Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
112 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.51% | — | Ovarro Tbox Ms-cpu32 FirmwareOvarro Tbox Ms-cpu32-s2 FirmwareOvarro Tbox LT2 FirmwareOvarro Tbox TG2 Firmware+1 | 3/7/2023 | 17/6/2026 | The affected TBox RTUs allow low privilege users to access software security tokens of higher privilege. This could allow an attacker with “user” privileges to access files requiring higher privileges by establishing an SSH session and providing the other tokens. | |
| Modificada | Media (5.9) | 0.51% | — | Ovarro Tbox Ms-cpu32 FirmwareOvarro Tbox Ms-cpu32-s2 FirmwareOvarro Tbox LT2 FirmwareOvarro Tbox TG2 Firmware+1 | 3/7/2023 | 17/6/2026 | The affected TBox RTUs generate software security tokens using insufficient entropy. The random seed used to generate the software tokens is not initialized correctly, and other parts of the token are generated using predictable time-based values. An attacker with this knowledge could successfully brute force the… | |
| Modificada | Alta (7.2) | 0.70% | — | Ovarro Tbox Ms-cpu32 FirmwareOvarro Tbox Ms-cpu32-s2 FirmwareOvarro Tbox LT2 FirmwareOvarro Tbox TG2 Firmware+1 | 3/7/2023 | 17/6/2026 | The affected TBox RTUs run OpenVPN with root privileges and can run user defined configuration scripts. An attacker could set up a local OpenVPN server and push a malicious script onto the TBox host to acquire root privileges. | |
| Modificada | Media (6.5) | 0.23% | — | Ovarro Tbox Ms-cpu32 FirmwareOvarro Tbox Ms-cpu32-s2 FirmwareOvarro Tbox LT2 FirmwareOvarro Tbox TG2 Firmware+1 | 3/7/2023 | 17/6/2026 | The affected TBox RTUs store hashed passwords using MD5 encryption, which is an insecure encryption algorithm. | |
| Modificada | Media (5.3) | 0.49% | — | Ovarro Tbox Ms-cpu32 FirmwareOvarro Tbox Ms-cpu32-s2 FirmwareOvarro Tbox LT2 FirmwareOvarro Tbox TG2 Firmware+1 | 29/6/2023 | 17/6/2026 | The affected TBox RTUs are missing authorization for running some API commands. An attacker running these commands could reveal sensitive information such as software versions and web server file contents. | |
| Modificada | Media (4.4) | 0.19% | — | Intel Ethernet Network Controller E810-cam1 FirmwareIntel Ethernet Network Controller E810-cam2 FirmwareIntel Ethernet Network Controller E810-xxvam2 FirmwareIntel Ethernet Controller X710-am2 Firmware+11 | 16/2/2023 | 17/6/2026 | Out-of-bounds write in firmware for some Intel(R) Ethernet Network Controllers and Adapters E810 Series before version 1.7.0.8 and some Intel(R) Ethernet 700 Series Controllers and Adapters before version 9.101 may allow a privileged user to potentially enable denial of service via local access. | |
| Modificada | Alta (8.8) | 0.94% | — | Siemens 6gk6108-4am00-2ba2 FirmwareSiemens 6gk6108-4am00-2da2 FirmwareSiemens 6gk5804-0ap00-2aa2 FirmwareSiemens 6gk5812-1aa00-2aa2 Firmware+182 | 11/10/2022 | 17/6/2026 | Affected devices do not properly authorize the change password function of the web interface. This could allow low privileged users to escalate their privileges. | |
| Modificada | Crítica (9.8) | 1.3% | — | Ovarro TwinsoftOvarro Tbox Lt2-530 FirmwareOvarro Tbox Lt2-532 FirmwareOvarro Tbox Lt2-540 Firmware+4 | 28/7/2022 | 17/6/2026 | An attacker may use TWinSoft and a malicious source project file (TPG) to extract files on machine executing Ovarro TWinSoft, which could lead to code execution. | |
| Modificada | Crítica (9.8) | 0.89% | — | Ovarro TwinsoftOvarro Tbox Lt2-530 FirmwareOvarro Tbox Lt2-532 FirmwareOvarro Tbox Lt2-540 Firmware+4 | 28/7/2022 | 17/6/2026 | Ovarro TBox proprietary Modbus file access functions allow attackers to read, alter, or delete the configuration file. | |
| Modificada | Crítica (9.8) | 1.4% | — | Ovarro TwinsoftOvarro Tbox Lt2-530 FirmwareOvarro Tbox Lt2-532 FirmwareOvarro Tbox Lt2-540 Firmware+4 | 28/7/2022 | 17/6/2026 | The “ipk” package containing the configuration created by TWinSoft can be uploaded, extracted, and executed in Ovarro TBox, allowing malicious code execution. | |
| Modificada | Crítica (9.8) | 0.81% | — | Ovarro TwinsoftOvarro Tbox Lt2-530 FirmwareOvarro Tbox Lt2-532 FirmwareOvarro Tbox Lt2-540 Firmware+4 | 28/7/2022 | 17/6/2026 | Ovarro TBox TWinSoft uses the custom hardcoded user “TWinSoft” with a hardcoded key. | |
| Modificada | Alta (7.5) | 0.85% | — | Ovarro TwinsoftOvarro Tbox Lt2-530 FirmwareOvarro Tbox Lt2-532 FirmwareOvarro Tbox Lt2-540 Firmware+4 | 28/7/2022 | 17/6/2026 | An attacker could use specially crafted invalid Modbus frames to crash the Ovarro TBox system. | |
| Modificada | Crítica (9.8) | 0.81% | — | Ovarro TwinsoftOvarro Tbox Lt2-530 FirmwareOvarro Tbox Lt2-532 FirmwareOvarro Tbox Lt2-540 Firmware+4 | 28/7/2022 | 17/6/2026 | An attacker can decrypt the Ovarro TBox login password by communication capture and brute force attacks. | |
| Modificada | Media (4.8) | 0.58% | — | Meikyo Watch Boot Nino Rpc-m2c FirmwareMeikyo Watch Boot Light Rpc-m5c FirmwareMeikyo Watch Boot L-zero Rpc-m4l FirmwareMeikyo Watch Boot Mini Rpc-m4h Firmware+11 | 18/5/2022 | 17/6/2026 | Cross-site scripting vulnerability in Rebooter(WATCH BOOT nino RPC-M2C [End of Sale] all firmware versions, WATCH BOOT light RPC-M5C [End of Sale] all firmware versions, WATCH BOOT L-zero RPC-M4L [End of Sale] all firmware versions, WATCH BOOT mini RPC-M4H [End of Sale] all firmware versions, WATCH BOOT nino RPC-M2CS… | |
| Modificada | Alta (8.8) | 0.54% | — | Meikyo Watch Boot Nino Rpc-m2c FirmwareMeikyo Watch Boot Light Rpc-m5c FirmwareMeikyo Watch Boot L-zero Rpc-m4l FirmwareMeikyo Watch Boot Mini Rpc-m4h Firmware+11 | 18/5/2022 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Rebooter(WATCH BOOT nino RPC-M2C [End of Sale] all firmware versions, WATCH BOOT light RPC-M5C [End of Sale] all firmware versions, WATCH BOOT L-zero RPC-M4L [End of Sale] all firmware versions, WATCH BOOT mini RPC-M4H [End of Sale] all firmware versions, WATCH BOOT… | |
| Modificada | Alta (8.1) | 0.92% | — | Kalkitech Sync241-m1 FirmwareKalkitech Sync241-m2 FirmwareKalkitech Sync241-m4 FirmwareKalkitech Sync261-m1 Firmware+16 | 6/1/2022 | 17/6/2026 | A security vulnerability originally reported in the SYNC2101 product, and applicable to specific sub-families of SYNC devices, allows an attacker to download the configuration file used in the device and apply a modified configuration file back to the device. The attack requires network access to the SYNC device and… | |
| Modificada | Media (6.7) | 0.25% | — | Intel Ethernet Controller V710-at2 FirmwareIntel Ethernet Controller X710-tm4 FirmwareIntel Ethernet Controller X710-at2 FirmwareIntel Ethernet Controller Xxv710-am2 Firmware+7 | 17/11/2021 | 17/6/2026 | Out-of-bounds write in the firmware for Intel(R) Ethernet 700 Series Controllers before version 8.2 may allow a privileged user to potentially enable an escalation of privilege via local access. | |
| Modificada | Media (4.4) | 0.23% | — | Intel Ethernet Network Controller E810-xxvam2 FirmwareIntel Ethernet Network Controller E810-cam1 FirmwareIntel Ethernet Network Controller E810-cam2 Firmware | 17/11/2021 | 17/6/2026 | Improper input validation in the firmware for the Intel(R) Ethernet Network Controller E810 before version 1.6.0.6 may allow a privileged user to potentially enable a denial of service via local access. | |
| Modificada | Media (4.4) | 0.23% | — | Intel Ethernet Network Controller E810-xxvam2 FirmwareIntel Ethernet Network Controller E810-cam1 FirmwareIntel Ethernet Network Controller E810-cam2 Firmware | 17/11/2021 | 17/6/2026 | Improper access control in the firmware for the Intel(R) Ethernet Network Controller E810 before version 1.5.5.6 may allow a privileged user to potentially enable a denial of service via local access. | |
| Modificada | Media (4.4) | 0.23% | — | Intel Ethernet Network Controller E810-xxvam2 FirmwareIntel Ethernet Network Controller E810-cam1 FirmwareIntel Ethernet Network Controller E810-cam2 Firmware | 17/11/2021 | 17/6/2026 | Protection mechanism failure in the firmware for the Intel(R) Ethernet Network Controller E810 before version 1.5.5.6 may allow a privileged user to enable a denial of service via local access. | |
| Modificada | Media (6.1) | 0.83% | — | Cisco Integrated Management ControllerCisco UCS ManagerCisco Encs 5100 FirmwareCisco Encs 5400 Firmware+21 | 6/5/2021 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of the parameters in an HTTP request. An attacker could… | |
| Modificada | Media (6.7) | 0.34% | — | Intel V710-at2 FirmwareIntel X710-tm4 FirmwareIntel X710-at2 FirmwareIntel Xxv710-am2 Firmware+4 | 12/11/2020 | 17/6/2026 | Improper buffer restrictions in the firmware of the Intel(R) Ethernet 700 Series Controllers may allow a privileged user to potentially enable escalation of privilege and/or denial of service via local access. | |
| Modificada | Media (6.7) | 0.34% | — | Intel V710-at2 FirmwareIntel X710-tm4 FirmwareIntel X710-at2 FirmwareIntel Xxv710-am2 Firmware+4 | 12/11/2020 | 17/6/2026 | Insufficient access control in the firmware of the Intel(R) Ethernet 700 Series Controllers before version 7.3 may allow a privileged user to potentially enable escalation of privilege and/or denial of service via local access. | |
| Modificada | Media (6.7) | 0.38% | — | Intel V710-at2 FirmwareIntel X710-tm4 FirmwareIntel X710-at2 FirmwareIntel Xxv710-am2 Firmware+4 | 12/11/2020 | 17/6/2026 | A logic issue in the firmware of the Intel(R) Ethernet 700 Series Controllers may allow a privileged user to potentially enable escalation of privilege and/or denial of service via local access. | |
| Modificada | Media (6.7) | 0.34% | — | Intel V710-at2 FirmwareIntel X710-tm4 FirmwareIntel X710-at2 FirmwareIntel Xxv710-am2 Firmware+4 | 12/11/2020 | 17/6/2026 | Protection mechanism failure in Intel(R) Ethernet 700 Series Controllers before version 7.3 may allow a privileged user to potentially enable escalation of privilege and/or denial of service via local access. |