CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
99505 | CVE-2017-2685 | Candidate | Siemens SINUMERIK Integrate Operate Clients between 2.0.3.00.016 (including) and 2.0.6 (excluding) and between 3.0.4.00.032 (including) and 3.0.6 (excluding) contain a vulnerability that could allow an attacker to read and manipulate data in TLS sessions while performing a man-in-the-middle (MITM) attack. | Assigned (20161201) | None (candidate not yet proposed) | View | |
99504 | CVE-2017-2684 | Candidate | Siemens SIMATIC Logon prior to V1.5 SP3 Update 2 could allow an attacker with knowledge of a valid user name, and physical or network access to the affected system, to bypass the application-level authentication. | Assigned (20161201) | None (candidate not yet proposed) | View | |
99503 | CVE-2017-2683 | Candidate | A non-privileged user of the Siemens web application RUGGEDCOM NMS < V1.2 on port 8080/TCP and 8081/TCP could perform a persistent Cross-Site Scripting (XSS) attack, potentially resulting in obtaining administrative permissions. | Assigned (20161201) | None (candidate not yet proposed) | View | |
99502 | CVE-2017-2682 | Candidate | The Siemens web application RUGGEDCOM NMS < V1.2 on port 8080/TCP and 8081/TCP could allow a remote attacker to perform a Cross-Site Request Forgery (CSRF) attack, potentially allowing an attacker to execute administrative operations, provided the targeted user has an active session and is induced to trigger a malicious request. | Assigned (20161201) | None (candidate not yet proposed) | View | |
99501 | CVE-2017-2681 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20161201) | None (candidate not yet proposed) | View |
Page 1043 of 20943, showing 5 records out of 104715 total, starting on record 5211, ending on 5215