Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.68% | — | Rockwellautomation 1756-en2tr Series A FirmwareRockwellautomation 1756-en2tr Series B FirmwareRockwellautomation 1756-en2tr Series C FirmwareRockwellautomation 1756-en4tr Firmware+1 | 9/9/2025 | 17/6/2026 | A security issue exists in the protected mode of EN4TR devices, where sending specifically crafted messages during a Forward Close operation can cause the device to crash. | |
| Analizada | Alta (7.1) | 0.25% | — | Rockwellautomation 1756-en2tr Series A FirmwareRockwellautomation 1756-en2tr Series B FirmwareRockwellautomation 1756-en2tr Series C FirmwareRockwellautomation 1756-en4tr Firmware+1 | 9/9/2025 | 17/6/2026 | A security issue exists in the protected mode of 1756-EN4TR and 1756-EN2TR communication modules, where a Concurrent Forward Close operation can trigger a Major Non-Recoverable (MNFR) fault. This condition may lead to unexpected system crashes and loss of device availability. | |
| Analizada | Alta (8.7) | 0.52% | — | Rockwellautomation Compactlogix 5380 FirmwareRockwellautomation Compact Guardlogix 5380 FirmwareRockwellautomation Compactlogix 5480 FirmwareRockwellautomation Controllogix 5580 Firmware+2 | 8/10/2024 | 17/6/2026 | Due to a memory leak, a denial-of-service vulnerability exists in the Rockwell Automation affected products. A malicious actor could exploit this vulnerability by performing multiple actions on certain web pages of the product causing the affected products to become fully unavailable and require a power cycle to… | |
| Analizada | Alta (7.5) | 0.64% | — | Rockwellautomation Controllogix 5580 FirmwareRockwellautomation Guardlogix 5580 FirmwareRockwellautomation Compactlogix 5380 FirmwareRockwellautomation Compact Guardlogix 5380 Firmware+4 | 15/4/2024 | 17/6/2026 | A specific malformed fragmented packet type (fragmented packets may be generated automatically by devices that send large amounts of data) can cause a major nonrecoverable fault (MNRF) Rockwell Automation's ControlLogix 5580, Guard Logix 5580, CompactLogix 5380, and 1756-EN4TR. If exploited, the affected product will… | |
| Modificada | Alta (7.5) | 3.7% | — | Rockwellautomation 1756-en4tr FirmwareRockwellautomation 1756-en4trk FirmwareRockwellautomation 1756-en4trxt Firmware | 12/7/2023 | 17/6/2026 | Where this vulnerability exists in the Rockwell Automation 1756-EN4* Ethernet/IP communication products, it could allow a malicious user to cause a denial of service by asserting the target system through maliciously crafted CIP messages. |