Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
787 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.41% | — | Schneider-electric 5032 16pt Digital Configurable ModuleAI | 14/8/2025 | 17/6/2026 | A security issue exists within the 5032 16pt Digital Configurable module’s web server. Intercepted session credentials can be used within a 3-minute timeout window, allowing unauthorized users to perform privileged actions. | |
| Aplazada | Media (6) | 0.44% | — | Schneider-electric Apogee PXC Series BacnetAISchneider-electric Apogee PXC Series P2 EthernetAISchneider-electric Talon TC Series BacnetAI | 11/2/2025 | 17/6/2026 | A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All versions), TALON TC Series (BACnet) (All versions). Affected devices contain an out-of-bounds read in the memory dump function. This could allow an attacker with Medium (MED) or higher privileges to… | |
| Aplazada | Alta (8.7) | 0.20% | — | Schneider-electric Apogee PXC SeriesAISchneider-electric Talon TC SeriesAI | 11/2/2025 | 17/6/2026 | A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All versions), TALON TC Series (BACnet) (All versions). Affected devices contain a weak encryption mechanism based on a hard-coded key. This could allow an attacker to guess or decrypt the password from… | |
| Analizada | Alta (8.7) | 0.82% | — | Schneider-electric Powerlogic Pm5341 FirmwareSchneider-electric Powerlogic Pm5340 FirmwareSchneider-electric Powerlogic Pm5320 Firmware | 13/11/2024 | 17/6/2026 | CWE-400: An Uncontrolled Resource Consumption vulnerability exists that could cause the device to become unresponsive resulting in communication loss when a large amount of IGMP packets is present in the network. | |
| Analizada | Crítica (10) | 0.65% | — | Schneider-electric Ecostruxure IT Gateway | 13/11/2024 | 17/6/2026 | CWE-862: Missing Authorization vulnerability exists that could cause unauthorized access when enabled on the network and potentially impacting connected devices. | |
| Aplazada | Alta (7.2) | 0.46% | — | Schneider-electric Data Center ExpertAI | 11/10/2024 | 17/6/2026 | CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that could compromise the Data Center Expert software when an upgrade bundle is manipulated to include arbitrary bash scripts that are executed as root. | |
| Aplazada | Baja (3.3) | 0.16% | — | Schneider-electric Zelio Soft 2AI | 8/10/2024 | 17/6/2026 | CWE-20: Improper Input Validation vulnerability exists that could cause a crash of the Zelio Soft 2 application when a specially crafted project file is loaded by an application user. | |
| Analizada | Alta (7.8) | 0.21% | — | Schneider-electric Zelio Soft 2 | 8/10/2024 | 17/6/2026 | CWE-416: Use After Free vulnerability exists that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when application user opens a malicious Zelio Soft 2 project file. | |
| Analizada | Alta (7.8) | 0.21% | — | Schneider-electric Vijeo DesignerSchneider-electric Vijeo Designer Embedded IN Ecostruxure Machine Expert | 11/9/2024 | 17/6/2026 | CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentiality, integrity and availability of the workstation when non-admin authenticated user tries to perform privilege escalation by tampering with the binaries. | |
| Aplazada | Alta (7.5) | 0.48% | — | Schneider-electric Accutech ManagerAI | 20/8/2024 | 17/6/2026 | CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists that could cause a crash of the Accutech Manager when receiving a specially crafted request over port 2536/TCP. | |
| Modificada | Alta (7.5) | 0.43% | — | Schneider-electric Whc-5918a Firmware | 11/7/2024 | 17/6/2026 | CWE-200: Information Exposure vulnerability exists that could cause disclosure of credentials when a specially crafted message is sent to the device. | |
| Modificada | Media (6.1) | 0.26% | — | Schneider-electric Modicon M241 FirmwareSchneider-electric Modicon M251 FirmwareSchneider-electric Modicon M258 FirmwareSchneider-electric Modicon M262 Firmware+1 | 11/7/2024 | 17/6/2026 | CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause a vulnerability leading to a cross-site scripting condition where attackers can have a victim’s browser run arbitrary JavaScript when they visit a page containing the injected payload. | |
| Modificada | Alta (7.8) | 0.24% | — | Schneider-electric Ecostruxure Foxboro DCS Control Core Services | 11/7/2024 | 17/6/2026 | CWE-20: Improper Input Validation vulnerability exists that could cause local denial-of-service, privilege escalation, and potentially kernel execution when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver. | |
| Modificada | Media (5.5) | 0.15% | — | Schneider-electric Ecostruxure Foxboro DCS Control Core Services | 11/7/2024 | 17/6/2026 | CWE-129: Improper Validation of Array Index vulnerability exists that could cause local denial-of-service when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver. | |
| Modificada | Alta (7.1) | 0.15% | — | Schneider-electric Ecostruxure Foxboro DCS Control Core Services | 11/7/2024 | 17/6/2026 | CWE-787: Out-of-Bounds Write vulnerability exists that could cause local denial-of-service, or kernel memory leak when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver. | |
| Modificada | Alta (7.8) | 0.28% | — | Schneider-electric Foxrtu Station | 11/7/2024 | 17/6/2026 | CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could result in remote code execution when an authenticated user executes a saved project file that has been tampered by a malicious actor. | |
| Modificada | Media (6.8) | 0.18% | — | Schneider-electric Powerlogic P5 Firmware | 12/6/2024 | 17/6/2026 | CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists that could cause denial of service, device reboot, or an attacker gaining full control of the relay when a specially crafted reset token is entered into the front panel of the device. | |
| Modificada | Alta (7.8) | 0.17% | — | Schneider-electric Easergy Studio | 12/6/2024 | 17/6/2026 | CWE-428: Unquoted search path or element vulnerability exists in Easergy Studio, which could cause privilege escalation when a valid user replaces a trusted file name on the system and reboots the machine. | |
| Modificada | Alta (7.8) | 0.24% | — | Schneider-electric Ecostruxure IT Gateway | 12/6/2024 | 17/6/2026 | CWE-798: Use of hard-coded credentials vulnerability exists that could cause local privilege escalation when logged in as a non-administrative user. | |
| Modificada | Alta (7.5) | 0.89% | — | Schneider-electric Sage RTU Firmware | 12/6/2024 | 17/6/2026 | CWE-125: Out-of-bounds Read vulnerability exists that could cause denial of service of the device’s web interface when an attacker sends a specially crafted HTTP request. | |
| Modificada | Media (6.4) | 0.11% | — | Schneider-electric Spacelogic As-b FirmwareSchneider-electric Spacelogic As-p Firmware | 12/6/2024 | 17/6/2026 | CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability exists that could cause escalation of privileges when an attacker abuses a limited admin account. | |
| Modificada | Media (4.5) | 0.23% | — | Schneider-electric Spacelogic As-b FirmwareSchneider-electric Spacelogic As-p Firmware | 12/6/2024 | 17/6/2026 | CWE-532: Insertion of Sensitive Information into Log File vulnerability exists that could cause exposure of SNMP credentials when an attacker has access to the controller logs. | |
| Modificada | Alta (8.1) | 0.39% | — | Schneider-electric Sage RTU Firmware | 12/6/2024 | 17/6/2026 | CWE-120: Buffer Copy without Checking Size of Input (‘Classic Buffer Overflow’) vulnerability exists that could allow a user with access to the device’s web interface to cause a fault on the device when sending a malformed HTTP request. | |
| Modificada | Alta (7.5) | 0.79% | — | Schneider-electric Sage RTU Firmware | 12/6/2024 | 17/6/2026 | CWE-252: Unchecked Return Value vulnerability exists that could cause denial of service of the device when an attacker sends a specially crafted HTTP request. | |
| Modificada | Alta (8.8) | 0.37% | — | Schneider-electric Sage RTU Firmware | 12/6/2024 | 17/6/2026 | CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated user with access to the device’s web interface to perform unauthorized file and firmware uploads when crafting custom web requests. |