Known vulnerabilities in SIMATIC S7-1500 TM MFP - BIOS - page 2

Vendor: Siemens
Software CPE: cpe:2.3:a:siemens:simatic_s7-1500_tm_mfp_-_bios:*:*:*:*:*:*:*:*
Total vulnerabilities: 58
Public exploits: 4
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting SIMATIC S7-1500 TM MFP - BIOS SIMATIC S7-1500 TM MFP - BIOS is affected by 58 known vulnerabilities: 8 high, 11 medium, 39 low Critical High Medium Low

Vulnerabilities (58)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU70499 - Out-of-bounds read
CVE-2022-3435
CWE-125 Medium
No
No
- 27.12.2022 SB2022122717
SB2022122722
SB2022122723
and 48 more
#VU69653 - Release of invalid pointer or reference
CVE-2021-42377
CWE-763 Medium
No
No
- 28.11.2022 SB2021120809
SB2022112852
SB2022112855
and 8 more
#VU69652 - Improper input validation
CVE-2021-42375
CWE-20 Low
No
No
- 28.11.2022 SB2021120809
SB2022112852
SB2022112855
and 8 more
#VU69651 - NULL Pointer Dereference
CVE-2021-42373
CWE-476 Medium
No
No
- 28.11.2022 SB2021120809
SB2022112852
SB2022112855
and 8 more
#VU68108 - Use After Free
CVE-2022-1882
CWE-416 Low
No
No
- 11.10.2022 SB2022101107
SB2022101111
SB2022101505
and 12 more
#VU67866 - Out-of-bounds write
CVE-2022-20422
CWE-787 Low
No
No
- 04.10.2022 SB2022100403
SB2022111721
SB2022111722
and 15 more
#VU67509 - Out-of-bounds read
CVE-2022-2905
CWE-125 Low
No
No
- 20.09.2022 SB2022092041
SB2022092046
SB2022092047
and 17 more
#VU67477 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2022-3028
CWE-362 Low
No
No
- 20.09.2022 SB2022092003
SB2022092006
SB2022092007
and 63 more
#VU66397 - Double Free
CVE-2022-2588
CWE-415 Low
Available
Exploited
- 11.08.2022 SB2022081109
SB2022081110
SB2022081111
and 99 more
#VU66394 - Resource Management Errors
CVE-2022-2585
CWE-399 Low
Available
No
- 11.08.2022 SB2022081107
SB2022081114
SB2022081115
and 21 more
#VU59877 - NULL Pointer Dereference
CVE-2021-42376
CWE-476 Low
No
No
- 20.01.2022 SB2021120809
SB2022012015
SB2022112852
and 10 more
#VU58694 - Use After Free
CVE-2021-42380
CWE-416 Low
No
No
- 08.12.2021 SB2021120809
SB2021120810
SB2021120727
and 15 more
#VU58692 - Use After Free
CVE-2021-42379
CWE-416 Low
No
No
- 08.12.2021 SB2021120809
SB2021120810
SB2022012015
and 16 more
#VU58685 - Use After Free
CVE-2021-42384
CWE-416 Low
No
No
- 08.12.2021 SB2021120809
SB2021120810
SB2022012015
and 16 more
#VU58680 - Use After Free
CVE-2021-42378
CWE-416 Low
No
No
- 08.12.2021 SB2021120809
SB2021120810
SB2022012015
and 16 more
#VU58678 - Use After Free
CVE-2021-42386
CWE-416 Low
No
No
- 08.12.2021 SB2021120809
SB2021120810
SB2022012015
and 16 more
#VU58670 - Out-of-bounds read
CVE-2021-42374
CWE-125 Medium
No
No
- 08.12.2021 SB2021120809
SB2021120810
SB2021120727
and 12 more
#VU55972 - Integer overflow
CVE-2021-35942
CWE-190 Medium
No
No
- 18.08.2021 SB2021081817
SB2021081818
SB2021100416
and 32 more
#VU55916 - NULL Pointer Dereference
CVE-2021-38604
CWE-476 Medium
No
No
- 17.08.2021 SB2021081710
SB2022081401
SB2023061617
and 4 more
#VU54560 - Use After Free
CVE-2021-33574
CWE-416 High
No
No
- 06.07.2021 SB2021070603
SB2021070604
SB2021092807
and 22 more


Showing elements 21 - 40 out of 58