cbcvebase.

Siemens Simatic Pcs Neo vulnerabilities

23 known vulnerabilities affecting siemens/simatic_pcs_neo.

Total CVEs
23
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH13MEDIUM7

Vulnerabilities

Page 1 of 2
CVE-2021-20093P2CRITICALCVSS 9.1fixed in 3.12021-06-16
CVE-2021-20093 [CRITICAL] CWE-125 CVE-2021-20093: A buffer over-read vulnerability exists in Wibu-Systems CodeMeter versions < 7.21a. An unauthenticat A buffer over-read vulnerability exists in Wibu-Systems CodeMeter versions < 7.21a. An unauthenticated remote attacker can exploit this issue to disclose heap memory contents or crash the CodeMeter Runtime Server.
nvd
CVE-2025-40795P2CRITICALCVSS 9.8v4.1v5.02025-09-09
CVE-2025-40795 [CRITICAL] CWE-121 CVE-2025-40795: A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (Al A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC PCS neo V6.0 (All versions < V6.0 SP1 Update 1), User Management Component (UMC) (All versions < V2.15.1.3). Affected products contain a stack-based buffer overflow vulnerability in the integrated UMC component. This could allow
nvd
CVE-2025-40566P2CRITICALCVSS 9.8fixed in 4.1fixed in 5.0+2 more2025-05-13
CVE-2025-40566 [CRITICAL] CWE-613 CVE-2025-40566: A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions < V4.1 Update 3), SIMATIC A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions < V4.1 Update 3), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1). Affected products do not correctly invalidate user sessions upon user logout. This could allow a remote unauthenticated attacker, who has obtained the session token by other means, to re-use a legitimate u
nvd
CVE-2023-46281P3HIGHCVSS 8.8fixed in 4.1fixed in V4.12023-12-12
CVE-2023-46281 [HIGH] CWE-942 CVE-2023-46281: A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcente A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versions < V2312), SIMATIC PCS neo (All versions < V4.1), SINEC NMS (All versions < V2.0 SP1), Totally Integrated Automation Portal (TIA Portal) V14 (All versions), Totally Integrated Automation Portal (TIA Portal) V15.1 (All versions), T
nvd
CVE-2020-7587P3HIGHCVSS 8.2fixed in 3.0v3.0+1 more2020-07-14
CVE-2020-7587 [HIGH] CWE-400 CVE-2020-7587: A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter E A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation (All versions < V3.2), Opcenter Execution Process (All versions < V3.2), Opcenter Intelligence (All versions < V3.3), Opcenter Quality (All versions < V11.3), Opcenter RD&L (V8.0), SIMATIC IT LMS (All versions < V2.6), SIMATIC IT Produ
nvd
CVE-2023-46098P3HIGHCVSS 8.8fixed in 4.1vAll versions < V4.12023-11-14
CVE-2023-46098 [HIGH] CWE-942 CVE-2023-46098: A vulnerability has been identified in SIMATIC PCS neo (All versions < V4.1). When accessing the Inf A vulnerability has been identified in SIMATIC PCS neo (All versions < V4.1). When accessing the Information Server from affected products, the products use an overly permissive CORS policy. This could allow an attacker to trick a legitimate user to trigger unwanted behavior.
nvd
CVE-2023-46097P3HIGHCVSS 8.0fixed in 4.1vAll versions < V4.12023-11-14
CVE-2023-46097 [HIGH] CWE-89 CVE-2023-46097: A vulnerability has been identified in SIMATIC PCS neo (All versions < V4.1). The PUD Manager of aff A vulnerability has been identified in SIMATIC PCS neo (All versions < V4.1). The PUD Manager of affected products does not properly neutralize user provided inputs. This could allow an authenticated adjacent attacker to execute SQL statements in the underlying database.
nvd
CVE-2025-30175P3HIGHCVSS 7.5v4.1v5.02025-05-13
CVE-2025-30175 [HIGH] CWE-787 CVE-2025-30175: A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (Al A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC NMS (All versions < V4.0), SINEMA Remote Connect (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All versions), Totally Integrated Automation
nvd
CVE-2025-30176P3HIGHCVSS 7.5v4.1v5.02025-05-13
CVE-2025-30176 [HIGH] CWE-125 CVE-2025-30176: A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (Al A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC NMS (All versions < V4.0), SINEMA Remote Connect (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All versions), Totally Integrated Automation
nvd
CVE-2025-40797P3HIGHCVSS 7.5v4.1v5.02025-09-09
CVE-2025-40797 [HIGH] CWE-125 CVE-2025-40797: A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (Al A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC PCS neo V6.0 (All versions < V6.0 SP1 Update 1), User Management Component (UMC) (All versions < V2.15.1.3). Affected products contain a out-of-bounds read vulnerability in the integrated UMC component. This could allow an unauthent
nvd
CVE-2025-40798P3HIGHCVSS 7.5v4.1v5.02025-09-09
CVE-2025-40798 [HIGH] CWE-125 CVE-2025-40798: A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (Al A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC PCS neo V6.0 (All versions < V6.0 SP1 Update 1), User Management Component (UMC) (All versions < V2.15.1.3). Affected products contain a out-of-bounds read vulnerability in the integrated UMC component. This could allow an unauthent
nvd
CVE-2025-40796P3HIGHCVSS 7.5v4.1v5.02025-09-09
CVE-2025-40796 [HIGH] CWE-125 CVE-2025-40796: A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (Al A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC PCS neo V6.0 (All versions < V6.0 SP1 Update 1), User Management Component (UMC) (All versions < V2.15.1.3). Affected products contain a out-of-bounds read vulnerability in the integrated UMC component. This could allow an unauthent
nvd
CVE-2022-27194P3HIGHCVSS 7.5fixed in 3.1v3.1+1 more2022-04-12
CVE-2022-27194 [HIGH] CWE-400 CVE-2022-27194: A vulnerability has been identified in SIMATIC PCS neo (Administration Console) (All versions < V3.1 A vulnerability has been identified in SIMATIC PCS neo (Administration Console) (All versions < V3.1 SP1), SINETPLAN (All versions), TIA Portal (V15, V15.1, V16 and V17). The affected system cannot properly process specially crafted packets sent to port 8888/tcp. A remote attacker could exploit this vulnerability to cause a Denial-of-Service condition
nvd
CVE-2023-46285P3HIGHCVSS 7.5fixed in 4.1fixed in V4.12023-12-12
CVE-2023-46285 [HIGH] CWE-20 CVE-2023-46285: A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcente A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versions < V2312), SIMATIC PCS neo (All versions < V4.1), SINEC NMS (All versions < V2.0 SP1), Totally Integrated Automation Portal (TIA Portal) V14 (All versions), Totally Integrated Automation Portal (TIA Portal) V15.1 (All versions), To
nvd
CVE-2023-46284P3HIGHCVSS 7.5fixed in 4.1fixed in V4.12023-12-12
CVE-2023-46284 [HIGH] CWE-120 CVE-2023-46284: A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcente A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versions < V2312), SIMATIC PCS neo (All versions < V4.1), SINEC NMS (All versions < V2.0 SP1), Totally Integrated Automation Portal (TIA Portal) V14 (All versions), Totally Integrated Automation Portal (TIA Portal) V15.1 (All versions), T
nvd
CVE-2023-46283P3HIGHCVSS 7.5fixed in 4.1fixed in V4.12023-12-12
CVE-2023-46283 [HIGH] CWE-120 CVE-2023-46283: A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcente A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versions < V2312), SIMATIC PCS neo (All versions < V4.1), SINEC NMS (All versions < V2.0 SP1), Totally Integrated Automation Portal (TIA Portal) V14 (All versions), Totally Integrated Automation Portal (TIA Portal) V15.1 (All versions), T
nvd
CVE-2020-7580P4MEDIUMCVSS 6.7vAll versions < V3.0 SP12020-06-10
CVE-2020-7580 [MEDIUM] CWE-428 CVE-2020-7580: A vulnerability has been identified in SIMATIC Automation Tool (All versions < V4 SP2), SIMATIC NET A vulnerability has been identified in SIMATIC Automation Tool (All versions < V4 SP2), SIMATIC NET PC Software V14 (All versions < V14 SP1 Update 14), SIMATIC NET PC Software V15 (All versions), SIMATIC NET PC Software V16 (All versions < V16 Upd3), SIMATIC PCS neo (All versions < V3.0 SP1), SIMATIC ProSave (All versions < V17), SIMATIC S7-1500 Softwa
nvd
CVE-2023-46096P4MEDIUMCVSS 6.5fixed in 4.1vAll versions < V4.12023-11-14
CVE-2023-46096 [MEDIUM] CWE-306 CVE-2023-46096: A vulnerability has been identified in SIMATIC PCS neo (All versions < V4.1). The PUD Manager of aff A vulnerability has been identified in SIMATIC PCS neo (All versions < V4.1). The PUD Manager of affected products does not properly authenticate users in the PUD Manager web service. This could allow an unauthenticated adjacent attacker to generate a privileged token and upload additional documents.
nvd
CVE-2020-7588P4MEDIUMCVSS 5.3vAll versions < V3.0 SP12020-07-14
CVE-2020-7588 [MEDIUM] CWE-20 CVE-2020-7588: A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter E A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation (All versions < V3.2), Opcenter Execution Process (All versions < V3.2), Opcenter Intelligence (All versions < V3.3), Opcenter Quality (All versions < V11.3), Opcenter RD&L (V8.0), SIMATIC IT LMS (All versions < V2.6), SIMATIC IT Prod
nvd
CVE-2020-7581P4MEDIUMCVSS 6.7vAll versions < V3.0 SP12020-07-14
CVE-2020-7581 [MEDIUM] CWE-428 CVE-2020-7581: A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter E A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation (All versions < V3.2), Opcenter Execution Process (All versions < V3.2), Opcenter Intelligence (All versions < V3.3), Opcenter Quality (All versions < V11.3), Opcenter RD&L (V8.0), SIMATIC Notifier Server for Windows (All versions),
nvd