Home/Product/siemens simatic itc2200 firmware
Product

siemens simatic itc2200 firmware

19 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2017-18922
>= 3.0.0.0 and < 3.2.1.0
It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious
9.8CRITICAL
CVE-2020-14405
>= 3.0.0.0 and < 3.2.1.0
An issue was discovered in LibVNCServer before 0.9.13. libvncclient/rfbproto.c does not limit TextChat size.
6.5MEDIUM
CVE-2020-14404
>= 3.0.0.0 and < 3.2.1.0
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/rre.c allows out-of-bounds access via encodings.
5.4MEDIUM
CVE-2020-14403
>= 3.0.0.0 and < 3.2.1.0
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/hextile.c allows out-of-bounds access via encodings.
5.4MEDIUM
CVE-2020-14402
>= 3.0.0.0 and < 3.2.1.0
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/corre.c allows out-of-bounds access via encodings.
5.4MEDIUM
CVE-2020-14401
>= 3.0.0.0 and < 3.2.1.0
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/scale.c has a pixel_value integer overflow.
6.5MEDIUM
CVE-2020-14398
>= 3.0.0.0 and < 3.2.1.0
An issue was discovered in LibVNCServer before 0.9.13. An improperly closed TCP connection causes an infinite loop in libvncclient
7.5HIGH
CVE-2020-14397
>= 3.0.0.0 and < 3.2.1.0
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/rfbregion.c has a NULL pointer dereference.
7.5HIGH
CVE-2020-14396
>= 3.0.0.0 and < 3.2.1.0
An issue was discovered in LibVNCServer before 0.9.13. libvncclient/tls_openssl.c has a NULL pointer dereference.
7.5HIGH
CVE-2019-20840
>= 3.0.0.0 and < 3.2.1.0
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/ws_decode.c can lead to a crash because of unaligned accesses
7.5HIGH
CVE-2019-20839
>= 3.0.0.0 and < 3.2.1.0
libvncclient/sockets.c in LibVNCServer before 0.9.13 has a buffer overflow via a long socket filename.
7.5HIGH
CVE-2018-21247
>= 3.0.0.0 and < 3.2.1.0
An issue was discovered in LibVNCServer before 0.9.13. There is an information leak (of uninitialized memory contents) in the libv
7.5HIGH
CVE-2019-20788
>= 3.0.0.0 and < 3.2.1.0
libvncclient/cursor.c in LibVNCServer through 0.9.12 has a HandleCursorShape integer overflow and heap-based buffer overflow via a
9.8CRITICAL
CVE-2019-15681
>= 3.0.0.0 and < 3.2.1.0
LibVNC commit before d01e1bb4246323ba6fcee3b82ef1faa9b1dac82a contains a memory leak (CWE-655) in VNC server code, which allow an
7.5HIGH
CVE-2018-20750
>= 3.0.0.0 and < 3.2.1.0
LibVNC through 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 wa
9.8CRITICAL
CVE-2018-20749
>= 3.0.0.0 and < 3.2.1.0
LibVNC before 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was
9.8CRITICAL
CVE-2018-20748
>= 3.0.0.0 and < 3.2.1.0
LibVNC before 0.9.12 contains multiple heap out-of-bounds write vulnerabilities in libvncclient/rfbproto.c. The fix for CVE-2018-2
9.8CRITICAL
CVE-2018-20019
>= 3.0.0.0 and < 3.2.1.0
LibVNC before commit a83439b9fbe0f03c48eb94ed05729cb016f8b72f contains multiple heap out-of-bound write vulnerabilities in VNC cli
9.8CRITICAL
CVE-2017-5753
< 3.1
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of informatio
5.6MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin