Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 491 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

787 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)19%—Schneider-electric Interactive Graphical Scada System Data Server9/2/202217/6/2026
A CWE-125: Out-of-bounds Read vulnerability exists that could cause denial of service when an attacker repeatedly sends a specially crafted message. Affected Product: Interactive Graphical SCADA System Data Server (V15.0.0.22020 and prior)
ModificadaAlta (7.5)18%—Schneider-electric Interactive Graphical Scada System Data Server9/2/202217/6/2026
A CWE-125: Out-of-bounds Read vulnerability exists that could cause memory leaks potentially resulting in denial of service when an attacker repeatedly sends a specially crafted message. Affected Product: Interactive Graphical SCADA System Data Server (V15.0.0.22020 and prior)
ModificadaCrítica (9.8)45%—Schneider-electric Interactive Graphical Scada System Data Server9/2/202217/6/2026
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow potentially leading to remote code execution when an attacker sends a specially crafted message. Affected Product: Interactive Graphical SCADA System Data Server (V15.0.0.22020 and prior)
ModificadaCrítica (9.8)3.5%—Schneider-electric Interactive Graphical Scada System Data Server9/2/202217/6/2026
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists that could cause modification of an existing file by adding at end of file or create a new file in the context of the Data Server potentially leading to remote code execution when an attacker sends a specially crafted message.…
ModificadaCrítica (9.8)3.5%—Schneider-electric Interactive Graphical Scada System Data Server9/2/202217/6/2026
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists that could cause modification of an existing file by inserting at beginning of file or create a new file in the context of the Data Server potentially leading to remote code execution when an attacker sends a specially crafted…
ModificadaCrítica (9.8)2.2%—Schneider-electric Interactive Graphical Scada System Data Server9/2/202217/6/2026
A CWE-190: Integer Overflow or Wraparound vulnerability exists that could cause heap-based buffer overflow, leading to denial of service and potentially remote code execution when an attacker sends multiple specially crafted messages. Affected Product: Interactive Graphical SCADA System Data Server (V15.0.0.22020 and…
ModificadaCrítica (9.8)1.1%—Schneider-electric Easergy P141 FirmwareSchneider-electric Easergy P142 FirmwareSchneider-electric Easergy P143 FirmwareSchneider-electric Easergy P145 Firmware+299/2/202217/6/2026
A CWE-798: Use of Hard-coded Credentials vulnerability exists. If an attacker were to obtain the TLS cryptographic key and take active control of the Courier tunneling communication network, they could potentially observe and manipulate traffic associated with product configuration.
ModificadaMedia (6.1)0.60%—Schneider-electric Spacelynk FirmwareSchneider-electric Wiser FOR KNX FirmwareSchneider-electric Fellerlynk Firmware9/2/202217/6/2026
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause a web session compromise when an attacker injects and then executes arbitrary malicious JavaScript code inside the target browser. Affected Product: spaceLYnk (V2.6.2 and prior), Wiser…
ModificadaAlta (8.1)0.41%—Schneider-electric Spacelynk FirmwareSchneider-electric Wiser FOR KNX FirmwareSchneider-electric Fellerlynk Firmware9/2/202217/6/2026
A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists that could induce users to perform unintended actions, leading to the override of the system�s configurations when an attacker persuades a user to visit a rogue website. Affected Product: spaceLYnk (V2.6.2 and prior), Wiser for KNX (formerly homeLYnk)…
ModificadaCrítica (9.8)1.1%—Schneider-electric Spacelynk FirmwareSchneider-electric Wiser FOR KNX FirmwareSchneider-electric Fellerlynk Firmware9/2/202217/6/2026
A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to manipulate the admin after numerous attempts at guessing credentials. Affected Product: spaceLYnk (V2.6.2 and prior), Wiser for KNX (formerly homeLYnk) (V2.6.2 and prior), fellerLYnk (V2.6.2 and…
ModificadaMedia (5.3)0.79%—Schneider-electric Spacelynk FirmwareSchneider-electric Wiser FOR KNX FirmwareSchneider-electric Fellerlynk Firmware9/2/202217/6/2026
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow modifications of the touch configurations in an unauthorized manner when an attacker attempts to modify the touch configurations. Affected Product: spaceLYnk (V2.6.2 and prior), Wiser for KNX (formerly homeLYnk) (V2.6.2 and…
ModificadaAlta (8.8)0.68%—Schneider-electric Hmibscea53d1edb FirmwareSchneider-electric Hmibscea53d1eds FirmwareSchneider-electric Hmibscea53d1edm FirmwareSchneider-electric Hmibscea53d1edl Firmware+39/2/202217/6/2026
A CWE-352: Cross-Site Request Forgery (CSRF) exists that could cause a remote attacker to gain unauthorized access to the product when conducting cross-domain attacks based on same-origin policy or cross-site request forgery protections bypass. Affected Product: EcoStruxure EV Charging Expert (formerly known as EVlink…
ModificadaAlta (7.4)0.94%—Schneider-electric Hmibscea53d1edb FirmwareSchneider-electric Hmibscea53d1eds FirmwareSchneider-electric Hmibscea53d1edm FirmwareSchneider-electric Hmibscea53d1edl Firmware+39/2/202217/6/2026
A CWE-1021 Improper Restriction of Rendered UI Layers or Frames vulnerability exists that could cause unintended modifications of the product settings or user accounts when deceiving the user to use the web interface rendered within iframes. Affected Product: EcoStruxure EV Charging Expert (formerly known as EVlink…
ModificadaAlta (7.8)0.20%—Schneider-electric Hmibmuhi29d2801 FirmwareSchneider-electric Hmibmusi29d2801 FirmwareSchneider-electric Hmibmuci29d2w01 FirmwareSchneider-electric Hmibmu0i29d2001 Firmware+339/2/202217/6/2026
A CWE-276: Incorrect Default Permissions vulnerability exists that could cause unauthorized access to the base installation directory leading to local privilege escalation. Affected Product: Harmony/Magelis iPC Series (All Versions), Vijeo Designer (All Versions prior to V6.2 SP11 Multiple HotFix 4), Vijeo Designer…
ModificadaMedia (5.4)0.45%—Schneider-electric Ecostruxure Power Monitoring Expert4/2/202217/6/2026
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could allow an authenticated attacker to view data, change settings, or impact availability of the software when the user visits a page containing the injected payload. Affected Product: EcoStruxure…
ModificadaAlta (8.8)1.2%—Schneider-electric Ecostruxure Power Monitoring Expert4/2/202217/6/2026
A CWE-20: Improper Input Validation vulnerability exists that could allow an unauthenticated attacker to view data, change settings, impact availability of the software, or potentially impact a user�s local machine when the user clicks a specially crafted link. Affected Product: EcoStruxure Power Monitoring Expert…
ModificadaMedia (6.5)0.77%—Schneider-electric Ecostruxure Power Monitoring Expert4/2/202217/6/2026
A CWE-20: Improper Input Validation vulnerability exists that could allow arbitrary files on the server to be read by authenticated users through a limited operating system service account. Affected Product: EcoStruxure Power Monitoring Expert (Versions 2020 and prior)
ModificadaAlta (8.8)2.8%—Schneider-electric Easergy P3 Firmware4/2/202217/6/2026
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could lead to a buffer overflow causing program crashes and arbitrary code execution when specially crafted packets are sent to the device over the network. Protection functions and tripping function via GOOSE can be impacted. Affected…
ModificadaAlta (7.5)0.93%—Schneider-electric Modicon M340 Bmxp341000 FirmwareSchneider-electric Modicon M340 Bmxp342000 FirmwareSchneider-electric Modicon M340 Bmxp342010 FirmwareSchneider-electric Modicon M340 Bmxp3420102 Firmware+24/2/202217/6/2026
A CWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause a denial of service on ports 80 (HTTP) and 502 (Modbus), when sending a large number of TCP RST or FIN packets to any open TCP port of the PLC. Affected Product: Modicon M340 CPUs: BMXP34 (All Versions)
ModificadaAlta (8.8)2.8%—Schneider-electric Easergy P5 Firmware4/2/202217/6/2026
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could lead to a buffer overflow causing program crashes and arbitrary code execution when specially crafted packets are sent to the device over the network. Protection functions and tripping function via GOOSE can be impacted. Affected…
ModificadaAlta (7.5)2.4%—Schneider-electric Easergy P5 Firmware4/2/202217/6/2026
A CWE-798: Use of Hard-coded Credentials vulnerability exists that could result in information disclosure. If an attacker were to obtain the SSH cryptographic key for the device and take active control of the local operational network connected to the product they could potentially observe and manipulate traffic…
ModificadaAlta (8.8)0.36%—Schneider-electric Modicon M340 Bmxp342020 FirmwareSchneider-electric 140cpu65 FirmwareSchneider-electric Tsxp57 FirmwareSchneider-electric Bmxnoc0401 Firmware+64/2/202217/6/2026
A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists on the web server used, that could cause a leak of sensitive data or unauthorized actions on the web server during the time the user is logged in. Affected Products: Modicon M340 CPUs: BMXP34 (All Versions), Modicon Quantum CPUs with integrated Ethernet…
ModificadaAlta (8.8)1.2%—Schneider-electric Ecostruxure Power Monitoring Expert28/1/202217/6/2026
A CWE-20: Improper Input Validation vulnerability exists that could cause arbitrary code execution when the user visits a page containing the injected payload. This CVE is unique from CVE-2021-22826. Affected Product: EcoStruxure� Power Monitoring Expert 9.0 and prior versions
ModificadaAlta (8.8)1.2%—Schneider-electric Ecostruxure Power Monitoring Expert28/1/202217/6/2026
A CWE-20: Improper Input Validation vulnerability exists that could cause arbitrary code execution when the user visits a page containing the injected payload. This CVE is unique from CVE-2021-22827. Affected Product: EcoStruxure� Power Monitoring Expert 9.0 and prior versions
ModificadaAlta (8)0.77%—Schneider-electric Rack Power Distribution Unit With Network Management Card 2 FirmwareSchneider-electric Rack Power Distribution Unit With Network Management Card 3 Firmware28/1/202217/6/2026
A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could allow an attacker to access the system with elevated privileges when a privileged account clicks on a malicious URL that compromises the security token. Affected Products: AP7xxxx and AP8xxx with NMC2 (V6.9.6 or…