Sinumerik One
Vendor:
First CVE: Nov 12, 2020 · Active for 5 years
5
Total CVEs
More Total CVEs than 77% of tracked products
1.3
Avg CVEs / Year
Higher CVE frequency than 55% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 45% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Sinumerik One over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 12, 2020
5 years ago
Most Recent CVE
Dec 12, 2023
958 days ago
CVE Severity & Scoring
Sinumerik One5 CVEs
40%
60%
All CVEs352,785 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (20.0%)
Network3 (60.0%)
Unknown0 (0.0%)
Physical1 (20.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (80.0%)
Unknown0 (0.0%)
Required1 (20.0%)
Privileges Required
Low1 (20.0%)
High0 (0.0%)
None4 (80.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24408HIGH A vulnerability has been identified in SINUMERIK MC (All versions < V1.15 SP1), SINUMERIK ONE (All versions < V6.15 SP1). The sc SUID binary on affected devices provides several co | Mar 8, 2022 | 7.8 | 25 | NO | NO |
CVE-2020-27827HIGH A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially | Mar 18, 2021 | 7.5 | 25 | NO | NO |
CVE-2022-30694MEDIUM The login endpoint /FormLogin in affected web services does not apply proper origin checking.
This could allow authenticated remote attackers to track the activities of other us | Nov 8, 2022 | 6.5 | 23 | NO | NO |
CVE-2020-8745MEDIUM Insufficient control flow management in subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25 , Intel(R) TXE vers | Nov 12, 2020 | 6.8 | 23 | NO | NO |
CVE-2023-46156HIGH Affected devices improperly handle specially crafted packets sent to port 102/tcp.
This could allow an attacker to create a denial of service condition. A restart is needed to res | Dec 12, 2023 | 7.5 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (5 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (5 CVEs).
Media Mentions
Signals from CVEs in this product scope (5 CVEs).
Top CNAs Publishing CVEs For Sinumerik One
Top CWEs
Versions
No cataloged versions.