Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
435 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.1) | 37% | 💥 Exploit | Iclinks Scadaflex II FirmwareIclinks Weblib | 26/2/2022 | 17/6/2026 | On ICL ScadaFlex II SCADA Controller SC-1 and SC-2 1.03.07 devices, unauthenticated remote attackers can overwrite, delete, or create files. | |
| Modificada | Crítica (9.8) | 3.1% | — | Emerson Openenterprise Scada Server | 24/2/2022 | 17/6/2026 | Emerson OpenEnterprise versions through 3.3.4 may allow an attacker to run an arbitrary commands with system privileges or perform remote code execution via a specific communication service. | |
| Modificada | Alta (7.5) | 0.28% | — | Emerson Openenterprise Scada Server | 24/2/2022 | 17/6/2026 | Inadequate encryption may allow the passwords for Emerson OpenEnterprise versions through 3.3.4 user accounts to be obtained. | |
| Modificada | Media (5.3) | 0.47% | — | Emerson Openenterprise Scada Server | 24/2/2022 | 17/6/2026 | Inadequate folder security permissions in Emerson OpenEnterprise versions through 3.3.4 may allow modification of important configuration files, which could cause the system to fail or behave in an unpredictable manner. | |
| Modificada | Alta (7.5) | 14% | — | Schneider-electric Interactive Graphical Scada System Data Collector | 11/2/2022 | 17/6/2026 | A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in denial of service, due to missing length check on user-supplied data from a constructed message received on the network. Affected Product: Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21320 and prior) | |
| Modificada | Crítica (9.1) | 21% | — | Schneider-electric Interactive Graphical Scada System Data Collector | 11/2/2022 | 17/6/2026 | A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause deletion of arbitrary files in the context of the user running IGSS due to lack of validation of network messages. Affected Product: Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21320 and prior) | |
| Modificada | Crítica (9.1) | 0.85% | — | Schneider-electric Interactive Graphical Scada System Data Collector | 11/2/2022 | 17/6/2026 | A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause deletion of arbitrary files in the context of the user running IGSS due to lack of validation of network messages. Affected Product: Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21243 and prior) | |
| Modificada | Alta (7.5) | 1.3% | — | Schneider-electric Interactive Graphical Scada System Data Collector | 11/2/2022 | 17/6/2026 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists that could cause disclosure of arbitrary files being read in the context of the user running IGSS, due to missing validation of user supplied data in network messages. Affected Product: Interactive Graphical SCADA System Data… | |
| Modificada | Crítica (9.8) | 1.9% | — | Schneider-electric Interactive Graphical Scada System Data Collector | 11/2/2022 | 17/6/2026 | A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could lead to remote code execution through a number of paths, when an attacker, writes arbitrary files to folders in context of the DC module, by sending constructed messages on the network. Affected Product: Interactive Graphical… | |
| Modificada | Crítica (9.8) | 20% | — | Schneider-electric Interactive Graphical Scada System Data Collector | 11/2/2022 | 17/6/2026 | A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in remote code execution due to missing length check on user supplied data, when a constructed message is received on the network. Affected Product: Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21243 and… | |
| Modificada | Alta (7.5) | 1.00% | — | Schneider-electric ClearscadaSchneider-electric Ecostruxure GEO Scada Expert 2019Schneider-electric Ecostruxure GEO Scada Expert 2020 | 9/2/2022 | 17/6/2026 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause Denial of Service against the Geo SCADA server when receiving a malformed HTTP request. Affected Product: ClearSCADA (All Versions), EcoStruxure Geo SCADA Expert 2019 (All Versions), EcoStruxure Geo SCADA Expert 2020… | |
| Modificada | Media (5.9) | 0.54% | — | Schneider-electric ClearscadaSchneider-electric Ecostruxure GEO Scada Expert 2019Schneider-electric Ecostruxure GEO Scada Expert 2020 | 9/2/2022 | 17/6/2026 | A CWE-295: Improper Certificate Validation vulnerability exists that could allow a Man-in-theMiddle attack when communications between the client and Geo SCADA database server are intercepted. Affected Product: ClearSCADA (All Versions), EcoStruxure Geo SCADA Expert 2019 (All Versions), EcoStruxure Geo SCADA Expert… | |
| Modificada | Media (5.9) | 0.57% | — | Schneider-electric ClearscadaSchneider-electric Ecostruxure GEO Scada Expert 2019Schneider-electric Ecostruxure GEO Scada Expert 2020 | 9/2/2022 | 17/6/2026 | A CWE-295: Improper Certificate Validation vulnerability exists that could allow a Man-in-theMiddle attack when communications between the client and Geo SCADA web server are intercepted. Affected Product: ClearSCADA (All Versions), EcoStruxure Geo SCADA Expert 2019 (All Versions), EcoStruxure Geo SCADA Expert 2020… | |
| Modificada | Alta (7.5) | 0.39% | — | Schneider-electric ClearscadaSchneider-electric Ecostruxure GEO Scada Expert 2019Schneider-electric Ecostruxure GEO Scada Expert 2020 | 9/2/2022 | 17/6/2026 | A CWE-326: Inadequate Encryption Strength vulnerability exists that could cause non-encrypted communication with the server when outdated versions of the ViewX client are used. Affected Product: ClearSCADA (All Versions), EcoStruxure Geo SCADA Expert 2019 (All Versions), EcoStruxure Geo SCADA Expert 2020 (All Versions) | |
| Modificada | Alta (7.5) | 1.2% | — | Schneider-electric Interactive Graphical Scada System Data Server | 9/2/2022 | 17/6/2026 | A CWE-862: Missing Authorization vulnerability exists that could cause information exposure when an attacker sends a specific message. Affected Product: Interactive Graphical SCADA System Data Server (V15.0.0.22020 and prior) | |
| Modificada | Alta (7.5) | 1.3% | — | Schneider-electric Interactive Graphical Scada System Data Server | 9/2/2022 | 17/6/2026 | A CWE-665: Improper Initialization vulnerability exists that could cause information exposure when an attacker sends a specially crafted message. Affected Product: Interactive Graphical SCADA System Data Server (V15.0.0.22020 and prior) | |
| Modificada | Alta (7.5) | 19% | — | Schneider-electric Interactive Graphical Scada System Data Server | 9/2/2022 | 17/6/2026 | A CWE-125: Out-of-bounds Read vulnerability exists that could cause denial of service when an attacker repeatedly sends a specially crafted message. Affected Product: Interactive Graphical SCADA System Data Server (V15.0.0.22020 and prior) | |
| Modificada | Alta (7.5) | 18% | — | Schneider-electric Interactive Graphical Scada System Data Server | 9/2/2022 | 17/6/2026 | A CWE-125: Out-of-bounds Read vulnerability exists that could cause memory leaks potentially resulting in denial of service when an attacker repeatedly sends a specially crafted message. Affected Product: Interactive Graphical SCADA System Data Server (V15.0.0.22020 and prior) | |
| Modificada | Crítica (9.8) | 45% | — | Schneider-electric Interactive Graphical Scada System Data Server | 9/2/2022 | 17/6/2026 | A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow potentially leading to remote code execution when an attacker sends a specially crafted message. Affected Product: Interactive Graphical SCADA System Data Server (V15.0.0.22020 and prior) | |
| Modificada | Crítica (9.8) | 3.5% | — | Schneider-electric Interactive Graphical Scada System Data Server | 9/2/2022 | 17/6/2026 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists that could cause modification of an existing file by adding at end of file or create a new file in the context of the Data Server potentially leading to remote code execution when an attacker sends a specially crafted message.… | |
| Modificada | Crítica (9.8) | 3.5% | — | Schneider-electric Interactive Graphical Scada System Data Server | 9/2/2022 | 17/6/2026 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists that could cause modification of an existing file by inserting at beginning of file or create a new file in the context of the Data Server potentially leading to remote code execution when an attacker sends a specially crafted… | |
| Modificada | Crítica (9.8) | 2.2% | — | Schneider-electric Interactive Graphical Scada System Data Server | 9/2/2022 | 17/6/2026 | A CWE-190: Integer Overflow or Wraparound vulnerability exists that could cause heap-based buffer overflow, leading to denial of service and potentially remote code execution when an attacker sends multiple specially crafted messages. Affected Product: Interactive Graphical SCADA System Data Server (V15.0.0.22020 and… | |
| Modificada | Alta (7.5) | 0.95% | — | Schneider-electric Scadapack 312e FirmwareSchneider-electric Scadapack 313e FirmwareSchneider-electric Scadapack 314e FirmwareSchneider-electric Scadapack 330e Firmware+5 | 28/1/2022 | 17/6/2026 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause a Denial of Service of the RTU when receiving a specially crafted request over Modbus, and the RTU is configured as a Modbus server. Affected Products: SCADAPack 312E, 313E, 314E, 330E, 333E, 334E, 337E, 350E and 357E… | |
| Modificada | Crítica (9.8) | 1.4% | — | Myscada Mypro | 23/12/2021 | 17/6/2026 | mySCADA myPRO: Versions 8.20.0 and prior has a vulnerable debug interface which includes a ping utility, which may allow an attacker to inject arbitrary operating system commands. | |
| Modificada | Alta (7.5) | 0.65% | — | Myscada Mypro | 23/12/2021 | 17/6/2026 | mySCADA myPRO Versions 8.20.0 and prior stores passwords using MD5, which may allow an attacker to crack the previously retrieved password hashes. |