Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2997▼ 66 respecto a la semana anterior
Críticas / altas1460▲ 109 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

787 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.1)1.0%—Schneider-electric Sage RTU Firmware12/6/202417/6/2026
CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability exists that could allow an authenticated user with access to the device’s web interface to corrupt files and impact device functionality when sending a crafted HTTP request.
ModificadaCrítica (9.8)0.53%—Schneider-electric Sage RTU Firmware12/6/202417/6/2026
CWE-787: Out-of-bounds Write vulnerability exists that could result in an authentication bypass when sending a malformed POST request and particular configuration parameters are set.
ModificadaMedia (6.5)0.37%—Schneider-electric Evlink Home Firmware12/6/202417/6/2026
CWE-668: Exposure of the Resource Wrong Sphere vulnerability exists that exposes a SSH interface over the product network interface. This does not allow to directly exploit the product or make any unintended operation as the SSH interface access is protected by an authentication mechanism. Impacts are limited to port…
ModificadaMedia (6.5)0.35%—Schneider-electric Modicon M340 FirmwareSchneider-electric Bmxnoe0100 FirmwareSchneider-electric Bmxnoe0110 Firmware12/6/202417/6/2026
CWE-552: Files or Directories Accessible to External Parties vulnerability exists which may prevent user to update the device firmware and prevent proper behavior of the webserver when specific files or directories are removed from the filesystem.
AnalizadaAlta (7.7)0.23%—Schneider-electric Ecostruxure Control ExpertSchneider-electric Ecostruxure Process Expert14/2/202417/6/2026
CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to a project file protected with application password when opening the file with EcoStruxure Control Expert.
AnalizadaAlta (8.1)0.32%—Schneider-electric Modicon M340 Bmxp341000 FirmwareSchneider-electric Modicon M340 Bmxp341000h FirmwareSchneider-electric Modicon M340 Bmxp342000 FirmwareSchneider-electric Modicon M340 Bmxp342010 Firmware+4214/2/202417/6/2026
CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause a denial of service and loss of confidentiality, integrity of controllers when conducting a Man in the Middle attack.
AnalizadaAlta (7.1)0.15%—Schneider-electric Ecostruxure Control ExpertSchneider-electric Ecostruxure Process Expert14/2/202417/6/2026
CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause unauthorized access to the project file in EcoStruxure Control Expert when a local user tampers with the memory of the engineering workstation.
ModificadaAlta (7.8)0.49%—Schneider-electric Easergy Studio9/1/202417/6/2026
A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker logged in with a user level account to gain higher privileges by providing a harmful serialized object.
ModificadaAlta (7.1)0.24%—Schneider-electric Easy UPS Online Monitoring Software14/12/202317/6/2026
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause arbitrary file deletion upon service restart when accessed by a local and low-privileged attacker.
ModificadaMedia (4.9)0.28%—Schneider-electric Eb450 FirmwareSchneider-electric Eb45e FirmwareSchneider-electric Eh450 FirmwareSchneider-electric Eh45e Firmware+1214/12/202317/6/2026
A CWE-494: Download of Code Without Integrity Check vulnerability exists that could allow a privileged user to install an untrusted firmware.
ModificadaMedia (6.1)0.42%—Schneider-electric Eb450 FirmwareSchneider-electric Eb45e FirmwareSchneider-electric Eh450 FirmwareSchneider-electric Eh45e Firmware+1214/12/202317/6/2026
A CWE-601:URL Redirection to Untrusted Site (‘Open Redirect’) vulnerability exists that could cause disclosure of information through phishing attempts over HTTP.
ModificadaMedia (5.3)0.58%—Schneider-electric Galaxy VL FirmwareSchneider-electric Galaxy VS Firmware15/11/202317/6/2026
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause a file system enumeration and file download when an attacker navigates to the Network Management Card via HTTPS.
ModificadaMedia (6.1)0.41%—Schneider-electric Ecostruxure Power Monitoring Expert15/11/202317/6/2026
A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability that could cause a vulnerability leading to a cross site scripting condition where attackers can have a victim’s browser run arbitrary JavaScript when they visit a page containing the injected payload.
ModificadaMedia (6.1)0.45%—Schneider-electric Ecostruxure Power Monitoring Expert15/11/202317/6/2026
A CWE-601 URL Redirection to Untrusted Site vulnerability exists that could cause an openredirect vulnerability leading to a cross site scripting attack. By providing a URL-encoded input attackers can cause the software’s web application to redirect to the chosen domain after a successful login is performed.
ModificadaMedia (4.8)0.40%—Schneider-electric Ion8650 FirmwareSchneider-electric Ion8800 Firmware15/11/202317/6/2026
A CWE-79 Improper Neutralization of Input During Web Page Generation vulnerability exists that could cause compromise of a user’s browser when an attacker with admin privileges has modified system values.
ModificadaMedia (4.9)0.31%—Schneider-electric Ion8650 FirmwareSchneider-electric Ion8800 Firmware15/11/202317/6/2026
A CWE-494 Download of Code Without Integrity Check vulnerability exists that could allow modified firmware to be uploaded when an authorized admin user begins a firmware update procedure which could result in full control over the device.
ModificadaCrítica (9.8)35%—Schneider-electric Spacelogic C-bus Toolkit4/10/202317/6/2026
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause tampering of files on the personal computer running C-Bus when using the File Command.
ModificadaCrítica (9.8)0.92%—Schneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Ecostruxure Power Operation With Advanced ReportsSchneider-electric Ecostruxure Power Scada Operation With Advanced Reports4/10/202317/6/2026
A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker to execute arbitrary code on the targeted system by sending a specifically crafted packet to the application.
ModificadaCrítica (9.8)0.73%—Schneider-electric C-bus Toolkit4/10/202317/6/2026
A CWE-269: Improper Privilege Management vulnerability exists that could cause a remote code execution when the transfer command is used over the network.
ModificadaAlta (7.8)0.18%—Schneider-electric Interactive Graphical Scada System14/9/202317/6/2026
A CWE-306: Missing Authentication for Critical Function vulnerability exists in the IGSS Update Service that could allow a local attacker to change update source, potentially leading to remote code execution when the attacker force an update containing malicious content.
ModificadaMedia (5.3)0.18%—Schneider-electric Pro-face Gp-pro EX9/8/202317/6/2026
A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause memory corruption when an authenticated user opens a tampered log file from GP-Pro EX.
ModificadaAlta (7.8)0.18%—Schneider-electric Accutech Manager12/7/202317/6/2026
A CWE-120: Buffer Copy without Checking Size of Input (Classic Buffer Overflow) vulnerability exists that could cause user privilege escalation if a local user sends specific string input to a local function call.
ModificadaAlta (7.2)0.86%—Schneider-electric Struxureware Data Center Expert12/7/202317/6/2026
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution when an admin user on DCE tampers with backups which are then manually restored.
ModificadaAlta (7.2)0.86%—Schneider-electric Struxureware Data Center Expert12/7/202317/6/2026
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution when an admin user on DCE uploads or tampers with install packages.
ModificadaAlta (8.8)0.60%—Schneider-electric Struxureware Data Center Expert12/7/202317/6/2026
A CWE-89: Improper Neutralization of Special Elements vulnerability used in an SQL Command ('SQL Injection') vulnerability exists that could allow a user already authenticated on DCE to access unauthorized content, change, or delete content, or perform unauthorized actions when tampering with the mass configuration…