Siemens
Siemens Simatic Pcs7: vulnerabilities and CVEs
Siemens Simatic Pcs7 has 25 published vulnerabilities, 0 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs25
Last 12 months0
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-14023 | Medium (4.9) | 3.7% | — | Nov 6, 2017 | An Improper Input Validation issue was discovered in Siemens SIMATIC PCS 7 V8.1 prior to V8.1 SP1 with WinCC V7.3 Upd 13, and V8.2 all versions. The improper input validation vulnerability has been identified, which may… |
| CVE-2017-12069 | High (8.2) | 2.9% | — | Aug 30, 2017 | An XXE vulnerability has been identified in OPC Foundation UA .NET Sample Code before 2017-03-21 and Local Discovery Server (LDS) before 1.03.367. Among the affected products are Siemens SIMATIC PCS7 (All versions V8.1… |
| CVE-2016-7165 | Medium (6.4) | 0.38% | — | Nov 15, 2016 | A vulnerability has been identified in Primary Setup Tool (PST) (All versions < V4.2 HF1), SIMATIC IT Production Suite (All versions < V7.0 SP1 HFX 2), SIMATIC NET PC-Software (All versions < V14), SIMATIC PCS 7 V7.1… |
| CVE-2014-8552 | Medium (5) | 2.0% | — | Nov 26, 2014 | The WinCC server in Siemens SIMATIC WinCC 7.0 through SP3, 7.2 before Update 9, and 7.3 before Update 2; SIMATIC PCS 7 7.1 through SP4, 8.0 through SP2, and 8.1; and TIA Portal 13 before Update 6 allows remote attackers… |
| CVE-2014-8551 | High (10) | 5.3% | — | Nov 26, 2014 | The WinCC server in Siemens SIMATIC WinCC 7.0 through SP3, 7.2 before Update 9, and 7.3 before Update 2; SIMATIC PCS 7 7.1 through SP4, 8.0 through SP2, and 8.1; and TIA Portal 13 before Update 6 allows remote attackers… |
| CVE-2014-4686 | Medium (6.8) | 1.1% | — | Jul 24, 2014 | The Project administration application in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, has a hardcoded encryption key, which allows remote attackers to obtain sensitive information by extracting… |
| CVE-2014-4685 | Medium (4.6) | 0.36% | — | Jul 24, 2014 | Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows local users to gain privileges by leveraging weak system-object access control. |
| CVE-2014-4684 | Medium (6) | 1.3% | — | Jul 24, 2014 | The database server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote authenticated users to gain privileges via a request to TCP port 1433. |
| CVE-2014-4683 | Medium (4.9) | 1.2% | — | Jul 24, 2014 | The WebNavigator server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote authenticated users to gain privileges via a (1) HTTP or (2) HTTPS request. |
| CVE-2014-4682 | Medium (5) | 1.7% | — | Jul 24, 2014 | The WebNavigator server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote attackers to obtain sensitive information via an HTTP request. |
| CVE-2013-3959 | Medium (4) | 1.3% | — | Jun 14, 2013 | The Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMATIC PCS7 8.0 SP1 and earlier and other products, exhibits different behavior for NetBIOS user names depending on whether the user account exists,… |
| CVE-2013-3958 | High (7.5) | 1.9% | — | Jun 14, 2013 | The login implementation in the Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMATIC PCS7 8.0 SP1 and earlier and other products, has a hardcoded account, which makes it easier for remote attackers to… |
| CVE-2013-3957 | High (7.5) | 1.8% | — | Jun 14, 2013 | SQL injection vulnerability in the login screen in the Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMATIC PCS7 8.0 SP1 and earlier and other products, allows remote attackers to execute arbitrary SQL… |
| CVE-2013-0679 | Medium (4) | 2.3% | — | Mar 21, 2013 | Directory traversal vulnerability in the web server in Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, allows remote authenticated users to read arbitrary files via vectors involving… |
| CVE-2013-0678 | Medium (4) | 1.5% | — | Mar 21, 2013 | Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, does not properly represent WebNavigator credentials in a database, which makes it easier for remote authenticated users to obtain… |
| CVE-2013-0677 | Medium (5.8) | 1.9% | — | Mar 21, 2013 | The web server in Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, allows remote attackers to obtain sensitive information or cause a denial of service via a crafted project file. |
| CVE-2013-0676 | Medium (4) | 1.5% | — | Mar 21, 2013 | Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, does not properly assign privileges for the database containing WebNavigator credentials, which allows remote authenticated users to… |
| CVE-2013-0675 | Medium (6.1) | 1.0% | — | Mar 21, 2013 | Buffer overflow in CCEServer (aka the central communications component) in Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, allows remote attackers to cause a denial of service via a… |
| CVE-2013-0674 | Medium (6.8) | 3.4% | — | Mar 21, 2013 | Buffer overflow in the RegReader ActiveX control in Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, allows remote attackers to execute arbitrary code via a long parameter. |
| CVE-2012-3034 | Medium (4.3) | 2.2% | — | Sep 18, 2012 | WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers to discover a username and password via crafted parameters to unspecified methods in ActiveX… |
| CVE-2012-3032 | High (7.5) | 2.4% | — | Sep 18, 2012 | SQL injection vulnerability in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers to execute arbitrary SQL commands via a crafted SOAP message. |
| CVE-2012-3031 | Medium (4.3) | 2.1% | — | Sep 18, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allow remote attackers to inject arbitrary web script or HTML via a… |
| CVE-2012-3030 | Medium (5) | 2.6% | — | Sep 18, 2012 | WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, stores sensitive information under the web root with insufficient access control, which allows remote attackers to read a… |
| CVE-2012-3028 | Medium (6.8) | 0.98% | — | Sep 18, 2012 | Cross-site request forgery (CSRF) vulnerability in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers to hijack the authentication of arbitrary users… |
| CVE-2012-3015 | Medium (6.9) | 0.46% | — | Jul 26, 2012 | Untrusted search path vulnerability in Siemens SIMATIC STEP7 before 5.5 SP1, as used in SIMATIC PCS7 7.1 SP3 and earlier and other products, allows local users to gain privileges via a Trojan horse DLL in a STEP7… |