cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,poc,trended,trended_no_1,published,trended_score CVE-2022-30938,https://securityvulnerability.io/vulnerability/CVE-2022-30938,Memory Corruption in EN100 Ethernet Modules by Siemens,"A vulnerability exists within Siemens' EN100 Ethernet modules that can be exploited through specifically crafted HTTP packets. When an attacker targets the /txtrace endpoint and manipulates a particular argument, it results in a memory corruption issue. This can cause the affected application to crash, leading to a denial of service condition, impacting the availability of the services relying on these modules.",Siemens,"En100 Ethernet Module Dnp3 Ip Variant,En100 Ethernet Module Iec 104 Variant,En100 Ethernet Module Iec 61850 Variant,En100 Ethernet Module Modbus Tcp Variant,En100 Ethernet Module Profinet Io Variant",7.5,HIGH,0.0007800000021234155,false,,false,false,false,,false,false,2022-07-12T10:06:41.000Z,0 CVE-2022-30937,https://securityvulnerability.io/vulnerability/CVE-2022-30937,Memory Corruption Vulnerability in Siemens EN100 Ethernet Modules,"A memory corruption vulnerability exists in various Siemens EN100 Ethernet modules when processing specially crafted HTTP packets sent to the /txtrace endpoint. Successful exploitation of this vulnerability could lead to application crashes, resulting in a denial of service. All versions of affected modules, including those for DNP3, IEC 104, Modbus TCP, and PROFINET IO, are susceptible, with particular versions of the IEC 61850 module being especially at risk. Users are advised to implement mitigation strategies to protect their network infrastructures.",Siemens,"En100 Ethernet Module Dnp3 Ip Variant,En100 Ethernet Module Iec 104 Variant,En100 Ethernet Module Iec 61850 Variant,En100 Ethernet Module Modbus Tcp Variant,En100 Ethernet Module Profinet Io Variant",7.5,HIGH,0.0007800000021234155,false,,false,false,false,,false,false,2022-06-14T09:21:54.000Z,0 CVE-2018-4838,https://securityvulnerability.io/vulnerability/CVE-2018-4838,,"A vulnerability has been identified in EN100 Ethernet module IEC 61850 variant (All versions < V4.30), EN100 Ethernet module DNP3 variant (All versions < V1.04), EN100 Ethernet module PROFINET IO variant (All versions), EN100 Ethernet module Modbus TCP variant (All versions), EN100 Ethernet module IEC 104 variant (All versions < V1.22). The web interface (TCP/80) of affected devices allows an unauthenticated user to upgrade or downgrade the firmware of the device, including to older versions with known vulnerabilities.",Siemens,"En100 Ethernet Module Iec 61850 Variant,En100 Ethernet Module Dnp3 Variant,En100 Ethernet Module Profinet Io Variant,En100 Ethernet Module Modbus Tcp Variant,En100 Ethernet Module Iec 104 Variant",7.5,HIGH,0.0009399999980814755,false,,false,false,false,,false,false,2018-03-08T17:00:00.000Z,0 CVE-2018-4840,https://securityvulnerability.io/vulnerability/CVE-2018-4840,,"A vulnerability has been identified in DIGSI 4 (All versions < V4.92), EN100 Ethernet module DNP3 variant (All versions < V1.05.00), EN100 Ethernet module IEC 104 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.30), EN100 Ethernet module Modbus TCP variant (All versions), EN100 Ethernet module PROFINET IO variant (All versions). The device engineering mechanism allows an unauthenticated remote user to upload a modified device configuration overwriting access authorization passwords.",Siemens,"Digsi 4,En100 Ethernet Module Dnp3 Variant,En100 Ethernet Module Iec 104 Variant,En100 Ethernet Module Iec 61850 Variant,En100 Ethernet Module Modbus Tcp Variant,En100 Ethernet Module Profinet Io Variant",7.5,HIGH,0.0013899999903514981,false,,false,false,false,,false,false,2018-03-08T17:00:00.000Z,0 CVE-2018-4839,https://securityvulnerability.io/vulnerability/CVE-2018-4839,,"A vulnerability has been identified in DIGSI 4 (All versions < V4.92), EN100 Ethernet module DNP3 variant (All versions < V1.05.00), EN100 Ethernet module IEC 104 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.30), EN100 Ethernet module Modbus TCP variant (All versions), EN100 Ethernet module PROFINET IO variant (All versions), Other SIPROTEC 4 relays (All versions), Other SIPROTEC Compact relays (All versions), SIPROTEC 4 7SD80 (All versions < V4.70), SIPROTEC 4 7SJ61 (All versions < V4.96), SIPROTEC 4 7SJ62 (All versions < V4.96), SIPROTEC 4 7SJ64 (All versions < V4.96), SIPROTEC 4 7SJ66 (All versions < V4.30), SIPROTEC Compact 7SJ80 (All versions < V4.77), SIPROTEC Compact 7SK80 (All versions < V4.77). An attacker with local access to the engineering system or in a privileged network position and able to obtain certain network traffic could possibly reconstruct access authorization passwords.",Siemens,"Digsi 4,En100 Ethernet Module Dnp3 Variant,En100 Ethernet Module Iec 104 Variant,En100 Ethernet Module Iec 61850 Variant,En100 Ethernet Module Modbus Tcp Variant,En100 Ethernet Module Profinet Io Variant,Other Siprotec 4 Relays,Other Siprotec Compact Relays,Siprotec 4 7sd80,Siprotec 4 7sj61,Siprotec 4 7sj62,Siprotec 4 7sj64,Siprotec 4 7sj66,Siprotec Compact 7sj80,Siprotec Compact 7sk80",5.3,MEDIUM,0.0005499999970197678,false,,false,false,false,,false,false,2018-03-08T17:00:00.000Z,0