Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
203 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 9.4% | — | Veeam ONE Firmware | 28/7/2020 | 17/6/2026 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0.0.750_20200415. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SSRSReport class. Due to the improper restriction of XML External Entity (XXE)… | |
| Modificada | Alta (7.5) | 1.2% | — | Mobile-industrial-robots Mir100 FirmwareMobile-industrial-robots Mir200 FirmwareMobile-industrial-robots Mir250 FirmwareMobile-industrial-robots Mir500 Firmware+6 | 24/6/2020 | 17/6/2026 | The Apache server on port 80 that host the web interface is vulnerable to a DoS by spamming incomplete HTTP headers, effectively blocking the access to the dashboard. | |
| Modificada | Crítica (9.8) | 0.97% | — | Aliasrobotics Mir100 FirmwareAliasrobotics Mir200 FirmwareAliasrobotics Mir250 FirmwareAliasrobotics Mir500 Firmware+6 | 24/6/2020 | 17/6/2026 | MiR robot controllers (central computation unit) makes use of Ubuntu 16.04.2 an operating system, Thought for desktop uses, this operating system presents insecure defaults for robots. These insecurities include a way for users to escalate their access beyond what they were granted via file creation, access race… | |
| Modificada | Media (4.6) | 0.97% | — | Aliasrobotics Mir100 FirmwareAliasrobotics Mir200 FirmwareAliasrobotics Mir250 FirmwareAliasrobotics Mir500 Firmware+6 | 24/6/2020 | 17/6/2026 | The BIOS onboard MiR's Computer is not protected by password, therefore, it allows a Bad Operator to modify settings such as boot order. This can be leveraged by a Malicious operator to boot from a Live Image. | |
| Modificada | Media (6.4) | 0.38% | — | Mobile-industrial-robots Mir100 FirmwareMobile-industrial-robots Mir200 FirmwareMobile-industrial-robots Mir250 FirmwareMobile-industrial-robots Mir500 Firmware+6 | 24/6/2020 | 17/6/2026 | There is no mechanism in place to prevent a bad operator to boot from a live OS image, this can lead to extraction of sensible files (such as the shadow file) or privilege escalation by manually adding a new user with sudo privileges on the machine. | |
| Modificada | Crítica (9.8) | 1.5% | — | Mobile-industrial-robots Mir100 FirmwareMobile-industrial-robots Mir200 FirmwareMobile-industrial-robots Mir250 FirmwareMobile-industrial-robots Mir500 Firmware+6 | 24/6/2020 | 17/6/2026 | The password for the safety PLC is the default and thus easy to find (in manuals, etc.). This allows a manipulated program to be uploaded to the safety PLC, effectively disabling the emergency stop in case an object is too close to the robot. Navigation and any other components dependent on the laser scanner are not… | |
| Modificada | Crítica (9.8) | 0.96% | — | Mobile-industrial-robots Mir100 FirmwareMobile-industrial-robots Mir200 FirmwareMobile-industrial-robots Mir250 FirmwareMobile-industrial-robots Mir500 Firmware+6 | 24/6/2020 | 17/6/2026 | The access tokens for the REST API are directly derived from the publicly available default credentials for the web interface. Given a USERNAME and a PASSWORD, the token string is generated directly with base64(USERNAME:sha256(PASSWORD)). An unauthorized attacker inside the network can use the default credentials to… | |
| Modificada | Alta (7.1) | 0.90% | — | Mobile-industrial-robots Mir100 FirmwareMobile-industrial-robots Mir200 FirmwareMobile-industrial-robots Mir250 FirmwareMobile-industrial-robots Mir500 Firmware+6 | 24/6/2020 | 17/6/2026 | The access tokens for the REST API are directly derived (sha256 and base64 encoding) from the publicly available default credentials from the Control Dashboard (refer to CVE-2020-10270 for related flaws). This flaw in combination with CVE-2020-10273 allows any attacker connected to the robot networks (wired or… | |
| Modificada | Alta (7.5) | 0.86% | — | Aliasrobotics Mir100 FirmwareAliasrobotics Mir200 FirmwareAliasrobotics Mir250 FirmwareAliasrobotics Mir500 Firmware+6 | 24/6/2020 | 17/6/2026 | MiR controllers across firmware versions 2.8.1.1 and before do not encrypt or protect in any way the intellectual property artifacts installed in the robots. This flaw allows attackers with access to the robot or the robot network (while in combination with other flaws) to retrieve and easily exfiltrate all installed… | |
| Modificada | Crítica (9.8) | 2.5% | — | Aliasrobotics Mir100 FirmwareAliasrobotics Mir200 FirmwareAliasrobotics Mir250 FirmwareAliasrobotics Mir500 Firmware+6 | 24/6/2020 | 17/6/2026 | MiR100, MiR200 and other MiR robots use the Robot Operating System (ROS) default packages exposing the computational graph without any sort of authentication. This allows attackers with access to the internal wireless and wired networks to take control of the robot seamlessly. In combination with CVE-2020-10269 and… | |
| Modificada | Crítica (9.8) | 1.8% | — | Aliasrobotics Mir100 FirmwareAliasrobotics Mir200 FirmwareAliasrobotics Mir250 FirmwareAliasrobotics Mir500 Firmware+6 | 24/6/2020 | 17/6/2026 | MiR100, MiR200 and other MiR robots use the Robot Operating System (ROS) default packages exposing the computational graph to all network interfaces, wireless and wired. This is the result of a bad set up and can be mitigated by appropriately configuring ROS and/or applying custom patches as appropriate. Currently,… | |
| Modificada | Crítica (9.8) | 1.7% | — | Aliasrobotics Mir100 FirmwareAliasrobotics Mir200 FirmwareAliasrobotics Mir250 FirmwareAliasrobotics Mir500 Firmware+6 | 24/6/2020 | 17/6/2026 | Out of the wired and wireless interfaces within MiR100, MiR200 and other vehicles from the MiR fleet, it's possible to access the Control Dashboard on a hardcoded IP address. Credentials to such wireless interface default to well known and widely spread users (omitted) and passwords (omitted). This information is also… | |
| Modificada | Crítica (9.8) | 1.4% | — | Aliasrobotics Mir100 FirmwareAliasrobotics Mir200 FirmwareAliasrobotics Mir250 FirmwareAliasrobotics Mir500 Firmware+6 | 24/6/2020 | 17/6/2026 | One of the wireless interfaces within MiR100, MiR200 and possibly (according to the vendor) other MiR fleet vehicles comes pre-configured in WiFi Master (Access Point) mode. Credentials to such wireless Access Point default to well known and widely spread SSID (MiR_RXXXX) and passwords (omitted). This information is… | |
| Analizada | Media (5.4) | 18% | ⚠ Explotación activa | Treck Tcp/ipDell Wyse 5050 All-in-one FirmwareDell Wyse 7030 FirmwareDell Wyse 5030 Firmware | 17/6/2020 | 17/6/2026 | The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read. | |
| Modificada | Media (6.5) | 0.85% | — | Satoshilabs Trezor Model T FirmwareSatoshilabs Trezor ONE Firmware | 16/6/2020 | 17/6/2026 | BIP-143 in the Bitcoin protocol specification mishandles the signing of a Segwit transaction, which allows attackers to trick a user into making two signatures in certain cases, potentially leading to a huge transaction fee. NOTE: this affects all hardware wallets. It was fixed in 1.9.1 for the Trezor One and 2.3.1… | |
| Modificada | Media (4.4) | 0.29% | — | Dell Chengming 3967 FirmwareDell Chengming 3977 FirmwareDell Chengming 3980 FirmwareDell Chengming 3988 Firmware+350 | 10/6/2020 | 17/6/2026 | Dell Client Consumer and Commercial platforms include an improper authorization vulnerability in the Dell Manageability interface for which an unauthorized actor, with local system access with OS administrator privileges, could bypass the BIOS Administrator authentication to restore BIOS Setup configuration to default… | |
| Modificada | Media (4.2) | 0.37% | — | Trezor ONE Firmware | 8/8/2019 | 17/6/2026 | On Trezor One devices before 1.8.2, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. For example, a hardware implant in the USB cable might be able to leverage… | |
| Modificada | Crítica (9.8) | 2.1% | — | TCL Alcatel Linkzone Firmware | 2/8/2019 | 17/6/2026 | The web interface of Alcatel LINKZONE MW40-V-V1.0 MW40_LU_02.00_02 devices is vulnerable to an authentication bypass that allows an unauthenticated user to have access to the web interface without knowing the administrator's password. | |
| Modificada | Alta (7.5) | 2.0% | — | Essential Phone Firmware | 25/4/2019 | 17/6/2026 | The Essential Phone Android device with a build fingerprint of essential/mata/mata:8.1.0/OPM1.180104.166/297:user/release-keys contains a pre-installed platform app with a package name of com.ts.android.hiddenmenu (versionName=1.0, platformBuildVersionName=8.1.0) that contains an exported activity app component named… | |
| Modificada | Alta (8.8) | 7.6% | — | Audiocodes 420hd IP Phone Firmware | 1/4/2019 | 17/6/2026 | An issue was discovered on AudioCodes 450HD IP Phone devices with firmware 3.0.0.535.106. The traceroute and ping functionality, which uses a parameter in a request to command.cgi from the Monitoring page in the web UI, unsafely puts user-alterable data directly into an OS command, leading to Remote Code Execution via… | |
| Modificada | Alta (8.8) | 68% | 💥 Exploit | Audiocodes 420hd IP Phone Firmware | 21/3/2019 | 17/6/2026 | AudioCodes IP phone 420HD devices using firmware version 2.2.12.126 allow Remote Code Execution. | |
| Modificada | Media (4.8) | 0.77% | — | Audiocodes 420hd IP Phone Firmware | 21/3/2019 | 17/6/2026 | AudioCodes IP phone 420HD devices using firmware version 2.2.12.126 allow XSS. | |
| Modificada | Media (5.3) | 6.6% | — | Ismartalarm Cubeone Firmware | 20/11/2018 | 17/6/2026 | Incorrect access control for the diagnostic files of the iSmartAlarm Cube One through 2.2.4.10 allows an attacker to retrieve them via a specifically crafted TCP request to port 12345 and 22306, and access sensitive information from the device. | |
| Modificada | Crítica (9.8) | 1.5% | — | D-link Dir-809 A1 FirmwareD-link Dir-809 A2 FirmwareD-link Dir-809 Guestzone Firmware | 9/10/2018 | 17/6/2026 | An issue was discovered on D-Link DIR-809 A1 through 1.09, A2 through 1.11, and Guest Zone through 1.09 devices. Device passwords, such as the admin password and the WPA key, are stored in cleartext. | |
| Modificada | Alta (7.5) | 1.8% | — | D-link Dir-809 A1 FirmwareD-link Dir-809 A2 FirmwareD-link Dir-809 Guestzone Firmware | 9/10/2018 | 17/6/2026 | An issue was discovered on D-Link DIR-809 A1 through 1.09, A2 through 1.11, and Guest Zone through 1.09 devices. One can bypass authentication mechanisms to download the configuration file. |