CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

siemens

sinumerik_one_firmware

5 known vulnerabilities · sorted by CVSS score

CVE-2022-24408
HIGH7.8

A vulnerability has been identified in SINUMERIK MC (All versions < V1.15 SP1), SINUMERIK ONE (All versions < V6.15 SP1). The sc SUID binary on affected devices provides several commands that are used to execute system commands or modify system files. A specific set of operations using sc could allow local attackers to escalate their privileges to root.

siemens / sinumerik_mc_firmware+3
Local
Published Mar 8, 2022
CVE-2020-27827
HIGH7.5

A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.

lldpd_project / lldpd+26
Network
Published Mar 18, 2021
CVE-2023-46156
HIGH7.5

Affected devices improperly handle specially crafted packets sent to port 102/tcp. This could allow an attacker to create a denial of service condition. A restart is needed to restore normal operations.

siemens / simatic_drive_controller_cpu_1504d_tf_firmware+75
Network
Published Dec 12, 2023
CVE-2020-8745
MEDIUM6.8

Insufficient control flow management in subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25 , Intel(R) TXE versions before 3.1.80 and 4.0.30 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

intel / converged_security_and_manageability_engine+27
Physical
Published Nov 12, 2020
CVE-2022-30694
MEDIUM6.5

The login endpoint /FormLogin in affected web services does not apply proper origin checking. This could allow authenticated remote attackers to track the activities of other users via a login cross-site request forgery attack.

siemens / simatic_s7-1500_software_controller+112
Network
Published Nov 8, 2022