Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

134 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.5%—Siemens Simatic PCS 7Siemens Simatic WinccSiemens Simatic Wincc (tia Portal)Siemens Simatic Wincc Runtime Professional14/5/201917/6/2026
A vulnerability has been identified in SIMATIC PCS 7 V8.0 and earlier (All versions), SIMATIC PCS 7 V8.1 (All versions < V8.1 with WinCC V7.3 Upd 19), SIMATIC PCS 7 V8.2 (All versions < V8.2 SP1 with WinCC V7.4 SP1 Upd11), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP2 with WinCC V7.4 SP1 Upd11), SIMATIC WinCC (TIA…
ModificadaAlta (7.5)1.6%—Siemens Simatic Cp443-1 OPC UA FirmwareSiemens Simatic ET 200 Open Controller CPU 1515sp PC2 FirmwareSiemens Simatic IPC Diagmonitor FirmwareSiemens Simatic NET PC Software Firmware+2317/4/201917/6/2026
A vulnerability has been identified in SIMATIC CP 443-1 OPC UA (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions < V2.7), SIMATIC HMI Comfort Outdoor Panels 7" & 15" (incl. SIPLUS variants) (All versions < V15.1 Upd 4), SIMATIC HMI Comfort Panels 4" - 22" (incl.…
ModificadaAlta (7.5)1.4%—Siemens Cp1604 FirmwareSiemens Cp1616 FirmwareSiemens Simatic Rf185c FirmwareSiemens Simatic Cp343-1 Advanced Firmware+4917/4/201917/6/2026
The webserver of the affected devices contains a vulnerability that may lead to a denial of service condition. An attacker may cause a denial of service situation which leads to a restart of the webserver of the affected device. The security vulnerability could be exploited by an attacker with network access to the…
ModificadaCrítica (9.8)34%—WibukeySiemens Simatic Wincc Open Architecture5/2/201917/6/2026
An exploitable heap overflow vulnerability exists in the WkbProgramLow function of WibuKey Network server management, version 6.40.2402.500. A specially crafted TCP packet can cause a heap overflow, potentially leading to remote code execution. An attacker can send a malformed TCP packet to trigger this vulnerability.
ModificadaAlta (8.8)1.7%—Siemens Simatic HMI Comfort Panels FirmwareSiemens Simatic HMI Comfort Outdoor Panels FirmwareSiemens Simatic HMI KTP Mobile Panels Ktp400f FirmwareSiemens Simatic HMI KTP Mobile Panels Ktp700 Firmware+813/12/201817/6/2026
A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V14), SIMATIC HMI Comfort Outdoor Panels 7" & 15" (All versions < V14), SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900 and KTP900F (All versions < V14), SIMATIC WinCC Runtime Advanced (All versions < V14),…
ModificadaAlta (8.1)1.7%—Siemens Simatic HMI Comfort Panels FirmwareSiemens Simatic HMI Comfort Outdoor Panels FirmwareSiemens Simatic HMI KTP Mobile Panels Ktp400f FirmwareSiemens Simatic HMI KTP Mobile Panels Ktp700 Firmware+813/12/201817/6/2026
A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15 Update 4), SIMATIC HMI Comfort Outdoor Panels 7" & 15" (All versions < V15 Update 4), SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900 and KTP900F (All versions < V15 Update 4), SIMATIC WinCC Runtime Advanced…
ModificadaAlta (7.5)3.6%—Siemens Simatic HMI Comfort Panels FirmwareSiemens Simatic HMI Comfort Outdoor Panels FirmwareSiemens Simatic HMI KTP Mobile Panels Ktp400f FirmwareSiemens Simatic HMI KTP Mobile Panels Ktp700 Firmware+813/12/201817/6/2026
A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15 Update 4), SIMATIC HMI Comfort Outdoor Panels 7" & 15" (All versions < V15 Update 4), SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900 and KTP900F (All versions < V15 Update 4), SIMATIC WinCC Runtime Advanced…
ModificadaCrítica (9.1)2.3%—Siemens Simatic Wincc Open Architecture12/9/201817/6/2026
A vulnerability has been identified in SIMATIC WinCC OA V3.14 and prior (All versions < V3.14-P021). Improper access control to a data point of the affected product could allow an unauthenticated remote user to escalate its privileges in the context of SIMATIC WinCC OA V3.14. This vulnerability could be exploited by…
ModificadaAlta (8.6)0.44%—Siemens Simatic Step 7 (tia Portal)Siemens Simatic Wincc (tia Portal)7/8/201817/6/2026
A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V10, V11, V12 (All versions), SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V13 (All versions < V13 SP2 Update 2), SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V14 (All versions < V14 SP1 Update 6), SIMATIC STEP 7 (TIA…
ModificadaAlta (7.8)0.36%—Siemens Simatic Step 7 (tia Portal)Siemens Simatic Wincc (tia Portal)7/8/201817/6/2026
A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V10, V11, V12 (All versions), SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V13 (All versions < V13 SP2 Update 2), SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V14 (All versions < V14 SP1 Update 6), SIMATIC STEP 7 (TIA…
ModificadaAlta (7.5)2.4%—Siemens Openpcs 7Siemens Simatic BatchSiemens Simatic NET PCSiemens Simatic PCS 7+524/4/201817/6/2026
A vulnerability has been identified in OpenPCS 7 V7.1 and earlier (All versions), OpenPCS 7 V8.0 (All versions), OpenPCS 7 V8.1 (All versions < V8.1 Upd5), OpenPCS 7 V8.2 (All versions), OpenPCS 7 V9.0 (All versions < V9.0 Upd1), SIMATIC BATCH V7.1 and earlier (All versions), SIMATIC BATCH V8.0 (All versions < V8.0…
ModificadaMedia (4.6)0.26%—Siemens Simatic Wincc OA Operator23/4/201817/6/2026
A vulnerability has been identified in SIMATIC WinCC OA Operator iOS App (All versions < V1.4). Insufficient protection of sensitive information (e.g. session key for accessing server) in Siemens WinCC OA Operator iOS app could allow an attacker with physical access to the mobile device to read unencrypted data from…
ModificadaMedia (6.7)0.42%—Siemens Simatic Wincc OA UI20/3/201817/6/2026
A vulnerability has been identified in SIMATIC WinCC OA UI for Android (All versions < V3.15.10), SIMATIC WinCC OA UI for iOS (All versions < V3.15.10). Insufficient limitation of CONTROL script capabilities could allow read and write access from one HMI project cache folder to other HMI project cache folders within…
ModificadaMedia (4.9)3.7%—Siemens Simatic Pcs7Siemens Simatic Wincc6/11/201717/6/2026
An Improper Input Validation issue was discovered in Siemens SIMATIC PCS 7 V8.1 prior to V8.1 SP1 with WinCC V7.3 Upd 13, and V8.2 all versions. The improper input validation vulnerability has been identified, which may allow an authenticated remote attacker who is a member of the administrators group to crash…
ModificadaAlta (8.2)2.9%—Siemens Simatic Pcs7Siemens WinccOcpfoundation Local Discovery ServerOcpfoundation UA .net30/8/201717/6/2026
An XXE vulnerability has been identified in OPC Foundation UA .NET Sample Code before 2017-03-21 and Local Discovery Server (LDS) before 1.03.367. Among the affected products are Siemens SIMATIC PCS7 (All versions V8.1 and earlier), SIMATIC WinCC (All versions < V7.4 SP1), SIMATIC WinCC Runtime Professional (All…
ModificadaMedia (5.4)0.32%—Siemens Simatic Wincc Sm@rtclientSiemens Simatic Wincc Sm@rtclient Lite8/8/201717/6/2026
A vulnerability was discovered in Siemens SIMATIC WinCC Sm@rtClient for Android (All versions before V1.0.2.2) and SIMATIC WinCC Sm@rtClient for Android Lite (All versions before V1.0.2.2). An attacker with physical access to an unlocked mobile device, that has the affected app running, could bypass the app's…
ModificadaAlta (7.4)0.95%—Siemens Simatic Wincc Sm@rtclient8/8/201717/6/2026
A vulnerability was discovered in Siemens SIMATIC WinCC Sm@rtClient for Android (All versions before V1.0.2.2). The existing TLS protocol implementation could allow an attacker to read and modify data within a TLS session while performing a Man-in-the-Middle (MitM) attack.
ModificadaMedia (4.9)1.9%—Siemens Simatic WinccSiemens Simatic Wincc (tia Portal)Siemens Simatic Wincc Runtime11/5/201717/6/2026
A vulnerability was discovered in Siemens SIMATIC WinCC (V7.3 before Upd 11 and V7.4 before SP1), SIMATIC WinCC Runtime Professional (V13 before SP2 and V14 before SP1), SIMATIC WinCC (TIA Portal) Professional (V13 before SP2 and V14 before SP1) that could allow an authenticated, remote attacker who is member of the…
ModificadaMedia (6.5)0.47%—Siemens PCS 7Siemens Primary Setup ToolSiemens Security Configuration ToolSiemens Simatic Automation Tool+1211/5/201717/6/2026
A vulnerability has been identified in Primary Setup Tool (PST) (All versions < V4.2 HF1), SIMATIC Automation Tool (All versions < V3.0), SIMATIC NET PC-Software (All versions < V14 SP1), SIMATIC PCS 7 V8.1 (All versions), SIMATIC PCS 7 V8.2 (All versions < V8.2 SP1), SIMATIC STEP 7 (TIA Portal) V13 (All versions <…
ModificadaAlta (8.1)1.4%—Siemens Simatic PCS 7Siemens Simatic Wincc17/12/201617/6/2026
A vulnerability in SIEMENS SIMATIC WinCC (All versions < SIMATIC WinCC V7.2) and SIEMENS SIMATIC PCS 7 (All versions < SIMATIC PCS 7 V8.0 SP1) could allow a remote attacker to crash an ActiveX component or leak parts of the application memory if a user is tricked into clicking on a malicious link under certain…
ModificadaMedia (6.4)0.38%—Siemens Primary Setup ToolSiemens Security Configuration ToolSiemens Simatic IT Production SuiteSiemens Simatic NET PC Software+1415/11/201617/6/2026
A vulnerability has been identified in Primary Setup Tool (PST) (All versions < V4.2 HF1), SIMATIC IT Production Suite (All versions < V7.0 SP1 HFX 2), SIMATIC NET PC-Software (All versions < V14), SIMATIC PCS 7 V7.1 (All versions), SIMATIC PCS 7 V8.0 (All versions), SIMATIC PCS 7 V8.1 (All versions), SIMATIC PCS 7…
ModificadaAlta (7.5)4.4%—Siemens Simatic Wincc22/7/201617/6/2026
Siemens SIMATIC WinCC 7.0 through SP3 and 7.2 allows remote attackers to read arbitrary WinCC station files via crafted packets.
ModificadaCrítica (9.8)10%—Siemens Simatic BatchSiemens Simatic WinccSiemens Simatic Openpcs 722/7/201617/6/2026
Siemens SIMATIC WinCC before 7.3 Update 10 and 7.4 before Update 1, SIMATIC BATCH before 8.1 SP1 Update 9 as distributed in SIMATIC PCS 7 through 8.1 SP1, SIMATIC OpenPCS 7 before 8.1 Update 3 as distributed in SIMATIC PCS 7 through 8.1 SP1, SIMATIC OpenPCS 7 before 8.2 Update 1 as distributed in SIMATIC PCS 7 8.2,…
ModificadaBaja (2.1)0.45%—Siemens Simatic Wincc Sm@rtclientSiemens Simatic Wincc Sm@rtclient Lite3/8/201517/6/2026
The Siemens SIMATIC WinCC Sm@rtClient and Sm@rtClient Lite applications before 01.00.01.00 for Android do not properly store passwords, which allows physically proximate attackers to obtain sensitive information via unspecified vectors.
ModificadaMedia (6.8)2.1%—Siemens Wincc8/4/201517/6/2026
Siemens SIMATIC HMI Basic Panels 2nd Generation before WinCC (TIA Portal) 13 SP1 Upd2, SIMATIC HMI Comfort Panels before WinCC (TIA Portal) 13 SP1 Upd2, SIMATIC WinCC Runtime Advanced before WinCC (TIA Portal) 13 SP1 Upd2, SIMATIC WinCC Runtime Professional before WinCC (TIA Portal) 13 SP1 Upd2, SIMATIC HMI Basic…
Orbitaley — Vulnerabilidades