Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2808▼ 273 respecto a la semana anterior
Críticas / altas1313▼ 193 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
2424 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.6) | 0.71% | — | Siemens 6gk1411-1ac00 FirmwareSiemens 6gk1411-5ac00 Firmware | 9/5/2023 | 17/6/2026 | A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC716 (All versions >= V2.0 < V2.1). The filename in the upload feature of the web based management of the affected device is susceptible to a path traversal vulnerability. This could allow an… | |
| Modificada | Media (4.3) | 0.39% | — | Siemens 6gk1411-1ac00 FirmwareSiemens 6gk1411-5ac00 Firmware | 9/5/2023 | 17/6/2026 | A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC712 (All versions < V2.1), SIMATIC Cloud Connect 7 CC716 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC716 (All versions < V2.1). The affected device uses a hard-coded password to… | |
| Modificada | Alta (7.2) | 1.5% | — | Siemens 6gk1411-1ac00 FirmwareSiemens 6gk1411-5ac00 Firmware | 9/5/2023 | 17/6/2026 | A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC716 (All versions >= V2.0 < V2.1). The web based management of affected devices does not properly validate user input, making it susceptible to command injection. This could allow an… | |
| Modificada | Baja (2.7) | 0.56% | — | Siemens Scalance Lpe9403 Firmware | 9/5/2023 | 17/6/2026 | A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). A heap-based buffer overflow vulnerability was found in the `edgebox_web_app` binary. The binary will crash if supplied with a backup password longer than 255 characters. This could allow an authenticated privileged attacker to cause a… | |
| Modificada | Baja (3.3) | 0.17% | — | Siemens Scalance Lpe9403 Firmware | 9/5/2023 | 17/6/2026 | A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). A path traversal vulnerability was found in the `deviceinfo` binary via the `mac` parameter. This could allow an authenticated attacker with access to the SSH interface on the affected device to read the contents of any file named `address`. | |
| Modificada | Baja (3.3) | 0.17% | — | Siemens Scalance Lpe9403 Firmware | 9/5/2023 | 17/6/2026 | A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). The `i2c` mutex file is created with the permissions bits of `-rw-rw-rw-`. This file is used as a mutex for multiple applications interacting with i2c. This could allow an authenticated attacker with access to the SSH interface on the… | |
| Modificada | Crítica (9.9) | 1.3% | — | Siemens Scalance Lpe9403 Firmware | 9/5/2023 | 17/6/2026 | A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). The web based management of affected device does not properly validate user input, making it susceptible to command injection. This could allow an authenticated remote attacker to access the underlying operating system as the root user. | |
| Modificada | Alta (7.4) | 0.26% | — | Siemens Scalance X200-4p IRT FirmwareSiemens Scalance X201-3p IRT FirmwareSiemens Scalance X201-3p IRT PRO FirmwareSiemens Scalance X202-2irt Firmware+9 | 11/4/2023 | 17/6/2026 | A vulnerability has been identified in SCALANCE X200-4P IRT (All versions < V5.5.2), SCALANCE X201-3P IRT (All versions < V5.5.2), SCALANCE X201-3P IRT PRO (All versions < V5.5.2), SCALANCE X202-2IRT (All versions < V5.5.2), SCALANCE X202-2IRT (All versions < V5.5.2), SCALANCE X202-2P IRT (All versions < V5.5.2),… | |
| Modificada | Alta (7.8) | 0.22% | — | Siemens JT Open ToolkitSiemens JT Utilities | 11/4/2023 | 17/6/2026 | A vulnerability has been identified in JT Open (All versions < V11.3.2.0), JT Utilities (All versions < V13.3.0.0). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted JT files. This could allow an attacker to execute code in the context of the… | |
| Modificada | Alta (7.5) | 0.59% | — | Siemens Polarion ALM | 11/4/2023 | 17/6/2026 | A vulnerability has been identified in Polarion ALM (All versions < V22R2). The application contains a XML External Entity Injection (XXE) vulnerability. This could allow an attacker to view files on the application server filesystem. | |
| Modificada | Alta (7.5) | 0.94% | — | Siemens Siprotec 5 6md85 FirmwareSiemens Siprotec 5 6md86 FirmwareSiemens Siprotec 5 6md89 FirmwareSiemens Siprotec 5 6mu85 Firmware+35 | 11/4/2023 | 17/6/2026 | Se ha identificado una vulnerabilidad en SIPROTEC 5 6MD85 (CP300) (Todas las versiones >= V7.80 < V9.40), SIPROTEC 5 6MD86 (CP300) (Todas las versiones >= V7.80 < V9.40), SIPROTEC 5 6MD89 ( CP300) (Todas las versiones >= V7.80 < V9.60), SIPROTEC 5 6MU85 (CP300) (Todas las versiones >= V7.80 <… | |
| Modificada | Crítica (9.8) | 2.8% | — | Siemens Cp-8031 FirmwareSiemens Cp-8050 Firmware | 11/4/2023 | 17/6/2026 | A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). Affected devices are vulnerable to command injection via the web server port 443/tcp, if the parameter “Remote Operation” is enabled. The parameter is disabled by default. The… | |
| Modificada | Alta (7.8) | 0.25% | — | Siemens TIA Portal | 11/4/2023 | 17/6/2026 | A vulnerability has been identified in Totally Integrated Automation Portal (TIA Portal) V15 (All versions), Totally Integrated Automation Portal (TIA Portal) V16 (All versions < V16 Update 7), Totally Integrated Automation Portal (TIA Portal) V17 (All versions < V17 Update 6), Totally Integrated Automation Portal… | |
| Modificada | Media (6.3) | 0.09% | — | Siemens Simatic Ipc647d FirmwareSiemens Simatic Ipc847d FirmwareSiemens Simatic Ipc1047 FirmwareMicrochip Maxview Storage Manager | 11/4/2023 | 17/6/2026 | A vulnerability has been identified in SIMATIC IPC1047 (All versions), SIMATIC IPC1047E (All versions with maxView Storage Manager < 4.09.00.25611 on Windows), SIMATIC IPC647D (All versions), SIMATIC IPC647E (All versions with maxView Storage Manager < 4.09.00.25611 on Windows), SIMATIC IPC847D (All versions), SIMATIC… | |
| Modificada | Alta (7.5) | 0.95% | — | Siemens Simatic CP 1242-7 V2 FirmwareSiemens Simatic CP 1243-1 FirmwareSiemens Simatic CP 1243-1 Dnp3 FirmwareSiemens Simatic CP 1243-1 IEC Firmware+20 | 11/4/2023 | 17/6/2026 | A vulnerability has been identified in SIMATIC CP 1242-7 V2 (6GK7242-7KX31-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 (6GK7243-1BX30-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions < V3.4.29), SIMATIC CP 1243-1 IEC (incl. SIPLUS variants) (All versions < V3.4.29),… | |
| Modificada | Alta (7.5) | 0.72% | — | Siemens Simatic CP 1242-7 V2 FirmwareSiemens Simatic CP 1243-1 FirmwareSiemens Simatic CP 1243-1 Dnp3 FirmwareSiemens Simatic CP 1243-1 IEC Firmware+20 | 11/4/2023 | 17/6/2026 | A vulnerability has been identified in SIMATIC CP 1242-7 V2 (6GK7242-7KX31-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 (6GK7243-1BX30-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions < V3.4.29), SIMATIC CP 1243-1 IEC (incl. SIPLUS variants) (All versions < V3.4.29),… | |
| Modificada | Alta (7.5) | 0.95% | — | Siemens Simatic CP 1242-7 V2 FirmwareSiemens Simatic CP 1243-1 FirmwareSiemens Simatic CP 1243-1 Dnp3 FirmwareSiemens Simatic CP 1243-1 IEC Firmware+20 | 11/4/2023 | 17/6/2026 | A vulnerability has been identified in SIMATIC CP 1242-7 V2 (6GK7242-7KX31-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 (6GK7243-1BX30-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions < V3.4.29), SIMATIC CP 1243-1 IEC (incl. SIPLUS variants) (All versions < V3.4.29),… | |
| Modificada | Alta (8.8) | 0.80% | — | Siemens Ruggedcom Crossbow | 14/3/2023 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.3). The audit log form of affected applications is vulnerable to SQL injection. This could allow authenticated remote attackers to execute arbitrary SQL queries on the server database. | |
| Modificada | Media (4.3) | 0.52% | — | Siemens Ruggedcom Crossbow | 14/3/2023 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.3). The client query handler of the affected application fails to check for proper permissions for specific read queries. This could allow authenticated remote attackers to access data they are not authorized for. | |
| Modificada | Alta (7.8) | 0.22% | — | Siemens Tecnomatix Plant Simulation | 14/3/2023 | 17/6/2026 | A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application is vulnerable to stack-based buffer while parsing specially crafted SPP files. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-20449) | |
| Modificada | Alta (7.8) | 0.22% | — | Siemens Tecnomatix Plant Simulation | 14/3/2023 | 17/6/2026 | A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted SPP files. This could allow an attacker to execute code in the context of the current process.… | |
| Modificada | Alta (7.8) | 2.5% | — | Siemens Tecnomatix Plant Simulation | 14/3/2023 | 17/6/2026 | A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application is vulnerable to stack-based buffer while parsing specially crafted SPP files. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-20433) | |
| Modificada | Alta (7.8) | 0.22% | — | Siemens Tecnomatix Plant Simulation | 14/3/2023 | 17/6/2026 | A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains a memory corruption vulnerability while parsing specially crafted SPP files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-20303,… | |
| Modificada | Alta (7.8) | 0.22% | — | Siemens Tecnomatix Plant Simulation | 14/3/2023 | 17/6/2026 | A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted SPP files. This could allow an attacker to execute code in the context of the current process.… | |
| Modificada | Alta (7.8) | 0.22% | — | Siemens Tecnomatix Plant Simulation | 14/3/2023 | 17/6/2026 | A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted SPP files. This could allow an attacker to execute code in the context of the current process.… |