Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
82 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.4% | — | Siemens Cp1604 FirmwareSiemens Cp1616 FirmwareSiemens Simatic Rf185c FirmwareSiemens Simatic Cp343-1 Advanced Firmware+49 | 17/4/2019 | 17/6/2026 | The webserver of the affected devices contains a vulnerability that may lead to a denial of service condition. An attacker may cause a denial of service situation which leads to a restart of the webserver of the affected device. The security vulnerability could be exploited by an attacker with network access to the… | |
| Modificada | Crítica (9.8) | 34% | — | WibukeySiemens Simatic Wincc Open Architecture | 5/2/2019 | 17/6/2026 | An exploitable heap overflow vulnerability exists in the WkbProgramLow function of WibuKey Network server management, version 6.40.2402.500. A specially crafted TCP packet can cause a heap overflow, potentially leading to remote code execution. An attacker can send a malformed TCP packet to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 1.7% | — | Siemens Simatic HMI Comfort Panels FirmwareSiemens Simatic HMI Comfort Outdoor Panels FirmwareSiemens Simatic HMI KTP Mobile Panels Ktp400f FirmwareSiemens Simatic HMI KTP Mobile Panels Ktp700 Firmware+8 | 13/12/2018 | 17/6/2026 | A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V14), SIMATIC HMI Comfort Outdoor Panels 7" & 15" (All versions < V14), SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900 and KTP900F (All versions < V14), SIMATIC WinCC Runtime Advanced (All versions < V14),… | |
| Modificada | Alta (8.1) | 1.7% | — | Siemens Simatic HMI Comfort Panels FirmwareSiemens Simatic HMI Comfort Outdoor Panels FirmwareSiemens Simatic HMI KTP Mobile Panels Ktp400f FirmwareSiemens Simatic HMI KTP Mobile Panels Ktp700 Firmware+8 | 13/12/2018 | 17/6/2026 | A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15 Update 4), SIMATIC HMI Comfort Outdoor Panels 7" & 15" (All versions < V15 Update 4), SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900 and KTP900F (All versions < V15 Update 4), SIMATIC WinCC Runtime Advanced… | |
| Modificada | Alta (7.5) | 3.6% | — | Siemens Simatic HMI Comfort Panels FirmwareSiemens Simatic HMI Comfort Outdoor Panels FirmwareSiemens Simatic HMI KTP Mobile Panels Ktp400f FirmwareSiemens Simatic HMI KTP Mobile Panels Ktp700 Firmware+8 | 13/12/2018 | 17/6/2026 | A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15 Update 4), SIMATIC HMI Comfort Outdoor Panels 7" & 15" (All versions < V15 Update 4), SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900 and KTP900F (All versions < V15 Update 4), SIMATIC WinCC Runtime Advanced… | |
| Modificada | Crítica (9.1) | 2.3% | — | Siemens Simatic Wincc Open Architecture | 12/9/2018 | 17/6/2026 | A vulnerability has been identified in SIMATIC WinCC OA V3.14 and prior (All versions < V3.14-P021). Improper access control to a data point of the affected product could allow an unauthenticated remote user to escalate its privileges in the context of SIMATIC WinCC OA V3.14. This vulnerability could be exploited by… | |
| Modificada | Alta (8.6) | 0.44% | — | Siemens Simatic Step 7 (tia Portal)Siemens Simatic Wincc (tia Portal) | 7/8/2018 | 17/6/2026 | A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V10, V11, V12 (All versions), SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V13 (All versions < V13 SP2 Update 2), SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V14 (All versions < V14 SP1 Update 6), SIMATIC STEP 7 (TIA… | |
| Modificada | Alta (7.8) | 0.36% | — | Siemens Simatic Step 7 (tia Portal)Siemens Simatic Wincc (tia Portal) | 7/8/2018 | 17/6/2026 | A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V10, V11, V12 (All versions), SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V13 (All versions < V13 SP2 Update 2), SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V14 (All versions < V14 SP1 Update 6), SIMATIC STEP 7 (TIA… | |
| Modificada | Alta (7.5) | 2.4% | — | Siemens Openpcs 7Siemens Simatic BatchSiemens Simatic NET PCSiemens Simatic PCS 7+5 | 24/4/2018 | 17/6/2026 | A vulnerability has been identified in OpenPCS 7 V7.1 and earlier (All versions), OpenPCS 7 V8.0 (All versions), OpenPCS 7 V8.1 (All versions < V8.1 Upd5), OpenPCS 7 V8.2 (All versions), OpenPCS 7 V9.0 (All versions < V9.0 Upd1), SIMATIC BATCH V7.1 and earlier (All versions), SIMATIC BATCH V8.0 (All versions < V8.0… | |
| Modificada | Media (4.6) | 0.26% | — | Siemens Simatic Wincc OA Operator | 23/4/2018 | 17/6/2026 | A vulnerability has been identified in SIMATIC WinCC OA Operator iOS App (All versions < V1.4). Insufficient protection of sensitive information (e.g. session key for accessing server) in Siemens WinCC OA Operator iOS app could allow an attacker with physical access to the mobile device to read unencrypted data from… | |
| Modificada | Media (6.7) | 0.42% | — | Siemens Simatic Wincc OA UI | 20/3/2018 | 17/6/2026 | A vulnerability has been identified in SIMATIC WinCC OA UI for Android (All versions < V3.15.10), SIMATIC WinCC OA UI for iOS (All versions < V3.15.10). Insufficient limitation of CONTROL script capabilities could allow read and write access from one HMI project cache folder to other HMI project cache folders within… | |
| Modificada | Media (4.9) | 3.7% | — | Siemens Simatic Pcs7Siemens Simatic Wincc | 6/11/2017 | 17/6/2026 | An Improper Input Validation issue was discovered in Siemens SIMATIC PCS 7 V8.1 prior to V8.1 SP1 with WinCC V7.3 Upd 13, and V8.2 all versions. The improper input validation vulnerability has been identified, which may allow an authenticated remote attacker who is a member of the administrators group to crash… | |
| Modificada | Media (5.4) | 0.32% | — | Siemens Simatic Wincc Sm@rtclientSiemens Simatic Wincc Sm@rtclient Lite | 8/8/2017 | 17/6/2026 | A vulnerability was discovered in Siemens SIMATIC WinCC Sm@rtClient for Android (All versions before V1.0.2.2) and SIMATIC WinCC Sm@rtClient for Android Lite (All versions before V1.0.2.2). An attacker with physical access to an unlocked mobile device, that has the affected app running, could bypass the app's… | |
| Modificada | Alta (7.4) | 0.95% | — | Siemens Simatic Wincc Sm@rtclient | 8/8/2017 | 17/6/2026 | A vulnerability was discovered in Siemens SIMATIC WinCC Sm@rtClient for Android (All versions before V1.0.2.2). The existing TLS protocol implementation could allow an attacker to read and modify data within a TLS session while performing a Man-in-the-Middle (MitM) attack. | |
| Modificada | Media (4.9) | 1.9% | — | Siemens Simatic WinccSiemens Simatic Wincc (tia Portal)Siemens Simatic Wincc Runtime | 11/5/2017 | 17/6/2026 | A vulnerability was discovered in Siemens SIMATIC WinCC (V7.3 before Upd 11 and V7.4 before SP1), SIMATIC WinCC Runtime Professional (V13 before SP2 and V14 before SP1), SIMATIC WinCC (TIA Portal) Professional (V13 before SP2 and V14 before SP1) that could allow an authenticated, remote attacker who is member of the… | |
| Modificada | Media (6.5) | 0.47% | — | Siemens PCS 7Siemens Primary Setup ToolSiemens Security Configuration ToolSiemens Simatic Automation Tool+12 | 11/5/2017 | 17/6/2026 | A vulnerability has been identified in Primary Setup Tool (PST) (All versions < V4.2 HF1), SIMATIC Automation Tool (All versions < V3.0), SIMATIC NET PC-Software (All versions < V14 SP1), SIMATIC PCS 7 V8.1 (All versions), SIMATIC PCS 7 V8.2 (All versions < V8.2 SP1), SIMATIC STEP 7 (TIA Portal) V13 (All versions <… | |
| Modificada | Alta (8.1) | 1.4% | — | Siemens Simatic PCS 7Siemens Simatic Wincc | 17/12/2016 | 17/6/2026 | A vulnerability in SIEMENS SIMATIC WinCC (All versions < SIMATIC WinCC V7.2) and SIEMENS SIMATIC PCS 7 (All versions < SIMATIC PCS 7 V8.0 SP1) could allow a remote attacker to crash an ActiveX component or leak parts of the application memory if a user is tricked into clicking on a malicious link under certain… | |
| Modificada | Media (6.4) | 0.38% | — | Siemens Primary Setup ToolSiemens Security Configuration ToolSiemens Simatic IT Production SuiteSiemens Simatic NET PC Software+14 | 15/11/2016 | 17/6/2026 | A vulnerability has been identified in Primary Setup Tool (PST) (All versions < V4.2 HF1), SIMATIC IT Production Suite (All versions < V7.0 SP1 HFX 2), SIMATIC NET PC-Software (All versions < V14), SIMATIC PCS 7 V7.1 (All versions), SIMATIC PCS 7 V8.0 (All versions), SIMATIC PCS 7 V8.1 (All versions), SIMATIC PCS 7… | |
| Modificada | Alta (7.5) | 4.4% | — | Siemens Simatic Wincc | 22/7/2016 | 17/6/2026 | Siemens SIMATIC WinCC 7.0 through SP3 and 7.2 allows remote attackers to read arbitrary WinCC station files via crafted packets. | |
| Modificada | Crítica (9.8) | 10% | — | Siemens Simatic BatchSiemens Simatic WinccSiemens Simatic Openpcs 7 | 22/7/2016 | 17/6/2026 | Siemens SIMATIC WinCC before 7.3 Update 10 and 7.4 before Update 1, SIMATIC BATCH before 8.1 SP1 Update 9 as distributed in SIMATIC PCS 7 through 8.1 SP1, SIMATIC OpenPCS 7 before 8.1 Update 3 as distributed in SIMATIC PCS 7 through 8.1 SP1, SIMATIC OpenPCS 7 before 8.2 Update 1 as distributed in SIMATIC PCS 7 8.2,… | |
| Modificada | Baja (2.1) | 0.45% | — | Siemens Simatic Wincc Sm@rtclientSiemens Simatic Wincc Sm@rtclient Lite | 3/8/2015 | 17/6/2026 | The Siemens SIMATIC WinCC Sm@rtClient and Sm@rtClient Lite applications before 01.00.01.00 for Android do not properly store passwords, which allows physically proximate attackers to obtain sensitive information via unspecified vectors. | |
| Modificada | Baja (1.9) | 0.36% | — | Siemens Simatic Wincc Sm@rtclient | 14/1/2015 | 17/6/2026 | The Siemens SIMATIC WinCC Sm@rtClient app before 1.0.2 for iOS allows physically proximate attackers to discover Sm@rtServer credentials by leveraging an error in the credential-processing mechanism. | |
| Modificada | Baja (1.9) | 0.36% | — | Siemens Simatic Wincc Sm@rtclient | 14/1/2015 | 17/6/2026 | The Siemens SIMATIC WinCC Sm@rtClient app before 1.0.2 for iOS allows local users to bypass an intended application-password requirement by leveraging the running of the app in the background state. | |
| Modificada | Baja (2.1) | 0.38% | — | Siemens Simatic Wincc Sm@rtclient | 14/1/2015 | 17/6/2026 | The Siemens SIMATIC WinCC Sm@rtClient app before 1.0.2 for iOS allows physically proximate attackers to extract the password from storage via unspecified vectors. | |
| Modificada | Media (5) | 2.0% | — | Siemens Simatic PCS 7Siemens Simatic Pcs7Siemens Simatic TiaportalSiemens Simatic Wincc | 26/11/2014 | 17/6/2026 | The WinCC server in Siemens SIMATIC WinCC 7.0 through SP3, 7.2 before Update 9, and 7.3 before Update 2; SIMATIC PCS 7 7.1 through SP4, 8.0 through SP2, and 8.1; and TIA Portal 13 before Update 6 allows remote attackers to read arbitrary files via crafted packets. |