Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.1% | — | Schneider-electric Modicon Tsxety4103 FirmwareSchneider-electric Modicon Tsxety5103 FirmwareSchneider-electric Modicon Tsxp574634 FirmwareSchneider-electric Modicon Tsxp575634 Firmware+16 | 18/11/2020 | 17/6/2026 | A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause write access and the execution of commands when… | |
| Modificada | Alta (8.8) | 1.1% | — | Schneider-electric Modicon Tsxety4103 FirmwareSchneider-electric Modicon Tsxety5103 FirmwareSchneider-electric Modicon Tsxp574634 FirmwareSchneider-electric Modicon Tsxp575634 Firmware+16 | 18/11/2020 | 17/6/2026 | A CWE-787: Out-of-bounds Write vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause corruption of data, a crash, or code execution when uploading a specially crafted file on the… | |
| Modificada | Alta (8.1) | 0.90% | — | Schneider-electric Modicon Tsxety4103 FirmwareSchneider-electric Modicon Tsxety5103 FirmwareSchneider-electric Modicon Tsxp574634 FirmwareSchneider-electric Modicon Tsxp575634 Firmware+16 | 18/11/2020 | 17/6/2026 | A CWE-125: Out-of-Bounds Read vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause a segmentation fault or a buffer overflow when uploading a specially crafted file on the controller… | |
| Modificada | Alta (7.5) | 1.2% | — | Schneider-electric BMX P34x FirmwareSchneider-electric BMX NOE 0100 FirmwareSchneider-electric BMX NOE 0110 FirmwareSchneider-electric BMX NOC 0401 Firmware+6 | 22/4/2020 | 17/6/2026 | A CWE-798: Use of Hardcoded Credentials vulnerability exists in Modicon Controllers (All versions of the following CPUs and Communication Module product references listed in the Security Notifications), which could cause the disclosure of FTP hardcoded credentials when using the Web server of the controller on an… | |
| Modificada | Alta (7.5) | 1.4% | — | Schneider-electric BMX P34x FirmwareSchneider-electric BMX NOE 0100 FirmwareSchneider-electric BMX NOE 0110 FirmwareSchneider-electric BMX NOC 0401 Firmware+6 | 20/11/2019 | 17/6/2026 | A CWE-200: Information Exposure vulnerability exists in Modicon Controllers (M340 CPUs, M340 communication modules, Premium CPUs, Premium communication modules, Quantum CPUs, Quantum communication modules - see security notification for specific versions), which could cause the disclosure of FTP hardcoded credentials… | |
| Modificada | Media (5) | 2.1% | — | Schneider-electric Modicon M340 BMX NOC 0401 FirmwareSchneider-electric Modicon M340 BMX NOE 0100 FirmwareSchneider-electric Modicon M340 BMX NOE 0100h FirmwareSchneider-electric Modicon M340 BMX NOE 0110 Firmware+8 | 4/4/2013 | 16/6/2026 | The Schneider Electric M340 PLC modules allow remote attackers to cause a denial of service (resource consumption) via unspecified vectors. NOTE: the vendor reportedly disputes this issue because it "could not be duplicated" and "an attacker could not remotely exploit this observed behavior to deny PLC control… |