Known vulnerabilities in SPPA-T3000 Application Server

Vendor: Siemens
Software CPE: cpe:2.3:a:siemens:sppa-t3000_application_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 21
Public exploits: 2
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting SPPA-T3000 Application Server SPPA-T3000 Application Server is affected by 21 known vulnerabilities: 1 critical, 8 high, 9 medium, 3 low Critical High Medium Low

Vulnerabilities (21)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU58976 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-45046
CWE-94 High
Available
Exploited
- 15.12.2021 SB2021121504
SB2021121511
SB2021121512
and 178 more
#VU58816 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-44228
CWE-94 Critical
Available
Exploited
- 10.12.2021 SB2021121003
SB2021121101
SB2021121201
and 338 more
#VU23757 - Exposure of sensitive information to an unauthorized actor
CVE-2019-18335
CWE-200 Medium
No
No
- 19.12.2019 SB2019121918
#VU23756 - Exposure of sensitive information to an unauthorized actor
CVE-2019-18332
CWE-200 Medium
No
No
- 19.12.2019 SB2019121918
#VU23755 - Exposure of sensitive information to an unauthorized actor
CVE-2019-18334
CWE-200 Medium
No
No
R8.2 SP1 19.12.2019 SB2019121917
#VU23753 - Exposure of sensitive information to an unauthorized actor
CVE-2019-18331
CWE-200 Medium
No
No
R8.2 SP1 19.12.2019 SB2019121917
#VU23742 - Improper Authentication
CVE-2019-18320
CWE-287 High
No
No
- 19.12.2019 SB2019121918
#VU23739 - Improper Authentication
CVE-2019-18317
CWE-287 Medium
No
No
- 19.12.2019 SB2019121918
#VU23740 - Improper Authentication
CVE-2019-18318
CWE-287 Medium
No
No
- 19.12.2019 SB2019121918
#VU23741 - Improper Authentication
CVE-2019-18319
CWE-287 Medium
No
No
- 19.12.2019 SB2019121918
#VU23738 - Deserialization of Untrusted Data
CVE-2019-18316
CWE-502 High
No
No
- 19.12.2019 SB2019121918
#VU23737 - Improper Authentication
CVE-2019-18315
CWE-287 High
No
No
- 19.12.2019 SB2019121918
#VU23736 - Improper Authentication
CVE-2019-18314
CWE-287 High
No
No
- 19.12.2019 SB2019121918
#VU23709 - Unrestricted Upload of File with Dangerous Type
CVE-2019-18288
CWE-434 High
No
No
- 19.12.2019 SB2019121918
#VU23708 - Exposure of sensitive information to an unauthorized actor
CVE-2019-18287
CWE-200 Low
No
No
- 19.12.2019 SB2019121918
#VU23707 - Exposure of sensitive information to an unauthorized actor
CVE-2019-18286
CWE-200 Low
No
No
- 19.12.2019 SB2019121918
#VU23706 - Cleartext Transmission of Sensitive Information
CVE-2019-18285
CWE-319 Medium
No
No
- 19.12.2019 SB2019121918
#VU23705 - Improper Authentication
CVE-2019-18284
CWE-287 High
No
No
- 19.12.2019 SB2019121918
#VU23704 - Deserialization of Untrusted Data
CVE-2019-18283
CWE-502 High
No
No
- 19.12.2019 SB2019121918
#VU11448 - Improper input validation
CVE-2018-4832
CWE-20 Low
No
No
- 02.04.2018 SB2018040201
SB2019121918


Showing elements 1 - 20 out of 21