Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

787 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.7)0.17%—Schneider-electric ClearscadaSchneider-electric Ecostruxure GEO Scada Expert 2019Schneider-electric Ecostruxure GEO Scada Expert 202026/5/202117/6/2026
Use of Password Hash with Insufficient Computational Effort vulnerability exists in ClearSCADA (all versions), EcoStruxure Geo SCADA Expert 2019 (all versions), and EcoStruxure Geo SCADA Expert 2020 (V83.7742.1 and prior), which could cause the revealing of account credentials when server database files are available.…
ModificadaMedia (6.5)0.80%—Schneider-electric Spacelynk FirmwareSchneider-electric Homelynk Firmware26/5/202117/6/2026
Information Exposure vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause information to be exposed when an unauthorized file is uploaded.
ModificadaMedia (5.9)0.82%—Schneider-electric Spacelynk FirmwareSchneider-electric Homelynk Firmware26/5/202117/6/2026
Information Exposure vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause a device to be compromised when it is first configured.
ModificadaCrítica (9.8)0.63%—Schneider-electric Spacelynk FirmwareSchneider-electric Homelynk Firmware26/5/202117/6/2026
Use of a Broken or Risky Cryptographic Algorithm vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior that could cause unauthorized access when credentials are discovered after a brute force attack.
ModificadaCrítica (9.8)0.95%—Schneider-electric Spacelynk FirmwareSchneider-electric Homelynk Firmware26/5/202117/6/2026
Insufficiently Protected Credentials vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior that could cause unauthorized access of when credentials are discovered after a brute force attack.
ModificadaAlta (7.5)1.1%—Schneider-electric Spacelynk FirmwareSchneider-electric Homelynk Firmware26/5/202117/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause a denial of service when an unauthorized file is uploaded.
ModificadaAlta (7.2)1.0%—Schneider-electric Spacelynk FirmwareSchneider-electric Homelynk Firmware26/5/202117/6/2026
Improper Verification of Cryptographic Signature vulnerability exists inhomeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could allow remote code execution when unauthorized code is copied to the device.
ModificadaAlta (7.2)1.0%—Schneider-electric Spacelynk FirmwareSchneider-electric Homelynk Firmware26/5/202117/6/2026
Improper Verification of Cryptographic Signature vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause remote code execution when an attacker loads unauthorized code.
ModificadaAlta (7.8)0.21%—Schneider-electric Spacelynk FirmwareSchneider-electric Homelynk Firmware26/5/202117/6/2026
Improper Privilege Management vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause shell access when unauthorized code is loaded into the system folder.
ModificadaAlta (7.8)0.26%—Schneider-electric Spacelynk FirmwareSchneider-electric Homelynk Firmware26/5/202117/6/2026
Improper Privilege Management vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause a code execution issue when an attacker loads unauthorized code on the web server.
ModificadaCrítica (9.8)1.4%—Schneider-electric Mcsesp083f23g0 FirmwareSchneider-electric Mcsesp083f23g0t FirmwareSchneider-electric Mcsesm043f23f0 FirmwareSchneider-electric Mcsesm053f1cu0 Firmware+1226/5/202117/6/2026
Weak Password Recovery Mechanism for Forgotten Password vulnerability exists on Modicon Managed Switch MCSESM* and MCSESP* V8.21 and prior which could cause an unauthorized password change through HTTP / HTTPS when basic user information is known by a remote attacker.
ModificadaAlta (7.8)0.25%—Schneider-electric Vijeo DesignerSchneider-electric Ecostruxure Machine Expert26/5/202117/6/2026
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause denial of service or unauthorized access to system information when interacting directly with a driver installed by Vijeo Designer or EcoStruxure Machine Expert
ModificadaAlta (7.5)0.98%—Schneider-electric Modicon M241 FirmwareSchneider-electric Modicon M251 Firmware26/5/202117/6/2026
Improper Input Validation vulnerability exists in Modicon M241/M251 logic controllers firmware prior to V5.1.9.1 that could cause denial of service when specific crafted requests are sent to the controller over HTTP.
ModificadaAlta (7.2)31%—Schneider-electric C-bus Toolkit13/4/202117/6/2026
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) that could allow a remote code execution when restoring a project.
ModificadaAlta (8.8)41%—Schneider-electric C-bus Toolkit13/4/202117/6/2026
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) that could allow a remote code execution when a file is uploaded.
ModificadaAlta (7.8)27%—Schneider-electric C-bus Toolkit13/4/202117/6/2026
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) that could allow a remote code execution when restoring project files.
ModificadaAlta (8.8)39%—Schneider-electric C-bus Toolkit13/4/202117/6/2026
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) that could allow a remote code execution when processing config files.
ModificadaAlta (7.8)0.77%—Schneider-electric C-bus Toolkit13/4/202117/6/2026
A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could allow remote code execution when an unprivileged user modifies a file. Affected Product: C-Bus Toolkit (V1.15.9 and prior)
ModificadaCrítica (9.8)2.4%—Schneider-electric Powerlogic Ion7400 FirmwareSchneider-electric Powerlogic Pm8000 FirmwareSchneider-electric Powerlogic Ion9000 Firmware11/3/202117/6/2026
A CWE-119:Improper restriction of operations within the bounds of a memory buffer vulnerability exists in PowerLogic ION7400, PM8000 and ION9000 (All versions prior to V3.0.0), which could cause the meter to reboot or allow for remote code execution.
ModificadaAlta (7.5)1.2%—Schneider-electric Powerlogic Ion8650 FirmwareSchneider-electric Powerlogic Ion8800 FirmwareSchneider-electric Powerlogic Ion7550 FirmwareSchneider-electric Powerlogic Ion7650 Firmware+711/3/202117/6/2026
A CWE-119:Improper restriction of operations within the bounds of a memory buffer vulnerability exists in PowerLogic ION8650, ION8800, ION7650, ION7700/73xx, and ION83xx/84xx/85xx/8600 (see security notifcation for affected versions), which could cause the meter to reboot.
ModificadaAlta (7.8)0.93%—Schneider-electric Interactive Graphical Scada System11/3/202117/6/2026
A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could result in arbitrary read or write conditions when malicious CGF (Configuration Group File) file is imported to…
ModificadaAlta (7.8)0.88%—Schneider-electric Interactive Graphical Scada System11/3/202117/6/2026
A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could result in arbitrary read or write conditions when malicious CGF (Configuration Group File) file is imported to…
ModificadaAlta (7.8)2.2%—Schneider-electric Interactive Graphical Scada System11/3/202117/6/2026
A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could cause remote code execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.
ModificadaAlta (7.8)2.2%—Schneider-electric Interactive Graphical Scada System11/3/202117/6/2026
A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could result in loss of data or remote code execution when malicious CGF (Configuration Group File) file is imported to…
ModificadaAlta (7.5)0.60%—Schneider-electric Powerlogic Ion7400 FirmwareSchneider-electric Powerlogic Ion7650 FirmwareSchneider-electric Powerlogic Ion8600 FirmwareSchneider-electric Powerlogic Ion8650 Firmware+619/2/202117/6/2026
A CWE-319: Cleartext transmission of sensitive information vulnerability exists in PowerLogic ION7400, ION7650, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000 and PM800 (see notification for affected versions), that could cause disclosure of user credentials when a malicious actor intercepts HTTP network traffic…
Orbitaley — Vulnerabilidades