Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
–

787 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.60%—Schneider-electric Struxureware Data Center Expert12/7/202317/6/2026
A CWE-89: Improper Neutralization of Special Elements vulnerability used in an SQL Command ('SQL Injection') vulnerability exists that could allow a user already authenticated on DCE to access unauthorized content, change, or delete content, or perform unauthorized actions when tampering with the alert settings of…
ModificadaAlta (7.8)32%—Schneider-electric Igss Dashboard14/6/202317/6/2026
A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpretation of malicious payload data, potentially leading to remote code execution when an attacker gets the user to open a malicious file.
ModificadaAlta (7.8)0.16%—Schneider-electric Ecostruxure Foxboro DCS Control Core Services14/6/202317/6/2026
A CWE-129: Improper Validation of Array Index vulnerability exists that could cause local denial-of-service, and potentially kernel execution when a malicious actor with local user access crafts a script/program using an unpredictable index to an IOCTL call in the Foxboro.sys driver.
ModificadaAlta (7.8)0.19%—Schneider-electric Ecostruxure Foxboro DCS Control Core Services14/6/202317/6/2026
A CWE-787: Out-of-Bounds Write vulnerability exists that could cause local denial-of-service, elevation of privilege, and potentially kernel execution when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver.
ModificadaAlta (7.8)0.60%—Schneider-electric Ecostruxure Operator Terminal ExpertSchneider-electric Pro-face Blue14/6/202317/6/2026
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause execution of malicious code when an unsuspicious user loads a project file from the local filesystem into the HMI.
ModificadaCrítica (9.8)0.38%—Schneider-electric Powerlogic Ion9000 FirmwareSchneider-electric Powerlogic Ion7400 FirmwareSchneider-electric Powerlogic Pm8000 FirmwareSchneider-electric Powerlogic Ion8650 Firmware+122/5/202317/6/2026
A CWE-319: Cleartext transmission of sensitive information vulnerability exists that could cause disclosure of sensitive information, denial of service, or modification of data if an attacker is able to intercept network traffic.
ModificadaMedia (5.5)0.17%—Schneider-electric OPC Factory Server16/5/202317/6/2026
A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause unauthorized read access to the file system when a malicious configuration file is loaded on to the software by a local user.
ModificadaMedia (6.5)0.59%—Schneider-electric Modicon M580 FirmwareSchneider-electric Modicon M340 FirmwareSchneider-electric Modicon Momentum Unity M1E Processor FirmwareSchneider-electric Modicon Mc80 Firmware+419/4/202317/6/2026
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause denial of service of the controller when a malicious project file is loaded onto the controller by an authenticated user.
ModificadaAlta (7.5)0.62%—Schneider-electric Modicon M580 FirmwareSchneider-electric Modicon M340 FirmwareSchneider-electric Modicon Momentum Unity M1E Processor FirmwareSchneider-electric Modicon Mc80 Firmware+319/4/202317/6/2026
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause denial of service of the controller when communicating over the Modbus TCP protocol.
ModificadaAlta (8.8)0.66%—Schneider-electric Insighthome FirmwareSchneider-electric Insightfacility FirmwareSchneider-electric Conext Gateway Firmware18/4/202317/6/2026
A CWE-20: Improper Input Validation vulnerability exists that could allow an authenticated attacker to gain the same privilege as the application on the server when a malicious payload is provided over HTTP for the server to execute.
ModificadaCrítica (9.8)1.1%—Schneider-electric Powerlogic Hdpm6000 Firmware18/4/202317/6/2026
A CWE-129: Improper validation of an array index vulnerability exists where a specially crafted Ethernet request could result in denial of service or remote code execution.
ModificadaAlta (7.5)0.71%—Schneider-electric APC Easy UPS Online Monitoring SoftwareSchneider-electric Easy UPS Online Monitoring Software18/4/202317/6/2026
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause Denial-of-Service when accessed by an unauthenticated user on the Schneider UPS Monitor service.
ModificadaCrítica (9.8)1.2%—Schneider-electric APC Easy UPS Online Monitoring SoftwareSchneider-electric Easy UPS Online Monitoring Software18/4/202317/6/2026
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code execution when manipulating internal methods through Java RMI interface.
ModificadaCrítica (9.8)1.3%—Schneider-electric APC Easy UPS Online Monitoring SoftwareSchneider-electric Easy UPS Online Monitoring Software18/4/202317/6/2026
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow changes to administrative credentials, leading to potential remote code execution without requiring prior authentication on the Java RMI interface.
ModificadaAlta (8.8)0.32%—Schneider-electric Ecostruxure Power Monitoring Expert18/4/202317/6/2026
A CWE-613: Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain unauthorized access over a hijacked session in PME after the legitimate user has signed out of their account.
ModificadaAlta (8.1)0.82%—Schneider-electric Struxureware Data Center Expert18/4/202317/6/2026
A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow a user that knows the credentials to execute unprivileged shell commands on the appliance over SSH. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
ModificadaAlta (7.8)0.59%—Schneider-electric Struxureware Data Center Expert18/4/202317/6/2026
A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that allows a local privilege escalation on the appliance when a maliciously crafted Operating System command is entered on the device. Affected products: StruxureWare Data Center Expert (V7.9.2…
ModificadaMedia (6.1)0.39%—Schneider-electric Struxureware Data Center Expert18/4/202317/6/2026
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists on a DCE endpoint through the logging capabilities of the webserver. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
ModificadaAlta (8.1)0.50%—Schneider-electric Struxureware Data Center Expert18/4/202317/6/2026
A CWE-862: Missing Authorization vulnerability exists that could allow viewing of unauthorized content, changes or deleting of content, or performing unauthorized functions when tampering the Device File Transfer settings on DCE endpoints. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
ModificadaMedia (6.1)0.40%—Schneider-electric Struxureware Data Center Expert18/4/202317/6/2026
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists on a DCE file upload endpoint when tampering with parameters over HTTP. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
ModificadaCrítica (9.8)1.2%—Schneider-electric Struxureware Data Center Expert18/4/202317/6/2026
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that allows remote code execution via the “hostname” parameter when maliciously crafted hostname syntax is entered. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
ModificadaCrítica (9.8)1.2%—Schneider-electric Struxureware Data Center Expert18/4/202317/6/2026
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that allows for remote code execution when using a parameter of the DCE network settings endpoint. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
ModificadaMedia (6.5)0.55%—Schneider-electric Struxureware Data Center Expert18/4/202317/6/2026
A CWE-863: Incorrect Authorization vulnerability exists that could allow access to device credentials on specific DCE endpoints not being properly secured when a hacker is using a low privileged user. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
ModificadaAlta (8.8)0.94%—Schneider-electric Struxureware Data Center Expert18/4/202317/6/2026
A CWE-863: Incorrect Authorization vulnerability exists that could allow remote code execution on upload and install packages when a hacker is using a low privileged user account. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
ModificadaMedia (6.5)0.46%—Schneider-electric Netbotz 355 FirmwareSchneider-electric Netbotz 450 FirmwareSchneider-electric Netbotz 455 FirmwareSchneider-electric Netbotz 550 Firmware+118/4/202317/6/2026
A CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists that could cause the user to be tricked into performing unintended actions when external address frames are not properly restricted. Affected Products: NetBotz 4 - 355/450/455/550/570 (V4.7.0 and prior)