Browse all 135 CVE security advisories affecting Siemens AG. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Siemens AG operates as a global conglomerate specializing in industrial automation, energy infrastructure, and healthcare technology. Its extensive portfolio of programmable logic controllers, human-machine interfaces, and medical imaging systems presents a broad attack surface, resulting in 135 recorded Common Vulnerabilities and Exposures. Historically, the most prevalent vulnerability classes affecting Siemens products include remote code execution, cross-site scripting, and privilege escalation flaws. These defects often stem from legacy protocols lacking robust authentication mechanisms or insecure default configurations in industrial control systems. Notable security incidents have highlighted risks associated with unpatched firmware and weak cryptographic implementations, particularly within SCADA environments. The company has responded by enhancing its product security lifecycle and issuing regular security advisories. However, the complexity of integrating these devices into critical infrastructure continues to pose significant challenges for defenders seeking to mitigate potential exploitation vectors effectively.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2019-13941 | Siemens OZW672和OZW772 授权问题漏洞 — OZW672 CWE-552 | 5.3 | - | 2020-02-11 |
| CVE-2019-19278 | Siemens SINAMICS PERFECT HARMONY GH180 竞争条件问题漏洞 — SINAMICS PERFECT HARMONY GH180 Drives MLFB 6SR32..-.....-.... MLFB 6SR4...-.....-.... MLFB 6SR5...-.....-.... With option A30 (HMIs 12 inches or larger) CWE-693 | 6.8 | - | 2020-01-16 |
| CVE-2019-10940 | Siemens SINEMA Server 安全漏洞 — SINEMA Server CWE-266 | 9.9 | - | 2020-01-16 |
| CVE-2019-13944 | Siemens EN100 Ethernet module 路径遍历漏洞 — EN100 Ethernet module DNP3 variant CWE-23 | 5.3 | - | 2019-12-12 |
| CVE-2019-13943 | Siemens EN100 Ethernet Module 跨站脚本漏洞 — EN100 Ethernet module DNP3 variant CWE-79 | 6.1 | - | 2019-12-12 |
| CVE-2019-13942 | Siemens EN100 Ethernet Module 缓冲区错误漏洞 — EN100 Ethernet module DNP3 variant CWE-119 | 7.5 | - | 2019-12-12 |
| CVE-2019-13932 | Siemens XHQ Operations Intelligence 安全漏洞 — XHQ CWE-20 | 8.2 | - | 2019-12-12 |
| CVE-2019-13931 | Siemens XHQ Operations Intelligence 跨站脚本漏洞 — XHQ CWE-80 | 5.4 | - | 2019-12-12 |
| CVE-2019-13930 | Siemens XHQ Operations Intelligence 跨站请求伪造漏洞 — XHQ CWE-352 | 8.1 | - | 2019-12-12 |
| CVE-2019-13945 | Siemens SIMATIC S7-200和S7-1200 输入验证错误漏洞 — SIMATIC S7-1200 CPU family (incl. SIPLUS variants) CWE-749 | 6.1 | - | 2019-12-12 |
| CVE-2019-13927 | Siemens Desigo PX 安全漏洞 — Desigo PX automation controllers PXC00-E.D, PXC50-E.D, PXC100-E.D, PXC200-E.D with Desigo PX Web modules PXA40-W0, PXA40-W1, PXA40-W2 CWE-472 | 8.2 | - | 2019-12-12 |
| CVE-2019-13936 | Siemens Polarion webclient 跨站脚本漏洞 — Polarion CWE-79 | 3.5 | Low | 2019-11-27 |
| CVE-2019-13935 | Siemens Polarion webclient 跨站脚本漏洞 — Polarion CWE-79 | 3.5 | Low | 2019-11-27 |
| CVE-2019-13934 | Siemens Polarion webclient 跨站脚本漏洞 — Polarion CWE-79 | 3.5 | Low | 2019-11-27 |
| CVE-2019-13929 | Siemens SIMATIC IT Unified Architecture Discrete Manufacturing 安全特征问题漏洞 — SIMATIC IT UADM CWE-321 | 6.5 | - | 2019-10-10 |
| CVE-2019-13921 | Siemens SIMATIC WinAC RTX(F)2010 资源管理错误漏洞 — SIMATIC WinAC RTX (F) 2010 CWE-410 | 7.5 | - | 2019-10-10 |
| CVE-2019-13923 | Siemens IE-WSN-PA Link WirelessHART Gateway 跨站脚本漏洞 — IE/WSN-PA Link WirelessHART Gateway CWE-80 | 6.1 | - | 2019-09-13 |
| CVE-2019-13922 | Siemens SINEMA Remote Connect Server 安全漏洞 — SINEMA Remote Connect Server CWE-311 | 4.9 | - | 2019-09-13 |
| CVE-2019-13920 | Siemens SINEMA Remote Connect Server 跨站请求伪造漏洞 — SINEMA Remote Connect Server CWE-352 | 4.3 | - | 2019-09-13 |
| CVE-2019-13919 | 西门子 SINEMA Remote Connect Server 安全漏洞 — SINEMA Remote Connect Server CWE-284 | 4.3 | - | 2019-09-13 |
| CVE-2019-13918 | Siemens SINEMA Remote Connect Server 安全漏洞 — SINEMA Remote Connect Server CWE-307 | 9.8 | - | 2019-09-13 |
| CVE-2019-10937 | Siemens SIMATIC TDC CP51M1 输入验证错误漏洞 — SIMATIC TDC CP51M1 CWE-20 | 7.5 | - | 2019-09-13 |
| CVE-2019-10928 | Siemens SCALANCE SC-600 命令注入漏洞 — SCALANCE SC-600 CWE-703 | 6.6 | - | 2019-08-13 |
| CVE-2019-10927 | 多款Siemens产品 安全漏洞 — SCALANCE SC-600 CWE-703 | 6.5 | - | 2019-08-13 |
| CVE-2019-10938 | Siemens SIPROTEC 5和Power Meters 访问控制错误漏洞 — SIPROTEC 5 devices with CPU variants CP200 CWE-284 | 9.8 | - | 2019-08-02 |
| CVE-2019-10930 | Siemens DIGSI 5 engineering software和SIPROTEC 5 - DIGSI Device Driver 代码问题漏洞 — All other SIPROTEC 5 device types with CPU variants CP300 and CP100 and the respective Ethernet communication modules CWE-552 | 9.1 | - | 2019-07-11 |
| CVE-2019-10935 | Siemens SIMATIC PCS 7和SIMATIC WinCC 代码问题漏洞 — SIMATIC PCS 7 V8.0 and earlier CWE-434 | 8.8 | - | 2019-07-11 |
| CVE-2019-10933 | Siemens Spectrum Power 跨站脚本漏洞 — Spectrum Power 3 (Corporate User Interface) CWE-80 | 6.1 | - | 2019-07-11 |
| CVE-2019-10931 | SIEMENS DIGSI 4 安全漏洞 — All other SIPROTEC 5 device types with CPU variants CP300 and CP100 and the respective Ethernet communication modules CWE-248 | 9.1 | - | 2019-07-11 |
| CVE-2019-10915 | Siemens TIA Administrator 访问控制错误漏洞 — TIA Administrator CWE-306 | 7.8 | - | 2019-07-11 |
This page lists every published CVE security advisory associated with Siemens AG. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.