NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
83701 | CVE-2017-2686 | Siemens RUGGEDCOM ROX I (all versions) contain a vulnerability that could allow an authenticated user to read arbitrary files through the web interface at port 10000/TCP and access sensitive information. | 2 | 4 | Medium | 2017-07-18 | 2017-07-11 | View | |
83147 | CVE-2017-2685 | Siemens SINUMERIK Integrate Operate Clients between 2.0.3.00.016 (including) and 2.0.6 (excluding) and between 3.0.4.00.032 (including) and 3.0.6 (excluding) contain a vulnerability that could allow an attacker to read and manipulate data in TLS sessions while performing a man-in-the-middle (MITM) attack. | 2 | 5.8 | Medium | 2017-03-18 | 2017-03-16 | View | |
82536 | CVE-2017-2684 | Siemens SIMATIC Logon prior to V1.5 SP3 Update 2 could allow an attacker with knowledge of a valid user name, and physical or network access to the affected system, to bypass the application-level authentication. | 2 | 6.8 | Medium | 2017-03-18 | 2017-03-15 | View | |
82535 | CVE-2017-2683 | A non-privileged user of the Siemens web application RUGGEDCOM NMS < V1.2 on port 8080/TCP and 8081/TCP could perform a persistent Cross-Site Scripting (XSS) attack, potentially resulting in obtaining administrative permissions. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-17 | View | |
82534 | CVE-2017-2682 | The Siemens web application RUGGEDCOM NMS < V1.2 on port 8080/TCP and 8081/TCP could allow a remote attacker to perform a Cross-Site Request Forgery (CSRF) attack, potentially allowing an attacker to execute administrative operations, provided the targeted user has an active session and is induced to trigger a malicious request. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-17 | View |
Page 683 of 17672, showing 5 records out of 88360 total, starting on record 3411, ending on 3415