Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

2356 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.6)0.90%—Siemens Ruggedcom Rm1224 Lte(4g) EU FirmwareSiemens Ruggedcom Rm1224 Lte(4g) NAM FirmwareSiemens Scalance M804pb FirmwareSiemens Scalance M812-1 (annex A) Firmware+2212/11/202417/6/2026
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.2), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V8.2), SCALANCE M812-1 ADSL-Router (6GK5812-1AA00-2AA2) (All versions < V8.2),…
AnalizadaAlta (8.7)0.48%—Siemens Simatic CP 1543-1 Firmware12/11/202417/6/2026
A vulnerability has been identified in SIMATIC CP 1543-1 V4.0 (6GK7543-1AX10-0XE0) (All versions >= V4.0.44 < V4.0.50). Affected devices do not properly handle authorization. This could allow an unauthenticated remote attacker to gain access to the filesystem.
AnalizadaAlta (7)0.19%—Siemens Solid Edge Se202412/11/202417/6/2026
A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 9). The affected applications suffer from a DLL hijacking vulnerability. This could allow an attacker to execute arbitrary code via placing a crafted DLL file on the system.
AnalizadaAlta (7.3)0.17%—Siemens Solid Edge Se202412/11/202417/6/2026
A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 9). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.
AnalizadaAlta (7.3)0.17%—Siemens Solid Edge Se202412/11/202417/6/2026
A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 9). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PSM files. This could allow an attacker to execute code in the context of the current process.
AnalizadaAlta (8.3)0.14%—Siemens Sinec NMS12/11/202417/6/2026
A vulnerability has been identified in SINEC NMS (All versions < V3.0 SP1). The affected application contains a database function, that does not properly restrict the permissions of users to write to the filesystem of the host system. This could allow an authenticated medium-privileged attacker to write arbitrary…
AnalizadaAlta (8.5)0.14%—Siemens Siport12/11/202417/6/2026
A vulnerability has been identified in SIPORT (All versions < V3.4.0). The affected application improperly assigns file permissions to installation folders. This could allow a local attacker with an unprivileged account to override or modify the service executables and subsequently gain elevated privileges.
AnalizadaMedia (5.3)0.27%—Siemens Sinec INS12/11/202417/6/2026
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly validate authorization of a user to query the "/api/sftp/users" endpoint. This could allow an authenticated remote attacker to gain knowledge about the list of configured users of the SFTP…
AnalizadaMedia (6.9)0.30%—Siemens Sinec INS12/11/202417/6/2026
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly invalidate sessions when the associated user is deleted or disabled or their permissions are modified. This could allow an authenticated attacker to continue performing malicious actions even…
AnalizadaMedia (6.9)0.52%—Siemens Sinec INS12/11/202417/6/2026
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly restrict the size of generated log files. This could allow an unauthenticated remote attacker to trigger a large amount of logged events to exhaust the system's resources and create a denial…
AnalizadaCrítica (9.4)0.74%—Siemens Sinec INS12/11/202417/6/2026
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly validate input sent to specific endpoints of its web API. This could allow an authenticated remote attacker with high privileges on the application to execute arbitrary code on the underlying…
AnalizadaMedia (6.9)0.29%—Siemens Sinec INS12/11/202417/6/2026
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application uses hard-coded cryptographic key material to obfuscate configuration files. This could allow an attacker to learn that cryptographic key material through reverse engineering of the application binary and…
AnalizadaCrítica (9.4)0.92%—Siemens Sinec INS12/11/202417/6/2026
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly sanitize user provided paths for SFTP-based file up- and downloads. This could allow an authenticated remote attacker to manipulate arbitrary files on the filesystem and achieve arbitrary…
AnalizadaCrítica (10)1.00%—Siemens Telecontrol Server Basic12/11/202417/6/2026
A vulnerability has been identified in PP TeleControl Server Basic 1000 to 5000 V3.1 (6NH9910-0AA31-0AE1) (All versions < V3.1.2.1 with redundancy configured), PP TeleControl Server Basic 256 to 1000 V3.1 (6NH9910-0AA31-0AD1) (All versions < V3.1.2.1 with redundancy configured), PP TeleControl Server Basic 32 to 64…
AnalizadaAlta (8.2)0.30%—Siemens Ozw672 FirmwareSiemens Ozw772 Firmware12/11/202417/6/2026
A vulnerability has been identified in OZW672 (All versions < V5.2), OZW772 (All versions < V5.2). The user accounts tab of affected devices is vulnerable to stored cross-site scripting (XSS) attacks. This could allow an authenticated remote attacker to inject arbitrary JavaScript code that is later executed by…
AnalizadaAlta (8.5)0.14%—Siemens Spectrum Power 712/11/202417/6/2026
A vulnerability has been identified in Spectrum Power 7 (All versions < V24Q3). The affected product contains several root-owned SUID binaries that could allow an authenticated local attacker to escalate privileges.
AplazadaAlta (7)0.22%—Siemens Simatic S7-plcsimAISiemens Simatic Step 7 SafetyAISiemens Simatic Step 7AISiemens Simatic Wincc UnifiedAI+712/11/202417/6/2026
A vulnerability has been identified in SIMATIC S7-PLCSIM V16 (All versions), SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 Safety V16 (All versions), SIMATIC STEP 7 Safety V17 (All versions < V17 Update 8), SIMATIC STEP 7 Safety V18 (All versions < V18 Update 5), SIMATIC STEP 7 V16 (All versions), SIMATIC STEP…
AnalizadaAlta (8.5)0.20%—Siemens Intermesh 7177 Hybrid 2.0 SubscriberSiemens Intermesh 7707 Fire Subscriber Firmware23/10/202417/6/2026
A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All versions < V7.2.12 only if the IP interface is enabled (which is not the default configuration)). The affected devices contain a SUID binary that could allow an authenticated local…
AnalizadaMedia (6.9)0.37%—Siemens Intermesh 7177 Hybrid 2.0 SubscriberSiemens Intermesh 7707 Fire Subscriber Firmware23/10/202417/6/2026
A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All versions < V7.2.12 only if the IP interface is enabled (which is not the default configuration)). The web server of affected devices allows to write arbitrary files to the web…
AnalizadaMedia (6.9)0.51%—Siemens Intermesh 7177 Hybrid 2.0 SubscriberSiemens Intermesh 7707 Fire Subscriber Firmware23/10/202417/6/2026
A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All versions < V7.2.12 only if the IP interface is enabled (which is not the default configuration)). The web server of affected devices does not authenticate GET requests that execute…
AnalizadaCrítica (10)1.2%—Siemens Intermesh 7177 Hybrid 2.0 SubscriberSiemens Intermesh 7707 Fire Subscriber Firmware23/10/202417/6/2026
A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All versions < V7.2.12 only if the IP interface is enabled (which is not the default configuration)). The web server of affected devices does not sanitize the input parameters in…
ModificadaAlta (7.8)0.33%—Siemens Simatic S7-1500 TM MFP FirmwareDebian LinuxLinux KernelSiemens Sinec OS21/10/20244/8/2026
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix index out of bounds in degamma hardware format translation Fixes index out of bounds issue in `cm_helper_translate_curve_to_degamma_hw_format` function. The issue could occur when the index 'i' exceeds the number of transfer…
ModificadaMedia (5.3)0.38%—Siemens Sinec Security Monitor8/10/202417/6/2026
A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate that user input complies with a list of allowed values. This could allow an authenticated remote attacker to compromise the integrity of the configuration of the affected…
ModificadaMedia (6.9)0.55%—Siemens Sinec Security Monitor8/10/202417/6/2026
A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate a file path that is supplied to an endpoint intended to create CSR files. This could allow an unauthenticated remote attacker to create files in writable directories outside the…
ModificadaCrítica (9.3)0.27%—Siemens Sinec Security Monitor8/10/202417/6/2026
A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly neutralize special elements in user input to the ```ssmctl-client``` command. This could allow an authenticated, lowly privileged local attacker to execute privileged commands in the…