Known vulnerabilities in SIMATIC S7-1500 TM MFP - BIOS

Vendor: Siemens
Software CPE: cpe:2.3:a:siemens:simatic_s7-1500_tm_mfp_-_bios:*:*:*:*:*:*:*:*
Total vulnerabilities: 58
Public exploits: 4
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting SIMATIC S7-1500 TM MFP - BIOS SIMATIC S7-1500 TM MFP - BIOS is affected by 58 known vulnerabilities: 8 high, 11 medium, 39 low Critical High Medium Low

Vulnerabilities (58)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU95093 - Improper input validation
CVE-2024-42154
CWE-20 Low
No
No
- 31.07.2024 SB20240731176
SB2024081301
SB2024081648
and 64 more
#VU95027 - Use of Uninitialized Resource
CVE-2024-42161
CWE-908 Low
No
No
- 31.07.2024 SB20240731110
SB2024080968
SB2024080969
and 30 more
#VU95010 - Double Free
CVE-2024-41046
CWE-415 Low
No
No
- 31.07.2024 SB2024073193
SB2024081301
SB2024081648
and 30 more
#VU94979 - NULL Pointer Dereference
CVE-2024-41055
CWE-476 Low
No
No
- 31.07.2024 SB2024073162
SB2024080968
SB2024080969
and 56 more
#VU94947 - Use After Free
CVE-2024-41049
CWE-416 Low
No
No
- 31.07.2024 SB2024073130
SB2024080967
SB2024080969
and 40 more
#VU77475 - Incorrect Default Permissions
CVE-2021-20269
CWE-276 Low
No
No
- 16.06.2023 SB2022031041
SB2023061617
SB2022081308
and 2 more
#VU69654 - Use After Free
CVE-2021-42383
CWE-416 Low
No
No
- 28.11.2022 SB2021120809
SB2022112852
SB2022112855
and 10 more
#VU61293 - Off-by-one Error
CVE-2021-3999
CWE-193 High
No
No
- 14.03.2022 SB2022031429
SB2022031430
SB2022031526
and 36 more
#VU61292 - Missing release of memory after effective lifetime
CVE-2021-3998
CWE-401 Medium
No
No
- 14.03.2022 SB2022031429
SB2022031430
SB2022030129
and 8 more
#VU58684 - Use After Free
CVE-2021-42382
CWE-416 Low
No
No
- 08.12.2021 SB2021120809
SB2021120810
SB2021120727
and 15 more
#VU58673 - Use After Free
CVE-2021-42381
CWE-416 Low
No
No
- 08.12.2021 SB2021120809
SB2021120810
SB2021120727
and 15 more
#VU54559 - Double Free
CVE-2021-27645
CWE-415 Low
No
No
- 06.07.2021 SB2021022425
SB2021070604
SB2022031430
and 13 more
#VU54337 - Improper input validation
CVE-2016-10228
CWE-20 Low
No
No
- 23.06.2021 SB2017030207
SB2021062314
SB2021062315
and 21 more
#VU51741 - Improper Handling of Exceptional Conditions
CVE-2021-28831
CWE-755 Medium
No
No
- 26.03.2021 SB2021032622
SB2021032626
SB2021032627
and 25 more
#VU50075 - Reachable Assertion
CVE-2021-3326
CWE-617 Medium
No
No
- 27.01.2021 SB2021012804
SB2021020710
SB2021020711
and 34 more
#VU50329 - Out-of-bounds read
CVE-2019-25013
CWE-125 Low
No
No
- 04.01.2021 SB2021020413
SB2021020414
SB2021020710
and 36 more
#VU50404 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2020-27618
CWE-835 Medium
No
No
- 04.01.2021 SB2021020709
SB2021020710
SB2021020711
and 31 more
#VU49670 - Reachable Assertion
CVE-2020-29562
CWE-617 Medium
No
No
- 04.12.2020 SB2021011906
SB2021020710
SB2021020711
and 11 more
#VU26628 - Use After Free
CVE-2020-1752
CWE-416 High
No
No
- 07.04.2020 SB2020040708
SB2020040709
SB2020110915
and 18 more
#VU26388 - Stack-based buffer overflow
CVE-2020-10029
CWE-121 High
No
No
- 25.03.2020 SB2020030423
SB2020032513
SB2020061304
and 26 more


Showing elements 1 - 20 out of 58