Known vulnerabilities in SIMATIC Cloud Connect 7 CC712
Vendor:
Siemens
Software:
SIMATIC Cloud Connect 7 CC712
Software CPE:
cpe:2.3:a:siemens:simatic_cloud_connect_7_cc712:*:*:*:*:*:*:*:*
Website:
https://www.siemens.com/
Total vulnerabilities:
8
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
Vulnerabilities (8)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU80852 - Integer overflow CVE-2023-28831 |
CWE-190 | Medium | 2.2 | 18.09.2023 |
SB2023091816 SB2023121343 |
||
| #VU76021 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2023-29128 |
CWE-22 | Low | 2.1 | 11.05.2023 |
SB2023051108 |
||
| #VU76018 - Insufficiently Protected Credentials CVE-2023-29107 |
CWE-522 | Medium | 2.1 | 11.05.2023 |
SB2023051108 |
||
| #VU76015 - Exposure of sensitive information to an unauthorized actor CVE-2023-29106 |
CWE-200 | Medium | 2.1 | 11.05.2023 |
SB2023051108 |
||
| #VU76014 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2023-29104 |
CWE-22 | Low | 2.1 | 11.05.2023 |
SB2023051108 |
||
| #VU76013 - Command injection CVE-2023-28832 |
CWE-77 | Low | 2.1 | 11.05.2023 |
SB2023051108 |
||
| #VU76012 - Missing Standardized Error Handling Mechanism CVE-2023-29105 |
CWE-544 | Medium | 2.1 | 11.05.2023 |
SB2023051108 |
||
| #VU76011 - Use of Hard-coded Password CVE-2023-29103 |
CWE-259 | Low | 2.1 | 11.05.2023 |
SB2023051108 |