Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
2424 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.30% | — | Siemens TIA Project-serverAISiemens Totally Integrated Automation PortalAI | 8/7/2025 | 17/6/2026 | A vulnerability has been identified in TIA Project-Server (All versions < V2.1.1), TIA Project-Server V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All versions), Totally Integrated Automation Portal (TIA Portal) V19… | |
| Analizada | Alta (8.5) | 0.14% | — | Siemens TIA Administrator | 8/7/2025 | 17/6/2026 | A vulnerability has been identified in TIA Administrator (All versions < V3.0.6). The affected application allows low-privileged users to trigger installations by overwriting cache files and modifying the downloads path. This would allow an attacker to escalate privilege and exceute arbitrary code. | |
| Analizada | Media (6.9) | 0.07% | — | Siemens TIA Administrator | 8/7/2025 | 17/6/2026 | A vulnerability has been identified in TIA Administrator (All versions < V3.0.6). The affected application improperly validates code signing certificates. This could allow an attacker to bypass the check and exceute arbitrary code during installations. | |
| Analizada | Alta (7.7) | 0.19% | — | Siemens Sicam Toolbox II | 8/7/2025 | 17/6/2026 | A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.11). During establishment of a https connection to the TLS server of a managed device, the affected application doesn't check device's certificate common name against an expected value. This could allow an attacker to execute an on-path… | |
| Analizada | Alta (7.7) | 0.19% | — | Siemens Sicam Toolbox II | 8/7/2025 | 17/6/2026 | A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.11). During establishment of a https connection to the TLS server of a managed device, the affected application doesn't check the extended key usage attribute of that device's certificate. This could allow an attacker to execute an on-path… | |
| Aplazada | Media (5.5) | 0.10% | — | Siemens PLC DesignerAI | 25/6/2025 | 17/6/2026 | A local, low-privileged attacker can learn the password of the connected controller in PLC Designer V4 due to an incorrect implementation that results in the password being displayed in plain text under special conditions. | |
| Aplazada | Alta (8.7) | 0.37% | — | Siemens Relion 670AISiemens Relion 650AISiemens Sam600-ioAI | 24/6/2025 | 17/6/2026 | A denial-of-service vulnerability due to improper prioritization of network traffic over protection mechanism exists in Relion 670/650 and SAM600-IO series device that if exploited could potentially cause critical functions like LDCM (Line Distance Communication Module) to malfunction. | |
| Aplazada | Alta (8.3) | 0.67% | — | Siemens Ruggedcom ROX Mx5000AISiemens Ruggedcom ROX Mx5000reAISiemens Ruggedcom ROX Rx1400AISiemens Ruggedcom ROX Rx1500AI+7 | 10/6/2025 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versions < V2.16.5), RUGGEDCOM ROX RX1400 (All versions < V2.16.5), RUGGEDCOM ROX RX1500 (All versions < V2.16.5), RUGGEDCOM ROX RX1501 (All versions < V2.16.5), RUGGEDCOM ROX RX1510 (All versions <… | |
| Aplazada | Media (5.9) | 0.28% | — | Siemens Ruggedcom Rst2428pAISiemens Scalance Xch328AISiemens Scalance Xcm324AISiemens Scalance Xcm328AI+3 | 10/6/2025 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.2), SCALANCE XCH328 (6GK5328-4TS01-2EC2) (All versions < V3.2), SCALANCE XCM324 (6GK5324-8TS01-2AC2) (All versions < V3.2), SCALANCE XCM328 (6GK5328-4TS01-2AC2) (All versions < V3.2), SCALANCE XCM332 (6GK5332-0GA01-2AC2) (All… | |
| Aplazada | Media (5.3) | 0.52% | — | Siemens Ruggedcom Rst2428pAISiemens Scalance Xch328AISiemens Scalance Xcm324AISiemens Scalance Xcm328AI+3 | 10/6/2025 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.2), SCALANCE XCH328 (6GK5328-4TS01-2EC2) (All versions < V3.2), SCALANCE XCM324 (6GK5324-8TS01-2AC2) (All versions < V3.2), SCALANCE XCM328 (6GK5328-4TS01-2AC2) (All versions < V3.2), SCALANCE XCM332 (6GK5332-0GA01-2AC2) (All… | |
| Aplazada | Alta (7.1) | 0.44% | — | Siemens Ruggedcom Rst2428pAISiemens Scalance Xch328AISiemens Scalance Xcm324AISiemens Scalance Xcm328AI+3 | 10/6/2025 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.2), SCALANCE XCH328 (6GK5328-4TS01-2EC2) (All versions < V3.2), SCALANCE XCM324 (6GK5324-8TS01-2AC2) (All versions < V3.2), SCALANCE XCM328 (6GK5328-4TS01-2AC2) (All versions < V3.2), SCALANCE XCM332 (6GK5332-0GA01-2AC2) (All… | |
| Aplazada | Media (5.3) | 0.38% | — | Siemens Ruggedcom Rst2428pAISiemens Scalance Xc316-8AISiemens Scalance Xc324-4AISiemens Scalance Xc332AI+15 | 10/6/2025 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.1), SCALANCE XC316-8 (6GK5324-8TS00-2AC2) (All versions < V3.1), SCALANCE XC324-4 (6GK5328-4TS00-2AC2) (All versions < V3.1), SCALANCE XC324-4 EEC (6GK5328-4TS00-2EC2) (All versions < V3.1), SCALANCE XC332 (6GK5332-0GA00-2AC2)… | |
| Analizada | Alta (8.7) | 0.62% | — | Siemens Sipass Integrated | 23/5/2025 | 17/6/2026 | A vulnerability has been identified in SiPass integrated (All versions < V2.95.3.18). Affected server applications contain an out of bounds read past the end of an allocated buffer while checking the integrity of incoming packets. This could allow an unauthenticated remote attacker to create a denial of service… | |
| Modificada | Media (5.9) | 0.16% | — | Siemens Sipass Integrated Ac5102 (acc-g2) FirmwareSiemens Sipass Integrated Acc-ap Firmware | 23/5/2025 | 17/6/2026 | A vulnerability has been identified in Building X - Security Manager Edge Controller (ACC-AP) (All versions). Affected devices do not properly check the integrity of firmware updates. This could allow a local attacker to upload a maliciously modified firmware onto the device. In a second scenario, a remote attacker… | |
| Modificada | Media (6.7) | 0.11% | — | Siemens Scalance Lpe9403 Firmware | 13/5/2025 | 8/9/2026 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge Client installed). Affected devices do transmit sensitive information in cleartext. This could allow a privileged local attacker to retrieve this sensitive information. | |
| Modificada | Alta (8.5) | 0.18% | — | Siemens Scalance Lpe9403 Firmware | 13/5/2025 | 8/9/2026 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge Client installed). Affected devices do not properly sanitize configuration parameters. This could allow a non-privileged local attacker to execute root commands on the device. | |
| Modificada | Alta (8.4) | 0.15% | — | Siemens Scalance Lpe9403 Firmware | 13/5/2025 | 8/9/2026 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge Client installed). Affected devices are vulnerable to an authentication bypass. This could allow a non-privileged local attacker to bypass the authentication of the SINEMA Remote… | |
| Modificada | Media (5.4) | 0.16% | — | Siemens Scalance Lpe9403 Firmware | 13/5/2025 | 17/6/2026 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices are vulnerable to a stack-based buffer overflow. This could allow a non-privileged local attacker to execute arbitrary code on the device or to cause a denial of service condition. | |
| Modificada | Media (5.4) | 0.16% | — | Siemens Scalance Lpe9403 Firmware | 13/5/2025 | 17/6/2026 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices are vulnerable to a stack-based buffer overflow. This could allow a non-privileged local attacker to execute arbitrary code on the device or to cause a denial of service condition. | |
| Analizada | Media (5.3) | 0.27% | — | Siemens Scalance Lpe9403 Firmware | 13/5/2025 | 17/6/2026 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions). Affected devices do not properly handle multiple incoming Profinet packets received in rapid succession. An unauthenticated remote attacker can exploit this flaw by sending multiple packets in a very short time frame, which… | |
| Modificada | Media (5.3) | 0.27% | — | Siemens Scalance Lpe9403 Firmware | 13/5/2025 | 17/6/2026 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices do not properly validate incoming Profinet packets. An unauthenticated remote attacker can exploit this flaw by sending a specially crafted malicious packet, which leads to a crash of the dcpd… | |
| Modificada | Media (5.3) | 0.27% | — | Siemens Scalance Lpe9403 Firmware | 13/5/2025 | 17/6/2026 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices do not properly validate incoming Profinet packets. An unauthenticated remote attacker can exploit this flaw by sending a specially crafted malicious packet, which leads to a crash of the dcpd… | |
| Modificada | Media (5.3) | 0.46% | — | Siemens Scalance Lpe9403 Firmware | 13/5/2025 | 17/6/2026 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices do not properly validate incoming Profinet packets. An unauthenticated remote attacker can exploit this flaw by sending a specially crafted malicious packet, which leads to a crash of the dcpd… | |
| Modificada | Alta (8.5) | 0.14% | — | Siemens Scalance Lpe9403 Firmware | 13/5/2025 | 17/6/2026 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices do not properly assign permissions to critical ressources. This could allow a non-privileged local attacker to interact with the backupmanager service. | |
| Modificada | Media (6.7) | 0.17% | — | Siemens Scalance Lpe9403 Firmware | 13/5/2025 | 17/6/2026 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices are vulnerable to path traversal attacks. This could allow a privileged local attacker to restore backups that are outside the backup folder. |