Known vulnerabilities in SCALANCE M876-4 (EU)

Vendor: Siemens
Software CPE: cpe:2.3:h:siemens:scalance_m876-4_eu:*:*:*:*:*:*:*:*
Total vulnerabilities: 83
Public exploits: 6
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting SCALANCE M876-4 (EU) SCALANCE M876-4 (EU) is affected by 83 known vulnerabilities: 2 high, 16 medium, 65 low Critical High Medium Low

Vulnerabilities (83)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU84423 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-49691
CWE-78 Low
No
No
8.0 14.12.2023 SB2023121421
SB2024061413
#VU84397 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-49692
CWE-78 Low
No
No
7.2.2 13.12.2023 SB2023121344
#VU83426 - Improper Access Control
CVE-2023-44374
CWE-284 Medium
No
No
8.0 22.11.2023 SB2023112223
SB2023121421
SB2024061413
#VU83425 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2023-44373
CWE-74 Low
No
No
8.0 22.11.2023 SB2023112223
SB2023121421
SB2024061413
#VU83424 - Unchecked Return Value
CVE-2023-44322
CWE-252 Low
No
No
8.0 22.11.2023 SB2023112223
SB2023121421
#VU83420 - Resource exhaustion
CVE-2023-44321
CWE-400 Low
No
No
- 22.11.2023 SB2023112223
SB2023121423
SB2024031320
#VU83418 - Direct Request ('Forced Browsing')
CVE-2023-44320
CWE-425 Low
No
No
- 22.11.2023 SB2023112223
SB2023121423
#VU83417 - Use of Weak Hash
CVE-2023-44319
CWE-328 Low
No
No
8.0 22.11.2023 SB2023112223
SB2023121421
SB2024061413
#VU83416 - Use of Hard-coded Cryptographic Key
CVE-2023-44318
CWE-321 Low
No
No
- 22.11.2023 SB2023112223
SB2023121423
SB2024031320
and 1 more
#VU83415 - Acceptance of Extraneous Untrusted Data With Trusted Data
CVE-2023-44317
CWE-349 Low
No
No
7.2.2 22.11.2023 SB2023112223
SB2023121344
SB2024061413
#VU70424 - Improper input validation
CVE-2022-46143
CWE-20 Low
No
No
8.0 19.12.2022 SB2022121925
SB2023121421
#VU66368 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2022-36323
CWE-74 Low
No
No
8.0 10.08.2022 SB2022081042
SB2023121421
SB2024061413
#VU63388 - Exposure of sensitive information to an unauthorized actor
CVE-2022-1353
CWE-200 Low
No
No
7.2 18.05.2022 SB2022060826
SB2022060828
SB2022061213
and 58 more
#VU61671 - Memory corruption
CVE-2018-25032
CWE-119 Medium
No
No
7.2 28.03.2022 SB2022032844
SB2022032845
SB2022033018
and 192 more
#VU60007 - Improper input validation
CVE-2021-4034
CWE-20 Medium
Available
Exploited
7.2 26.01.2022 SB2022012601
SB2022012604
SB2022012605
and 51 more
#VU58694 - Use After Free
CVE-2021-42380
CWE-416 Low
No
No
7.2 08.12.2021 SB2021120809
SB2021120810
SB2021120727
and 15 more
#VU58680 - Use After Free
CVE-2021-42378
CWE-416 Low
No
No
7.2 08.12.2021 SB2021120809
SB2021120810
SB2022012015
and 16 more
#VU19946 - Exposure of sensitive information to an unauthorized actor
CVE-2019-1125
CWE-200 Low
Available
No
7.2 06.08.2019 SB2019080607
SB2019080703
SB2019080714
and 24 more
#VU19108 - Out-of-bounds read
CVE-2019-1073
CWE-125 Low
No
No
7.2 10.07.2019 SB2019071013
SB2023031715
#VU19107 - Out-of-bounds read
CVE-2019-1071
CWE-125 Low
No
No
7.2 10.07.2019 SB2019071013
SB2023031715


Showing elements 1 - 20 out of 83