Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

787 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)2.8%—Schneider-electric Ecostruxure Control Expert19/11/202017/6/2026
A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause unauthorized command execution when a brute force attack is done over Modbus.
ModificadaAlta (7.8)0.33%—Schneider-electric Ecostruxure Control Expert19/11/202017/6/2026
A CWE-863: Incorrect Authorization vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause bypass of authentication when overwriting memory using a debugger.
ModificadaAlta (7)0.28%—Schneider-electric Enterprise Server Installer19/11/202017/6/2026
A CWE-428 Windows Unquoted Search Path vulnerability exists in EcoStruxure Building Operation Enterprise Server installer V1.9 - V3.1 and Enterprise Central installer V2.0 - V3.1 that could cause any local Windows user who has write permission on at least one of the subfolders of the Connect Agent service binary path,…
ModificadaMedia (6.1)0.81%—Schneider-electric Ecostruxure Building Operation19/11/202017/6/2026
A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability exists in EcoStruxure Building Operation WebStation V2.0 - V3.1 that could cause an attacker to inject HTML and JavaScript code into the user's browser.
ModificadaAlta (8.8)1.1%—Schneider-electric Modicon Tsxety4103 FirmwareSchneider-electric Modicon Tsxety5103 FirmwareSchneider-electric Modicon Tsxp574634 FirmwareSchneider-electric Modicon Tsxp575634 Firmware+1618/11/202017/6/2026
A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause write access and the execution of commands when…
ModificadaAlta (8.8)1.1%—Schneider-electric Modicon Tsxety4103 FirmwareSchneider-electric Modicon Tsxety5103 FirmwareSchneider-electric Modicon Tsxp574634 FirmwareSchneider-electric Modicon Tsxp575634 Firmware+1618/11/202017/6/2026
A CWE-787: Out-of-bounds Write vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause corruption of data, a crash, or code execution when uploading a specially crafted file on the…
ModificadaAlta (8.1)0.90%—Schneider-electric Modicon Tsxety4103 FirmwareSchneider-electric Modicon Tsxety5103 FirmwareSchneider-electric Modicon Tsxp574634 FirmwareSchneider-electric Modicon Tsxp575634 Firmware+1618/11/202017/6/2026
A CWE-125: Out-of-Bounds Read vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause a segmentation fault or a buffer overflow when uploading a specially crafted file on the controller…
ModificadaAlta (7.8)1.4%—Schneider-electric Scadapack X70 Security Administrator16/9/202017/6/2026
A CWE-502 Deserialization of Untrusted Data vulnerability exists in SCADAPack x70 Security Administrator (V1.2.0 and prior) which could allow arbitrary code execution when an attacker builds a custom .SDB file containing a malicious serialized buffer.
ModificadaAlta (7.8)0.82%—Schneider-electric Scadapack 7X Remote Connect16/9/202017/6/2026
A CWE-284 Improper Access Control vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows an attacker to place executables in a specific folder and run code whenever RemoteConnect is executed by the user.
ModificadaAlta (8.8)1.2%—Schneider-electric Scadapack 7X Remote Connect16/9/202017/6/2026
A CWE-285 Improper Authorization vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows improper access to executable code folders.
ModificadaMedia (5.5)0.88%—Schneider-electric Scadapack 7X Remote Connect16/9/202017/6/2026
A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Transversal') vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows an attacker to place content in any unprotected folder on the target system using a crafted .RCZ file.
ModificadaAlta (7.8)1.4%—Schneider-electric Scadapack 7X Remote Connect16/9/202017/6/2026
A CWE-502 Deserialization of Untrusted Data vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which could allow arbitrary code execution when an attacker builds a custom .PRJ file containing a malicious serialized buffer.
ModificadaAlta (7.8)0.33%—Schneider-electric Somove31/8/202017/6/2026
Incorrect Default Permission vulnerability exists in SoMove (V2.8.1) and prior which could cause elevation of privilege and provide full access control to local system users to SoMove component and services when a SoMove installer script is launched.
ModificadaAlta (7.5)1.5%—Schneider-electric Spacelynk FirmwareSchneider-electric Wiser FOR KNX Firmware31/8/202017/6/2026
Improper Restriction of Excessive Authentication Attempts vulnerability exists in all hardware versions of spaceLYnk and Wiser for KNX (formerly homeLYnk) which could allow an attacker to guess a password when brute force is used.
ModificadaAlta (7.5)1.4%—Schneider-electric Modicon M218 Firmware31/8/202017/6/2026
Out-of-bounds Write vulnerability exists in Modicon M218 Logic Controller (V5.0.0.7 and prior) which could cause Denial of Service when sending specific crafted IPV4 packet to the controller: Sending a specific IPv4 protocol package to Schneider Electric Modicon M218 Logic Controller can cause IPv4 devices to go down.…
ModificadaAlta (7.8)0.19%—Schneider-electric Modbus Driver SuiteSchneider-electric Modbus Serial Driver31/8/202017/6/2026
Improper Privilege Management vulnerability exists in Schneider Electric Modbus Serial Driver (see security notification for versions) which could cause local privilege escalation when the Modbus Serial Driver service is invoked. The driver does not properly assign, modify, track, or check privileges for an actor,…
ModificadaCrítica (9.8)1.7%—Schneider-electric APC Easy UPS Online Software31/8/202017/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in SFAPV9601 - APC Easy UPS On-Line Software (V2.0 and earlier) when accessing a vulnerable method of `SoundUploadServlet` which may lead to uploading executable files to non-specified directories.
ModificadaCrítica (9.8)1.7%—Schneider-electric APC Easy UPS Online Software31/8/202017/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in SFAPV9601 - APC Easy UPS On-Line Software (V2.0 and earlier) when accessing a vulnerable method of `FileUploadServlet` which may lead to uploading executable files to non-specified directories.
ModificadaMedia (4.7)0.93%—Schneider-electric Software Update Utility23/7/202017/6/2026
A CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability exists in Schneider Electric Software Update (SESU), V2.4.0 and prior, which could cause execution of malicious code on the victim's machine. In order to exploit this vulnerability, an attacker requires privileged access on the engineering…
ModificadaAlta (7.5)1.3%—Schneider-electric Easergy Builder23/7/202017/6/2026
A CWE-521: Weak Password Requirements vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker to compromise a user account.
ModificadaAlta (7.5)1.1%—Schneider-electric Easergy Builder23/7/202017/6/2026
A CWE-20: Improper input validation vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker to modify project configuration files.
ModificadaMedia (5.5)0.22%—Schneider-electric Easergy Builder23/7/202017/6/2026
A CWE-312: Cleartext Storage of Sensitive Information vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker to read user credentials.
ModificadaAlta (7.8)0.20%—Schneider-electric Easergy Builder23/7/202017/6/2026
A CWE-316: Cleartext Storage of Sensitive Information in Memory vulnerability exists in Easergy Builder V1.4.7.2 and prior which could allow an attacker access to login credentials.
ModificadaAlta (7.8)0.26%—Schneider-electric Easergy Builder23/7/202017/6/2026
A CWE-321: Use of hard-coded cryptographic key stored in cleartext vulnerability exists in Easergy Builder V1.4.7.2 and prior which could allow an attacker to decrypt a password.
ModificadaAlta (7.8)0.22%—Schneider-electric Easergy Builder23/7/202017/6/2026
A CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker access to the authorization credentials for a device and gain full access.