Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

18 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.7)0.48%—Siemens Simatic CP 1543-1 Firmware12/11/202417/6/2026
A vulnerability has been identified in SIMATIC CP 1543-1 V4.0 (6GK7543-1AX10-0XE0) (All versions >= V4.0.44 < V4.0.50). Affected devices do not properly handle authorization. This could allow an unauthenticated remote attacker to gain access to the filesystem.
ModificadaAlta (8.8)2.4%—Siemens Simatic CP 1242-7 V2 FirmwareSiemens Simatic CP 1243-1 FirmwareSiemens Simatic CP 1243-7 LTE EU FirmwareSiemens Simatic CP 1243-7 LTE US Firmware+1112/7/20223/9/2026
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2), SCALANCE M804PB (6GK5804-0AP00-2AA2), SCALANCE M812-1 ADSL-Router (6GK5812-1AA00-2AA2), SCALANCE M812-1 ADSL-Router (6GK5812-1BA00-2AA2), SCALANCE M816-1 ADSL-Router…
ModificadaCrítica (9.8)2.2%—Siemens Simatic CP 1242-7 V2 FirmwareSiemens Simatic CP 1243-1 FirmwareSiemens Simatic CP 1243-7 LTE EU FirmwareSiemens Simatic CP 1243-7 LTE US Firmware+1112/7/202217/6/2026
A vulnerability has been identified in SIMATIC CP 1242-7 V2 (All versions < V3.3.46), SIMATIC CP 1243-1 (All versions < V3.3.46), SIMATIC CP 1243-7 LTE EU (All versions < V3.3.46), SIMATIC CP 1243-7 LTE US (All versions < V3.3.46), SIMATIC CP 1243-8 IRC (All versions < V3.3.46), SIMATIC CP 1542SP-1 IRC (All versions…
ModificadaCrítica (10)2.1%—Siemens Simatic CP 1242-7 V2 FirmwareSiemens Simatic CP 1243-1 FirmwareSiemens Simatic CP 1243-7 LTE EU FirmwareSiemens Simatic CP 1243-7 LTE US Firmware+1112/7/202217/6/2026
A vulnerability has been identified in SIMATIC CP 1242-7 V2 (All versions < V3.3.46), SIMATIC CP 1243-1 (All versions < V3.3.46), SIMATIC CP 1243-7 LTE EU (All versions < V3.3.46), SIMATIC CP 1243-7 LTE US (All versions < V3.3.46), SIMATIC CP 1243-8 IRC (All versions < V3.3.46), SIMATIC CP 1542SP-1 IRC (All versions…
ModificadaAlta (7.5)5.3%—StrongswanDebian LinuxFedoraproject FedoraSiemens Sinema Remote Connect Server+2118/10/202117/6/2026
The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to fill the cache and later trigger the replacement of cache entries. The code attempts to select a less-often-used cache entry by means of a random number generator, but…
ModificadaMedia (6.5)0.25%—Siemens Simatic CP 1543-1 FirmwareSiemens Simatic CP 1545-1 Firmware14/9/202117/6/2026
A vulnerability has been identified in SIMATIC CP 1543-1 (incl. SIPLUS variants) (All versions < V3.0), SIMATIC CP 1545-1 (All versions < V1.1). An attacker with access to the subnet of the affected device could retrieve sensitive information stored in cleartext.
ModificadaBaja (3.7)6.3%—Haxx LibcurlFedoraproject FedoraDebian LinuxNetapp Cloud Backup+295/8/202117/6/2026
libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into account and it compared the involved paths *case insensitively*,which could lead to libcurl reusing…
ModificadaMedia (5.9)64%—OpensslDebian LinuxFreebsdNetapp Active IQ Unified Manager+10225/3/202117/6/2026
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer…
ModificadaAlta (7.5)3.2%—Lldpd Project LldpdOpenvswitchRedhat Openshift Container PlatformRedhat Openstack+1318/3/202117/6/2026
A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.
ModificadaAlta (8.8)12%—ProftpdDebian LinuxFedoraproject FedoraOpensuse Backports SLE+320/2/202017/6/2026
In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c, and possible remote code execution.
ModificadaAlta (7.5)2.1%—ProftpdSiemens Simatic NET CP 1543-1 FirmwareSiemens Simatic NET CP 1545-1 FirmwareOpensuse Backports SLE+120/2/202017/6/2026
ProFTPD 1.3.7 has an out-of-bounds (OOB) read vulnerability in mod_cap via the cap_text.c cap_to_text function.
ModificadaCrítica (9.8)58%—ProftpdFedoraproject FedoraDebian LinuxSiemens Simatic CP 1543-1 Firmware19/7/201917/6/2026
An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and information disclosure without authentication, a related issue to CVE-2015-3306.
ModificadaAlta (7.5)32%—Linux KernelRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+476/9/201817/6/2026
The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack with low rates of specially modified packets targeting IP fragment re-assembly. An attacker may cause a denial of service condition by sending specially crafted IP fragments. Various vulnerabilities in IP fragmentation have been discovered…
ModificadaAlta (7.1)0.91%—Siemens Simatic CP 343-1 STD FirmwareSiemens Simatic CP 343-1 Lean FirmwareSiemens Simatic CP 343-1 ADV FirmwareSiemens Simatic CP 443-1 STD Firmware+7511/5/201717/6/2026
Specially crafted PROFINET DCP packets sent on a local Ethernet segment (Layer 2) to an affected product could cause a denial of service condition of that product. Human interaction is required to recover the system. PROFIBUS interfaces are not affected.
ModificadaAlta (7.1)1.1%—Siemens Simatic CP 343-1 STD FirmwareSiemens Simatic CP 343-1 Lean FirmwareSiemens Simatic CP 343-1 ADV FirmwareSiemens Simatic CP 443-1 STD Firmware+8911/5/201717/6/2026
Specially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affected products on a local Ethernet segment (Layer 2). Human interaction is required to recover the systems. PROFIBUS interfaces are not affected.
AnalizadaAlta (7.5)3.6%⚠ Explotación activaSiemens Simatic CP 1543-1 FirmwareSiemens Siplus NET CP 1543-1 Firmware18/11/201617/6/2026
A vulnerability has been identified in SIMATIC CP 1543-1 (All versions < V2.0.28), SIPLUS NET CP 1543-1 (All versions < V2.0.28). Under special conditions it was possible to write SNMP variables on port 161/udp which should be read-only and should only be configured with TIA-Portal. A write to these variables could…
ModificadaMedia (6.6)1.6%—Siemens Simatic CP 1543-1 Firmware18/11/201617/6/2026
A vulnerability has been identified in SIMATIC CP 1543-1 (All versions < V2.0.28), SIPLUS NET CP 1543-1 (All versions < V2.0.28). Users with elevated privileges to TIA-Portal and project data on the engineering station could possibly get privileged access on affected devices.
AnalizadaAlta (7.5)100%⚠ Explotación activaOpensslFilezilla-project Filezilla ServerSiemens Application Processing Engine FirmwareSiemens CP 1543-1 Firmware+247/4/201417/6/2026
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to…