Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
787 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.88% | — | Schneider-electric Ecostruxure Machine ExpertSchneider-electric SomachineSchneider-electric Somachine MotionSchneider-electric Modicon M218 Firmware+3 | 22/4/2020 | 17/6/2026 | A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists which could leak sensitive information transmitted between the software and the Modicon M218, M241, M251, and M258 controllers. | |
| Modificada | Crítica (9.8) | 0.69% | — | Schneider-electric Ecostruxure Machine ExpertSchneider-electric SomachineSchneider-electric Somachine MotionSchneider-electric Modicon M218 Firmware+3 | 22/4/2020 | 17/6/2026 | A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists which could allow the attacker to execute malicious code on the Modicon M218, M241, M251, and M258 controllers. | |
| Modificada | Alta (7.5) | 1.2% | — | Schneider-electric BMX P34x FirmwareSchneider-electric BMX NOE 0100 FirmwareSchneider-electric BMX NOE 0110 FirmwareSchneider-electric BMX NOC 0401 Firmware+6 | 22/4/2020 | 17/6/2026 | A CWE-798: Use of Hardcoded Credentials vulnerability exists in Modicon Controllers (All versions of the following CPUs and Communication Module product references listed in the Security Notifications), which could cause the disclosure of FTP hardcoded credentials when using the Web server of the controller on an… | |
| Modificada | Alta (7.5) | 1.6% | — | Schneider-electric Tricon TCM 4351 FirmwareSchneider-electric Tricon TCM 4352 FirmwareSchneider-electric Tricon TCM 4351a FirmwareSchneider-electric Tricon TCM 4351b Firmware+2 | 16/4/2020 | 17/6/2026 | **VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability could cause TCM modules to reset when under high network load in TCM v10.4.x and in system v10.3.x. This vulnerability was discovered and remediated in version v10.5.x on August 13, 2009. TCMs from v10.5.x and on will no longer exhibit this behavior. | |
| Modificada | Crítica (9.8) | 1.9% | — | Schneider-electric Tristation 1131 | 16/4/2020 | 17/6/2026 | **VERSION NOT SUPPORTED WHEN ASSIGNED** A legacy support account in the TriStation software version v4.9.0 and earlier could cause improper access to the TriStation host machine. This was addressed in TriStation version v4.9.1 and v4.10.1 released on May 30, 2013.1 | |
| Modificada | Alta (7.5) | 1.3% | — | Schneider-electric Tristation 1131 | 16/4/2020 | 17/6/2026 | **VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability with the former 'password' feature could allow a denial of service attack if the user is not following documented guidelines pertaining to dedicated TriStation connection and key-switch protection. This vulnerability was discovered and remediated in versions… | |
| Modificada | Alta (7.5) | 0.91% | — | Schneider-electric Tristation 1131 | 16/4/2020 | 17/6/2026 | **VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability could cause certain data to be visible on the network when the 'password' feature is enabled. This vulnerability was discovered in and remediated in versions v4.9.1 and v4.10.1 on May 30, 2013. The 'password' feature is an additional optional check performed by… | |
| Modificada | Media (6.1) | 0.80% | — | Schneider-electric Andover Continuum 9680 FirmwareSchneider-electric Andover Continuum 5740 FirmwareSchneider-electric Andover Continuum 5720 FirmwareSchneider-electric Andover Continuum Bcx4040 Firmware+7 | 23/3/2020 | 17/6/2026 | A CWE-79:Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists Andover Continuum (All versions), which could cause a Reflective Cross-site Scripting (XSS attack) when using the products' web server. | |
| Modificada | Media (6.1) | 0.79% | — | Schneider-electric Andover Continuum 9680 FirmwareSchneider-electric Andover Continuum 5740 FirmwareSchneider-electric Andover Continuum 5720 FirmwareSchneider-electric Andover Continuum Bcx4040 Firmware+7 | 23/3/2020 | 17/6/2026 | A CWE-79:Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists Andover Continuum (All versions), which could enable a successful Cross-site Scripting (XSS attack) when using the products' web server. | |
| Modificada | Crítica (9.8) | 1.5% | — | Schneider-electric Andover Continuum 9680 FirmwareSchneider-electric Andover Continuum 5740 FirmwareSchneider-electric Andover Continuum 5720 FirmwareSchneider-electric Andover Continuum Bcx4040 Firmware+7 | 23/3/2020 | 17/6/2026 | A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists in Andover Continuum (All versions), which could cause files on the application server filesystem to be viewable when an attacker interferes with an application's processing of XML data. | |
| Modificada | Alta (7.8) | 0.51% | — | Schneider-electric Interactive Graphical Scada System | 23/3/2020 | 17/6/2026 | A CWE-306: Missing Authentication for Critical Function vulnerability exists in IGSS (Versions 14 and prior using the service: IGSSupdate), which could allow a local user to execute processes that otherwise require escalation privileges when sending local network commands to the IGSS Update Service. | |
| Modificada | Alta (7.5) | 4.1% | — | Schneider-electric Interactive Graphical Scada System | 23/3/2020 | 17/6/2026 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory exists in IGSS (Versions 14 and prior using the service: IGSSupdate), which could allow a remote unauthenticated attacker to read arbitrary files from the IGSS server PC on an unrestricted or shared network when the IGSS Update Service is enabled. | |
| Modificada | Alta (7.5) | 1.3% | — | Schneider-electric 140noe77101 FirmwareSchneider-electric 140noe77111 FirmwareSchneider-electric Tsxh5744m FirmwareSchneider-electric Tsxh5724m Firmware+24 | 23/3/2020 | 17/6/2026 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Quantum Ethernet Network module 140NOE771x1 (Versions 7.0 and prior), Quantum processors with integrated Ethernet – 140CPU65xxxxx (all Versions), and Premium processors with integrated Ethernet (all Versions), which could cause a… | |
| Modificada | Alta (7.8) | 0.42% | — | Schneider-electric Ulti Zigbee Installation Toolkit | 23/3/2020 | 17/6/2026 | A CWE-426: Untrusted Search Path vulnerability exists in ZigBee Installation Kit (Versions prior to 1.0.1), which could cause execution of malicious code when a malicious file is put in the search path. | |
| Modificada | Crítica (9.8) | 1.6% | — | Schneider-electric Ecostruxure Control ExpertSchneider-electric Unity PROSchneider-electric Modicon M340 FirmwareSchneider-electric Modicon M580 Firmware | 23/3/2020 | 17/6/2026 | A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), reflective DLL, vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20), Modicon M580 (all versions prior… | |
| Modificada | Alta (7.8) | 0.43% | — | Schneider-electric Pmepxm0100 Prosoft Configurator | 23/3/2020 | 17/6/2026 | A CWE-427: Uncontrolled Search Path Element vulnerability exists in ProSoft Configurator (v1.002 and prior), for the PMEPXM0100 (H) module, which could cause the execution of untrusted code when using double click to open a project file which may trigger execution of a malicious DLL. | |
| Modificada | Alta (7.8) | 0.36% | — | Schneider-electric MSX Configurator | 22/1/2020 | 17/6/2026 | A CWE-427:Uncontrolled Search Path Element vulnerability exists in MSX Configurator (Software Version prior to V1.0.8.1), which could cause privilege escalation when injecting a malicious DLL. | |
| Modificada | Alta (7.5) | 1.6% | — | Schneider-electric Modicon M580 FirmwareSchneider-electric Modicon M340 FirmwareSchneider-electric Tsxh5744m FirmwareSchneider-electric Tsxh5724m Firmware+25 | 6/1/2020 | 17/6/2026 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon Quantum, Modicon Premium (see security notification for specific versions) which could cause a Denial of Service of the controller when reading specific memory blocks using Modbus TCP. | |
| Modificada | Alta (7.5) | 1.6% | — | Schneider-electric Modicon M580 FirmwareSchneider-electric Modicon M340 FirmwareSchneider-electric Tsxh5744m FirmwareSchneider-electric Tsxh5724m Firmware+25 | 6/1/2020 | 17/6/2026 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon Quantum, Modicon Premium (see security notification for specific versions) which could cause a Denial of Service when writing specific physical memory blocks using Modbus TCP. | |
| Modificada | Alta (7.3) | 0.95% | — | Schneider-electric Ecostruxure Control ExpertSchneider-electric Unity PROSchneider-electric Modicon M580 Bmep584040 FirmwareSchneider-electric Modicon M580 Bmeh584040 Firmware+19 | 6/1/2020 | 17/6/2026 | Incorrect Authorization vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20) , and Modicon M580 (all versions prior to V3.10), which could cause a bypass of the authentication process between EcoStruxure Control… | |
| Modificada | Alta (7.8) | 0.17% | — | Schneider-electric Clearscada | 6/1/2020 | 17/6/2026 | A CWE-287: Improper Authentication vulnerability exists in a folder within EcoStruxure Geo SCADA Expert (ClearSCADA) -with initial releases before 1 January 2019- which could cause a low privilege user to delete or modify database, setting or certificate files. Those users must have access to the file system of that… | |
| Modificada | Alta (7.5) | 1.4% | — | Schneider-electric Modicon M580 FirmwareSchneider-electric Modicon M340 FirmwareSchneider-electric Tsxh5744m FirmwareSchneider-electric Tsxh5724m Firmware+25 | 6/1/2020 | 17/6/2026 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon Quantum, Modicon Premium (see security notification for specific versions) which could cause a Denial of Service when reading data with invalid index using Modbus TCP. | |
| Modificada | Media (6.1) | 0.64% | — | Schneider-electric Andover Continuum 9680 FirmwareSchneider-electric Andover Continuum 5740 FirmwareSchneider-electric Andover Continuum 5720 FirmwareSchneider-electric Andover Continuum Bcx4040 Firmware+7 | 20/11/2019 | 17/6/2026 | A CWE-79: Failure to Preserve Web Page Structure vulnerability exists in Andover Continuum (models 9680, 5740 and 5720, bCX4040, bCX9640, 9900, 9940, 9924 and 9702) , which could enable a successful Cross-site Scripting (XSS attack) when using the products web server. | |
| Modificada | Alta (7.5) | 1.4% | — | Schneider-electric BMX P34x FirmwareSchneider-electric BMX NOE 0100 FirmwareSchneider-electric BMX NOE 0110 FirmwareSchneider-electric BMX NOC 0401 Firmware+6 | 20/11/2019 | 17/6/2026 | A CWE-200: Information Exposure vulnerability exists in Modicon Controllers (M340 CPUs, M340 communication modules, Premium CPUs, Premium communication modules, Quantum CPUs, Quantum communication modules - see security notification for specific versions), which could cause the disclosure of FTP hardcoded credentials… | |
| Modificada | Alta (7.5) | 30% | — | Schneider-electric Modicon M580 FirmwareSchneider-electric Modicon M340 FirmwareSchneider-electric Tsxmcpc002m FirmwareSchneider-electric Tsxmcpc512k Firmware+19 | 29/10/2019 | 17/6/2026 | A CWE-538: File and Directory Information Exposure vulnerability exists in Modicon M580, Modicon M340, Modicon Premium , Modicon Quantum (all firmware versions), which could cause the disclosure of information from the controller when using TFTP protocol. |