Siemens

First CVE: Nov 22, 2016Active for: 10 years
1,809
CVEs Published
More CVEs Published than 93% of tracked CNAs
164.5
Avg CVEs / Year
More Avg CVEs / Year than 93% of tracked CNAs
7.4
Avg CVSS Score
Higher Avg CVSS Score than 63% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Siemens as a CNA, 88.2% affect products that Siemens develops as a vendor.

88.2%
11.8%
Self-reported: 1,596Third-party: 213

Of all the CVEs published that affect products developed by Siemens, 72.5% are self-published by Siemens as a CNA.

72.5%
27.5%
Self-published: 1,596Published by other CNAs: 605

Trends Over Time

The number and severity of CVEs published by Siemens over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 22, 2016
9 years ago
Most Recent CVE
Jul 14, 2026
10 days ago

Top CVEs

All CVEs published by Siemens as a CNA, regardless of affected vendor or product.

1,809 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versions < V7.3 Update 1). The affected system a
Apr 12, 20229.852NONO
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by s
Oct 12, 20217.248NONO
A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header.
Jul 14, 202610.046NONO
A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). The web interface of affected devices i
Jun 13, 20237.246NONO
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker with access to the Web Based Management (443/tcp) of the affec
Jan 10, 20238.845NONO
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP1). An attacker with access to the webserver of an affected system could download arbitrary files from the u
Sep 14, 20217.744NONO
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX RX1400 (All versions < V2.17.1)
May 12, 20269.140NONO
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application uses a password hashing implementation with a static, hardcoded salt s
Jun 9, 20269.838NONO
Affected devices do not properly validate and sanitize Technology Object (TO) name rendered on the "Motion Control Diagnostics" page of the web interface. This could allow an authe
May 12, 20269.138NONO
Affected devices do not properly validate and sanitize PLC/station name rendered on the "communication" parameters page of the web interface. This could allow an authenticated att
May 12, 20269.138NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA1,809 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local676 (37.4%)
Network1,042 (57.6%)
Unknown0 (0.0%)
Physical25 (1.4%)
Adjacent Network66 (3.6%)
Attack Complexity
Low1,719 (95.0%)
High90 (5.0%)
Unknown0 (0.0%)
User Interaction
None1,147 (63.4%)
Unknown0 (0.0%)
Required662 (36.6%)
Privileges Required
Low462 (25.5%)
High116 (6.4%)
None1,231 (68.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (1809 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
0.1% of CVEs· 70th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Siemens as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Siemens as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs