Browse all 1658 CVE security advisories affecting Siemens. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Siemens operates as a global industrial technology conglomerate, primarily manufacturing automation systems, power infrastructure, and medical imaging devices. Its extensive portfolio of programmable logic controllers and human-machine interfaces frequently exposes critical vulnerabilities, with recorded Common Vulnerabilities and Exposures numbering in the thousands. Historically, these systems have suffered from remote code execution flaws, buffer overflows, and insecure default configurations that allow unauthorized privilege escalation. Notable incidents include the Stuxnet worm, which exploited Siemens PLCs to disrupt Iranian nuclear centrifuges, highlighting the severe physical consequences of digital compromise in industrial control environments. The company has since strengthened its security posture through firmware updates and secure-by-design principles, yet legacy devices remain vulnerable due to long operational lifecycles and limited patching capabilities in isolated networks.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2022-25754 | 多款 Siemens 产品跨站请求伪造漏洞 — SCALANCE X302-7 EEC (230V) CWE-352 | 7.5 | - | 2022-04-12 |
| CVE-2022-25753 | 多款 Siemens 产品 缓冲区错误漏洞 — SCALANCE X302-7 EEC (230V) CWE-121 | 7.5 | - | 2022-04-12 |
| CVE-2022-25752 | 多款 Siemens 产品安全特征问题漏洞 — SCALANCE X302-7 EEC (230V) CWE-330 | 7.5 | - | 2022-04-12 |
| CVE-2022-25751 | 多款 Siemens 产品输入验证错误漏洞 — SCALANCE X302-7 EEC (230V) CWE-20 | 7.5 | - | 2022-04-12 |
| CVE-2022-25650 | Siemens Mendix 安全漏洞 — Mendix Applications using Mendix 7 CWE-284 | 6.5 | - | 2022-04-12 |
| CVE-2022-23450 | Siemens SIMATIC 代码问题漏洞 — SIMATIC Energy Manager Basic CWE-502 | 9.8 | - | 2022-04-12 |
| CVE-2022-23449 | Siemens SIMATIC 代码问题漏洞 — SIMATIC Energy Manager Basic CWE-427 | 7.3 | - | 2022-04-12 |
| CVE-2022-23448 | Siemens SIMATIC安全漏洞 — SIMATIC Energy Manager Basic CWE-732 | 7.8 | - | 2022-04-12 |
| CVE-2021-42029 | Siemens SIMATIC 安全漏洞 — SIMATIC STEP 7 (TIA Portal) V15 CWE-284 | 9.8 | - | 2022-04-12 |
| CVE-2021-40368 | Siemens SIMATIC S7-400 缓冲区错误漏洞 — SIMATIC S7-400 CPU 412-1 DP V7 CWE-119 | 7.5 | High | 2022-04-12 |
| CVE-2022-25622 | 多款Siemens SIMATIC产品资源管理错误漏洞 — SIMATIC CFU DIQ CWE-400 | 5.3 | Medium | 2022-04-12 |
| CVE-2022-26317 | Siemens Mendix 安全特征问题特征问题漏洞 — Mendix Applications using Mendix 7 CWE-284 | 7.5 | - | 2022-03-08 |
| CVE-2022-26314 | Siemens Mendix 安全漏洞 — Mendix Forgot Password Appstore module CWE-307 | 9.8 | - | 2022-03-08 |
| CVE-2022-26313 | Siemens Mendix 访问控制错误漏洞 — Mendix Forgot Password Appstore module CWE-284 | 9.8 | - | 2022-03-08 |
| CVE-2022-24661 | Siemens Simcenter STAR-CCM+ 缓冲区错误漏洞 — Simcenter STAR-CCM+ Viewer CWE-119 | 7.8 | - | 2022-03-08 |
| CVE-2022-24408 | Siemens SINUMERIK 安全漏洞 — SINUMERIK MC CWE-269 | 7.8 | - | 2022-03-08 |
| CVE-2022-24309 | Siemens Mendix 安全漏洞 — Mendix Runtime V7 CWE-284 | 6.8 | Medium | 2022-03-08 |
| CVE-2021-44478 | Siemens Polarion Subversion Webclient 跨站脚本漏洞 — Polarion ALM CWE-79 | 6.1 | - | 2022-03-08 |
| CVE-2021-42020 | Siemens RUGGEDCOM代码问题漏洞 — RUGGEDCOM i800 CWE-754 | 7.5 | High | 2022-03-08 |
| CVE-2021-42019 | Siemens RUGGEDCOM 输入验证错误漏洞 — RUGGEDCOM i800 CWE-190 | 5.9 | Medium | 2022-03-08 |
| CVE-2021-42018 | Siemens RUGGEDCOM 缓冲区错误漏洞 — RUGGEDCOM i800 CWE-122 | 5.9 | Medium | 2022-03-08 |
| CVE-2021-42017 | Siemens RUGGEDCOM 安全特征问题漏洞 — RUGGEDCOM i800 CWE-358 | 5.9 | Medium | 2022-03-08 |
| CVE-2021-42016 | Siemens RUGGEDCOM 安全漏洞 — RUGGEDCOM i800 CWE-208 | 7.5 | High | 2022-03-08 |
| CVE-2021-41543 | Siemens Climatix Pol909 日志信息泄露漏洞 — Climatix POL909 (AWB module) CWE-284 | 6.5 | - | 2022-03-08 |
| CVE-2021-41542 | Climatix POL909 跨站脚本漏洞 — Climatix POL909 (AWB module) CWE-79 | 6.1 | - | 2022-03-08 |
| CVE-2021-41541 | Climatix POL909跨站脚本漏洞 — Climatix POL909 (AWB module) CWE-79 | 6.1 | - | 2022-03-08 |
| CVE-2021-37208 | Siemens RUGGEDCOM 跨站脚本漏洞 — RUGGEDCOM i800 CWE-79 | 9.6 | Critical | 2022-03-08 |
| CVE-2021-37209 | Siemens RUGGEDCOM 加密问题漏洞 — RUGGEDCOM i800 CWE-326 | 6.7 | Medium | 2022-03-08 |
| CVE-2022-24281 | Siemens SINEC NMS SQL注入漏洞 — SINEC NMS CWE-89 | 7.2 | High | 2022-03-08 |
| CVE-2022-24282 | Siemens SINEC NMS 代码问题漏洞 — SINEC NMS CWE-502 | 7.2 | High | 2022-03-08 |
This page lists every published CVE security advisory associated with Siemens. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.