Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
53 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.41% | — | Bacnetstack Bacnet Stack | 5/12/2025 | 17/6/2026 | BACnet Protocol Stack library provides a BACnet application layer, network layer and media access (MAC) layer communications services. Prior to 1.5.0.rc2, The npdu_is_expected_reply function in src/bacnet/npdu.c indexes request_pdu[offset+2/3/5] and reply_pdu[offset+1/2/4] without verifying that those APDU bytes… | |
| Aplazada | Alta (8.7) | 0.50% | — | Bacnet Test ServerAI | 26/11/2025 | 17/6/2026 | BACnet Test Server versions up to and including 1.01 contains a remote denial of service vulnerability in its BACnet/IP BVLC packet handling. The server fails to properly validate the BVLC Length field in incoming UDP BVLC frames on the default BACnet port (47808/udp). A remote unauthenticated attacker can send a… | |
| Aplazada | Media (6.3) | 0.27% | — | Johnsoncontrols Apogee PXC Series BacnetAIJohnsoncontrols Apogee PXC Series P2 EthernetAIJohnsoncontrols Talon TC Series BacnetAI | 9/9/2025 | 17/6/2026 | A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All versions), TALON TC Series (BACnet) (All versions). Affected devices connected to the network allow unrestricted access to sensitive files, such as databases. This could allow an attacker to download… | |
| Aplazada | Alta (7.1) | 0.24% | — | Bacnet Atec 550-440AIBacnet Atec 550-441AIBacnet Atec 550-445AIBacnet Atec 550-446AI | 13/5/2025 | 17/6/2026 | A vulnerability has been identified in BACnet ATEC 550-440 (All versions), BACnet ATEC 550-441 (All versions), BACnet ATEC 550-445 (All versions), BACnet ATEC 550-446 (All versions). Affected devices improperly handle specific incoming BACnet MSTP messages. This could allow an attacker residing in the same BACnet… | |
| Aplazada | Alta (8.7) | 0.39% | — | Optigo Networks Visual Bacnet Capture ToolAIOptigo Networks Visual Networks Capture ToolAI | 13/3/2025 | 17/6/2026 | Optigo Networks Visual BACnet Capture Tool and Optigo Visual Networks Capture Tool version 3.1.2rc11 are vulnerable to an attacker impersonating the web application service and mislead victim clients. | |
| Aplazada | Crítica (9.3) | 0.45% | — | Optigo Networks Visual Bacnet Capture ToolAIOptigo Networks Visual Networks Capture ToolAI | 13/3/2025 | 17/6/2026 | Optigo Networks Visual BACnet Capture Tool and Optigo Visual Networks Capture Tool version 3.1.2rc11 contain an exposed web management service that could allow an attacker to bypass authentication measures and gain controls over utilities within the products. | |
| Aplazada | Alta (8.7) | 0.39% | — | Optigo Networks Visual Bacnet Capture ToolAIOptigo Networks Visual Networks Capture ToolAI | 13/3/2025 | 17/6/2026 | Optigo Networks Visual BACnet Capture Tool and Optigo Visual Networks Capture Tool version 3.1.2rc11 contain a hard coded secret key. This could allow an attacker to generate valid JWT (JSON Web Token) sessions. | |
| Aplazada | Media (6) | 0.44% | — | Schneider-electric Apogee PXC Series BacnetAISchneider-electric Apogee PXC Series P2 EthernetAISchneider-electric Talon TC Series BacnetAI | 11/2/2025 | 17/6/2026 | A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All versions), TALON TC Series (BACnet) (All versions). Affected devices contain an out-of-bounds read in the memory dump function. This could allow an attacker with Medium (MED) or higher privileges to… | |
| Aplazada | Alta (7.1) | 0.36% | — | BacnetAI | 18/11/2024 | 17/6/2026 | A low privileged remote attacker may modify the BACNet service properties due to incorrect permission assignment for critical resources which may lead to a DoS limited to BACNet communication. | |
| Analizada | Media (6.9) | 0.61% | — | Ccontrols Basrouter Bacnet Basrt-b Firmware | 10/10/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in Contemporary Control System BASrouter BACnet BASRT-B 2.7.2. This affects an unknown part of the component UDP Packet Handler. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to… | |
| Aplazada | Alta (8.7) | 1.3% | — | Contemporary Control Systems Basrouter BacnetAI | 14/5/2024 | 17/6/2026 | A vulnerability classified as critical was found in Contemporary Control System BASrouter BACnet BASRT-B 2.7.2. This vulnerability affects unknown code of the component Application Protocol Data Unit. The manipulation leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed to… | |
| Aplazada | Media (6.3) | 0.55% | — | Shanghai Sunfull Automation Bacnet Server Hmi1002-armAI | 6/5/2024 | 17/6/2026 | A vulnerability classified as critical has been found in Shanghai Sunfull Automation BACnet Server HMI1002-ARM 2.0.4. This affects an unknown part of the component Message Handler. The manipulation leads to buffer overflow. The exploit has been disclosed to the public and may be used. The associated identifier of this… | |
| Aplazada | Media (6.5) | 0.44% | — | Contemporary Controls Basrouter Bacnet Basrt-bAI | 27/4/2024 | 17/6/2026 | A vulnerability classified as critical has been found in Contemporary Controls BASrouter BACnet BASRT-B 2.7.2. Affected is an unknown function of the component Device-Communication-Control Service. The manipulation with the input 55ff0500370015f30104025506110afb7519035d0841e4bece257b6acfc71f leads to denial of… | |
| Analizada | Crítica (9.1) | 1.1% | — | Bacnetstack Bacnet Stack | 29/2/2024 | 17/6/2026 | BACnet Stack before 1.3.2 has a decode function APDU buffer over-read in bacapp_decode_application_data in bacapp.c. | |
| Modificada | Alta (7.5) | 0.39% | — | Sauter-controls Nova 220 Eyk220f001 FirmwareSauter-controls Nova 230 Eyk230f001 FirmwareSauter-controls Nova 106 Eyk300f001 FirmwareSauter-controls Modunet300 Ey-am300f001 Firmware+2 | 2/3/2023 | 17/6/2026 | SAUTER Controls Nova 200–220 Series with firmware version 3.3-006 and prior and BACnetstac version 4.2.1 and prior have only FTP and Telnet available for device management. Any sensitive information communicated through these protocols, such as credentials, is sent in cleartext. An attacker could obtain sensitive… | |
| Modificada | Media (6.5) | 0.63% | — | Siemens Pxc00-e96.a FirmwareSiemens Pxc100-e96.a FirmwareSiemens Pxx-485.3 FirmwareSiemens Pxc16.2-pe.a Firmware+5 | 13/12/2022 | 17/6/2026 | A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.20), APOGEE PXC Modular (BACnet) (All versions < V3.5.5), APOGEE PXC Modular (P2 Ethernet) (All versions < V2.8.20), TALON TC Compact (BACnet) (All versions < V3.5.5), TALON… | |
| Modificada | Alta (7.5) | 23% | 💥 Exploit | Carel Pcoweb Card FirmwareCarel ApplicaCarel Pcoweb Hvac Bacnet Gateway | 31/8/2022 | 17/6/2026 | Carel pCOWeb HVAC BACnet Gateway 2.1.0, Firmware: A2.1.0 - B2.1.0, Application Software: 2.15.4A Software v16 13020200 suffers from an unauthenticated arbitrary file disclosure vulnerability. Input passed through the 'file' GET parameter through the 'logdownload.cgi' Bash script is not properly verified before being… | |
| Modificada | Crítica (9.8) | 3.4% | — | Siemens Apogee MBC (ppc) (P2 Ethernet) FirmwareSiemens Apogee MEC (ppc) (P2 Ethernet) FirmwareSiemens Apogee PXC Bacnet Automation Controller FirmwareSiemens Apogee PXC Compact (P2 Ethernet) Firmware+4 | 14/9/2021 | 17/6/2026 | A vulnerability has been identified in APOGEE MBC (PPC) (P2 Ethernet) (All versions >= V2.6.3), APOGEE MEC (PPC) (P2 Ethernet) (All versions >= V2.6.3), APOGEE PXC Compact (BACnet) (All versions < V3.5.3), APOGEE PXC Compact (P2 Ethernet) (All versions >= V2.8), APOGEE PXC Modular (BACnet) (All versions < V3.5.3),… | |
| Modificada | Alta (7.5) | 34% | 💥 Exploit | Bacnet Protocol Stack Project Bacnet Protocol Stack | 30/5/2019 | 17/6/2026 | BACnet Protocol Stack through 0.8.6 has a segmentation fault leading to denial of service in BACnet APDU Layer because a malformed DCC in AtomicWriteFile, AtomicReadFile and DeviceCommunicationControl services. An unauthenticated remote attacker could cause a denial of service (bacserv daemon crash) because there is… | |
| Modificada | Alta (7.5) | 3.4% | — | ABB Pm554-tp-eth FirmwarePhoenixcontact ILC 151 ETH FirmwareSchneider-electric Modicon M221 FirmwareSiemens 6es7211-1ae40-0xb0 Firmware+6 | 17/4/2019 | 17/6/2026 | ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple versions. Researchers have found some controllers are susceptible to a denial-of-service attack due to a flood of network packets. | |
| Modificada | Alta (7.5) | 13% | 💥 Exploit | Lutron Quantum Bacnet Integration Firmware | 23/4/2018 | 17/6/2026 | Lutron Quantum BACnet Integration 2.0 (firmware 3.2.243) doesn't check for correct user authentication before showing the /deviceIP information, which leads to internal network information disclosure. | |
| Modificada | Crítica (9.8) | 1.6% | — | Bacnet Protocol Stack Project Bacnet Protocol Stack | 20/4/2018 | 17/6/2026 | bvlc.c in skarg BACnet Protocol Stack bacserv 0.9.1 and 0.8.5 is affected by a Buffer Overflow because of a lack of packet-size validation. The affected component is bacserv BACnet/IP BVLC forwarded NPDU. The function bvlc_bdt_forward_npdu() calls bvlc_encode_forwarded_npdu() which copies the content from the request… | |
| Modificada | Alta (7.5) | 1.4% | — | Lutron Quantum Bacnet Integration Firmware | 21/2/2018 | 17/6/2026 | An issue was discovered on Lutron Quantum BACnet Integration 2.0 (firmware 3.2.243) devices. Remote attackers can obtain potentially sensitive information via a /DbXmlInfo.xml request, as demonstrated by the Latitude/Longitude of the device. | |
| Modificada | Media (4.3) | 2.5% | — | Siemens Climatix Bacnet/ip | 28/6/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the integrated web server on the Siemens Climatix BACnet/IP communication module with firmware before 10.34 allows remote attackers to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Alta (7.5) | 2.6% | — | Scadaengine Bacnet OPC Server | 14/3/2015 | 17/6/2026 | The SOAP web interface in SCADA Engine BACnet OPC Server before 2.1.371.24 allows remote attackers to bypass authentication and read or write to arbitrary database fields via unspecified vectors. |