Siemens
Siemens Automation License Manager: vulnerabilidades y CVE
Siemens Automation License Manager tiene 15 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE15
Últimos 12 meses0
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-44087 | Crítica (9.2) | 11% | — | 10 sept 2024 | A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6.0 (All versions < V6.0 SP12 Upd3), Automation License Manager V6.2 (All versions < V6.2 Upd3). Affected… |
| CVE-2022-43514 | Crítica (9.8) | 1.5% | — | 10 ene 2023 | A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6 (All versions < V6.0 SP9 Upd4), TeleControl Server Basic V3 (All versions < V3.1.2). The affected… |
| CVE-2022-43513 | Alta (7.5) | 0.97% | — | 10 ene 2023 | A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6 (All versions < V6.0 SP9 Upd4), TeleControl Server Basic V3 (All versions < V3.1.2). The affected… |
| CVE-2021-25659 | Alta (7.5) | 1.0% | — | 10 ago 2021 | A vulnerability has been identified in Automation License Manager 5 (All versions), Automation License Manager 6 (All versions < V6.0 SP9 Update 2). Sending specially crafted packets to port 4410/tcp of an affected… |
| CVE-2020-7583 | Alta (7.8) | 0.27% | — | 14 ago 2020 | A vulnerability has been identified in Automation License Manager 5 (All versions), Automation License Manager 6 (All versions < V6.0.8). The application does not properly validate the users' privileges when executing… |
| CVE-2018-11456 | Media (5.8) | 1.3% | — | 7 ago 2018 | A vulnerability has been identified in Automation License Manager 5 (All versions < 5.3.4.4). An attacker with network access to the device could send specially crafted network packets to determine whether or not a… |
| CVE-2018-11455 | Alta (8.8) | 5.3% | — | 7 ago 2018 | A vulnerability has been identified in Automation License Manager 5 (All versions < 5.3.4.4), Automation License Manager 6 (All versions < 6.0.1). A directory traversal vulnerability could allow a remote attacker to… |
| CVE-2016-8565 | Crítica (9.1) | 2.9% | — | 13 oct 2016 | Siemens Automation License Manager (ALM) before 5.3 SP3 allows remote attackers to write to files, rename files, create directories, or delete directories via crafted packets. |
| CVE-2016-8564 | Media (6.5) | 1.1% | — | 13 oct 2016 | SQL injection vulnerability in Siemens Automation License Manager (ALM) before 5.3 SP3 Update 1 allows remote attackers to execute arbitrary SQL commands via crafted traffic to TCP port 4410. |
| CVE-2016-8563 | Alta (7.5) | 3.0% | — | 13 oct 2016 | Siemens Automation License Manager (ALM) before 5.3 SP3 Update 1 allows remote attackers to cause a denial of service (ALM service outage) via crafted packets to TCP port 4410. |
| CVE-2012-4691 | Baja (3.3) | 0.89% | — | 18 dic 2012 | Memory leak in Siemens Automation License Manager (ALM) 4.x and 5.x before 5.2 allows remote attackers to cause a denial of service (memory consumption) via crafted packets. |
| CVE-2011-4532 | Media (5) | 3.2% | — | 8 ene 2012 | Absolute path traversal vulnerability in the ALMListView.ALMListCtrl ActiveX control in almaxcx.dll in the graphical user interface in Siemens Automation License Manager (ALM) 2.0 through 5.1+SP1+Upd2 allows remote… |
| CVE-2011-4531 | Media (5) | 8.4% | — | 8 ene 2012 | Siemens Automation License Manager (ALM) 4.0 through 5.1+SP1+Upd1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via crafted content in a (1) get_target_ocx_param or (2)… |
| CVE-2011-4530 | Media (5) | 4.1% | — | 8 ene 2012 | Siemens Automation License Manager (ALM) 4.0 through 5.1+SP1+Upd1 does not properly copy fields obtained from clients, which allows remote attackers to cause a denial of service (exception and daemon crash) via long… |
| CVE-2011-4529 | Alta (7.5) | 6.9% | — | 8 ene 2012 | Multiple buffer overflows in Siemens Automation License Manager (ALM) 4.0 through 5.1+SP1+Upd1 allow remote attackers to execute arbitrary code via a long serialid field in an _licensekey command, as demonstrated by the… |