Known vulnerabilities in Totally Integrated Automation Portal (TIA Portal) 17
Vendor:
Siemens
Version:
17
Software CPE:
cpe:2.3:a:siemens:totally_integrated_automation_portal_tia_portal:*:*:*:*:*:*:*:*
Website:
https://www.siemens.com/
Total vulnerabilities:
11
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Vulnerabilities by Severity
Vulnerabilities (11)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU112903 - Unrestricted Upload of File with Dangerous Type CVE-2025-27127 |
CWE-434 | Medium | 20 Update 3 | 15.07.2025 |
SB2025071534 |
||
| #VU109419 - Out-of-bounds read CVE-2025-30176 |
CWE-125 | High | 2.15.1.1 | 19.05.2025 |
SB2025051943 |
||
| #VU109418 - Out-of-bounds write CVE-2025-30175 |
CWE-787 | High | 2.15.1.1 | 19.05.2025 |
SB2025051943 |
||
| #VU109417 - Out-of-bounds read CVE-2025-30174 |
CWE-125 | High | 2.15.1.1 | 19.05.2025 |
SB2025051943 |
||
| #VU102502 - Heap-based Buffer Overflow CVE-2024-49775 |
CWE-122 | High | - | 09.01.2025 |
SB2025010960 |
||
| #VU97161 - Heap-based Buffer Overflow CVE-2024-33698 |
CWE-122 | High | 17 Update 8 | 11.09.2024 |
SB2024091139 |
||
| #VU84382 - Improper input validation CVE-2023-46285 |
CWE-20 | Medium | - | 13.12.2023 |
SB2023121329 |
||
| #VU84378 - Memory corruption CVE-2023-46284 |
CWE-119 | Medium | - | 13.12.2023 |
SB2023121329 |
||
| #VU84375 - Memory corruption CVE-2023-46283 |
CWE-119 | Medium | - | 13.12.2023 |
SB2023121329 |
||
| #VU84371 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2023-46282 |
CWE-79 | Low | - | 13.12.2023 |
SB2023121329 |
||
| #VU84369 - Overly Permissive Cross-domain Whitelist CVE-2023-46281 |
CWE-942 | Medium | - | 13.12.2023 |
SB2023121329 |