Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

787 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.63%—Schneider-electric Netbotz 355 FirmwareSchneider-electric Netbotz 450 FirmwareSchneider-electric Netbotz 455 FirmwareSchneider-electric Netbotz 550 Firmware+118/4/202317/6/2026
A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could cause account takeover when a brute force attack is performed on the account. Affected Products: NetBotz 4 - 355/450/455/550/570 (V4.7.0 and prior)
ModificadaMedia (6.1)0.38%—Schneider-electric Netbotz 355 FirmwareSchneider-electric Netbotz 450 FirmwareSchneider-electric Netbotz 455 FirmwareSchneider-electric Netbotz 550 Firmware+118/4/202317/6/2026
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause code and session manipulation when malicious code is inserted into the browser. Affected Products: NetBotz 4 - 355/450/455/550/570 (V4.7.0 and prior)
ModificadaMedia (6.7)0.19%—Schneider-electric Easergy Builder Installer18/4/202317/6/2026
A CWE-427 - Uncontrolled Search Path Element vulnerability exists that could allow an attacker with a local privileged account to place a specially crafted file on the target machine, which may give the attacker the ability to execute arbitrary code during the installation process initiated by a valid user. Affected…
ModificadaAlta (8.8)0.36%—Schneider-electric Merten Instabus Tastermodul 1fach System M FirmwareSchneider-electric Merten Instabus Tastermodul 2fach System M FirmwareSchneider-electric Merten Tasterschnittstelle 4fach Plus FirmwareSchneider-electric Merten KNX Argus 180/2,20m UP System Firmware+318/4/202317/6/2026
A CWE-287: Improper Authentication vulnerability exists that could allow a device to be compromised when a key of less than seven digits is entered and the attacker has access to the KNX installation.
ModificadaAlta (8.8)0.84%—Schneider-electric Ecostruxure Control Expert18/4/202317/6/2026
A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that could cause remote code execution when a valid user visits a malicious link provided through the web endpoints. Affected Products: EcoStruxure Control Expert (V15.1 and above)
ModificadaMedia (5.5)0.15%—Schneider-electric Ecostruxure Control Expert18/4/202317/6/2026
A CWE-269: Improper Privilege Management vulnerability exists that could cause a local user to perform a denial of service through the console server service that is part of EcoStruxure Control Expert. Affected Products: EcoStruxure Control Expert (V15.1 and above)
ModificadaMedia (5.3)0.44%—Schneider-electric Custom ReportsSchneider-electric Igss DashboardSchneider-electric Igss Data Server21/3/202317/6/2026
A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow deletion of reports from the IGSS project report directory, this would lead to loss of data when an attacker abuses this functionality. Affected Products: IGSS Data…
ModificadaMedia (6.5)0.24%—Schneider-electric Custom ReportsSchneider-electric Igss DashboardSchneider-electric Igss Data Server21/3/202317/6/2026
A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could allow the renaming of files in the IGSS project report directory, this could lead to denial of service when an attacker sends specific crafted messages to the Data Server TCP port. Affected Products: IGSS Data…
ModificadaMedia (5.3)0.24%—Schneider-electric Custom ReportsSchneider-electric Igss DashboardSchneider-electric Igss Data Server21/3/202317/6/2026
A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause access to delete files in the IGSS project report directory, this could lead to loss of data when an attacker sends specific crafted messages to the Data Server TCP port. Affected Products: IGSS Data…
ModificadaAlta (8.8)0.61%—Schneider-electric Custom ReportsSchneider-electric Igss DashboardSchneider-electric Igss Data Server21/3/202317/6/2026
A CWE-20: Improper Input Validation vulnerability exists in Custom Reports that could cause a macro to be executed, potentially leading to remote code execution when a user opens a malicious report file planted by an attacker. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS…
ModificadaAlta (8.8)0.73%—Schneider-electric Custom ReportsSchneider-electric Igss DashboardSchneider-electric Igss Data Server21/3/202317/6/2026
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists in Custom Reports that could cause a remote code execution when a victim tries to open a malicious report. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS…
ModificadaAlta (7.8)6.5%—Schneider-electric Custom ReportsSchneider-electric Igss DashboardSchneider-electric Igss Data Server21/3/202317/6/2026
A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpretation of malicious payload data, potentially leading to remote code execution when an attacker gets the user to open a malicious file. Affected Products: IGSS Data…
ModificadaAlta (8.8)0.40%—Schneider-electric Custom ReportsSchneider-electric Igss DashboardSchneider-electric Igss Data Server21/3/202317/6/2026
A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause manipulation of dashboard files in the IGSS project report directory, when an attacker sends specific crafted messages to the Data Server TCP port, this could lead to remote code execution when a victim…
ModificadaAlta (8.8)0.88%—Schneider-electric Custom ReportsSchneider-electric Igss DashboardSchneider-electric Igss Data Server21/3/202317/6/2026
A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow the creation of a malicious report file in the IGSS project report directory, this could lead to remote code execution when a victim eventually opens the report. Affected Products: IGSS Data…
ModificadaMedia (5.3)0.42%—Schneider-electric ClearscadaSchneider-electric Ecostruxure GEO Scada Expert 2019Schneider-electric Ecostruxure GEO Scada Expert 2020Schneider-electric Ecostruxure GEO Scada Expert 202124/2/202317/6/2026
A CWE-117: Improper Output Neutralization for Logs vulnerability exists that could cause the misinterpretation of log files when malicious packets are sent to the Geo SCADA server's database web port (default 443). Affected products: EcoStruxure Geo SCADA Expert 2019, EcoStruxure Geo SCADA Expert 2020, EcoStruxure Geo…
ModificadaAlta (7.8)0.17%—Schneider-electric Ecostruxure Power Commission1/2/202317/6/2026
A CWE-285: Improper Authorization vulnerability exists that could cause unauthorized access to certain software functions when an attacker gets access to localhost interface of the EcoStruxure Power Commission application. Affected Products: EcoStruxure Power Commission (Versions prior to V2.25)
ModificadaAlta (7.8)0.16%—Schneider-electric APC Easy UPS Online Monitoring SoftwareSchneider-electric Easy UPS Online Monitoring Software1/2/202317/6/2026
A CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause local privilege escalation when local attacker connects to the database. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GA), APC Easy UPS Online…
ModificadaAlta (7.8)0.18%—Schneider-electric APC Easy UPS Online Monitoring SoftwareSchneider-electric Easy UPS Online Monitoring Software1/2/202317/6/2026
A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could cause local privilege escalation when a local attacker modifies the webroot directory. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to…
ModificadaCrítica (9.8)1.1%—Schneider-electric APC Easy UPS Online Monitoring SoftwareSchneider-electric Easy UPS Online Monitoring Software1/2/202317/6/2026
A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could cause remote code execution when the attacker uploads a malicious JSP file. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GA), APC Easy…
ModificadaCrítica (9.8)0.71%—Schneider-electric APC Easy UPS Online Monitoring SoftwareSchneider-electric Easy UPS Online Monitoring Software1/2/202317/6/2026
A CWE-306: Missing Authentication for Critical Function The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019,…
ModificadaCrítica (9.8)2.1%—Schneider-electric Interactive Graphical Scada System1/2/202317/6/2026
A CWE-190: Integer Overflow or Wraparound vulnerability exists that could cause heap-based buffer overflow, leading to denial of service and potentially remote code execution when an attacker sends multiple specially crafted messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to…
ModificadaCrítica (9.8)1.2%—Schneider-electric Interactive Graphical Scada System1/2/202317/6/2026
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow potentially leading to remote code execution when an attacker sends a specially crafted message. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to V15.0.0.22073)
ModificadaAlta (7.5)0.63%—Schneider-electric Modicon M340 Bmxp341000 FirmwareSchneider-electric Modicon M340 Bmxp342000 FirmwareSchneider-electric Modicon M340 Bmxp342010 FirmwareSchneider-electric Modicon M340 Bmxp3420102 Firmware+371/2/202317/6/2026
A CWE-200: Information Exposure vulnerability exists that could cause the exposure of sensitive information stored on the memory of the controller when communicating over the Modbus TCP protocol. Affected Products: Modicon M340 CPU (part numbers BMXP34*) (Versions prior to V3.30), Modicon M580 CPU (part numbers BMEP*…
ModificadaAlta (7.5)0.57%—Schneider-electric Ecostruxure GEO Scada Expert 2019Schneider-electric Ecostruxure GEO Scada Expert 2020Schneider-electric Ecostruxure GEO Scada Expert 202131/1/202317/6/2026
A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause information disclosure when specific messages are sent to the server over the database server TCP port. Affected Products: EcoStruxure Geo SCADA Expert 2019 - 2021 (formerly known as ClearSCADA) (Versions prior…
ModificadaAlta (7.5)0.57%—Schneider-electric Ecostruxure GEO Scada Expert 2019Schneider-electric Ecostruxure GEO Scada Expert 2020Schneider-electric Ecostruxure GEO Scada Expert 202131/1/202317/6/2026
A CWE-863: Incorrect Authorization vulnerability exists that could cause Denial of Service against the Geo SCADA server when specific messages are sent to the server over the database server TCP port.