Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.2) | 11% | — | Siemens Automation License ManagerAI | 10/9/2024 | 17/6/2026 | A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6.0 (All versions < V6.0 SP12 Upd3), Automation License Manager V6.2 (All versions < V6.2 Upd3). Affected applications do not properly validate certain fields in incoming network packets on port 4410/tcp.… | |
| Modificada | Crítica (9.8) | 1.5% | — | Siemens Automation License Manager | 10/1/2023 | 17/6/2026 | A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6 (All versions < V6.0 SP9 Upd4), TeleControl Server Basic V3 (All versions < V3.1.2). The affected component does not correctly validate the root path on folder related operations, allowing to modify files… | |
| Modificada | Alta (7.5) | 0.97% | — | Siemens Automation License Manager | 10/1/2023 | 17/6/2026 | A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6 (All versions < V6.0 SP9 Upd4), TeleControl Server Basic V3 (All versions < V3.1.2). The affected components allow to rename license files with user chosen input without authentication. This could allow… | |
| Modificada | Alta (7.5) | 1.0% | — | Siemens Automation License Manager | 10/8/2021 | 17/6/2026 | A vulnerability has been identified in Automation License Manager 5 (All versions), Automation License Manager 6 (All versions < V6.0 SP9 Update 2). Sending specially crafted packets to port 4410/tcp of an affected system could lead to extensive memory being consumed and as such could cause a denial-of-service… | |
| Modificada | Alta (7.8) | 0.27% | — | Siemens Automation License Manager | 14/8/2020 | 17/6/2026 | A vulnerability has been identified in Automation License Manager 5 (All versions), Automation License Manager 6 (All versions < V6.0.8). The application does not properly validate the users' privileges when executing some operations, which could allow a user with low permissions to arbitrary modify files that should… | |
| Modificada | Media (5.8) | 1.3% | — | Siemens Automation License Manager | 7/8/2018 | 17/6/2026 | A vulnerability has been identified in Automation License Manager 5 (All versions < 5.3.4.4). An attacker with network access to the device could send specially crafted network packets to determine whether or not a network port on another remote system is accessible or not. This allows the attacker to do basic network… | |
| Modificada | Alta (8.8) | 5.3% | — | Siemens Automation License Manager | 7/8/2018 | 17/6/2026 | A vulnerability has been identified in Automation License Manager 5 (All versions < 5.3.4.4), Automation License Manager 6 (All versions < 6.0.1). A directory traversal vulnerability could allow a remote attacker to move arbitrary files, which can result in code execution, compromising confidentiality, integrity and… | |
| Modificada | Crítica (9.1) | 2.9% | — | Siemens Automation License Manager | 13/10/2016 | 17/6/2026 | Siemens Automation License Manager (ALM) before 5.3 SP3 allows remote attackers to write to files, rename files, create directories, or delete directories via crafted packets. | |
| Modificada | Media (6.5) | 1.1% | — | Siemens Automation License Manager | 13/10/2016 | 17/6/2026 | SQL injection vulnerability in Siemens Automation License Manager (ALM) before 5.3 SP3 Update 1 allows remote attackers to execute arbitrary SQL commands via crafted traffic to TCP port 4410. | |
| Modificada | Alta (7.5) | 3.0% | — | Siemens Automation License Manager | 13/10/2016 | 17/6/2026 | Siemens Automation License Manager (ALM) before 5.3 SP3 Update 1 allows remote attackers to cause a denial of service (ALM service outage) via crafted packets to TCP port 4410. | |
| Modificada | Baja (3.3) | 0.89% | — | Siemens Automation License Manager | 18/12/2012 | 16/6/2026 | Memory leak in Siemens Automation License Manager (ALM) 4.x and 5.x before 5.2 allows remote attackers to cause a denial of service (memory consumption) via crafted packets. | |
| Modificada | Media (5) | 3.2% | 💥 Exploit | Siemens Automation License Manager | 8/1/2012 | 16/6/2026 | Absolute path traversal vulnerability in the ALMListView.ALMListCtrl ActiveX control in almaxcx.dll in the graphical user interface in Siemens Automation License Manager (ALM) 2.0 through 5.1+SP1+Upd2 allows remote attackers to overwrite arbitrary files via the Save method. | |
| Modificada | Media (5) | 8.4% | 💥 Exploit | Siemens Automation License Manager | 8/1/2012 | 16/6/2026 | Siemens Automation License Manager (ALM) 4.0 through 5.1+SP1+Upd1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via crafted content in a (1) get_target_ocx_param or (2) send_target_ocx_param command. | |
| Modificada | Media (5) | 4.1% | 💥 Exploit | Siemens Automation License Manager | 8/1/2012 | 16/6/2026 | Siemens Automation License Manager (ALM) 4.0 through 5.1+SP1+Upd1 does not properly copy fields obtained from clients, which allows remote attackers to cause a denial of service (exception and daemon crash) via long fields, as demonstrated by fields to the (1) open_session->workstation->NAME or (2) grant->VERSION… | |
| Modificada | Alta (7.5) | 6.9% | 💥 Exploit | Siemens Automation License Manager | 8/1/2012 | 16/6/2026 | Multiple buffer overflows in Siemens Automation License Manager (ALM) 4.0 through 5.1+SP1+Upd1 allow remote attackers to execute arbitrary code via a long serialid field in an _licensekey command, as demonstrated by the (1) check_licensekey or (2) read_licensekey command. |