SIMATI… | MEDIUM | 6.8 | Apr 8, 2015 |
| CVE-2015-2822 | Siemens SIMATIC HMI Comfort Panels before WinCC (TIA Portal) 13 SP1 Upd2 and SIMATIC WinCC Runtime Advanced before WinCC (TIA Portal) 13 SP1 Upd2 allow man-in-… | MEDIUM | 4.3 | Apr 8, 2015 |
| CVE-2015-1358 | The remote-management module in the (1) Multi Panels, (2) Comfort Panels, and (3) RT Advanced functionality in Siemens SIMATIC WinCC (TIA Portal) before 13 SP1… | MEDIUM | 5.0 | Feb 18, 2015 |
| CVE-2014-4686 | The Project administration application in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, has a hardcoded encryption key, which allows re… | MEDIUM | 6.8 | Jul 24, 2014 |
| CVE-2014-4685 | Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows local users to gain privileges by leveraging weak system-object access control. | MEDIUM | 4.6 | Jul 24, 2014 |
| CVE-2014-4684 | The database server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote authenticated users to gain privileges via a request… | MEDIUM | 6.0 | Jul 24, 2014 |
| CVE-2014-4683 | The WebNavigator server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote authenticated users to gain privileges via a (1)… | MEDIUM | 4.9 | Jul 24, 2014 |
| CVE-2014-4682 | The WebNavigator server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote attackers to obtain sensitive information via an… | MEDIUM | 5.0 | Jul 24, 2014 |
| CVE-2013-4912 | Open redirect vulnerability in Siemens WinCC (TIA Portal) 11 and 12 before 12 SP1 allows remote attackers to redirect users to arbitrary web sites and conduct… | MEDIUM | 5.8 | Jul 31, 2013 |
| CVE-2013-4911 | Cross-site request forgery (CSRF) vulnerability in Siemens WinCC (TIA Portal) 11 and 12 before 12 SP1 allows remote attackers to hijack the authentication of u… | MEDIUM | 6.8 | Jul 31, 2013 |
| CVE-2013-3959 | The Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMATIC PCS7 8.0 SP1 and earlier and other products, exhibits different behavior for NetBIOS… | MEDIUM | 4.0 | Jun 14, 2013 |
| CVE-2013-3958 | The login implementation in the Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMATIC PCS7 8.0 SP1 and earlier and other products, has a hardc… | HIGH | 7.5 | Jun 14, 2013 |
| CVE-2013-3957 | SQL injection vulnerability in the login screen in the Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMATIC PCS7 8.0 SP1 and earlier and othe… | HIGH | 7.5 | Jun 14, 2013 |
| CVE-2013-0679 | Directory traversal vulnerability in the web server in Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, allows remote authe… | MEDIUM | 4.0 | Mar 21, 2013 |
| CVE-2013-0678 | Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, does not properly represent WebNavigator credentials in a database, which… | MEDIUM | 4.0 | Mar 21, 2013 |
| CVE-2013-0677 | The web server in Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, allows remote attackers to obtain sensitive information… | MEDIUM | 5.8 | Mar 21, 2013 |
| CVE-2013-0676 | Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, does not properly assign privileges for the database containing WebNavigat… | MEDIUM | 4.0 | Mar 21, 2013 |
| CVE-2013-0675 | Buffer overflow in CCEServer (aka the central communications component) in Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products,… | MEDIUM | 6.1 | Mar 21, 2013 |
| CVE-2013-0674 | Buffer overflow in the RegReader ActiveX control in Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, allows remote attacker… | MEDIUM | 6.8 | Mar 21, 2013 |
| CVE-2012-3034 | WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers to discover a username and password via… | MEDIUM | 4.3 | Sep 18, 2012 |
| CVE-2012-3032 | SQL injection vulnerability in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers to execut… | HIGH | 7.5 | Sep 18, 2012 |
| CVE-2012-3031 | Multiple cross-site scripting (XSS) vulnerabilities in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allow rem… | MEDIUM | 4.3 | Sep 18, 2012 |
| CVE-2012-3030 | WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, stores sensitive information under the web root with insufficien… | MEDIUM | 5.0 | Sep 18, 2012 |
Showing 1 to 25 of 43 CVEs