Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Siemens AG — Vulnerabilities & Security Advisories 135

Browse all 135 CVE security advisories affecting Siemens AG. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Siemens AG operates as a global conglomerate specializing in industrial automation, energy infrastructure, and healthcare technology. Its extensive portfolio of programmable logic controllers, human-machine interfaces, and medical imaging systems presents a broad attack surface, resulting in 135 recorded Common Vulnerabilities and Exposures. Historically, the most prevalent vulnerability classes affecting Siemens products include remote code execution, cross-site scripting, and privilege escalation flaws. These defects often stem from legacy protocols lacking robust authentication mechanisms or insecure default configurations in industrial control systems. Notable security incidents have highlighted risks associated with unpatched firmware and weak cryptographic implementations, particularly within SCADA environments. The company has responded by enhancing its product security lifecycle and issuing regular security advisories. However, the complexity of integrating these devices into critical infrastructure continues to pose significant challenges for defenders seeking to mitigate potential exploitation vectors effectively.

Top products by Siemens AG: SICAM MMU SINUMERIK 808D V4.7, SINUMERIK 808D V4.8, SINUMERIK 828D V4.7, SINUMERIK 840D sl V4.7, SINUMERIK 840D sl V4.8 SICLOCK TC100, SICLOCK TC400 SCALANCE M875 SIMATIC PCS 7 V8.0 and earlier SINEMA Remote Connect Server EN100 Ethernet module DNP3 variant SIMATIC HMI Comfort Panels 4" - 22" TeleControl Server Basic Siveillance VMS 2017 R2 SIMATIC HMI Comfort Panels 4" - 22", SIMATIC HMI Comfort Outdoor Panels 7" & 15", SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900 und KTP900F, SIMATIC WinCC Runtime Advanced, SIMATIC WinCC Runtime Professional, SIMATIC WinCC (TIA Portal), SIMATIC HMI Classic Devices (TP/MP/OP/MP Mobile Panel) SIMATIC RTLS Locating Manager XHQ Polarion SINUMERIK 828D V4.7, SINUMERIK 840D sl V4.7, SINUMERIK 840D sl V4.8 ROX II SCALANCE SC-600 SIEMENS LOGO!8 SINAMICS PERFECT HARMONY GH180 with NXG I control, MLFBs: 6SR2...-, 6SR3...-, 6SR4...- All other SIPROTEC 5 device types with CPU variants CP300 and CP100 and the respective Ethernet communication modules Firmware variant IEC 61850 for EN100 Ethernet module SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V10, V11, V12, SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V13, SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V14, SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V15 TIM 1531 IRC Automation License Manager 5 SIMATIC S7-300 CPU family Polarion Subversion Webclient Spectrum Power 4 SIMATIC S7-1200 CPU family (incl. SIPLUS variants) SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) SIMATIC IT UADM
CVE IDTitleCVSSSeverityPublished
CVE-2020-15790 Siemens Spectrum Power 信息泄露漏洞 — Spectrum Power 4CWE-548 5.3 -2020-09-09
CVE-2020-15789 Siemens Polarion Subversion Web 跨站请求伪造漏洞 — Polarion Subversion WebclientCWE-352 8.1 -2020-09-09
CVE-2020-15788 Siemens Polarion Subversion Webclient 跨站脚本漏洞 — Polarion Subversion WebclientCWE-80 6.1 -2020-09-09
CVE-2020-15785 Siemens Siveillance Video Client 加密问题漏洞 — Siveillance Video ClientCWE-319 5.3 -2020-09-09
CVE-2020-15784 SUSE Linux Enterprise Server 安全漏洞 — Spectrum Power 4CWE-312 5.3 -2020-09-09
CVE-2020-10056 Siemens LMU 安全漏洞 — License Management Utility (LMU)CWE-250 7.8 -2020-09-09
CVE-2020-10051 Siemens SIMATIC RTLS 代码问题漏洞 — SIMATIC RTLS Locating ManagerCWE-428 7.8 -2020-09-09
CVE-2020-10050 Siemens SIMATIC RTLS Locating Manager 安全漏洞 — SIMATIC RTLS Locating ManagerCWE-276 7.8 -2020-09-09
CVE-2020-10049 Siemens SIMATIC RTLS Locating Manager 安全漏洞 — SIMATIC RTLS Locating ManagerCWE-276 7.3 -2020-09-09
CVE-2020-7583 Siemens Automation License Manager 授权问题漏洞 — Automation License Manager 5CWE-285 7.1 -2020-08-14
CVE-2020-15781 Siemens SICAM A8000 RTUs 跨站脚本漏洞 — SICAM WEB firmware for SICAM A8000 RTUsCWE-79 9.6 -2020-08-14
CVE-2020-10055 Siemens Desigo CC和Desigo CC Compact 代码注入漏洞 — Desigo CCCWE-94 8.1 -2020-08-14
CVE-2020-7593 Siemens LOGO! 8 BM 缓冲区错误漏洞 — LOGO! 8 BM (incl. SIPLUS variants)CWE-120 9.8 -2020-07-14
CVE-2020-7592 多款Siemens产品安全漏洞 — SIMATIC HMI Basic Panels 1st Generation (incl. SIPLUS variants)CWE-319 8.1 -2020-07-14
CVE-2020-7584 SIMATIC S7-200 SMART SR CPU和ST CPU 资源管理错误漏洞 — SIMATIC S7-200 SMART CPU familyCWE-400 7.5 -2020-07-14
CVE-2020-10045 Siemens SICAM MMU、SGU和T 访问控制错误漏洞 — SICAM MMUCWE-294 9.8 -2020-07-14
CVE-2020-10044 Siemens SICAM MMU、SGU和T 访问控制错误漏洞 — SICAM MMUCWE-306 7.5 -2020-07-14
CVE-2020-10043 Siemens SICAM MMU、SGU和T 跨站脚本漏洞 — SICAM MMUCWE-80 6.1 -2020-07-14
CVE-2020-10042 Siemens SICAM MMU、SGU和T 缓冲区错误漏洞 — SICAM MMUCWE-120 9.8 -2020-07-14
CVE-2020-10041 Siemens SICAM MMU、SGU和T 跨站脚本漏洞 — SICAM MMUCWE-79 5.4 -2020-07-14
CVE-2020-10040 Siemens SICAM MMU、SGU和T 安全漏洞 — SICAM MMUCWE-916 5.5 -2020-07-14
CVE-2020-10039 Siemens SICAM MMU、SGU和T 安全漏洞 — SICAM MMUCWE-311 8.1 -2020-07-14
CVE-2020-10038 Siemens SICAM MMU、SGU和T 访问控制错误漏洞 — SICAM MMUCWE-306 9.8 -2020-07-14
CVE-2020-10037 Siemens SICAM MMU、SGU和T 缓冲区错误漏洞 — SICAM MMUCWE-125 7.5 -2020-07-14
CVE-2019-10939 多款Siemens产品安全漏洞 — TIM 3V-IE (incl. SIPLUS NET variants)CWE-489 9.1 -2020-04-14
CVE-2019-19277 Siemens SIPORT MP 安全漏洞 — SIPORT MPCWE-778 6.5 -2020-03-10
CVE-2019-18336 多款Siemens产品资源管理错误漏洞 — SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants)CWE-400 7.5 -2020-03-10
CVE-2020-7579 Siemens Spectrum Power 跨站脚本漏洞 — Spectrum Power™ 5CWE-80 6.1 -2020-03-10
CVE-2019-19279 Siemens SIPROTEC 4和SIPROTEC Compact 输入验证错误漏洞 — SIPROTEC 4 and SIPROTEC Compact relays equipped with EN100 Ethernet communication modulesCWE-20 7.5 -2020-03-10
CVE-2019-19281 多款Siemens产品资源管理错误漏洞 — SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants)CWE-400 7.5 -2020-03-10

This page lists every published CVE security advisory associated with Siemens AG. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.