Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
46 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 35% | — | Rockwellautomation Micrologix 1400 B Firmware | 5/4/2018 | 17/6/2026 | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive information, modification of settings,… | |
| Modificada | Media (5.3) | 6.0% | — | Rockwellautomation Micrologix 1400 B Firmware | 5/4/2018 | 17/6/2026 | An exploitable insufficient resource pool vulnerability exists in the session communication functionality of Allen Bradley Micrologix 1400 Series B Firmware 21.2 and before. A specially crafted stream of packets can cause a flood of the session resource pool resulting in legitimate connections to the PLC being… | |
| Modificada | Alta (7.5) | 4.7% | — | Rockwellautomation Micrologix 1400 B Firmware | 5/4/2018 | 17/6/2026 | An exploitable denial of service vulnerability exists in the processing of snmp-set commands of the Allen Bradley Micrologix 1400 Series B FRN 21.2 and below. A specially crafted snmp-set request, when sent without associated firmware flashing snmp-set commands, can cause a device power cycle resulting in downtime for… | |
| Modificada | Alta (7.5) | 4.8% | — | Rockwellautomation Micrologix 1400 B Firmware | 5/4/2018 | 17/6/2026 | An exploitable denial of service vulnerability exists in the program download functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a device fault resulting in halted operations. An attacker can send an unauthenticated packet to trigger this vulnerability. | |
| Modificada | Alta (7.5) | 4.6% | — | Rockwellautomation Micrologix 1400 B Firmware | 5/4/2018 | 17/6/2026 | An exploitable denial of service vulnerability exists in the Ethernet functionality of the Allen Bradley Micrologix 1400 Series B FRN 21.2 and below. A specially crafted packet can cause a device power cycle resulting in a fault state and deletion of ladder logic. An attacker can send one unauthenticated packet to… | |
| Modificada | Alta (7.5) | 4.5% | — | Rockwellautomation Micrologix 1100 FirmwareRockwellautomation Micrologix 1400 Firmware | 28/10/2015 | 17/6/2026 | Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices before B FRN 15.003 allow remote attackers to cause a denial of service (memory corruption and device crash) via a crafted HTTP request. | |
| Modificada | Media (4) | 1.6% | — | Rockwellautomation Micrologix 1100 FirmwareRockwellautomation Micrologix 1400 Firmware | 28/10/2015 | 17/6/2026 | Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices before B FRN 15.003 allow remote authenticated users to insert the content of an arbitrary file into a FRAME element via unspecified vectors. | |
| Modificada | Crítica (9.8) | 7.0% | — | Rockwellautomation Micrologix 1100 FirmwareRockwellautomation Micrologix 1400 Firmware | 28/10/2015 | 17/6/2026 | Stack-based buffer overflow on Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices through B FRN 15.003 allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Media (4.3) | 2.8% | — | Rockwellautomation Micrologix 1100 FirmwareRockwellautomation Micrologix 1400 Firmware | 28/10/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the web server on Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices before B FRN 15.003 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.5) | 4.3% | — | Rockwellautomation Micrologix 1100 FirmwareRockwellautomation Micrologix 1400 Firmware | 28/10/2015 | 17/6/2026 | SQL injection vulnerability on Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices before B FRN 15.003 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.1) | 4.2% | — | Rockwellautomation AB Micrologix Controller | 3/10/2014 | 17/6/2026 | The DNP3 feature on Rockwell Automation Allen-Bradley MicroLogix 1400 1766-Lxxxxx A FRN controllers 7 and earlier and 1400 1766-Lxxxxx B FRN controllers before 15.001 allows remote attackers to cause a denial of service (process disruption) via malformed packets over (1) an Ethernet network or (2) a serial line. | |
| Modificada | Alta (7.5) | 36% | — | Rockwellautomation Ethernet/ip FirmwareRockwellautomation Compactlogix FirmwareRockwellautomation Flexlogix FirmwareRockwellautomation Flex I/O Ethernet/ip Firmware+8 | 24/1/2013 | 16/6/2026 | When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP that instructs the product to reset, a DoS can occur. This situation could cause loss of availability and a disruption of communication with other connected… | |
| Modificada | Media (5) | 57% | — | Rockwellautomation Controllogix ControllersRockwellautomation Guardlogix ControllersRockwellautomation MicrologixRockwellautomation Softlogix Controllers+13 | 24/1/2013 | 16/6/2026 | An information exposure of confidential information results when the device receives a specially crafted CIP packet to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP. Successful exploitation of this vulnerability could cause loss of confidentiality. Rockwell Automation EtherNet/IP products; 1756-ENBT,… | |
| Modificada | Media (4.8) | 9.3% | — | Rockwellautomation Controllogix ControllersRockwellautomation Guardlogix ControllersRockwellautomation MicrologixRockwellautomation Softlogix Controllers+13 | 24/1/2013 | 16/6/2026 | The Web server password authentication mechanism used by the products is vulnerable to a MitM and Replay attack. Successful exploitation of this vulnerability will allow unauthorized access of the product’s Web server to view and alter product configuration and diagnostics information. Rockwell Automation EtherNet/IP… | |
| Modificada | Alta (8.5) | 23% | — | Rockwellautomation Controllogix ControllersRockwellautomation Guardlogix ControllersRockwellautomation MicrologixRockwellautomation Softlogix Controllers+13 | 24/1/2013 | 16/6/2026 | When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP that changes the product’s configuration and network parameters, a DoS condition can occur. This situation could cause loss of availability and a disruption… | |
| Modificada | Alta (7.5) | 27% | — | Rockwellautomation Controllogix ControllersRockwellautomation Guardlogix ControllersRockwellautomation MicrologixRockwellautomation Softlogix Controllers+13 | 24/1/2013 | 16/6/2026 | The device does not properly validate the data being sent to the buffer. An attacker can send a malformed CIP packet to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP, which creates a buffer overflow and causes the NIC to crash. Successful exploitation of this vulnerability could cause loss of… | |
| Modificada | Crítica (9.8) | 7.8% | — | Rockwellautomation Controllogix ControllersRockwellautomation Guardlogix ControllersRockwellautomation MicrologixRockwellautomation Softlogix Controllers+13 | 24/1/2013 | 16/6/2026 | The device does not properly authenticate users and the potential exists for a remote user to upload a new firmware image to the Ethernet card, whether it is a corrupt or legitimate firmware image. Successful exploitation of this vulnerability could cause loss of availability, integrity, and confidentiality and a… | |
| Modificada | Alta (7.5) | 27% | — | Rockwellautomation Controllogix ControllersRockwellautomation Guardlogix ControllersRockwellautomation MicrologixRockwellautomation Softlogix Controllers+13 | 24/1/2013 | 16/6/2026 | The device does not properly validate the data being sent to the buffer. An attacker can send a malformed CIP packet to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP, which creates a buffer overflow and causes the CPU to crash. Successful exploitation of this vulnerability could cause loss of… | |
| Modificada | Alta (7.5) | 33% | — | Rockwellautomation Controllogix ControllersRockwellautomation Guardlogix ControllersRockwellautomation MicrologixRockwellautomation Softlogix Controllers+13 | 24/1/2013 | 16/6/2026 | When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP that instructs the CPU to stop logic execution and enter a fault state, a DoS can occur. This situation could cause loss of availability and a disruption of… | |
| Modificada | Alta (7.1) | 4.0% | — | Rockwellautomation AB Micrologix ControllerRockwellautomation Plc-5 ControllerRockwellautomation SLC 500 Controller | 8/12/2012 | 16/6/2026 | Rockwell Automation Allen-Bradley MicroLogix controller 1100, 1200, 1400, and 1500; SLC 500 controller platform; and PLC-5 controller platform, when Static status is not enabled, allow remote attackers to cause a denial of service via messages that trigger modification of status bits. | |
| Modificada | Alta (10) | 5.9% | — | Rockwellautomation AB Micrologix Controller 1100Rockwellautomation AB Micrologix Controller 1400 | 19/1/2010 | 16/6/2026 | Multiple unspecified vulnerabilities on the Rockwell Automation AB Micrologix 1100 and 1400 controllers allow remote attackers to obtain privileged access or cause a denial of service (halt) via unknown vectors. |