Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

130 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.7%—Rockwellautomation Micrologix 1400 B Firmware4/6/201817/6/2026
An exploitable file write vulnerability exists in the memory module functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a file write resulting in a new program being written to the memory module. An attacker can send an unauthenticated packet to trigger…
ModificadaCrítica (9.8)38%—Rockwellautomation Micrologix 1400 B Firmware5/4/201817/6/2026
An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive information, modification of settings,…
ModificadaCrítica (9.8)38%—Rockwellautomation Micrologix 1400 B Firmware5/4/201817/6/2026
An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive information, modification of settings,…
ModificadaCrítica (9.8)38%—Rockwellautomation Micrologix 1400 B Firmware5/4/201817/6/2026
An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive information, modification of settings,…
ModificadaCrítica (9.8)38%—Rockwellautomation Micrologix 1400 B Firmware5/4/201817/6/2026
An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive information, modification of settings,…
ModificadaCrítica (9.8)38%—Rockwellautomation Micrologix 1400 B Firmware5/4/201817/6/2026
An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive information, modification of settings,…
ModificadaCrítica (9.8)38%—Rockwellautomation Micrologix 1400 B Firmware5/4/201817/6/2026
An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive information, modification of settings,…
ModificadaCrítica (9.8)37%—Rockwellautomation Micrologix 1400 B Firmware5/4/201817/6/2026
An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive information, modification of settings,…
ModificadaCrítica (9.8)38%—Rockwellautomation Micrologix 1400 B Firmware5/4/201817/6/2026
An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive information, modification of settings,…
ModificadaCrítica (9.8)35%—Rockwellautomation Micrologix 1400 B Firmware5/4/201817/6/2026
An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive information, modification of settings,…
ModificadaCrítica (9.8)38%—Rockwellautomation Micrologix 1400 B Firmware5/4/201817/6/2026
An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive information, modification of settings,…
ModificadaCrítica (9.8)39%—Rockwellautomation Micrologix 1400 B Firmware5/4/201817/6/2026
An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive information, modification of settings,…
ModificadaCrítica (9.8)35%—Rockwellautomation Micrologix 1400 B Firmware5/4/201817/6/2026
An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive information, modification of settings,…
ModificadaMedia (5.3)6.0%—Rockwellautomation Micrologix 1400 B Firmware5/4/201817/6/2026
An exploitable insufficient resource pool vulnerability exists in the session communication functionality of Allen Bradley Micrologix 1400 Series B Firmware 21.2 and before. A specially crafted stream of packets can cause a flood of the session resource pool resulting in legitimate connections to the PLC being…
ModificadaAlta (7.5)4.7%—Rockwellautomation Micrologix 1400 B Firmware5/4/201817/6/2026
An exploitable denial of service vulnerability exists in the processing of snmp-set commands of the Allen Bradley Micrologix 1400 Series B FRN 21.2 and below. A specially crafted snmp-set request, when sent without associated firmware flashing snmp-set commands, can cause a device power cycle resulting in downtime for…
ModificadaAlta (7.5)4.8%—Rockwellautomation Micrologix 1400 B Firmware5/4/201817/6/2026
An exploitable denial of service vulnerability exists in the program download functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a device fault resulting in halted operations. An attacker can send an unauthenticated packet to trigger this vulnerability.
ModificadaAlta (7.5)4.6%—Rockwellautomation Micrologix 1400 B Firmware5/4/201817/6/2026
An exploitable denial of service vulnerability exists in the Ethernet functionality of the Allen Bradley Micrologix 1400 Series B FRN 21.2 and below. A specially crafted packet can cause a device power cycle resulting in a fault state and deletion of ladder logic. An attacker can send one unauthenticated packet to…
ModificadaMedia (5.9)2.6%—Rockwellautomation Compactlogix 5380 FirmwareRockwellautomation Controllogix 5580 Firmware6/5/201717/6/2026
A Resource Exhaustion issue was discovered in Rockwell Automation ControlLogix 5580 controllers V28.011, V28.012, and V28.013; ControlLogix 5580 controllers V29.011; CompactLogix 5380 controllers V28.011; and CompactLogix 5380 controllers V29.011. This vulnerability may allow an attacker to cause a denial of service…
ModificadaCrítica (10)10%—Rockwellautomation Softlogix 5800 Controller FirmwareRockwellautomation Rslogix Emulate 5000 FirmwareRockwellautomation Guardlogix 5570 Controller FirmwareRockwellautomation Flexlogix L34 Controller Firmware+1213/2/201717/6/2026
An issue was discovered in Rockwell Automation Logix5000 Programmable Automation Controller FRN 16.00 through 21.00 (excluding all firmware versions prior to FRN 16.00, which are not affected). By sending malformed common industrial protocol (CIP) packet, an attacker may be able to overflow a stack-based buffer and…
ModificadaAlta (8.6)4.7%—Rockwellautomation Rslogix 500 Professional EditionRockwellautomation Rslogix 500 Standard EditionRockwellautomation Rslogix 500 Starter EditionRockwellautomation Rslogix Micro Developer+119/9/201617/6/2026
Buffer overflow in Rockwell Automation RSLogix Micro Starter Lite, RSLogix Micro Developer, RSLogix 500 Starter Edition, RSLogix 500 Standard Edition, and RSLogix 500 Professional Edition allows remote attackers to execute arbitrary code via a crafted RSS project file.
ModificadaMedia (6.1)7.6%💥 ExploitRockwellautomation Compactlogix 1769-l16er-bb1b FirmwareRockwellautomation Compactlogix 1769-l18er-bb1b FirmwareRockwellautomation Compactlogix 1769-l18erm-bb1b FirmwareRockwellautomation Compactlogix 1769-l24er-qb1b Firmware+192/3/201617/6/2026
Cross-site scripting (XSS) vulnerability in the web server in Rockwell Automation Allen-Bradley CompactLogix 1769-L* before 28.011+ allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)4.5%—Rockwellautomation Micrologix 1100 FirmwareRockwellautomation Micrologix 1400 Firmware28/10/201517/6/2026
Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices before B FRN 15.003 allow remote attackers to cause a denial of service (memory corruption and device crash) via a crafted HTTP request.
ModificadaMedia (4)1.6%—Rockwellautomation Micrologix 1100 FirmwareRockwellautomation Micrologix 1400 Firmware28/10/201517/6/2026
Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices before B FRN 15.003 allow remote authenticated users to insert the content of an arbitrary file into a FRAME element via unspecified vectors.
ModificadaCrítica (9.8)7.0%—Rockwellautomation Micrologix 1100 FirmwareRockwellautomation Micrologix 1400 Firmware28/10/201517/6/2026
Stack-based buffer overflow on Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices through B FRN 15.003 allows remote attackers to execute arbitrary code via unspecified vectors.
ModificadaMedia (4.3)2.8%—Rockwellautomation Micrologix 1100 FirmwareRockwellautomation Micrologix 1400 Firmware28/10/201517/6/2026
Cross-site scripting (XSS) vulnerability in the web server on Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices before B FRN 15.003 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Orbitaley — Vulnerabilidades