Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1306▼ 184 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

787 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)2.7%—Schneider-electric Powerlogic Egx100 FirmwareSchneider-electric Powerlogic Egx300 Firmware11/6/202117/6/2026
A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that could cause denial of service or remote code execution via a specially crafted HTTP packet.This CVE ID is unique from CVE-2021-2276
ModificadaAlta (7.5)1.3%—Schneider-electric Powerlogic Egx100 FirmwareSchneider-electric Powerlogic Egx300 Firmware11/6/202117/6/2026
A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that could cause denial of service via a specially crafted HTTP packet
ModificadaCrítica (9.8)2.7%—Schneider-electric Powerlogic Egx100 FirmwareSchneider-electric Powerlogic Egx300 Firmware11/6/202117/6/2026
A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that could cause denial of service or remote code execution via a specially crafted HTTP packet
ModificadaMedia (5.3)1.9%—Schneider-electric Powerlogic Pm5560 FirmwareSchneider-electric Powerlogic Pm5561 FirmwareSchneider-electric Powerlogic Pm5562 FirmwareSchneider-electric Powerlogic Pm5563 Firmware11/6/202117/6/2026
A CWE-287: Improper Authentication vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and PowerLogic EGX300 (see security notification for version infromation) that could cause loss of connectivity to the device via Modbus TCP protocol when an attacker sends a specially crafted HTTP…
ModificadaCrítica (9.8)1.9%—Schneider-electric Powerlogic Pm5560 FirmwareSchneider-electric Powerlogic Pm5561 FirmwareSchneider-electric Powerlogic Pm5562 FirmwareSchneider-electric Powerlogic Pm5563 Firmware+111/6/202117/6/2026
A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and PowerLogic EGX300 (see security notification for version infromation) that could allow an attacker administrator level access to a device.
ModificadaAlta (7.8)1.4%—Schneider-electric Interactive Graphical Scada System11/6/202117/6/2026
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in remote code execution, when a malicious CGF or WSP file is being parsed by IGSS Definition.
ModificadaAlta (7.8)0.66%—Schneider-electric Interactive Graphical Scada System11/6/202117/6/2026
A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in disclosure of information or remote code e+F15xecution due to missing length check on user supplied data, when a malicious CGF file is…
ModificadaAlta (7.8)1.2%—Schneider-electric Interactive Graphical Scada System11/6/202117/6/2026
A CWE-763: Release of invalid pointer or reference vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to missing checks of user-supplied input data, when a malicious CGF file is imported to IGSS Definition.
ModificadaAlta (7.8)1.2%—Schneider-electric Interactive Graphical Scada System11/6/202117/6/2026
A CWE-416: Use after free vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to use of unchecked input data, when a malicious CGF file is imported to IGSS Definition.
ModificadaAlta (7.8)1.2%—Schneider-electric Interactive Graphical Scada System11/6/202117/6/2026
A CWE-824: Access of uninitialized pointer vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to lack validation of user-supplied input data, when a malicious CGF file is imported to IGSS Definition.
ModificadaAlta (7.8)1.3%—Schneider-electric Interactive Graphical Scada System11/6/202117/6/2026
A CWE-125: Out-of-bounds read vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in disclosure of information or remote code execution due to lack of sanity checks on user-supplied input data, when a malicious CGF file is imported to IGSS Definition.
ModificadaAlta (7.8)1.3%—Schneider-electric Interactive Graphical Scada System11/6/202117/6/2026
A CWE-125: Out-of-bounds read vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in disclosure of information or remote code execution due to lack of user-supplied data validation, when a malicious CGF file is imported to IGSS Definition.
ModificadaAlta (7.8)1.3%—Schneider-electric Interactive Graphical Scada System11/6/202117/6/2026
A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in disclosure of information or remote code execution due to lack of sanity checks on user-supplied data, when a malicious CGF file is imported to IGSS Definition.
ModificadaAlta (7.8)1.2%—Schneider-electric Interactive Graphical Scada System11/6/202117/6/2026
A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to lack of proper validation of user-supplied data, when a malicious CGF file is imported to IGSS Definition.
ModificadaAlta (7.8)1.2%—Schneider-electric Interactive Graphical Scada System11/6/202117/6/2026
A CWE-125: Out-of-bounds read vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to missing length checks, when a malicious WSP file is being parsed by IGSS Definition.
ModificadaAlta (7.8)1.2%—Schneider-electric Interactive Graphical Scada System11/6/202117/6/2026
A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to missing size checks, when a malicious WSP (Workspace) file is being parsed by IGSS Definition.
ModificadaAlta (7.8)0.85%—Schneider-electric Interactive Graphical Scada System11/6/202117/6/2026
A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in disclosure of information or execution of arbitrary code due to lack of input validation, when a malicious CGF (Configuration Group File) file is imported to IGSS Definition.
ModificadaAlta (7.8)1.2%—Schneider-electric Interactive Graphical Scada System11/6/202117/6/2026
A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21041 and prior that could result in loss of data or remote code execution due to missing length checks, when a malicious CGF file is imported to IGSS Definition.
ModificadaMedia (5.3)0.92%—Schneider-electric Modicon X80 Bmxnor0200h RTU Firmware11/6/202117/6/2026
A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Modicon X80 BMXNOR0200H RTU SV1.70 IR22 and prior that could cause information leak concerning the current RTU configuration including communication parameters dedicated to telemetry, when a specially crafted HTTP request is…
ModificadaBaja (3.9)0.25%—Schneider-electric Triconex Model 3009 MP FirmwareSchneider-electric TCM 4351b Firmware26/5/202117/6/2026
Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex Model 3009 MP installed on Tricon V11.3.x systems that could cause module reset when TCM receives malformed TriStation packets while the write-protect keyswitch is in the program position. This CVE ID is unique from CVE-2021-22742,…
ModificadaBaja (3.9)0.25%—Schneider-electric Triconex Model 3009 MP FirmwareSchneider-electric TCM 4351b Firmware26/5/202117/6/2026
Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex Model 3009 MP installed on Tricon V11.3.x systems that could cause module reset when TCM receives malformed TriStation packets while the write-protect keyswitch is in the program position. This CVE ID is unique from CVE-2021-22742,…
ModificadaBaja (3.9)0.25%—Schneider-electric Triconex Model 3009 MP FirmwareSchneider-electric TCM 4351b Firmware26/5/202117/6/2026
Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex Model 3009 MP installed on Tricon V11.3.x systems that could cause module reset when TCM receives malformed TriStation packets while the write-protect keyswitch is in the program position. This CVE ID is unique from CVE-2021-22742,…
ModificadaBaja (3.9)0.25%—Schneider-electric Triconex Model 3009 MP FirmwareSchneider-electric TCM 4351b Firmware26/5/202117/6/2026
Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex Model 3009 MP installed on Tricon V11.3.x systems that could cause module reset when TCM receives malformed TriStation packets while the write-protect keyswitch is in the program position. This CVE ID is unique from CVE-2021-22742,…
ModificadaBaja (3.9)0.22%—Schneider-electric Triconex Model 3009 MP FirmwareSchneider-electric TCM 4351b Firmware26/5/202117/6/2026
Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex TCM 4351B installed on Tricon V11.3.x systems that could cause module reset when TCM receives malformed TriStation packets while the write-protect keyswitch is in the program position.
ModificadaBaja (3.9)0.25%—Schneider-electric Triconex Model 3009 MP FirmwareSchneider-electric TCM 4351b Firmware26/5/202117/6/2026
Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex Model 3009 MP installed on Tricon V11.3.x systems that could cause module reset when TCM receives malformed TriStation packets while the write-protect keyswitch is in the program position.
Orbitaley — Vulnerabilidades