Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
787 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 2.1% | — | Schneider-electric Ecostruxure Energy ExpertSchneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Power ManagerSchneider-electric Powerscada Expert With Advanced Reporting AND Dashboards+1 | 1/12/2020 | 17/6/2026 | A CWE-284:Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow for arbitrary code execution on the server when an authorized user access an affected webpage. | |
| Modificada | Crítica (9.8) | 2.3% | — | Schneider-electric Modicon M340 Bmxp3420302 FirmwareSchneider-electric Modicon M340 Bmxp342000 FirmwareSchneider-electric Modicon M340 Bmxp341000 FirmwareSchneider-electric Modicon M340 Bmxp3420102 Firmware+12 | 1/12/2020 | 17/6/2026 | CWE-287: Improper Authentication vulnerability exists which could cause the execution of commands on the webserver without authentication when sending specially crafted HTTP requests. | |
| Modificada | Media (6.5) | 1.4% | — | Schneider-electric Webreports | 19/11/2020 | 17/6/2026 | A CWE-284 Improper Access Control vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause a remote attacker being able to access a restricted web resources due to improper access control. | |
| Modificada | Alta (8.8) | 1.8% | — | Schneider-electric Webreports | 19/11/2020 | 17/6/2026 | A CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause an authenticated remote user being able to inject arbitrary XML code and obtain disclosure of confidential data, denial of service, server side request forgery… | |
| Modificada | Media (5.4) | 0.84% | — | Schneider-electric Webreports | 19/11/2020 | 17/6/2026 | A CWE-79 Multiple Improper Neutralization of Input During Web Page Generation (Cross-site Scripting Reflected) vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause a remote attacker to inject arbitrary web script or HTML due to incorrect sanitization of user supplied data and… | |
| Modificada | Media (5.4) | 0.84% | — | Schneider-electric Webreports | 19/11/2020 | 17/6/2026 | A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting Stored) vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause an authenticated remote user being able to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied… | |
| Modificada | Alta (8.8) | 2.4% | — | Schneider-electric Webreports | 19/11/2020 | 17/6/2026 | A CWE-434 Unrestricted Upload of File with Dangerous Type vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause an authenticated remote user being able to upload arbitrary files due to incorrect verification of user supplied files and achieve remote code execution. | |
| Modificada | Media (4.3) | 0.53% | — | Schneider-electric Modicon M221 Firmware | 19/11/2020 | 17/6/2026 | A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Modicon M221 (all references, all versions) that could allow non sensitive information disclosure when the attacker has captured the traffic between EcoStruxure Machine - Basic software and Modicon M221 controller. | |
| Modificada | Media (5.7) | 0.21% | — | Schneider-electric Modicon M221 Firmware | 19/11/2020 | 17/6/2026 | A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Modicon M221 (all references, all versions) that could allow the attacker to find the password hash when the attacker has captured the traffic between EcoStruxure Machine - Basic software and Modicon M221 controller and broke the encryption keys. | |
| Modificada | Alta (7.3) | 0.30% | — | Schneider-electric Modicon M221 Firmware | 19/11/2020 | 17/6/2026 | A CWE-334: Small Space of Random Values vulnerability exists in Modicon M221 (all references, all versions) that could allow the attacker to break the encryption keys when the attacker has captured the traffic between EcoStruxure Machine - Basic software and Modicon M221 controller. | |
| Modificada | Alta (7.3) | 0.30% | — | Schneider-electric Modicon M221 Firmware | 19/11/2020 | 17/6/2026 | A CWE-326: Inadequate Encryption Strength vulnerability exists in Modicon M221 (all references, all versions) that could allow the attacker to break the encryption key when the attacker has captured the traffic between EcoStruxure Machine - Basic software and Modicon M221 controller. | |
| Modificada | Crítica (9.8) | 3.2% | — | Schneider-electric Easergy T300 Firmware | 19/11/2020 | 17/6/2026 | A CWE-306: Missing Authentication for Critical Function vulnerability exists in Easergy T300 (with firmware 2.7 and older) that could cause a wide range of problems, including information exposure, denial of service, and command execution when access to a resource from an attacker is not restricted or incorrectly… | |
| Modificada | Alta (7.5) | 1.9% | — | Schneider-electric Ecostruxure Control Expert | 19/11/2020 | 17/6/2026 | A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause a crash of the PLC simulator present in EcoStruxureª Control Expert software when receiving a specially crafted request… | |
| Modificada | Alta (7.8) | 2.5% | — | Schneider-electric Interactive Graphical Scada System | 19/11/2020 | 17/6/2026 | A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition. | |
| Modificada | Alta (7.8) | 2.5% | — | Schneider-electric Interactive Graphical Scada System | 19/11/2020 | 17/6/2026 | A CWE-125 Out-of-bounds Read vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition. | |
| Modificada | Alta (7.8) | 2.5% | — | Schneider-electric Interactive Graphical Scada System | 19/11/2020 | 17/6/2026 | A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition. | |
| Modificada | Alta (7.8) | 2.5% | — | Schneider-electric Interactive Graphical Scada System | 19/11/2020 | 17/6/2026 | A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition. | |
| Modificada | Alta (7.8) | 2.5% | — | Schneider-electric Interactive Graphical Scada System | 19/11/2020 | 17/6/2026 | A CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition. | |
| Modificada | Alta (7.8) | 2.4% | — | Schneider-electric Interactive Graphical Scada System | 19/11/2020 | 17/6/2026 | A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition. | |
| Modificada | Alta (7.8) | 1.7% | — | Schneider-electric Interactive Graphical Scada System | 19/11/2020 | 17/6/2026 | A CWE-787: Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247, that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition. | |
| Modificada | Alta (7.8) | 1.7% | — | Schneider-electric Interactive Graphical Scada System | 19/11/2020 | 17/6/2026 | A CWE-787: Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247, that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition. | |
| Modificada | Alta (7.8) | 2.5% | — | Schneider-electric Interactive Graphical Scada System | 19/11/2020 | 17/6/2026 | A CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 and prior that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition. | |
| Modificada | Alta (7.8) | 0.31% | — | Schneider-electric Operator Terminal Expert Runtime | 19/11/2020 | 17/6/2026 | A CWE-269 Improper Privilege Management vulnerability exists in EcoStruxureª Operator Terminal Expert runtime (Vijeo XD) that could cause privilege escalation on the workstation when interacting directly with a driver installed by the runtime software of EcoStruxureª Operator Terminal Expert. | |
| Modificada | Alta (7.5) | 1.3% | — | Schneider-electric Ecostruxure Control Expert | 19/11/2020 | 17/6/2026 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause a crash of the PLC simulator present in EcoStruxureª Control Expert software when receiving a specially crafted request over Modbus. | |
| Modificada | Alta (8.8) | 1.2% | — | Schneider-electric Ecostruxure Control Expert | 19/11/2020 | 17/6/2026 | A CWE-494: Download of Code Without Integrity Check vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause unauthorized command execution when sending specially crafted requests over Modbus. |