Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
787 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.7) | 0.17% | — | Schneider-electric ClearscadaSchneider-electric Ecostruxure GEO Scada Expert 2019Schneider-electric Ecostruxure GEO Scada Expert 2020 | 26/5/2021 | 17/6/2026 | Use of Password Hash with Insufficient Computational Effort vulnerability exists in ClearSCADA (all versions), EcoStruxure Geo SCADA Expert 2019 (all versions), and EcoStruxure Geo SCADA Expert 2020 (V83.7742.1 and prior), which could cause the revealing of account credentials when server database files are available.… | |
| Modificada | Media (6.5) | 0.80% | — | Schneider-electric Spacelynk FirmwareSchneider-electric Homelynk Firmware | 26/5/2021 | 17/6/2026 | Information Exposure vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause information to be exposed when an unauthorized file is uploaded. | |
| Modificada | Media (5.9) | 0.82% | — | Schneider-electric Spacelynk FirmwareSchneider-electric Homelynk Firmware | 26/5/2021 | 17/6/2026 | Information Exposure vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause a device to be compromised when it is first configured. | |
| Modificada | Crítica (9.8) | 0.63% | — | Schneider-electric Spacelynk FirmwareSchneider-electric Homelynk Firmware | 26/5/2021 | 17/6/2026 | Use of a Broken or Risky Cryptographic Algorithm vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior that could cause unauthorized access when credentials are discovered after a brute force attack. | |
| Modificada | Crítica (9.8) | 0.95% | — | Schneider-electric Spacelynk FirmwareSchneider-electric Homelynk Firmware | 26/5/2021 | 17/6/2026 | Insufficiently Protected Credentials vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior that could cause unauthorized access of when credentials are discovered after a brute force attack. | |
| Modificada | Alta (7.5) | 1.1% | — | Schneider-electric Spacelynk FirmwareSchneider-electric Homelynk Firmware | 26/5/2021 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause a denial of service when an unauthorized file is uploaded. | |
| Modificada | Alta (7.2) | 1.0% | — | Schneider-electric Spacelynk FirmwareSchneider-electric Homelynk Firmware | 26/5/2021 | 17/6/2026 | Improper Verification of Cryptographic Signature vulnerability exists inhomeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could allow remote code execution when unauthorized code is copied to the device. | |
| Modificada | Alta (7.2) | 1.0% | — | Schneider-electric Spacelynk FirmwareSchneider-electric Homelynk Firmware | 26/5/2021 | 17/6/2026 | Improper Verification of Cryptographic Signature vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause remote code execution when an attacker loads unauthorized code. | |
| Modificada | Alta (7.8) | 0.21% | — | Schneider-electric Spacelynk FirmwareSchneider-electric Homelynk Firmware | 26/5/2021 | 17/6/2026 | Improper Privilege Management vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause shell access when unauthorized code is loaded into the system folder. | |
| Modificada | Alta (7.8) | 0.26% | — | Schneider-electric Spacelynk FirmwareSchneider-electric Homelynk Firmware | 26/5/2021 | 17/6/2026 | Improper Privilege Management vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause a code execution issue when an attacker loads unauthorized code on the web server. | |
| Modificada | Crítica (9.8) | 1.4% | — | Schneider-electric Mcsesp083f23g0 FirmwareSchneider-electric Mcsesp083f23g0t FirmwareSchneider-electric Mcsesm043f23f0 FirmwareSchneider-electric Mcsesm053f1cu0 Firmware+12 | 26/5/2021 | 17/6/2026 | Weak Password Recovery Mechanism for Forgotten Password vulnerability exists on Modicon Managed Switch MCSESM* and MCSESP* V8.21 and prior which could cause an unauthorized password change through HTTP / HTTPS when basic user information is known by a remote attacker. | |
| Modificada | Alta (7.8) | 0.25% | — | Schneider-electric Vijeo DesignerSchneider-electric Ecostruxure Machine Expert | 26/5/2021 | 17/6/2026 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause denial of service or unauthorized access to system information when interacting directly with a driver installed by Vijeo Designer or EcoStruxure Machine Expert | |
| Modificada | Alta (7.5) | 0.98% | — | Schneider-electric Modicon M241 FirmwareSchneider-electric Modicon M251 Firmware | 26/5/2021 | 17/6/2026 | Improper Input Validation vulnerability exists in Modicon M241/M251 logic controllers firmware prior to V5.1.9.1 that could cause denial of service when specific crafted requests are sent to the controller over HTTP. | |
| Modificada | Alta (7.2) | 31% | — | Schneider-electric C-bus Toolkit | 13/4/2021 | 17/6/2026 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) that could allow a remote code execution when restoring a project. | |
| Modificada | Alta (8.8) | 41% | — | Schneider-electric C-bus Toolkit | 13/4/2021 | 17/6/2026 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) that could allow a remote code execution when a file is uploaded. | |
| Modificada | Alta (7.8) | 27% | — | Schneider-electric C-bus Toolkit | 13/4/2021 | 17/6/2026 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) that could allow a remote code execution when restoring project files. | |
| Modificada | Alta (8.8) | 39% | — | Schneider-electric C-bus Toolkit | 13/4/2021 | 17/6/2026 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) that could allow a remote code execution when processing config files. | |
| Modificada | Alta (7.8) | 0.77% | — | Schneider-electric C-bus Toolkit | 13/4/2021 | 17/6/2026 | A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could allow remote code execution when an unprivileged user modifies a file. Affected Product: C-Bus Toolkit (V1.15.9 and prior) | |
| Modificada | Crítica (9.8) | 2.4% | — | Schneider-electric Powerlogic Ion7400 FirmwareSchneider-electric Powerlogic Pm8000 FirmwareSchneider-electric Powerlogic Ion9000 Firmware | 11/3/2021 | 17/6/2026 | A CWE-119:Improper restriction of operations within the bounds of a memory buffer vulnerability exists in PowerLogic ION7400, PM8000 and ION9000 (All versions prior to V3.0.0), which could cause the meter to reboot or allow for remote code execution. | |
| Modificada | Alta (7.5) | 1.2% | — | Schneider-electric Powerlogic Ion8650 FirmwareSchneider-electric Powerlogic Ion8800 FirmwareSchneider-electric Powerlogic Ion7550 FirmwareSchneider-electric Powerlogic Ion7650 Firmware+7 | 11/3/2021 | 17/6/2026 | A CWE-119:Improper restriction of operations within the bounds of a memory buffer vulnerability exists in PowerLogic ION8650, ION8800, ION7650, ION7700/73xx, and ION83xx/84xx/85xx/8600 (see security notifcation for affected versions), which could cause the meter to reboot. | |
| Modificada | Alta (7.8) | 0.93% | — | Schneider-electric Interactive Graphical Scada System | 11/3/2021 | 17/6/2026 | A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could result in arbitrary read or write conditions when malicious CGF (Configuration Group File) file is imported to… | |
| Modificada | Alta (7.8) | 0.88% | — | Schneider-electric Interactive Graphical Scada System | 11/3/2021 | 17/6/2026 | A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could result in arbitrary read or write conditions when malicious CGF (Configuration Group File) file is imported to… | |
| Modificada | Alta (7.8) | 2.2% | — | Schneider-electric Interactive Graphical Scada System | 11/3/2021 | 17/6/2026 | A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could cause remote code execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition. | |
| Modificada | Alta (7.8) | 2.2% | — | Schneider-electric Interactive Graphical Scada System | 11/3/2021 | 17/6/2026 | A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could result in loss of data or remote code execution when malicious CGF (Configuration Group File) file is imported to… | |
| Modificada | Alta (7.5) | 0.60% | — | Schneider-electric Powerlogic Ion7400 FirmwareSchneider-electric Powerlogic Ion7650 FirmwareSchneider-electric Powerlogic Ion8600 FirmwareSchneider-electric Powerlogic Ion8650 Firmware+6 | 19/2/2021 | 17/6/2026 | A CWE-319: Cleartext transmission of sensitive information vulnerability exists in PowerLogic ION7400, ION7650, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000 and PM800 (see notification for affected versions), that could cause disclosure of user credentials when a malicious actor intercepts HTTP network traffic… |