Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2829▼ 255 respecto a la semana anterior
Críticas / altas1324▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
2424 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 0.36% | — | Siemens Cpci85 Firmware | 13/6/2023 | 17/6/2026 | A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). The affected devices contain the hash of the root password in a hard-coded form, which could be exploited for UART console login to the device. An attacker with direct physical… | |
| Modificada | Alta (7.2) | 48% | — | Siemens Cpci85 Firmware | 13/6/2023 | 17/6/2026 | A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). The web interface of affected devices is vulnerable to command injection due to missing server side input sanitation. This could allow an authenticated privileged remote attacker… | |
| Modificada | Alta (7.8) | 0.22% | — | Siemens Jt2goSiemens Teamcenter Visualization | 13/6/2023 | 17/6/2026 | A vulnerability has been identified in JT2Go (All versions < V14.2.0.3), Teamcenter Visualization V13.2 (All versions < V13.2.0.13), Teamcenter Visualization V13.3 (All versions < V13.3.0.10), Teamcenter Visualization V14.0 (All versions < V14.0.0.6), Teamcenter Visualization V14.1 (All versions < V14.1.0.8),… | |
| Modificada | Alta (7.8) | 0.22% | — | Siemens Jt2goSiemens Teamcenter Visualization | 13/6/2023 | 17/6/2026 | A vulnerability has been identified in JT2Go (All versions < V14.2.0.3), Teamcenter Visualization V13.2 (All versions < V13.2.0.13), Teamcenter Visualization V13.3 (All versions < V13.3.0.10), Teamcenter Visualization V14.0 (All versions < V14.0.0.6), Teamcenter Visualization V14.1 (All versions < V14.1.0.8),… | |
| Modificada | Media (5.5) | 0.19% | — | Siemens Jt2goSiemens Teamcenter Visualization | 13/6/2023 | 17/6/2026 | A vulnerability has been identified in JT2Go (All versions < V14.2.0.3), Teamcenter Visualization V13.2 (All versions < V13.2.0.13), Teamcenter Visualization V13.3 (All versions < V13.3.0.10), Teamcenter Visualization V14.0 (All versions < V14.0.0.6), Teamcenter Visualization V14.1 (All versions < V14.1.0.8),… | |
| Modificada | Media (5.5) | 0.18% | — | Siemens Jt2goSiemens Teamcenter Visualization | 13/6/2023 | 17/6/2026 | A vulnerability has been identified in JT2Go (All versions < V14.2.0.3), Teamcenter Visualization V13.2 (All versions < V13.2.0.13), Teamcenter Visualization V13.3 (All versions < V13.3.0.10), Teamcenter Visualization V14.0 (All versions < V14.0.0.6), Teamcenter Visualization V14.1 (All versions < V14.1.0.8),… | |
| Modificada | Media (4.8) | 0.43% | — | Siemens Q200 Firmware | 13/6/2023 | 17/6/2026 | A vulnerability has been identified in SICAM P850 (7KG8500-0AA00-0AA0) (All versions < V3.11), SICAM P850 (7KG8500-0AA00-2AA0) (All versions < V3.11), SICAM P850 (7KG8500-0AA10-0AA0) (All versions < V3.11), SICAM P850 (7KG8500-0AA10-2AA0) (All versions < V3.11), SICAM P850 (7KG8500-0AA30-0AA0) (All versions < V3.11),… | |
| Modificada | Alta (8.8) | 0.36% | — | Siemens Q200 Firmware | 13/6/2023 | 17/6/2026 | A vulnerability has been identified in SICAM P850 (7KG8500-0AA00-0AA0) (All versions < V3.11), SICAM P850 (7KG8500-0AA00-2AA0) (All versions < V3.11), SICAM P850 (7KG8500-0AA10-0AA0) (All versions < V3.11), SICAM P850 (7KG8500-0AA10-2AA0) (All versions < V3.11), SICAM P850 (7KG8500-0AA30-0AA0) (All versions < V3.11),… | |
| Modificada | Alta (7.8) | 0.21% | — | Siemens Wincc | 13/6/2023 | 17/6/2026 | A vulnerability has been identified in SIMATIC WinCC (All versions < V7.5.2.13). Affected applications fail to set proper access rights for their installation folder if a non-default installation path was chosen during installation. This could allow an authenticated local attacker to inject arbitrary code and escalate… | |
| Modificada | Media (5.5) | 0.12% | — | Siemens Totally Integrated Automation Portal | 13/6/2023 | 17/6/2026 | A vulnerability has been identified in Totally Integrated Automation Portal (TIA Portal) V14 (All versions), Totally Integrated Automation Portal (TIA Portal) V15 (All versions), Totally Integrated Automation Portal (TIA Portal) V15.1 (All versions), Totally Integrated Automation Portal (TIA Portal) V16 (All… | |
| Modificada | Alta (8.8) | 0.29% | — | Siemens Simatic NET PC SoftwareSiemens Simatic PCS 7Siemens Simatic WinccSiemens Sinaut St7sc | 13/6/2023 | 17/6/2026 | A vulnerability has been identified in SIMATIC NET PC Software V14 (All versions), SIMATIC NET PC Software V15 (All versions), SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions), SIMATIC PCS 7 V9.1 (All versions), SIMATIC WinCC (All versions < V8.0), SINAUT Software ST7sc (All versions). Before… | |
| Modificada | Media (4.6) | 0.28% | — | Siemens Simotion D425-2 DP FirmwareSiemens Simotion D425-2 Dp/pn FirmwareSiemens Simotion D435-2 DP FirmwareSiemens Simotion D435-2 Dp/pn Firmware+9 | 13/6/2023 | 17/6/2026 | A vulnerability has been identified in SIMOTION C240 (All versions >= V5.4 < V5.5 SP1), SIMOTION C240 PN (All versions >= V5.4 < V5.5 SP1), SIMOTION D410-2 DP (All versions >= V5.4 < V5.5 SP1), SIMOTION D410-2 DP/PN (All versions >= V5.4 < V5.5 SP1), SIMOTION D425-2 DP (All versions >= V5.4 < V5.5 SP1), SIMOTION… | |
| Modificada | Crítica (9.8) | 0.43% | — | Fortinet Fortisiem | 13/6/2023 | 17/6/2026 | A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions, 6.1 all versions, 5.4 all versions, 5.3 all versions may allow an attacker able to access user DB content to impersonate any admin user on… | |
| Modificada | Alta (8.8) | 1.0% | — | Siemens Simatic PCS 7Siemens Simatic S7-pmSiemens Simatic Step 7 | 13/6/2023 | 17/6/2026 | Se ha identificado una vulnerabilidad en SIMATIC PCS 7 (todas las versiones < V9.1 SP2 UC04), SIMATIC S7-PM (todas las versiones), SIMATIC STEP 7 V5 (todas las versiones < V5.7). El producto afectado contiene un sistema de gestión de bases de datos que podría permitir a usuarios remotos con pocos privilegios… | |
| Modificada | Alta (7.5) | 0.36% | — | Fortinet Fortisiem | 13/6/2023 | 17/6/2026 | A use of a broken or risky cryptographic algorithm [CWE-327] in Fortinet FortiSIEM before 6.7.1 allows a remote unauthenticated attacker to perform brute force attacks on GUI endpoints via taking advantage of outdated hashing methods. | |
| Modificada | Alta (8.8) | 0.53% | — | Fortinet Fortisiem | 13/6/2023 | 17/6/2026 | An Improper Restriction of Excessive Authentication Attempts [CWE-307] in FortiSIEM below 7.0.0 may allow a non-privileged user with access to several endpoints to brute force attack these endpoints. | |
| Modificada | Alta (7.8) | 0.26% | — | Siemens Jt2goSiemens Teamcenter Visualization | 7/6/2023 | 17/6/2026 | Datalogics Library APDFLThe v18.0.4PlusP1e and prior contains a stack-based buffer overflow due to documents containing corrupted fonts, which could allow an attack that causes an unhandled crash during the rendering process. | |
| Modificada | Alta (7.8) | 0.23% | — | Siemens Solid Edge Se2023 | 9/5/2023 | 17/6/2026 | A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 3), Solid Edge SE2023 (All versions < V223.0 Update 2). Affected applications contain a memory corruption vulnerability while parsing specially crafted STP files. This could allow an attacker to execute code in the context of the… | |
| Modificada | Media (5.5) | 0.20% | — | Siemens Solid Edge Se2023 | 9/5/2023 | 17/6/2026 | A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 3), Solid Edge SE2023 (All versions < V223.0 Update 2). Affected applications contain an out of bounds read past the end of an allocated buffer while parsing a specially crafted OBJ file. This vulnerability could allow an attacker… | |
| Modificada | Alta (8.8) | 1.1% | — | Siemens Siveillance Video | 9/5/2023 | 17/6/2026 | A vulnerability has been identified in Siveillance Video 2020 R2 (All versions < V20.2 HotfixRev14), Siveillance Video 2020 R3 (All versions < V20.3 HotfixRev12), Siveillance Video 2021 R1 (All versions < V21.1 HotfixRev12), Siveillance Video 2021 R2 (All versions < V21.2 HotfixRev8), Siveillance Video 2022 R1 (All… | |
| Modificada | Alta (8.8) | 1.1% | — | Siemens Siveillance Video | 9/5/2023 | 17/6/2026 | A vulnerability has been identified in Siveillance Video 2020 R2 (All versions < V20.2 HotfixRev14), Siveillance Video 2020 R3 (All versions < V20.3 HotfixRev12), Siveillance Video 2021 R1 (All versions < V21.1 HotfixRev12), Siveillance Video 2021 R2 (All versions < V21.2 HotfixRev8), Siveillance Video 2022 R1 (All… | |
| Modificada | Baja (2.7) | 0.68% | — | Siemens 6gk1411-1ac00 FirmwareSiemens 6gk1411-5ac00 Firmware | 9/5/2023 | 17/6/2026 | A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC716 (All versions >= V2.0 < V2.1). The filename in the upload feature of the web based management of the affected device is susceptible to a path traversal vulnerability. This could allow an… | |
| Modificada | Media (5.3) | 0.65% | — | Siemens 6gk1411-1ac00 FirmwareSiemens 6gk1411-5ac00 Firmware | 9/5/2023 | 17/6/2026 | A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC716 (All versions >= V2.0 < V2.1). The export endpoint discloses some undocumented files. This could allow an unauthenticated remote attacker to gain access to additional information resources. | |
| Modificada | Alta (7.5) | 0.72% | — | Siemens 6gk1411-1ac00 FirmwareSiemens 6gk1411-5ac00 Firmware | 9/5/2023 | 17/6/2026 | A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC716 (All versions >= V2.0 < V2.1). The export endpoint is accessible via REST API without authentication. This could allow an unauthenticated remote attacker to download the files available via… | |
| Modificada | Alta (7.5) | 0.55% | — | Siemens 6gk1411-1ac00 FirmwareSiemens 6gk1411-5ac00 Firmware | 9/5/2023 | 17/6/2026 | A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC712 (All versions < V2.1), SIMATIC Cloud Connect 7 CC716 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC716 (All versions < V2.1). The affected device is vulnerable to a denial of… |