Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2585▼ 302 respecto a la semana anterior
Críticas / altas1355▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

14 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.9)0.36%—Br-automation Automation RuntimeAI19/1/202617/6/2026
An Allocation of Resources Without Limits or Throttling vulnerability in the ANSL-Server component of B&R Automation Runtime versions prior to 6.5 and prior to R4.93 could be exploited by an unauthenti-cated attacker on the network to win a race condition, resulting in permanent denial-of-service (DoS) conditions on…
AplazadaMedia (5.1)0.26%—Br-automation Automation RuntimeAI7/10/202517/6/2026
Reflected cross-site scripting (XSS) vulnerabilities exist in System Diagnostics Manager (SDM) of B&R Automation Runtime versions before 6.4 that enables a remote attacker to execute arbitrary JavaScript code in the context of the attacked user’s browser session
AplazadaAlta (8.2)0.34%—B R Automation Mapp ViewAIBr-automation Automation RuntimeAI15/1/202517/6/2026
A “Use of a Broken or Risky Cryptographic Algorithm” vulnerability in the SSL/TLS component used in B&R Automation Runtime versions before 6.1 and B&R mapp View versions before 6.1 may be abused by unauthenticated network-based attackers to masquerade as services on impacted devices.
AplazadaMedia (5.3)0.25%—Br-automation Automation RuntimeAI12/8/202417/6/2026
Enabled IP Forwarding feature in B&R Automation Runtime versions before 6.0.2 may allow remote attack-ers to compromise network security by routing IP-based packets through the host, potentially by-passing firewall, router, or NAC filtering.
AnalizadaAlta (8.3)0.25%—Br-automation Automation Runtime12/8/202417/6/2026
Diffie-Hellman groups with insufficient strength are used in the SSL/TLS stack of B&R Automation Runtime versions before 6.0.2, allowing a network attacker to decrypt the SSL/TLS communication.
AplazadaAlta (7.2)0.17%—B&R Industrial Automation Scene ViewerAIB&R Industrial Automation Mapp VisionAIB&R Industrial Automation Mapp ViewAIB&R Industrial Automation Mapp CockpitAI+2114/5/202417/6/2026
An Uncontrolled Search Path Element vulnerability in B&R Industrial Automation Scene Viewer, B&R Industrial Automation Automation Runtime, B&R Industrial Automation mapp Vision, B&R Industrial Automation mapp View, B&R Industrial Automation mapp Cockpit, B&R Industrial Automation mapp Safety, B&R Industrial Automation…
ModificadaMedia (6.1)0.37%—Br-automation Automation Runtime5/2/202417/6/2026
A reflected cross-site scripting (XSS) vulnerability exists in the SVG version of System Diagnostics Manager of B&R Automation Runtime versions <= G4.93 that enables a remote attacker to execute arbitrary JavaScript code in the context of the attacked user’s browser session.
ModificadaCrítica (9.8)0.23%—Br-automation Automation Runtime5/2/202417/6/2026
The FTP server used on the B&R Automation Runtime supports unsecure encryption mechanisms, such as SSLv3, TLSv1.0 and TLS1.1. An network-based attacker can exploit the flaws to conduct man-in-the-middle attacks or to decrypt communications between the affected product clients.
ModificadaMedia (5.9)0.54%—Br-automation Automation Runtime26/7/202317/6/2026
Improper initialization implementation in Portmapper used in B&R Industrial Automation Automation Runtime <G4.93 allows unauthenticated network-based attackers to cause permanent denial-of-service conditions.
ModificadaMedia (6.1)0.56%—Br-automation Automation Runtime14/2/202317/6/2026
A reflected cross-site scripting (XSS) vulnerability exists in System Diagnostics Manager of B&R Automation Runtime versions >=3.00 and <=C4.93 that enables a remote attacker to execute arbitrary JavaScript in the context of the users browser session.
ModificadaAlta (8.6)0.96%—Br-automation Automation Runtime13/5/202217/6/2026
Buffer Overflow vulnerability in B&R Automation Runtime webserver allows an unauthenticated network-based attacker to stop the cyclic program on the device and cause a denial of service.
ModificadaAlta (7.3)0.88%—Beckhoff Twincat Extended Automation Runtime19/11/202017/6/2026
The default installation path of the TwinCAT XAR 3.1 software in all versions is underneath C:\TwinCAT. If the directory does not exist it and further subdirectories are created with permissions which allow every local user to modify the content. The default installation registers TcSysUI.exe for automatic execution…
ModificadaAlta (7.5)1.1%—Br-automation Automation Runtime15/10/202017/6/2026
A memory leak in the TFTP service in B&R Automation Runtime versions <N4.26, <N4.34, <F4.45, <E4.53, <D4.63, <A4.73 and prior could allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition.
ModificadaCrítica (9.4)1.6%—Br-automation Automation RuntimeBr-automation Automation Studio20/4/202017/6/2026
An authentication weakness in the SNMP service in B&R Automation Runtime versions 2.96, 3.00, 3.01, 3.06 to 3.10, 4.00 to 4.63, 4.72 and above allows unauthenticated users to modify the configuration of B&R products via SNMP.