Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.7) | 0.23% | — | Allen Bradley 1756-en2AIAllen Bradley 1756-en3AIRockwellautomation 1756-enbtAI | 14/7/2026 | 14/7/2026 | A denial-of-service security issue exists across all the 1756-EN2, EN3, and ENBT communication module due to improper validation of CIP Implicit Connection packets. An attacker on the network can exploit this by sending crafted packets to continuously disrupt device connections, though device connections will recover… | |
| Modificada | Crítica (9.8) | 1.3% | — | Rockwellautomation 1756-en2t Series A FirmwareRockwellautomation 1756-en2t Series B FirmwareRockwellautomation 1756-en2t Series C FirmwareRockwellautomation 1756-en2t Series D Firmware+29 | 20/9/2023 | 17/6/2026 | A buffer overflow vulnerability exists in the Rockwell Automation select 1756-EN* communication devices. If exploited, a threat actor could potentially leverage this vulnerability to perform a remote code execution. To exploit this vulnerability, a threat actor would have to send a maliciously crafted CIP request to… | |
| Modificada | Crítica (9.8) | 5.5% | — | Rockwellautomation 1756-en2f Series A FirmwareRockwellautomation 1756-en2f Series B FirmwareRockwellautomation 1756-en2f Series C FirmwareRockwellautomation 1756-en2t Series A Firmware+8 | 12/7/2023 | 17/6/2026 | Where this vulnerability exists in the Rockwell Automation 1756 EN2* and 1756 EN3* ControlLogix communication products, it could allow a malicious user to perform remote code execution with persistence on the target system through maliciously crafted CIP messages. This includes the ability to modify, deny, and… | |
| Modificada | Alta (8.6) | 4.3% | — | Rockwellautomation Micrologix 1400 FirmwareRockwellautomation 1756-enbt FirmwareRockwellautomation 1756-eweb Series A FirmwareRockwellautomation 1756-eweb Series B Firmware+12 | 7/12/2018 | 17/6/2026 | Rockwell Automation MicroLogix 1400 Controllers and 1756 ControlLogix Communications Modules An unauthenticated, remote threat actor could send a CIP connection request to an affected device, and upon successful connection, send a new IP configuration to the affected device even if the controller in the system is set… | |
| Modificada | Media (6.1) | 7.6% | 💥 Exploit | Rockwellautomation Compactlogix 1769-l16er-bb1b FirmwareRockwellautomation Compactlogix 1769-l18er-bb1b FirmwareRockwellautomation Compactlogix 1769-l18erm-bb1b FirmwareRockwellautomation Compactlogix 1769-l24er-qb1b Firmware+19 | 2/3/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the web server in Rockwell Automation Allen-Bradley CompactLogix 1769-L* before 28.011+ allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |