Known vulnerabilities in SCALANCE WUM763-1

Vendor: Siemens
Software CPE: cpe:2.3:h:siemens:scalance_wum763-1:*:*:*:*:*:*:*:*
Total vulnerabilities: 31
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.2

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting SCALANCE WUM763-1 SCALANCE WUM763-1 is affected by 31 known vulnerabilities: 1 high, 10 medium, 20 low Critical High Medium Low

Vulnerabilities (31)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU84423 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-49691
CWE-78 Low
No
No
- 14.12.2023 SB2023121421
SB2024061413
#VU83426 - Improper Access Control
CVE-2023-44374
CWE-284 Medium
No
No
- 22.11.2023 SB2023112223
SB2023121421
SB2024061413
#VU83425 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2023-44373
CWE-74 Low
No
No
- 22.11.2023 SB2023112223
SB2023121421
SB2024061413
#VU83417 - Use of Weak Hash
CVE-2023-44319
CWE-328 Low
No
No
- 22.11.2023 SB2023112223
SB2023121421
SB2024061413
#VU83416 - Use of Hard-coded Cryptographic Key
CVE-2023-44318
CWE-321 Low
No
No
- 22.11.2023 SB2023112223
SB2023121423
SB2024031320
and 1 more
#VU83415 - Acceptance of Extraneous Untrusted Data With Trusted Data
CVE-2023-44317
CWE-349 Low
No
No
- 22.11.2023 SB2023112223
SB2023121344
SB2024061413
#VU74346 - Missing Encryption of Sensitive Data
CVE-2022-47522
CWE-311 Medium
Available
No
- 04.04.2023 SB2023040407
SB2023042808
SB2023051034
and 2 more
#VU73786 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-23395
CWE-79 Low
No
No
2.0 17.03.2023 SB2022030225
SB2023031731
SB2024032155
and 1 more
#VU73785 - Information Exposure Through an Error Message
CVE-2018-12886
CWE-209 Medium
No
No
2.0 17.03.2023 SB2019052235
SB2023031731
#VU70421 - Improper control of a resource through its lifetime
CVE-2022-46144
CWE-664 Medium
No
No
- 19.12.2022 SB2022121925
SB2024061413
#VU69654 - Use After Free
CVE-2021-42383
CWE-416 Low
No
No
2.0 28.11.2022 SB2021120809
SB2022112852
SB2022112855
and 10 more
#VU69651 - NULL Pointer Dereference
CVE-2021-42373
CWE-476 Medium
No
No
2.0 28.11.2022 SB2021120809
SB2022112852
SB2022112855
and 8 more
#VU66368 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2022-36323
CWE-74 Low
No
No
- 10.08.2022 SB2022081042
SB2023121421
SB2024061413
#VU61671 - Memory corruption
CVE-2018-25032
CWE-119 Medium
No
No
2.0 28.03.2022 SB2022032844
SB2022032845
SB2022033018
and 192 more
#VU58692 - Use After Free
CVE-2021-42379
CWE-416 Low
No
No
2.0 08.12.2021 SB2021120809
SB2021120810
SB2022012015
and 16 more
#VU58685 - Use After Free
CVE-2021-42384
CWE-416 Low
No
No
2.0 08.12.2021 SB2021120809
SB2021120810
SB2022012015
and 16 more
#VU58684 - Use After Free
CVE-2021-42382
CWE-416 Low
No
No
2.0 08.12.2021 SB2021120809
SB2021120810
SB2021120727
and 15 more
#VU58683 - Use After Free
CVE-2021-42385
CWE-416 Low
No
No
2.0 08.12.2021 SB2021120809
SB2021120810
SB2022012015
and 16 more
#VU58678 - Use After Free
CVE-2021-42386
CWE-416 Low
No
No
2.0 08.12.2021 SB2021120809
SB2021120810
SB2022012015
and 16 more
#VU58670 - Out-of-bounds read
CVE-2021-42374
CWE-125 Medium
No
No
2.0 08.12.2021 SB2021120809
SB2021120810
SB2021120727
and 12 more


Showing elements 1 - 20 out of 31