Known vulnerabilities in SIMATIC WinCC OA
Vendor:
Siemens
Software:
SIMATIC WinCC OA
Software CPE:
cpe:2.3:a:siemens:simatic_wincc_oa:*:*:*:*:*:*:*:*
Website:
https://www.siemens.com/
Total vulnerabilities:
5
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (5)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU80650 - Heap-based Buffer Overflow CVE-2023-3935 |
CWE-122 | High | 3.19 P006 | 12.09.2023 |
SB2023091244 SB2023111628 SB2024010512 |
||
| #VU70381 - Argument Injection or Modification CVE-2022-44731 |
CWE-88 | Medium | 3.16 P035, 3.17 P024, 3.18 P014 | 15.12.2022 |
SB2022121533 |
||
| #VU64575 - Use of Client-Side Authentication CVE-2022-33139 |
CWE-603 | High | - | 22.06.2022 |
SB2022062210 SB2022101313 |
||
| #VU28936 - Unquoted Search Path or Element CVE-2020-7580 |
CWE-428 | Low | 3.16-P018, 3.17-P003 | 10.06.2020 |
SB2020061031 |
||
| #VU9594 - Improper input validation CVE-2017-3737 |
CWE-20 | Medium | - | 08.12.2017 |
SB2017120804 SB2017120902 SB2017121001 and 21 more |