Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

34 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)2.1%—Mitsubishielectric Smartrtu FirmwareInea Me-rtu Firmware28/10/201917/6/2026
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Hard-coded SSH keys allow an attacker to gain unauthorised access or disclose encrypted data on the RTU due to the keys not being regenerated on initial installation or with firmware updates. In…
ModificadaMedia (6.5)1.3%—Mitsubishielectric Smartrtu FirmwareInea Me-rtu Firmware28/10/201917/6/2026
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. A world-readable /usr/smartrtu/init/settings.xml configuration file on the file system allows an attacker to read sensitive configuration settings such as usernames, passwords, and other…
ModificadaMedia (5.3)1.1%—Yokogawa FCJ FirmwareYokogawa Fcn-100 FirmwareYokogawa Fcn-rtu FirmwareYokogawa Fcn-500 Firmware12/10/201817/6/2026
Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The application utilizes multiple methods of session management which could result in a denial of service to the remote management functions.
ModificadaCrítica (9.8)1.9%—Yokogawa FCJ FirmwareYokogawa Fcn-100 FirmwareYokogawa Fcn-rtu FirmwareYokogawa Fcn-500 Firmware12/10/201817/6/2026
Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The web application improperly protects credentials which could allow an attacker to obtain credentials for remote access to controllers.
ModificadaAlta (7.5)1.3%—Yokogawa FCJ FirmwareYokogawa Fcn-100 FirmwareYokogawa Fcn-rtu FirmwareYokogawa Fcn-500 Firmware12/10/201817/6/2026
Yokogawa STARDOM Controllers FCJ,FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The controller application fails to prevent memory exhaustion by unauthorized requests. This could allow an attacker to cause the controller to become unstable.
ModificadaAlta (8.1)1.2%—Yokogawa FCJ FirmwareYokogawa Fcn-100 FirmwareYokogawa Fcn-rtu FirmwareYokogawa Fcn-500 Firmware12/10/201817/6/2026
Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The affected controllers utilize hard-coded credentials which may allow an attacker gain unauthorized access to the maintenance functions and obtain or modify information. This attack can be executed only during maintenance work.
ModificadaCrítica (9.8)6.9%—Yokogawa FCJ FirmwareYokogawa Fcn-100 FirmwareYokogawa Fcn-rtu FirmwareYokogawa Fcn-500 Firmware31/7/201817/6/2026
Yokogawa STARDOM FCJ controllers R4.02 and prior, FCN-100 controllers R4.02 and prior, FCN-RTU controllers R4.02 and prior, and FCN-500 controllers R4.02 and prior utilize hard-coded credentials that could allow an attacker to gain unauthorized administrative access to the device, which could result in remote code…
ModificadaMedia (5.3)1.2%—Schneider-electric Telvent RTU Firmware12/3/201617/6/2026
Schneider Electric Telvent Sage 2300 RTUs with firmware before C3413-500-S01, and LANDAC II-2, Sage 1410, Sage 1430, Sage 1450, Sage 2400, and Sage 3030M RTUs with firmware before C3414-500-S02J2, allow remote attackers to obtain sensitive information from device memory by reading a padding field of an Ethernet packet.
ModificadaAlta (10)3.9%—Sixnet UDRSixnet RTU Firmware21/8/201316/6/2026
The universal protocol implementation in Sixnet UDR before 2.0 and RTU firmware before 4.8 allows remote attackers to execute arbitrary code; read, modify, or create files; or obtain file metadata via function opcodes.
Orbitaley — Vulnerabilidades