Known vulnerabilities in SIMATIC PCS 7 8.0
Vendor:
Siemens
Software:
SIMATIC PCS 7
Version:
8.0
Software CPE:
cpe:2.3:a:siemens:simatic_pcs_7:*:*:*:*:*:*:*:*
Website:
https://www.siemens.com/
Total vulnerabilities:
8
Public exploits:
0
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Vulnerabilities by Severity
Vulnerabilities (8)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU60534 - Exposure of sensitive information to an unauthorized actor CVE-2021-40360 |
CWE-200 | Low | 9.1 SP1 | 11.02.2022 |
SB2022021107 |
||
| #VU60533 - File And Directory Information Exposure CVE-2021-40363 |
CWE-538 | Low | 9.1 SP1 | 11.02.2022 |
SB2022021106 |
||
| #VU19158 - Unrestricted Upload of File with Dangerous Type CVE-2019-10935 |
CWE-434 | Medium | 7.4 SP1 Update 11 | 12.07.2019 |
SB2019071205 |
||
| #VU18656 - Improper Access Control CVE-2019-10922 |
CWE-284 | High | - | 31.05.2019 |
SB2019051415 |
||
| #VU11448 - Improper input validation CVE-2018-4832 |
CWE-20 | Low | - | 02.04.2018 |
SB2018040201 SB2019121918 |
||
| #VU8071 - Improper Restriction of XML External Entity Reference ('XXE') CVE-2017-12069 |
CWE-611 | Low | - | 01.09.2017 |
SB2017090106 |
||
| #VU6191 - Exposure of sensitive information to an unauthorized actor CVE-2014-8552 |
CWE-200 | Medium | - | 05.04.2017 |
SB2014121901 |
||
| #VU6190 - Improper input validation CVE-2014-8551 |
CWE-20 | Critical | - | 05.04.2017 |
SB2014121901 |