CVE List

Id CVE No. Status Description Phase Votes Comments Actions
99505  CVE-2017-2685  Candidate  Siemens SINUMERIK Integrate Operate Clients between 2.0.3.00.016 (including) and 2.0.6 (excluding) and between 3.0.4.00.032 (including) and 3.0.6 (excluding) contain a vulnerability that could allow an attacker to read and manipulate data in TLS sessions while performing a man-in-the-middle (MITM) attack.  Assigned (20161201)  None (candidate not yet proposed)    View
99504  CVE-2017-2684  Candidate  Siemens SIMATIC Logon prior to V1.5 SP3 Update 2 could allow an attacker with knowledge of a valid user name, and physical or network access to the affected system, to bypass the application-level authentication.  Assigned (20161201)  None (candidate not yet proposed)    View
99503  CVE-2017-2683  Candidate  A non-privileged user of the Siemens web application RUGGEDCOM NMS < V1.2 on port 8080/TCP and 8081/TCP could perform a persistent Cross-Site Scripting (XSS) attack, potentially resulting in obtaining administrative permissions.  Assigned (20161201)  None (candidate not yet proposed)    View
99502  CVE-2017-2682  Candidate  The Siemens web application RUGGEDCOM NMS < V1.2 on port 8080/TCP and 8081/TCP could allow a remote attacker to perform a Cross-Site Request Forgery (CSRF) attack, potentially allowing an attacker to execute administrative operations, provided the targeted user has an active session and is induced to trigger a malicious request.  Assigned (20161201)  None (candidate not yet proposed)    View
99501  CVE-2017-2681  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20161201)  None (candidate not yet proposed)    View

Page 1043 of 20943, showing 5 records out of 104715 total, starting on record 5211, ending on 5215

Actions