VDB

GCVE-VVD-NCSC-2025-8

GCVE-VVD-NCSC-2025-8
Advisory PublishedCVSS 4.7/10
Vulnetix · Advisory published January 14, 2025
Siemens heeft kwetsbaarheden verholpen in diverse producten als Industrial Edge Management, Mendix, SIMATIC, SIPROTEC en Siveillance.

Weaknesses (CWE)

CWE-532Insertion of Sensitive Information into Log FileCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-352Cross-Site Request Forgery (CSRF)CWE-552Files or Directories Accessible to External PartiesCWE-90Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')

Risk Scores

CVSS 3.1
4.7/10
Medium · CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N/E:P/RL:U/RC:C

Affected Products

VendorProductVersionsPlatforms
siemensindustrial_edge_management_os__iem-os_
siemenssimatic_s7-1200_cpu_1211c_ac_dc_rly
siemenssimatic_s7-1200_cpu_1211c_dc_dc_dc
siemenssimatic_s7-1200_cpu_1211c_dc_dc_rly
siemenssimatic_s7-1200_cpu_1212c_ac_dc_rly
siemenssimatic_s7-1200_cpu_1212c_dc_dc_dc
siemenssimatic_s7-1200_cpu_1212c_dc_dc_rly
siemenssimatic_s7-1200_cpu_1212fc_dc_dc_dc
siemenssimatic_s7-1200_cpu_1212fc_dc_dc_rly
siemenssimatic_s7-1200_cpu_1214c_ac_dc_rly
siemenssimatic_s7-1200_cpu_1214c_dc_dc_dc
siemenssimatic_s7-1200_cpu_1214c_dc_dc_rly
siemenssimatic_s7-1200_cpu_1214fc_dc_dc_dc
siemenssimatic_s7-1200_cpu_1214fc_dc_dc_rly
siemenssimatic_s7-1200_cpu_1215c_ac_dc_rly
siemenssimatic_s7-1200_cpu_1215c_dc_dc_dc
siemenssimatic_s7-1200_cpu_1215c_dc_dc_rly
siemenssimatic_s7-1200_cpu_1215fc_dc_dc_dc
siemenssimatic_s7-1200_cpu_1215fc_dc_dc_rly
siemenssimatic_s7-1200_cpu_1217c_dc_dc_dc
siemenssiplus_s7-1200_cpu_1212_ac_dc_rly
siemenssiplus_s7-1200_cpu_1212_dc_dc_rly
siemenssiplus_s7-1200_cpu_1212c_dc_dc_dc
siemenssiplus_s7-1200_cpu_1212c_dc_dc_dc_rail
siemenssiplus_s7-1200_cpu_1214_ac_dc_rly
siemenssiplus_s7-1200_cpu_1214_dc_dc_dc
siemenssiplus_s7-1200_cpu_1214_dc_dc_rly
siemenssiplus_s7-1200_cpu_1214c_dc_dc_dc_rail
siemenssiplus_s7-1200_cpu_1214fc_dc_dc_dc
siemenssiplus_s7-1200_cpu_1214fc_dc_dc_rly
siemenssiplus_s7-1200_cpu_1215_ac_dc_rly
siemenssiplus_s7-1200_cpu_1215_dc_dc_dc
siemenssiplus_s7-1200_cpu_1215_dc_dc_rly
siemenssiplus_s7-1200_cpu_1215c_dc_dc_dc
siemenssiplus_s7-1200_cpu_1215fc_dc_dc_dc
siemenssiprotec_5_6md84__cp300_
siemenssiprotec_5_6md85__cp300_
siemenssiprotec_5_6md86__cp300_
siemenssiprotec_5_6md89__cp300_
siemenssiprotec_5_6mu85__cp300_
siemenssiprotec_5_7ke85__cp300_
siemenssiprotec_5_7sa82__cp100_
siemenssiprotec_5_7sa82__cp150_
siemenssiprotec_5_7sa86__cp300_
siemenssiprotec_5_7sa87__cp300_
siemenssiprotec_5_7sd82__cp100_
siemenssiprotec_5_7sd82__cp150_
siemenssiprotec_5_7sd86__cp300_
siemenssiprotec_5_7sd87__cp300_
siemenssiprotec_5_7sj81__cp100_
siemenssiprotec_5_7sj81__cp150_
siemenssiprotec_5_7sj82__cp100_
siemenssiprotec_5_7sj82__cp150_
siemenssiprotec_5_7sj85__cp300_
siemenssiprotec_5_7sj86__cp300_
siemenssiprotec_5_7sk82__cp100_
siemenssiprotec_5_7sk82__cp150_
siemenssiprotec_5_7sk85__cp300_
siemenssiprotec_5_7sl82__cp100_
siemenssiprotec_5_7sl82__cp150_
siemenssiprotec_5_7sl86__cp300_
siemenssiprotec_5_7sl87__cp300_
siemenssiprotec_5_7ss85__cp300_
siemenssiprotec_5_7st85__cp300_
siemenssiprotec_5_7st86__cp300_
siemenssiprotec_5_7sx82__cp150_
siemenssiprotec_5_7sx85__cp300_
siemenssiprotec_5_7sy82__cp150_
siemenssiprotec_5_7um85__cp300_
siemenssiprotec_5_7ut82__cp100_
siemenssiprotec_5_7ut82__cp150_
siemenssiprotec_5_7ut85__cp300_
siemenssiprotec_5_7ut86__cp300_
siemenssiprotec_5_7ut87__cp300_
siemenssiprotec_5_7ve85__cp300_
siemenssiprotec_5_7vk87__cp300_
siemenssiprotec_5_7vu85__cp300_
siemenssiprotec_5_compact_7sx800__cp050_
siemensmendix_ldap

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

100 records in the GCVE database · Updated April 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›