Siemens

Tim 4r-ie Firmware

9 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.44%
  • Published 14.04.2020 20:15:14
  • Last modified 21.11.2024 04:20:11

A vulnerability has been identified in TIM 3V-IE (incl. SIPLUS NET variants) (All versions < V2.8), TIM 3V-IE Advanced (incl. SIPLUS NET variants) (All versions < V2.8), TIM 3V-IE DNP3 (incl. SIPLUS NET variants) (All versions < V3.3), TIM 4R-IE (inc...

  • EPSS 25%
  • Published 07.08.2017 20:29:00
  • Last modified 20.04.2025 01:37:25

The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to have unspecified impact via a large number of crafted requests.

Exploit
  • EPSS 60.88%
  • Published 07.08.2017 20:29:00
  • Last modified 20.04.2025 01:37:25

The decodenetnum function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (assertion failure) via a 6 or mode 7 packet containing a long data value.

  • EPSS 4.21%
  • Published 21.07.2017 14:29:00
  • Last modified 20.04.2025 01:37:25

The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infinite loop) via a crafted NTP packet.

  • EPSS 4.59%
  • Published 30.01.2017 21:59:00
  • Last modified 20.04.2025 01:37:25

NTP before 4.2.8p6 and 4.3.x before 4.3.90, when configured in broadcast mode, allows man-in-the-middle attackers to conduct replay attacks by sniffing the network.

  • EPSS 9.71%
  • Published 30.01.2017 21:59:00
  • Last modified 20.04.2025 01:37:25

ntpd in NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (NULL pointer dereference) via a ntpdc reslist command.

  • EPSS 2.18%
  • Published 05.07.2016 01:59:01
  • Last modified 12.04.2025 10:46:40

The process_packet function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (peer-variable modification) by sending spoofed packets from many source IP addresses in a certain scenario, as demonstr...

  • EPSS 12.64%
  • Published 05.07.2016 01:59:00
  • Last modified 12.04.2025 10:46:40

ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (ephemeral-association demobilization) by sending a spoofed crypto-NAK packet with incorrect authentication data at a certain time.

Exploit
  • EPSS 3.67%
  • Published 26.01.2016 19:59:00
  • Last modified 12.04.2025 10:46:40

NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted key, aka a "skeleton key."