Siemens / Simatic S7-1500 Firmware
13 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2020-8744 | Improper initialization in subsystem for Intel(R) CSME versions before12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE versions before 4.0.30 Inte… | HIGH | 7.8 | Nov 12, 2020 |
| CVE-2019-6575 | A vulnerability has been identified in SIMATIC CP 443-1 OPC UA (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All ver… | HIGH | 7.5 | Apr 17, 2019 |
| CVE-2019-6568 | The webserver of the affected devices contains a vulnerability that may lead to a denial of service condition. An attacker may cause a denial of service situat… | HIGH | 7.5 | Apr 17, 2019 |
| CVE-2018-16559 | A vulnerability has been identified in SIMATIC S7-1500 CPU (All versions >= V2.0 and < V2.5), SIMATIC S7-1500 CPU (All versions <= V1.8.5). Specially crafted n… | HIGH | 7.5 | Apr 17, 2019 |
| CVE-2018-16558 | A vulnerability has been identified in SIMATIC S7-1500 CPU (All versions >= V2.0 and < V2.5), SIMATIC S7-1500 CPU (All versions <= V1.8.5). Specially crafted n… | HIGH | 7.5 | Apr 17, 2019 |
| CVE-2018-13815 | A vulnerability has been identified in SIMATIC S7-1200 (All versions), SIMATIC S7-1500 (All Versions < V2.6). An attacker could exhaust the available connectio… | HIGH | 7.5 | Dec 13, 2018 |
| CVE-2018-13805 | A vulnerability has been identified in SIMATIC ET 200SP Open Controller (All versions >= V2.0 and < V2.1.6), SIMATIC S7-1500 Software Controller (All versions… | HIGH | 7.5 | Oct 10, 2018 |
| CVE-2018-3639 | hw: cpu: speculative store bypass | MEDIUM | 5.5 | May 22, 2018 |
| CVE-2018-4843 | A vulnerability has been identified in SIMATIC S7-400 CPU 414-3 PN/DP V7 (All versions < V7.0.3), SIMATIC S7-400 CPU 414F-3 PN/DP V7 (All versions < V7.0.3), S… | MEDIUM | 6.5 | Mar 20, 2018 |
| CVE-2017-12741 | Specially crafted packets sent to port 161/udp could cause a denial of service condition. The affected devices must be restarted manually. | HIGH | 8.7 | Dec 26, 2017 |
| CVE-2017-2681 | Specially crafted PROFINET DCP packets sent on a local Ethernet segment (Layer 2) to an affected product could cause a denial of service condition of that prod… | HIGH | 7.1 | May 11, 2017 |
| CVE-2017-2680 | Specially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affected products on a local Ethernet segment (Layer 2). Human in… | HIGH | 7.1 | May 11, 2017 |
| CVE-2014-0160 KEV | openssl: information disclosure in handling of TLS heartbeat extension packets | HIGH | 7.5 | Apr 7, 2014 |
Showing 1 to 13 of 13 CVEs