Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3007▼ 68 respecto a la semana anterior
Críticas / altas1421▲ 55 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

152 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.60%—Schneider-electric Struxureware Data Center Expert12/7/202317/6/2026
A CWE-89: Improper Neutralization of Special Elements vulnerability used in an SQL Command ('SQL Injection') vulnerability exists that could allow a user already authenticated on DCE to access unauthorized content, change, or delete content, or perform unauthorized actions when tampering with the alert settings of…
ModificadaAlta (7.8)0.16%—Schneider-electric Ecostruxure Foxboro DCS Control Core Services14/6/202317/6/2026
A CWE-129: Improper Validation of Array Index vulnerability exists that could cause local denial-of-service, and potentially kernel execution when a malicious actor with local user access crafts a script/program using an unpredictable index to an IOCTL call in the Foxboro.sys driver.
ModificadaAlta (7.8)0.19%—Schneider-electric Ecostruxure Foxboro DCS Control Core Services14/6/202317/6/2026
A CWE-787: Out-of-Bounds Write vulnerability exists that could cause local denial-of-service, elevation of privilege, and potentially kernel execution when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver.
ModificadaAlta (7.8)0.60%—Schneider-electric Ecostruxure Operator Terminal ExpertSchneider-electric Pro-face Blue14/6/202317/6/2026
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause execution of malicious code when an unsuspicious user loads a project file from the local filesystem into the HMI.
ModificadaAlta (8.8)0.32%—Schneider-electric Ecostruxure Power Monitoring Expert18/4/202317/6/2026
A CWE-613: Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain unauthorized access over a hijacked session in PME after the legitimate user has signed out of their account.
ModificadaAlta (8.1)0.82%—Schneider-electric Struxureware Data Center Expert18/4/202317/6/2026
A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow a user that knows the credentials to execute unprivileged shell commands on the appliance over SSH. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
ModificadaAlta (7.8)0.59%—Schneider-electric Struxureware Data Center Expert18/4/202317/6/2026
A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that allows a local privilege escalation on the appliance when a maliciously crafted Operating System command is entered on the device. Affected products: StruxureWare Data Center Expert (V7.9.2…
ModificadaMedia (6.1)0.39%—Schneider-electric Struxureware Data Center Expert18/4/202317/6/2026
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists on a DCE endpoint through the logging capabilities of the webserver. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
ModificadaAlta (8.1)0.50%—Schneider-electric Struxureware Data Center Expert18/4/202317/6/2026
A CWE-862: Missing Authorization vulnerability exists that could allow viewing of unauthorized content, changes or deleting of content, or performing unauthorized functions when tampering the Device File Transfer settings on DCE endpoints. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
ModificadaMedia (6.1)0.40%—Schneider-electric Struxureware Data Center Expert18/4/202317/6/2026
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists on a DCE file upload endpoint when tampering with parameters over HTTP. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
ModificadaCrítica (9.8)1.2%—Schneider-electric Struxureware Data Center Expert18/4/202317/6/2026
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that allows remote code execution via the “hostname” parameter when maliciously crafted hostname syntax is entered. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
ModificadaCrítica (9.8)1.2%—Schneider-electric Struxureware Data Center Expert18/4/202317/6/2026
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that allows for remote code execution when using a parameter of the DCE network settings endpoint. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
ModificadaMedia (6.5)0.55%—Schneider-electric Struxureware Data Center Expert18/4/202317/6/2026
A CWE-863: Incorrect Authorization vulnerability exists that could allow access to device credentials on specific DCE endpoints not being properly secured when a hacker is using a low privileged user. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
ModificadaAlta (8.8)0.94%—Schneider-electric Struxureware Data Center Expert18/4/202317/6/2026
A CWE-863: Incorrect Authorization vulnerability exists that could allow remote code execution on upload and install packages when a hacker is using a low privileged user account. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
ModificadaAlta (8.8)0.84%—Schneider-electric Ecostruxure Control Expert18/4/202317/6/2026
A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that could cause remote code execution when a valid user visits a malicious link provided through the web endpoints. Affected Products: EcoStruxure Control Expert (V15.1 and above)
ModificadaMedia (5.5)0.15%—Schneider-electric Ecostruxure Control Expert18/4/202317/6/2026
A CWE-269: Improper Privilege Management vulnerability exists that could cause a local user to perform a denial of service through the console server service that is part of EcoStruxure Control Expert. Affected Products: EcoStruxure Control Expert (V15.1 and above)
ModificadaMedia (5.3)0.42%—Schneider-electric ClearscadaSchneider-electric Ecostruxure GEO Scada Expert 2019Schneider-electric Ecostruxure GEO Scada Expert 2020Schneider-electric Ecostruxure GEO Scada Expert 202124/2/202317/6/2026
A CWE-117: Improper Output Neutralization for Logs vulnerability exists that could cause the misinterpretation of log files when malicious packets are sent to the Geo SCADA server's database web port (default 443). Affected products: EcoStruxure Geo SCADA Expert 2019, EcoStruxure Geo SCADA Expert 2020, EcoStruxure Geo…
ModificadaAlta (7.8)0.17%—Schneider-electric Ecostruxure Power Commission1/2/202317/6/2026
A CWE-285: Improper Authorization vulnerability exists that could cause unauthorized access to certain software functions when an attacker gets access to localhost interface of the EcoStruxure Power Commission application. Affected Products: EcoStruxure Power Commission (Versions prior to V2.25)
ModificadaAlta (7.5)0.57%—Schneider-electric Ecostruxure GEO Scada Expert 2019Schneider-electric Ecostruxure GEO Scada Expert 2020Schneider-electric Ecostruxure GEO Scada Expert 202131/1/202317/6/2026
A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause information disclosure when specific messages are sent to the server over the database server TCP port. Affected Products: EcoStruxure Geo SCADA Expert 2019 - 2021 (formerly known as ClearSCADA) (Versions prior…
ModificadaAlta (7.5)0.57%—Schneider-electric Ecostruxure GEO Scada Expert 2019Schneider-electric Ecostruxure GEO Scada Expert 2020Schneider-electric Ecostruxure GEO Scada Expert 202131/1/202317/6/2026
A CWE-863: Incorrect Authorization vulnerability exists that could cause Denial of Service against the Geo SCADA server when specific messages are sent to the server over the database server TCP port.
ModificadaCrítica (9.8)1.5%—Schneider-electric Ecostruxure Control ExpertSchneider-electric Ecostruxure Process ExpertSchneider-electric Modicon M340 Bmxp341000 FirmwareSchneider-electric Modicon M340 Bmxp342000 Firmware+3331/1/202317/6/2026
A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause execution of unauthorized Modbus functions on the controller when hijacking an authenticated Modbus session. Affected Products: EcoStruxure Control Expert (All Versions), EcoStruxure Process Expert (All Versions), Modicon M340 CPU…
ModificadaAlta (8.3)0.14%—Schneider-electric Ecostruxure Cybersecurity Admin Expert30/1/202317/6/2026
A CWE-295: Improper Certificate Validation vulnerability exists that could cause the CAE software to give wrong data to end users when using CAE to configure devices. Additionally, credentials could leak which would enable an attacker the ability to log into the configuration tool and compromise other devices in the…
ModificadaAlta (8.1)0.31%—Schneider-electric Ecostruxure Cybersecurity Admin Expert30/1/202317/6/2026
A CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause legitimate users to be locked out of devices or facilitate backdoor account creation by spoofing a device on the local network. Affected Products: EcoStruxure™ Cybersecurity Admin Expert (CAE) (Versions prior to 2.2)
ModificadaAlta (7.5)0.27%—Schneider-electric Ecostruxure Power Commission30/1/202317/6/2026
A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that could cause all remote domains to access the resources (data) supplied by the server when an attacker sends a fetch request from third-party site or malicious site. Affected Products: EcoStruxure Power Commission (Versions prior to V2.22)
ModificadaCrítica (9.8)0.78%—Schneider-electric Ecostruxure Power Commission30/1/202317/6/2026
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in a function that could allow an attacker to create or overwrite critical files that are used to execute code, such as programs or libraries and cause path traversal attacks. Affected Products: EcoStruxure…