Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

154 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.75%—Schneider-electric Modicon M340 BMX P34-2010 FirmwareSchneider-electric Modicon M340 BMX P34-2030 FirmwareSchneider-electric Modicon M580 Bmeh582040 FirmwareSchneider-electric Modicon M580 Bmeh582040c Firmware+4422/11/202217/6/2026
A CWE-191: Integer Underflow (Wrap or Wraparound) vulnerability exists that could cause a denial of service of the controller due to memory access violations when using the Modbus TCP protocol. Affected products: Modicon M340 CPU (part numbers BMXP34*)(V3.40 and prior), Modicon M580 CPU (part numbers BMEP* and…
ModificadaCrítica (9.8)0.77%—Schneider-electric Ecostruxure Control ExpertSchneider-electric Ecostruxure Process ExpertSchneider-electric Modicon M340 Bmxp341000 FirmwareSchneider-electric Modicon M340 Bmxp342000 Firmware+3212/9/202217/6/2026
A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists that could cause unauthorized access in read and write mode to the controller when communicating over Modbus. Affected Products: EcoStruxure Control Expert Including all Unity Pro versions (former name of EcoStruxure Control…
ModificadaAlta (7.5)0.93%—Schneider-electric Modicon M340 Bmxp341000 FirmwareSchneider-electric Modicon M340 Bmxp342000 FirmwareSchneider-electric Modicon M340 Bmxp342010 FirmwareSchneider-electric Modicon M340 Bmxp3420102 Firmware+24/2/202217/6/2026
A CWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause a denial of service on ports 80 (HTTP) and 502 (Modbus), when sending a large number of TCP RST or FIN packets to any open TCP port of the PLC. Affected Product: Modicon M340 CPUs: BMXP34 (All Versions)
ModificadaAlta (7.2)57%—Geutebrueck G-cam Ebc-2110 FirmwareGeutebrueck G-cam Ebc-2111 FirmwareGeutebrueck G-cam Efd-2241 FirmwareGeutebrueck G-cam Efd-2250 Firmware+1213/9/202117/6/2026
Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.
ModificadaAlta (7.2)49%—Geutebrueck G-cam Ebc-2110 FirmwareGeutebrueck G-cam Ebc-2111 FirmwareGeutebrueck G-cam Efd-2241 FirmwareGeutebrueck G-cam Efd-2250 Firmware+1213/9/202117/6/2026
Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.
ModificadaAlta (7.2)49%—Geutebrueck G-cam Ebc-2110 FirmwareGeutebrueck G-cam Ebc-2111 FirmwareGeutebrueck G-cam Efd-2241 FirmwareGeutebrueck G-cam Efd-2250 Firmware+1213/9/202117/6/2026
Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.
ModificadaAlta (7.2)49%—Geutebrueck G-cam Ebc-2110 FirmwareGeutebrueck G-cam Ebc-2111 FirmwareGeutebrueck G-cam Efd-2241 FirmwareGeutebrueck G-cam Efd-2250 Firmware+1213/9/202117/6/2026
Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.
ModificadaAlta (7.2)57%—Geutebrueck G-cam Ebc-2110 FirmwareGeutebrueck G-cam Ebc-2111 FirmwareGeutebrueck G-cam Efd-2241 FirmwareGeutebrueck G-cam Efd-2250 Firmware+1213/9/202117/6/2026
Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.
ModificadaAlta (7.2)66%—Geutebrueck G-cam Ebc-2110 FirmwareGeutebrueck G-cam Ebc-2111 FirmwareGeutebrueck G-cam Efd-2241 FirmwareGeutebrueck G-cam Efd-2250 Firmware+1213/9/202117/6/2026
Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to a stack-based buffer overflow condition in the action parameter, which may allow an attacker to remotely execute arbitrary code.
ModificadaAlta (7.2)57%—Geutebrueck G-cam Ebc-2110 FirmwareGeutebrueck G-cam Ebc-2111 FirmwareGeutebrueck G-cam Efd-2241 FirmwareGeutebrueck G-cam Efd-2250 Firmware+1213/9/202117/6/2026
Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.
ModificadaAlta (7.2)2.8%—Geutebrueck G-cam Ebc-2110 FirmwareGeutebrueck G-cam Ebc-2111 FirmwareGeutebrueck G-cam Efd-2241 FirmwareGeutebrueck G-cam Efd-2250 Firmware+1213/9/202117/6/2026
Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to a stack-based buffer overflow condition in the profile parameter which may allow an attacker to remotely execute arbitrary code.
ModificadaAlta (7.2)2.8%—Geutebrueck G-cam Ebc-2110 FirmwareGeutebrueck G-cam Ebc-2111 FirmwareGeutebrueck G-cam Efd-2241 FirmwareGeutebrueck G-cam Efd-2250 Firmware+1213/9/202117/6/2026
Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to a stack-based buffer overflow condition in the name parameter, which may allow an attacker to remotely execute arbitrary code.
ModificadaAlta (7.2)2.8%—Geutebrueck G-cam Ebc-2110 FirmwareGeutebrueck G-cam Ebc-2111 FirmwareGeutebrueck G-cam Efd-2241 FirmwareGeutebrueck G-cam Efd-2250 Firmware+1213/9/202117/6/2026
Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to a stack-based buffer overflow condition in the counter parameter which may allow an attacker to remotely execute arbitrary code.
ModificadaAlta (7.2)95%—Geutebrueck G-cam Ebc-2110 FirmwareGeutebrueck G-cam Ebc-2111 FirmwareGeutebrueck G-cam Efd-2241 FirmwareGeutebrueck G-cam Efd-2250 Firmware+1213/9/202117/6/2026
Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.
ModificadaCrítica (9.8)81%—Geutebrueck G-cam Ebc-2110 FirmwareGeutebrueck G-cam Ebc-2111 FirmwareGeutebrueck G-cam Efd-2241 FirmwareGeutebrueck G-cam Efd-2250 Firmware+1213/9/202117/6/2026
Multiple camera devices by UDP Technology, Geutebrück and other vendors allow unauthenticated remote access to sensitive files due to default user authentication settings. This can lead to manipulation of the device and denial of service.
ModificadaAlta (7.5)0.94%—Schneider-electric Modicon M340 Bmxp341000Schneider-electric Modicon M340 Bmxp342010Schneider-electric Modicon M340 Bmxp342020Schneider-electric Modicon M340 Bmxp342030+452/9/202117/6/2026
A CWE-476: NULL Pointer Dereference vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP* and BMEH*, all versions), Modicon M340 CPU (part numbers…
ModificadaMedia (6.5)0.84%—Schneider-electric Modicon M340 Bmxp341000Schneider-electric Modicon M340 Bmxp342010Schneider-electric Modicon M340 Bmxp342020Schneider-electric Modicon M340 Bmxp342030+452/9/202117/6/2026
A CWE-787: Out-of-bounds Write vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP* and BMEH*, all versions), Modicon M340 CPU (part numbers BMXP34*, all…
ModificadaMedia (6.5)0.84%—Schneider-electric Modicon M340 Bmxp341000Schneider-electric Modicon M340 Bmxp342010Schneider-electric Modicon M340 Bmxp342020Schneider-electric Modicon M340 Bmxp342030+452/9/202117/6/2026
A CWE-125: Out-of-bounds Read vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP* and BMEH*, all versions), Modicon M340 CPU (part numbers BMXP34*, all…
ModificadaMedia (6.5)0.84%—Schneider-electric Modicon M340 Bmxp341000Schneider-electric Modicon M340 Bmxp342010Schneider-electric Modicon M340 Bmxp342020Schneider-electric Modicon M340 Bmxp342030+452/9/202117/6/2026
A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP* and BMEH*, all…
ModificadaCrítica (9.1)1.0%—Schneider-electric Ecostruxure Control ExpertSchneider-electric Ecostruxure Process ExpertSchneider-electric RemoteconnectSchneider-electric Modicon M580 Bmep581020 Firmware+2814/7/202117/6/2026
Authentication Bypass by Spoofing vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Control Expert V15.0 SP1, EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), SCADAPack RemoteConnect for x70…
ModificadaMedia (5.4)0.55%—Netgear D6200 FirmwareNetgear D7000 FirmwareNetgear Jnr1010v2 FirmwareNetgear Jr6150 Firmware+1030/12/202017/6/2026
Certain NETGEAR devices are affected by stored XSS. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, JNR1010v2 before 1.1.0.62, JR6150 before 1.0.1.24, JWNR2010v5 before 1.1.0.62, R6020 before 1.0.0.42, R6050 before 1.0.1.24, R6080 before 1.0.0.42, R6120 before 1.0.0.66, R6220 before 1.1.0.100, R6260 before…
ModificadaAlta (7.6)0.63%—Netgear D6200 FirmwareNetgear D7000 FirmwareNetgear Jnr1010v2 FirmwareNetgear Jr6150 Firmware+1430/12/202017/6/2026
Certain NETGEAR devices are affected by stored XSS. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, JNR1010v2 before 1.1.0.62, JR6150 before 1.0.1.24, JWNR2010v5 before 1.1.0.62, R6020 before 1.0.0.42, R6050 before 1.0.1.24, R6080 before 1.0.0.42, R6120 before 1.0.0.66, R6220 before 1.1.0.100, R6260 before…
ModificadaMedia (5.4)0.55%—Netgear D6200 FirmwareNetgear D7000 FirmwareNetgear Jnr1010v2 FirmwareNetgear Jr6150 Firmware+1030/12/202017/6/2026
Certain NETGEAR devices are affected by stored XSS. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, JNR1010v2 before 1.1.0.62, JR6150 before 1.0.1.24, JWNR2010v5 before 1.1.0.62, R6020 before 1.0.0.42, R6050 before 1.0.1.24, R6080 before 1.0.0.42, R6120 before 1.0.0.66, R6220 before 1.1.0.100, R6260 before…
ModificadaMedia (5.3)1.1%—Schneider-electric Modicon M340 Bmxp341000 FirmwareSchneider-electric Modicon M340 Bmxp342000 FirmwareSchneider-electric Modicon M340 Bmxp3420102 FirmwareSchneider-electric Modicon M340 Bmxp3420102cl Firmware+1511/12/202017/6/2026
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security notification for affected versions), that could cause denial of HTTP and FTP services when a…
ModificadaAlta (7.5)1.3%—Schneider-electric Modicon M580 Bmep584040 FirmwareSchneider-electric Modicon M580 Bmep582040 FirmwareSchneider-electric Modicon M580 Bmep586040 FirmwareSchneider-electric Modicon M580 Bmep585040 Firmware+1211/12/202017/6/2026
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Legacy Controllers Modicon Quantum & Modicon Premium (see security notifications for affected versions), that could cause denial of service when a specially crafted Read Physical Memory request over…