Lucene search

K

Simatic S7-1500 Cpu 1512C Firmware Security Vulnerabilities

cve
cve

CVE-2019-10929

A vulnerability has been identified in SIMATIC CP 1626 (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants) (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions < V20.8), SIMATIC HMI Panel (incl. SIPLUS variants) ...

5.9CVSS

5.5AI Score

0.001EPSS

2019-08-13 07:15 PM
56
cve
cve

CVE-2019-10936

Affected devices improperly handle large amounts of specially crafted UDP packets. This could allow an unauthenticated remote attacker to trigger a denial of service condition.

7.5CVSS

7.5AI Score

0.002EPSS

2019-10-10 02:15 PM
94
cve
cve

CVE-2019-10943

A vulnerability has been identified in SIMATIC Drive Controller family (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants) (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions < V20.8), SIMATIC ET 200SP Open Cont...

7.5CVSS

7.3AI Score

0.001EPSS

2019-08-13 07:15 PM
51
cve
cve

CVE-2021-40365

Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device.

7.5CVSS

7.3AI Score

0.001EPSS

2022-12-13 04:15 PM
46
cve
cve

CVE-2021-44693

Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device.

4.9CVSS

5.7AI Score

0.001EPSS

2022-12-13 04:15 PM
63
cve
cve

CVE-2021-44694

Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device.

5.5CVSS

5.9AI Score

0.001EPSS

2022-12-13 04:15 PM
53
cve
cve

CVE-2021-44695

Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device.

4.9CVSS

5.7AI Score

0.001EPSS

2022-12-13 04:15 PM
44
cve
cve

CVE-2022-30694

The login endpoint /FormLogin in affected web services does not apply proper origin checking. This could allow authenticated remote attackers to track the activities of other users via a login cross-site request forgery attack.

6.5CVSS

4.6AI Score

0.001EPSS

2022-11-08 11:15 AM
77
2