Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
164 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.93% | — | Wago 750-823 FirmwareWago 750-829 FirmwareWago 750-831 FirmwareWago 750-832 Firmware+24 | 26/10/2021 | 17/6/2026 | In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests can trigger a parser error. Since the parser result is not checked under all conditions, a pointer dereference with an invalid address can occur. This leads to a denial of service situation. | |
| Analizada | Crítica (9.1) | 1.1% | — | Wago 750-823 FirmwareWago 750-829 FirmwareWago 750-831 FirmwareWago 750-832 Firmware+24 | 26/10/2021 | 17/6/2026 | Crafted web server requests can be utilised to read partial stack or heap memory or may trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22. | |
| Analizada | Alta (7.5) | 8.4% | — | Wago 750-8214 FirmwareWago 750-8216 FirmwareWago 750-8217 FirmwareWago 750-8213 Firmware+24 | 26/10/2021 | 17/6/2026 | Crafted web server requests may cause a heap-based buffer overflow and could therefore trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22. | |
| Modificada | Alta (7.5) | 1.0% | — | Wago 750-880/040-000 FirmwareWago 750-880/025-002 FirmwareWago 750-880/025-001 FirmwareWago 750-880/025-000 Firmware+5 | 31/8/2021 | 17/6/2026 | Missing Release of Resource after Effective Lifetime vulnerability in OpenSSL implementation of WAGO 750-831/xxx-xxx, 750-880/xxx-xxx, 750-881, 750-889 in versions FW4 up to FW15 allows an unauthenticated attacker to cause DoS on the device. | |
| Modificada | Alta (8.1) | 0.96% | — | Wago 750-890/040-000 FirmwareWago 750-890/025-001 FirmwareWago 750-890/025-002 FirmwareWago 750-890/025-000 Firmware+8 | 31/8/2021 | 17/6/2026 | This vulnerability allows an attacker who has access to the WBM to read and write settings-parameters of the device by sending specifically constructed requests without authentication on multiple WAGO PLCs in firmware versions up to FW07. | |
| Analizada | Alta (7.5) | 7.2% | — | Wago 750-893 FirmwareWago 750-891 FirmwareWago 750-890 FirmwareWago 750-889 Firmware+25 | 25/5/2021 | 17/6/2026 | CODESYS V2 runtime system before 2.4.7.55 has Improper Input Validation. | |
| Analizada | Crítica (9.1) | 1.2% | — | Wago 750-893 FirmwareWago 750-891 FirmwareWago 750-890 FirmwareWago 750-889 Firmware+24 | 25/5/2021 | 17/6/2026 | CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Read. | |
| Analizada | Crítica (9.8) | 1.2% | — | Wago 750-893 FirmwareWago 750-891 FirmwareWago 750-890 FirmwareWago 750-889 Firmware+24 | 25/5/2021 | 17/6/2026 | CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Write. | |
| Analizada | Crítica (9.8) | 1.2% | — | Wago 750-893 FirmwareWago 750-891 FirmwareWago 750-890 FirmwareWago 750-889 Firmware+24 | 25/5/2021 | 17/6/2026 | CODESYS V2 Web-Server before 1.1.9.20 has an Improperly Implemented Security Check. | |
| Analizada | Alta (7.5) | 1.0% | — | Wago 750-893 FirmwareWago 750-891 FirmwareWago 750-890 FirmwareWago 750-889 Firmware+24 | 25/5/2021 | 17/6/2026 | CODESYS V2 Web-Server before 1.1.9.20 has a a Buffer Copy without Checking the Size of the Input. | |
| Analizada | Crítica (9.8) | 1.4% | — | Wago 750-893 FirmwareWago 750-891 FirmwareWago 750-890 FirmwareWago 750-889 Firmware+24 | 25/5/2021 | 17/6/2026 | CODESYS V2 Web-Server before 1.1.9.20 has Improper Access Control. | |
| Analizada | Crítica (9.8) | 1.3% | — | Wago 750-893 FirmwareWago 750-891 FirmwareWago 750-890 FirmwareWago 750-889 Firmware+24 | 25/5/2021 | 17/6/2026 | CODESYS V2 Web-Server before 1.1.9.20 has a Stack-based Buffer Overflow. | |
| Analizada | Crítica (9.8) | 1.3% | — | Wago 750-893 FirmwareWago 750-891 FirmwareWago 750-890 FirmwareWago 750-889 Firmware+24 | 25/5/2021 | 17/6/2026 | CODESYS V2 runtime system SP before 2.4.7.55 has a Stack-based Buffer Overflow. | |
| Analizada | Alta (7.5) | 7.4% | — | Wago 750-893 FirmwareWago 750-891 FirmwareWago 750-890 FirmwareWago 750-889 Firmware+25 | 25/5/2021 | 17/6/2026 | CODESYS V2 runtime system SP before 2.4.7.55 has a Heap-based Buffer Overflow. | |
| Analizada | Media (5.3) | 0.27% | — | Wago 750-893 FirmwareWago 750-891 FirmwareWago 750-890 FirmwareWago 750-889 Firmware+24 | 25/5/2021 | 17/6/2026 | CODESYS V2 runtime system SP before 2.4.7.55 has Improper Neutralization of Special Elements used in an OS Command. | |
| Analizada | Media (6.5) | 1.1% | — | Wago 750-823 FirmwareWago 750-829 FirmwareWago 750-831 FirmwareWago 750-832 Firmware+23 | 24/5/2021 | 17/6/2026 | On WAGO PFC200 devices in different firmware versions with special crafted packets an authorised attacker with network access to the device can access the file system with higher privileges. | |
| Analizada | Alta (7.5) | 1.0% | — | Wago 750-823 FirmwareWago 750-829 FirmwareWago 750-831 FirmwareWago 750-832 Firmware+23 | 24/5/2021 | 17/6/2026 | On WAGO PFC200 devices in different firmware versions with special crafted packets an attacker with network access to the device could cause a denial of service for the login service of the runtime. | |
| Modificada | Crítica (9.8) | 1.1% | — | Wago 0852-0303 FirmwareWago 0852-1305 FirmwareWago 0852-1505 FirmwareWago 0852-1305/000-001 Firmware+1 | 13/5/2021 | 17/6/2026 | In multiple managed switches by WAGO in different versions without authorization and with specially crafted packets it is possible to create users. | |
| Modificada | Alta (7.5) | 1.0% | — | Wago 0852-0303 FirmwareWago 0852-1305 FirmwareWago 0852-1505 FirmwareWago 0852-1305/000-001 Firmware+1 | 13/5/2021 | 17/6/2026 | In multiple managed switches by WAGO in different versions it is possible to read out the password hashes of all Web-based Management users. | |
| Modificada | Media (5.3) | 0.75% | — | Wago 0852-0303 FirmwareWago 0852-1305 FirmwareWago 0852-1505 FirmwareWago 0852-1305/000-001 Firmware+1 | 13/5/2021 | 17/6/2026 | In multiple managed switches by WAGO in different versions special crafted requests can lead to cookies being transferred to third parties. | |
| Modificada | Alta (7.5) | 0.54% | — | Wago 0852-0303 FirmwareWago 0852-1305 FirmwareWago 0852-1505 FirmwareWago 0852-1305/000-001 Firmware+1 | 13/5/2021 | 17/6/2026 | In multiple managed switches by WAGO in different versions the webserver cookies of the web based UI contain user credentials. | |
| Modificada | Media (6.1) | 0.63% | — | Wago 0852-0303 FirmwareWago 0852-1305 FirmwareWago 0852-1505 FirmwareWago 0852-1305/000-001 Firmware+1 | 13/5/2021 | 17/6/2026 | In multiple managed switches by WAGO in different versions an attacker may trick a legitimate user to click a link to inject possible malicious code into the Web-Based Management. | |
| Modificada | Media (5.3) | 0.79% | — | Wago 0852-0303 FirmwareWago 0852-1305 FirmwareWago 0852-1505 FirmwareWago 0852-1305/000-001 Firmware+1 | 13/5/2021 | 17/6/2026 | In multiple managed switches by WAGO in different versions the activated directory listing provides an attacker with the index of the resources located inside the directory. | |
| Modificada | Alta (7.3) | 1.1% | — | Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux ARM SL+18 | 3/5/2021 | 17/6/2026 | CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's addressing scheme and may re-route, add, remove or change low level communication packages. | |
| Modificada | Alta (7.8) | 1.3% | — | Emerson Rosemount Transmitter Interface SoftwarePepperl-fuchs PactwareWago Dtminspector 3Wago Fdtcontainer Application+3 | 22/1/2021 | 17/6/2026 | M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage. |