Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.1% | — | Wago 0852-0303 FirmwareWago 0852-1305 FirmwareWago 0852-1505 FirmwareWago 0852-1305/000-001 Firmware+1 | 13/5/2021 | 17/6/2026 | In multiple managed switches by WAGO in different versions without authorization and with specially crafted packets it is possible to create users. | |
| Modificada | Alta (7.5) | 1.0% | — | Wago 0852-0303 FirmwareWago 0852-1305 FirmwareWago 0852-1505 FirmwareWago 0852-1305/000-001 Firmware+1 | 13/5/2021 | 17/6/2026 | In multiple managed switches by WAGO in different versions it is possible to read out the password hashes of all Web-based Management users. | |
| Modificada | Media (5.3) | 0.75% | — | Wago 0852-0303 FirmwareWago 0852-1305 FirmwareWago 0852-1505 FirmwareWago 0852-1305/000-001 Firmware+1 | 13/5/2021 | 17/6/2026 | In multiple managed switches by WAGO in different versions special crafted requests can lead to cookies being transferred to third parties. | |
| Modificada | Alta (7.5) | 0.54% | — | Wago 0852-0303 FirmwareWago 0852-1305 FirmwareWago 0852-1505 FirmwareWago 0852-1305/000-001 Firmware+1 | 13/5/2021 | 17/6/2026 | In multiple managed switches by WAGO in different versions the webserver cookies of the web based UI contain user credentials. | |
| Modificada | Media (6.1) | 0.63% | — | Wago 0852-0303 FirmwareWago 0852-1305 FirmwareWago 0852-1505 FirmwareWago 0852-1305/000-001 Firmware+1 | 13/5/2021 | 17/6/2026 | In multiple managed switches by WAGO in different versions an attacker may trick a legitimate user to click a link to inject possible malicious code into the Web-Based Management. | |
| Modificada | Media (5.3) | 0.79% | — | Wago 0852-0303 FirmwareWago 0852-1305 FirmwareWago 0852-1505 FirmwareWago 0852-1305/000-001 Firmware+1 | 13/5/2021 | 17/6/2026 | In multiple managed switches by WAGO in different versions the activated directory listing provides an attacker with the index of the resources located inside the directory. | |
| Modificada | Crítica (9.8) | 2.7% | — | Wago 852-303 FirmwareWago 852-1305 FirmwareWago 852-1505 Firmware | 17/6/2019 | 17/6/2026 | WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded users and passwords that can be used to login via SSH and TELNET. | |
| Modificada | Crítica (9.8) | 3.3% | — | Wago 852-303 FirmwareWago 852-1305 FirmwareWago 852-1505 Firmware | 17/6/2019 | 17/6/2026 | WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded private keys for the SSH daemon. The fingerprint of the SSH host key from the corresponding SSH daemon matches the embedded private key. |