Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

383 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.60%—Hitachienergy Foxman-unHitachienergy Unem11/6/202417/6/2026
vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway that if exploited an attacker could use to allow unintended commands or code to be executed on the UNEM server allowing sensitive data to be read or modified or could cause other unintended behavior
ModificadaCrítica (9.8)0.47%—Hitachienergy Foxman-unHitachienergy Unem11/6/202417/6/2026
A heap-based buffer overflow vulnerability exists in the FOXMAN-UN/UNEM that if exploited will generally lead to a denial of service but can be used to execute arbitrary code, which is usually outside the scope of a program's implicit security policy
ModificadaAlta (7.4)0.27%—Hitachienergy Foxman-unHitachienergy Foxman UNHitachienergy Unem11/6/202417/6/2026
A vulnerability exists in the FOXMAN-UN/UNEM server that affects the message queueing mechanism’s certificate validation. If exploited an attacker could spoof a trusted entity causing a loss of confidentiality and integrity.
AplazadaAlta (8)0.22%—Hitachienergy Sdm600AI30/4/202417/6/2026
A vulnerability exists in the web-authentication component of the SDM600. If exploited an attacker could escalate privileges on af-fected installations.
AplazadaAlta (7.5)0.31%—Hitachi OPS Center AnalyzerAI23/4/202417/6/2026
Session Hijacking vulnerability in Hitachi Ops Center Analyzer.This issue affects Hitachi Ops Center Analyzer: from 10.0.0-00 before 11.0.1-00.
AplazadaMedia (4.4)0.17%—Hitachi OPS Center AdministratorAI23/4/202417/6/2026
Insertion of Sensitive Information into Log File vulnerability in Hitachi Ops Center Administrator allows local users to gain sensitive information.This issue affects Hitachi Ops Center Administrator: before 11.0.1.
AplazadaCrítica (9.9)0.51%—Hitachi Virtual Storage PlatformAIHitachi Virtual Storage Platform Vp9500AIHitachi Virtual Storage Platform G1000AIHitachi Virtual Storage Platform G1500AI+3725/3/202417/6/2026
Insertion of Sensitive Information into Log File vulnerability in Hitachi Virtual Storage Platform, Hitachi Virtual Storage Platform VP9500, Hitachi Virtual Storage Platform G1000, G1500, Hitachi Virtual Storage Platform F1500, Hitachi Virtual Storage Platform 5100, 5500, 5100H, 5500H, Hitachi Virtual Storage Platform…
AplazadaMedia (5.6)0.17%—Hitachi Cosminexus Component ContainerAI12/3/202417/6/2026
Insertion of Sensitive Information into Log File vulnerability in Hitachi Cosminexus Component Container allows local users to gain sensitive information.This issue affects Cosminexus Component Container: from 11-30 before 11-30-05, from 11-20 before 11-20-07, from 11-10 before 11-10-10, from 11-00 before 11-00-12,…
AnalizadaMedia (5.3)0.38%—Hitachi Vantara Pentaho Data Integration AND Analytics28/2/202417/6/2026
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.6, including 9.5.x and 8.3.x, display the version of Tomcat when a server error is encountered.
AnalizadaCrítica (9.8)0.46%—Hitachi Global Link Manager20/2/202417/6/2026
Expression Language Injection vulnerability in Hitachi Global Link Manager on Windows allows Code Injection.This issue affects Hitachi Global Link Manager: before 8.8.7-03.
ModificadaAlta (7.1)0.14%—Hitachi Storage Plug-in30/1/202417/6/2026
Incorrect Default Permissions vulnerability in Hitachi Storage Plug-in for VMware vCenter allows local users to read and write specific files. This issue affects Hitachi Storage Plug-in for VMware vCenter: from 04.0.0 through 04.9.2.
ModificadaAlta (7.1)0.14%—Hitachi Tuning Manager16/1/202417/6/2026
Incorrect Default Permissions vulnerability in Hitachi Tuning Manager on Windows (Hitachi Tuning Manager server component) allows local users to read and write specific files.This issue affects Hitachi Tuning Manager: before 8.8.5-04.
ModificadaAlta (7.5)0.41%—Hitachi Device Manager16/1/202417/6/2026
Generation of Error Message Containing Sensitive Information vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Agent modules).This issue affects Hitachi Device Manager: before 8.8.5-04.
ModificadaAlta (7.5)0.44%—Hitachi Device Manager16/1/202417/6/2026
Missing Password Field Masking vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Agent component).This issue affects Hitachi Device Manager: before 8.8.5-04.
ModificadaMedia (4.5)0.35%—Hitachienergy Relion 650 FirmwareHitachienergy Relion 670 FirmwareHitachienergy Relion Sam600-io Firmware4/1/202417/6/2026
A vulnerability exists in the Relion update package signature validation. A tampered update package could cause the IED to restart. After restart the device is back to normal operation. An attacker could exploit the vulnerability by first gaining access to the system with security privileges and attempt to update the…
ModificadaAlta (7.5)0.64%—Hitachienergy Rtu520 FirmwareHitachienergy Rtu530 FirmwareHitachienergy Rtu540 FirmwareHitachienergy Rtu560 Firmware4/1/202417/6/2026
A vulnerability exists in the HCI Modbus TCP function included in the product versions listed above. If the HCI Modbus TCP is enabled and configured, an attacker could exploit the vulnerability by sending a specially crafted message to the RTU500 in a high rate, causing the targeted RTU500 CMU to reboot. The…
ModificadaAlta (7.5)0.67%—Hitachienergy Rtu500 Firmware19/12/202317/6/2026
Vulnerability exists in SCI IEC 60870-5-104 and HCI IEC 60870-5-104 that affects the RTU500 series product versions listed below. Specially crafted messages sent to the mentioned components are not validated properly and can result in buffer overflow and as final consequence to a reboot of an RTU500 CMU.
ModificadaAlta (7.5)0.32%💥 PoCHitachienergy Rtu500 Scripting Interface19/12/202317/6/2026
A vulnerability exists in the component RTU500 Scripting interface. When a client connects to a server using TLS, the server presents a certificate. This certificate links a public key to the identity of the service and is signed by a Certification Authority (CA), allowing the client to validate that the remote…
AnalizadaMedia (6.1)0.41%—Hitachienergy Rtu520 FirmwareHitachienergy Rtu530 FirmwareHitachienergy Rtu540 FirmwareHitachienergy Rtu560 Firmware14/12/202317/6/2026
A vulnerability exists in the webserver that affects the RTU500 series product versions listed below. A malicious actor could perform cross-site scripting on the webserver due to user input being improperly sanitized.
ModificadaAlta (8.8)0.64%—Hitachi Pentaho Data Integration AND Analytics12/12/202317/6/2026
Hitachi Vantara Pentaho Data Integration & Analytics versions before 9.5.0.1 and 9.3.0.5, including 8.3.x does not restrict JNDI identifiers during the creation of XActions, allowing control of system level data sources.
ModificadaMedia (6.5)1.6%💥 ExploitHitachi System Management Unit Firmware11/12/202317/6/2026
SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in Storage, Server or combined Server+Storage administrative roles are able to access SMU configuration backup, that would normally be barred to those specific administrative roles.
ModificadaMedia (6.5)0.54%💥 PoCVantara Hitachi Network Attached Storage5/12/202317/6/2026
SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in a Storage administrative role are able to access HNAS configuration backup and diagnostic data, that would normally be barred to that specific administrative role.
ModificadaMedia (6.1)0.41%—Hitachienergy Rtu520 FirmwareHitachienergy Rtu530 FirmwareHitachienergy Rtu540 FirmwareHitachienergy Rtu560 Firmware4/12/202317/6/2026
A vulnerability exists in the HCI IEC 60870-5-104 that affects the RTU500 series product versions listed below. Incomplete or wrong received APDU frame layout may cause blocking on link layer. Error reason was an endless blocking when reading incoming frames on link layer with wrong length information of APDU or…
ModificadaMedia (6.1)0.39%—Hitachienergy Rtu520 FirmwareHitachienergy Rtu530 FirmwareHitachienergy Rtu540 FirmwareHitachienergy Rtu560 Firmware4/12/202317/6/2026
A vulnerability exists in the webserver that affects the RTU500 series product versions listed below. A malicious actor could perform cross-site scripting on the webserver due to an RDT language file being improperly sanitized.
ModificadaAlta (7.5)0.70%—Hitachienergy Relion 670 FirmwareHitachienergy Relion 650 FirmwareHitachienergy Relion Sam600-io Firmware1/12/202317/6/2026
A vulnerability exists in the input validation of the GOOSE messages where out of range values received and processed by the IED caused a reboot of the device. In order for an attacker to exploit the vulnerability, goose receiving blocks need to be configured.