Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
355 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.0% | — | Pepperl-fuchs Wha-gw-f2d2-0-as-z2-eth FirmwarePepperl-fuchs Wha-gw-f2d2-0-as-z2-eth.eip Firmware | 31/8/2021 | 17/6/2026 | In PEPPERL+FUCHS WirelessHART-Gateway 3.0.7 to 3.0.9 the SSH and telnet services are active with hard-coded credentials. | |
| Modificada | Media (5.5) | 0.15% | — | Pepperl-fuchs Wha-gw-f2d2-0-as-z2-eth FirmwarePepperl-fuchs Wha-gw-f2d2-0-as- Z2-eth.eip Firmware | 31/8/2021 | 17/6/2026 | Any cookie-stealing vulnerabilities within the application or browser would enable an attacker to steal the user's credentials to the PEPPERL+FUCHS WirelessHART-Gateway 3.0.9. | |
| Modificada | Baja (3.3) | 0.24% | — | Pepperl-fuchs Wha-gw-f2d2-0-as-z2-eth FirmwarePepperl-fuchs Wha-gw-f2d2-0-as-z2-eth.eip Firmware | 31/8/2021 | 17/6/2026 | In PEPPERL+FUCHS WirelessHART-Gateway 3.0.8 and 3.0.9 the HttpOnly attribute is not set on a cookie. This allows the cookie's value to be read or set by client-side JavaScript. | |
| Modificada | Media (6.1) | 0.58% | — | Pepperl-fuchs Wha-gw-f2d2-0-as-z2-eth FirmwarePepperl-fuchs Wha-gw-f2d2-0-as-z2-eth.eip Firmware | 31/8/2021 | 17/6/2026 | In PEPPERL+FUCHS WirelessHART-Gateway 3.0.8 it is possible to inject arbitrary JavaScript into the application's response. | |
| Modificada | Alta (8.8) | 0.87% | — | Pepperl-fuchs Wha-gw-f2d2-0-as-z2-eth FirmwarePepperl-fuchs Wha-gw-f2d2-0-as-z2-eth.eip Firmware | 31/8/2021 | 17/6/2026 | In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 serious issue exists, if the application is not externally accessible or uses IP-based access restrictions. Attackers can use DNS Rebinding to bypass any IP or firewall based access restrictions that may be in place, by proxying through their target's browser. | |
| Modificada | Media (5.5) | 0.21% | — | Pepperl-fuchs Wha-gw-f2d2-0-as-z2-eth FirmwarePepperl-fuchs Wha-gw-f2d2-0-as-z2-eth.eip Firmware | 31/8/2021 | 17/6/2026 | In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.9 a form contains a password field with autocomplete enabled. The stored credentials can be captured by an attacker who gains control over the user's computer. Therefore the user must have logged in at least once. | |
| Modificada | Media (5.3) | 0.77% | — | Pepperl-fuchs Wha-gw-f2d2-0-as-z2-eth FirmwarePepperl-fuchs Wha-gw-f2d2-0-as-z2-eth.eip Firmware | 31/8/2021 | 17/6/2026 | In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 a vulnerability may allow remote attackers to rewrite links and URLs in cached pages to arbitrary strings. | |
| Modificada | Alta (7.5) | 1.2% | — | Pepperl-fuchs Wha-gw-f2d2-0-as-z2-eth FirmwarePepperl-fuchs Wha-gw-f2d2-0-as- Z2-eth.eip Firmware | 31/8/2021 | 17/6/2026 | In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.7 the filename parameter is vulnerable to unauthenticated path traversal attacks, enabling read access to arbitrary files on the server. | |
| Modificada | Alta (7.5) | 0.99% | — | Hilscher RCX RtosPepperl-fuchs Ice1-16di-g60l-v1d FirmwarePepperl-fuchs Ice1-16dio-g60l-c1-v1d FirmwarePepperl-fuchs Ice1-16dio-g60l-v1d Firmware+5 | 13/5/2021 | 17/6/2026 | In Hilscher rcX RTOS versions prios to V2.1.14.1 the actual UDP packet length is not verified against the length indicated by the packet. This may lead to a denial of service of the affected device. | |
| Modificada | Alta (8.6) | 1.1% | — | Hilscher Ethernet/ip Adapter FirmwarePepperl-fuchs WCS FirmwarePepperl-fuchs Pxv100-f200-b25-v1d FirmwarePepperl-fuchs Pxv100i-f200-b25-v1d Firmware+4 | 16/2/2021 | 17/6/2026 | A denial of service and memory corruption vulnerability was found in Hilscher EtherNet/IP Core V2 prior to V2.13.0.21that may lead to code injection through network or make devices crash without recovery. | |
| Modificada | Alta (7.5) | 1.0% | — | Hilscher Profinet IO Device FirmwarePepperl-fuchs Pgv100-f200a-b17-v1d FirmwarePepperl-fuchs Pgv150i-f200a-b17-v1d FirmwarePepperl-fuchs Pgv100-f200-b17-v1d-7477 Firmware+20 | 16/2/2021 | 17/6/2026 | A Denial of Service vulnerability was found in Hilscher PROFINET IO Device V3 in versions prior to V3.14.0.7. This may lead to unexpected loss of cyclic communication or interruption of acyclic communication. | |
| Modificada | Alta (7.8) | 1.3% | — | Emerson Rosemount Transmitter Interface SoftwarePepperl-fuchs PactwareWago Dtminspector 3Wago Fdtcontainer Application+3 | 22/1/2021 | 17/6/2026 | M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage. | |
| Modificada | Media (4.9) | 1.0% | — | Pepperl-fuchs Io-link Master 4-eip FirmwarePepperl-fuchs Io-link Master 8-eip FirmwarePepperl-fuchs Io-link Master 8-eip-l FirmwarePepperl-fuchs Io-link Master Dr-8-eip Firmware+8 | 22/1/2021 | 17/6/2026 | Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a NULL Pointer Dereference that leads to a DoS in discoveryd | |
| Modificada | Alta (8.8) | 31% | — | Pepperl-fuchs Io-link Master 4-eip FirmwarePepperl-fuchs Io-link Master 8-eip FirmwarePepperl-fuchs Io-link Master 8-eip-l FirmwarePepperl-fuchs Io-link Master Dr-8-eip Firmware+8 | 22/1/2021 | 17/6/2026 | Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated blind OS Command Injection. | |
| Modificada | Media (5.4) | 0.72% | — | Pepperl-fuchs Io-link Master 4-eip FirmwarePepperl-fuchs Io-link Master 8-eip FirmwarePepperl-fuchs Io-link Master 8-eip-l FirmwarePepperl-fuchs Io-link Master Dr-8-eip Firmware+8 | 22/1/2021 | 17/6/2026 | Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated reflected POST Cross-Site Scripting | |
| Modificada | Alta (8.8) | 0.57% | — | Pepperl-fuchs Io-link Master 4-eip FirmwarePepperl-fuchs Io-link Master 8-eip FirmwarePepperl-fuchs Io-link Master 8-eip-l FirmwarePepperl-fuchs Io-link Master Dr-8-eip Firmware+8 | 22/1/2021 | 17/6/2026 | Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a Cross-Site Request Forgery (CSRF) in the web interface. | |
| Modificada | Crítica (9.8) | 3.0% | — | Pepperl-fuchs Es7510-xt FirmwarePepperl-fuchs Es8509-xt FirmwarePepperl-fuchs Es8510-xt FirmwarePepperl-fuchs Es9528-xtv2 Firmware+25 | 15/10/2020 | 17/6/2026 | Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3 and below has an active TFTP-Service. | |
| Modificada | Alta (7.2) | 23% | — | Pepperl-fuchs Es7510-xt FirmwarePepperl-fuchs Es8509-xt FirmwarePepperl-fuchs Es8510-xt FirmwarePepperl-fuchs Es9528-xtv2 Firmware+24 | 15/10/2020 | 17/6/2026 | Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3 and below is prone to multiple… | |
| Modificada | Alta (8.8) | 1.0% | — | Pepperl-fuchs Es7510-xt FirmwarePepperl-fuchs Es8509-xt FirmwarePepperl-fuchs Es8510-xt FirmwarePepperl-fuchs Es9528-xtv2 Firmware+19 | 15/10/2020 | 17/6/2026 | Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3 and below is prone to unauthenticated… | |
| Modificada | Crítica (9.8) | 3.3% | — | Pepperl-fuchs Es7510-xt FirmwarePepperl-fuchs Es8509-xt FirmwarePepperl-fuchs Es8510-xt FirmwarePepperl-fuchs Es9528-xtv2 Firmware+22 | 15/10/2020 | 17/6/2026 | Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) use undocumented accounts. | |
| Modificada | Crítica (9.8) | 2.9% | — | Pepperl-fuchs Es7510-xt FirmwarePepperl-fuchs Es8509-xt FirmwarePepperl-fuchs Es8510-xt FirmwarePepperl-fuchs Es9528-xtv2 Firmware+9 | 15/10/2020 | 17/6/2026 | Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) allows unauthenticated device administration. | |
| Modificada | Media (4.7) | 0.49% | — | Perl DBIFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux+1 | 17/9/2020 | 17/6/2026 | An issue was discovered in the DBI module before 1.643 for Perl. The hv_fetch() documentation requires checking for NULL and the code does that. But, shortly thereafter, it calls SvOK(profile), causing a NULL pointer dereference. | |
| Modificada | Media (6.1) | 0.49% | — | Perl DBI | 16/9/2020 | 17/6/2026 | An issue was discovered in the DBI module through 1.643 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute in the data source name (DSN). NOTE: this issue exists because of an incomplete fix for CVE-2014-10401. | |
| Modificada | Alta (7.1) | 0.61% | — | Perl Database InterfaceOpensuse LeapDebian LinuxFedoraproject Fedora | 16/9/2020 | 17/6/2026 | A buffer overflow was found in perl-DBI < 1.643 in DBI.xs. A local attacker who is able to supply a string longer than 300 characters could cause an out-of-bounds write, affecting the availability of the service or integrity of data. | |
| Modificada | Media (5.5) | 0.55% | — | Perl Database InterfaceCanonical Ubuntu LinuxOpensuse LeapFedoraproject Fedora+1 | 16/9/2020 | 17/6/2026 | An untrusted pointer dereference flaw was found in Perl-DBI < 1.643. A local attacker who is able to manipulate calls to dbd_db_login6_sv() could cause memory corruption, affecting the service's availability. |