Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
siemens sinec nms vulnerabilities and exploits
(subscribe to this query)
4
CVSSv2
CVE-2021-37200
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP1). An attacker with access to the webserver of an affected system could download arbitrary files from the underlying filesystem by sending a specially crafted HTTP request.
Siemens Sinec Network Management System
Siemens Sinec Network Management System 1.0
9
CVSSv2
CVE-2021-33721
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2). The affected application incorrectly neutralizes special elements when creating batch operations which could lead to command injection. An authenticated remote attacker with administrative privileges c...
Siemens Sinec Network Management System
Siemens Sinec Network Management System 1.0
7.8
CVSSv2
CVE-2019-6575
A vulnerability has been identified in SIMATIC CP 443-1 OPC UA (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions < V2.7), SIMATIC HMI Comfort Outdoor Panels 7" & 15" (incl. SIPLUS variants) (All versions < V1...
Siemens Simatic Cp443-1 Opc Ua Firmware
Siemens Simatic Et 200 Open Controller Cpu 1515sp Pc2 Firmware
Siemens Simatic Ipc Diagmonitor Firmware
Siemens Simatic Net Pc Software Firmware
Siemens Simatic Rf188c Firmware
Siemens Simatic Rf600r Firmware
Siemens Simatic S7-1500 Firmware
Siemens Sinumerik Opc Ua Server
Siemens Simatic Wincc Oa
Siemens Simatic Wincc Runtime Advanced
Siemens Simatic Wincc Runtime Comfort
Siemens Simatic Wincc Runtime Hsp Comfort
Siemens Simatic Wincc Runtime Mobile
Siemens Sinema Server
Siemens Simatic S7-1500 Software Controller
Siemens Opc Unified Architecture
Siemens Sinec-nms 1.0
Siemens Telecontrol Server Basic
Siemens Sinec-nms
Siemens Simatic S7-1500f Firmware
Siemens Simatic S7-1500s Firmware
Siemens Simatic S7-1500t Firmware
6.5
CVSSv2
CVE-2022-25311
A vulnerability has been identified in SINEC NMS (All versions >= V1.0.3 < V2.0), SINEC NMS (All versions < V1.0.3), SINEMA Server V14 (All versions). The affected software do not properly check privileges between users during the same web browser session, creating an un...
Siemens Sinec Network Management System
Siemens Sinema Server 14.0
6.5
CVSSv2
CVE-2022-24281
A vulnerability has been identified in SINEC NMS (All versions < V1.0.3), SINEMA Server V14 (All versions). A privileged authenticated attacker could execute arbitrary commands in the local database by sending specially crafted requests to the webserver of the affected applica...
Siemens Sinec Network Management System
6.5
CVSSv2
CVE-2022-24282
A vulnerability has been identified in SINEC NMS (All versions >= V1.0.3 < V2.0), SINEC NMS (All versions < V1.0.3), SINEMA Server V14 (All versions). The affected system allows to upload JSON objects that are deserialized to Java objects. Due to insecure deserialization...
Siemens Sinec Network Management System
7.2
CVSSv2
CVE-2020-7580
A vulnerability has been identified in SIMATIC Automation Tool (All versions < V4 SP2), SIMATIC NET PC Software V14 (All versions < V14 SP1 Update 14), SIMATIC NET PC Software V15 (All versions), SIMATIC NET PC Software V16 (All versions < V16 Upd3), SIMATIC PCS neo (All...
Siemens Simatic Pcs 7
Siemens Simatic Wincc 7.4
Siemens Simatic Wincc Runtime Advanced
Siemens Sinema Server
Siemens Simatic Net Pc 16
Siemens Simatic Net Pc
Siemens Simatic Prosave
Siemens Simatic Pcs Neo
Siemens Simatic Automatic Tool
Siemens Simatic Step 7 5.6
Siemens Simatic Step 7
Siemens Simatic Wincc Open Architecture 3.17
Siemens Simatic Wincc Open Architecture 3.16
Siemens Sinumerik Operate
Siemens Sinumerik One Virtual
Siemens Sinec Network Management System
Siemens Sinamics Startdrive
Siemens Sinamics Starter Commissioning Tool
Siemens Simatic Wincc 7.5
Siemens Simatic Wincc
Siemens Simatic Wincc Runtime Professional
Siemens Simatic S7-1500 Software Controller
NA
CVE-2024-23810
A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP1). The affected application is vulnerable to SQL injection. This could allow an unauthenticated remote malicious user to execute arbitrary SQL queries on the server database.
NA
CVE-2024-23811
A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP1). The affected application allows users to upload arbitrary files via TFTP. This could allow an malicious user to upload malicious firmware images or other files, that could potentially lead to remote co...
NA
CVE-2024-23812
A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP1). The affected application incorrectly neutralizes special elements when creating a report which could lead to command injection.
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4946
CVE-2024-30309
CVE-2024-4761
CVE-2024-30051
type confusion
memory leak
CVE-2024-30293
reflected XSS
CVE-2024-3126
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »