Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
152 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.78% | — | Schneider-electric Ecostruxure Power Commission | 30/1/2023 | 17/6/2026 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could allow an attacker to create or overwrite critical files that are used to execute code, such as programs or libraries and cause unauthenticated code execution. Affected Products: EcoStruxure Power… | |
| Modificada | Crítica (9.8) | 1.2% | — | Schneider-electric Ecostruxure Control ExpertSchneider-electric Ecostruxure Process ExpertSchneider-electric Modicon M340 Bmxp341000 FirmwareSchneider-electric Modicon M340 Bmxp342000 Firmware+51 | 30/1/2023 | 17/6/2026 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when a malicious project file is loaded onto the controller. Affected Products: EcoStruxure Control Expert (All Versions),… | |
| Modificada | Alta (7.5) | 0.43% | — | Schneider-electric Ecostruxure Machine Expert - HvacSchneider-electric Somachine Hvac | 30/1/2023 | 17/6/2026 | A CWE-787: Out-of-bounds Write vulnerability exists that could cause sensitive information leakage when accessing a malicious web page from the commissioning software. Affected Products: SoMachine HVAC (Versions prior to V2.1.0), EcoStruxure Machine Expert – HVAC (Versions prior to V1.4.0) | |
| Modificada | Alta (7.8) | 0.26% | — | Schneider-electric Ecostruxure Operator Terminal ExpertSchneider-electric Pro-face Blue | 4/11/2022 | 17/6/2026 | A CWE-89: Improper Neutralization of Special Elements used in SQL Command (‘SQL Injection’) vulnerability exists that allows adversaries with local user privileges to craft a malicious SQL query and execute as part of project migration which could result in execution of malicious code. Affected Products: EcoStruxure… | |
| Modificada | Alta (7.8) | 0.20% | — | Schneider-electric Ecostruxure Operator Terminal ExpertSchneider-electric Pro-face Blue | 4/11/2022 | 17/6/2026 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in the SGIUtility component that allows adversaries with local user privileges to load malicious DLL which could result in execution of malicious code. Affected Products: EcoStruxure Operator Terminal… | |
| Modificada | Alta (7.8) | 0.11% | — | Schneider-electric Ecostruxure Operator Terminal ExpertSchneider-electric Pro-face Blue | 4/11/2022 | 17/6/2026 | A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists in the SGIUtility component that allows adversaries with local user privileges to load a malicious DLL which could result in execution of malicious code. Affected Products: EcoStruxure Operator Terminal Expert(V3.3 Hotfix 1 or prior),… | |
| Modificada | Alta (7.8) | 0.21% | — | Schneider-electric Ecostruxure Operator Terminal ExpertSchneider-electric Pro-face Blue | 4/11/2022 | 17/6/2026 | A CWE-704: Incorrect Project Conversion vulnerability exists that allows adversaries with local user privileges to load a project file from an adversary-controlled network share which could result in execution of malicious code. Affected Products: EcoStruxure Operator Terminal Expert(V3.3 Hotfix 1 or prior), Pro-face… | |
| Modificada | Alta (7.8) | 0.23% | — | Schneider-electric Ecostruxure Operator Terminal ExpertSchneider-electric Pro-face Blue | 4/11/2022 | 17/6/2026 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that allows adversaries with local user privileges to load a malicious DLL which could lead to execution of malicious code. Affected Products: EcoStruxure Operator Terminal Expert(V3.3 Hotfix 1 or prior),… | |
| Modificada | Alta (7.8) | 0.14% | — | Schneider-electric Ecostruxure Operator Terminal ExpertSchneider-electric Pro-face Blue | 4/11/2022 | 17/6/2026 | A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that allows adversaries with local user privileges to load a malicious DLL which could lead to execution of malicious code. Affected Products: EcoStruxure Operator Terminal Expert(V3.3 Hotfix 1 or prior), Pro-face BLUE(V3.3 Hotfix1 or… | |
| Modificada | Media (5.5) | 0.20% | — | Schneider-electric Ecostruxure Control Expert | 13/9/2022 | 17/6/2026 | A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a crash of the Control Expert software when an incorrect project file is opened. Affected Products: EcoStruxure Control Expert(V15.1 HF001 and prior). | |
| Modificada | Crítica (9.8) | 0.77% | — | Schneider-electric Ecostruxure Control ExpertSchneider-electric Ecostruxure Process ExpertSchneider-electric Modicon M340 Bmxp341000 FirmwareSchneider-electric Modicon M340 Bmxp342000 Firmware+32 | 12/9/2022 | 17/6/2026 | A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists that could cause unauthorized access in read and write mode to the controller when communicating over Modbus. Affected Products: EcoStruxure Control Expert Including all Unity Pro versions (former name of EcoStruxure Control… | |
| Modificada | Crítica (9.8) | 2.4% | — | ATT XmillSchneider-electric Ecostruxure Control ExpertSchneider-electric Ecostruxure Process ExpertSchneider-electric Remoteconnect | 14/4/2022 | 17/6/2026 | A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&T Labs Xmill 0.7. A crafted input file can lead to remote code execution. This is not the same as any of: CVE-2021-21810, CVE-2021-21811, CVE-2021-21812, CVE-2021-21815, CVE-2021-21825, CVE-2021-21826, CVE-2021-21828, CVE-2021-21829, or… | |
| Modificada | Alta (7.8) | 26% | — | Schneider-electric Ecostruxure Control ExpertSchneider-electric Ecostruxure Process ExpertSchneider-electric Remoteconnect | 13/4/2022 | 17/6/2026 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal) vulnerability exists that could cause malicious script to be deployed in an unauthorized location and may result in code execution on the engineering workstation when a malicious project file is loaded in the engineering software.… | |
| Modificada | Crítica (9.8) | 3.1% | — | Schneider-electric Struxureware Data Center Expert | 13/4/2022 | 17/6/2026 | A CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code execution when performed over the network. Affected Product: StruxureWare Data Center Expert (V7.8.1 and prior) | |
| Modificada | Crítica (9.8) | 2.2% | — | Schneider-electric Struxureware Data Center Expert | 13/4/2022 | 17/6/2026 | A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause remote code execution. Affected Product: StruxureWare Data Center Expert (V7.8.1 and prior) | |
| Modificada | Media (5.9) | 0.86% | — | Schneider-electric Ecostruxure Control ExpertSchneider-electric Ecostruxure Process Expert | 9/3/2022 | 17/6/2026 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause a disruption of communication between the Modicon controller and the engineering software, when an attacker is able to intercept and manipulate specific Modbus response data. Affected Product: EcoStruxure Process… | |
| Modificada | Media (5.9) | 0.64% | — | Schneider-electric Ecostruxure Control Expert | 9/3/2022 | 17/6/2026 | A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a disruption of communication between the Modicon controller and the engineering software when an attacker is able to intercept and manipulate specific Modbus response data. Affected Product:… | |
| Modificada | Alta (7.5) | 1.00% | — | Schneider-electric ClearscadaSchneider-electric Ecostruxure GEO Scada Expert 2019Schneider-electric Ecostruxure GEO Scada Expert 2020 | 9/2/2022 | 17/6/2026 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause Denial of Service against the Geo SCADA server when receiving a malformed HTTP request. Affected Product: ClearSCADA (All Versions), EcoStruxure Geo SCADA Expert 2019 (All Versions), EcoStruxure Geo SCADA Expert 2020… | |
| Modificada | Media (5.9) | 0.54% | — | Schneider-electric ClearscadaSchneider-electric Ecostruxure GEO Scada Expert 2019Schneider-electric Ecostruxure GEO Scada Expert 2020 | 9/2/2022 | 17/6/2026 | A CWE-295: Improper Certificate Validation vulnerability exists that could allow a Man-in-theMiddle attack when communications between the client and Geo SCADA database server are intercepted. Affected Product: ClearSCADA (All Versions), EcoStruxure Geo SCADA Expert 2019 (All Versions), EcoStruxure Geo SCADA Expert… | |
| Modificada | Media (5.9) | 0.57% | — | Schneider-electric ClearscadaSchneider-electric Ecostruxure GEO Scada Expert 2019Schneider-electric Ecostruxure GEO Scada Expert 2020 | 9/2/2022 | 17/6/2026 | A CWE-295: Improper Certificate Validation vulnerability exists that could allow a Man-in-theMiddle attack when communications between the client and Geo SCADA web server are intercepted. Affected Product: ClearSCADA (All Versions), EcoStruxure Geo SCADA Expert 2019 (All Versions), EcoStruxure Geo SCADA Expert 2020… | |
| Modificada | Alta (7.5) | 0.39% | — | Schneider-electric ClearscadaSchneider-electric Ecostruxure GEO Scada Expert 2019Schneider-electric Ecostruxure GEO Scada Expert 2020 | 9/2/2022 | 17/6/2026 | A CWE-326: Inadequate Encryption Strength vulnerability exists that could cause non-encrypted communication with the server when outdated versions of the ViewX client are used. Affected Product: ClearSCADA (All Versions), EcoStruxure Geo SCADA Expert 2019 (All Versions), EcoStruxure Geo SCADA Expert 2020 (All Versions) | |
| Modificada | Media (5.4) | 0.45% | — | Schneider-electric Ecostruxure Power Monitoring Expert | 4/2/2022 | 17/6/2026 | A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could allow an authenticated attacker to view data, change settings, or impact availability of the software when the user visits a page containing the injected payload. Affected Product: EcoStruxure… | |
| Modificada | Alta (8.8) | 1.2% | — | Schneider-electric Ecostruxure Power Monitoring Expert | 4/2/2022 | 17/6/2026 | A CWE-20: Improper Input Validation vulnerability exists that could allow an unauthenticated attacker to view data, change settings, impact availability of the software, or potentially impact a user�s local machine when the user clicks a specially crafted link. Affected Product: EcoStruxure Power Monitoring Expert… | |
| Modificada | Media (6.5) | 0.77% | — | Schneider-electric Ecostruxure Power Monitoring Expert | 4/2/2022 | 17/6/2026 | A CWE-20: Improper Input Validation vulnerability exists that could allow arbitrary files on the server to be read by authenticated users through a limited operating system service account. Affected Product: EcoStruxure Power Monitoring Expert (Versions 2020 and prior) | |
| Modificada | Alta (8.8) | 1.2% | — | Schneider-electric Ecostruxure Power Monitoring Expert | 28/1/2022 | 17/6/2026 | A CWE-20: Improper Input Validation vulnerability exists that could cause arbitrary code execution when the user visits a page containing the injected payload. This CVE is unique from CVE-2021-22826. Affected Product: EcoStruxure� Power Monitoring Expert 9.0 and prior versions |