Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 345 respecto a la semana anterior
Críticas / altas1316▼ 9 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 273 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.4) | 0.16% | — | Siemens Simatic CP 1604 FirmwareSiemens Simatic CP 1616 FirmwareSiemens Simatic CP 1623 FirmwareSiemens Simatic CP 1626 Firmware+1 | 10/10/2023 | 17/6/2026 | A vulnerability has been identified in SIMATIC CP 1604 (All versions), SIMATIC CP 1616 (All versions), SIMATIC CP 1623 (All versions), SIMATIC CP 1626 (All versions), SIMATIC CP 1628 (All versions). Affected devices insufficiently control continuous mapping of direct memory access (DMA) requests. This could allow… | |
| Modificada | Media (6.7) | 0.18% | — | Siemens Simatic CP 1604 FirmwareSiemens Simatic CP 1616 FirmwareSiemens Simatic CP 1623 FirmwareSiemens Simatic CP 1626 Firmware+1 | 10/10/2023 | 17/6/2026 | A vulnerability has been identified in SIMATIC CP 1604 (All versions), SIMATIC CP 1616 (All versions), SIMATIC CP 1623 (All versions), SIMATIC CP 1626 (All versions), SIMATIC CP 1628 (All versions). The kernel memory of affected devices is exposed to user-mode via direct memory access (DMA) which could allow a local… | |
| Modificada | Alta (7.5) | 0.94% | — | Fujifilm Docuprint M265 Z FirmwareFujifilm Docuprint M268 Z FirmwareFujifilm Docuprint M225 Z FirmwareFujifilm Docuprint M225 DW Firmware+212 | 11/7/2023 | 17/6/2026 | Null pointer dereference vulnerability exists in multiple vendors MFPs and printers which implement Debut web server 1.2 or 1.3. Processing a specially crafted request may lead an affected product to a denial-of-service (DoS) condition. As for the affected products/models/versions, see the detailed information… | |
| Modificada | Alta (7.5) | 1.8% | — | Brother Ads-2400n FirmwareBrother Ads-2800w FirmwareBrother Ads-3000n FirmwareBrother Ads-3600w Firmware+296 | 13/3/2020 | 17/6/2026 | Some Brother printers (such as the HL-L8360CDW v1.20) were affected by different information disclosure vulnerabilities that provided sensitive information to an unauthenticated user who visits a specific URL. | |
| Modificada | Alta (8.8) | 3.1% | — | Brother Ads-2400n FirmwareBrother Ads-2800w FirmwareBrother Ads-3000n FirmwareBrother Ads-3600w Firmware+296 | 13/3/2020 | 17/6/2026 | Some Brother printers (such as the HL-L8360CDW v1.20) were affected by a stack buffer overflow vulnerability as the web server did not parse the cookie value properly. This would allow an attacker to execute arbitrary code on the device. | |
| Modificada | Crítica (9.8) | 3.8% | — | Brother Ads-2400n FirmwareBrother Ads-2800w FirmwareBrother Ads-3000n FirmwareBrother Ads-3600w Firmware+296 | 13/3/2020 | 17/6/2026 | Some Brother printers (such as the HL-L8360CDW v1.20) were affected by a heap buffer overflow vulnerability as the IPP service did not parse attribute names properly. This would allow an attacker to execute arbitrary code on the device. | |
| Modificada | Alta (7.5) | 1.5% | — | Siemens DK Standard Ethernet ControllerSiemens Profinet DriverSiemens Simatic IPC SupportSiemens Ek-ertec 200 Firmware+48 | 11/2/2020 | 17/6/2026 | Profinet-IO (PNIO) stack versions prior V06.00 do not properly limit internal resource allocation when multiple legitimate diagnostic package requests are sent to the DCE-RPC interface. This could lead to a denial of service condition due to lack of memory for devices that include a vulnerable version of the stack.… | |
| Modificada | Media (6.5) | 0.51% | — | Siemens CP 1604 FirmwareSiemens CP 1616 Firmware | 17/4/2019 | 17/6/2026 | A vulnerability has been identified in CP 1604 (All versions), CP 1616 (All versions). The integrated configuration web server of the affected CP devices could allow a Cross-Site Request Forgery (CSRF) attack if an unsuspecting user is tricked into accessing a malicious link. Successful exploitation requires user… | |
| Modificada | Media (6.1) | 0.79% | — | Siemens CP 1604 FirmwareSiemens CP 1616 Firmware | 17/4/2019 | 17/6/2026 | A vulnerability has been identified in CP 1604 (All versions), CP 1616 (All versions). The integrated web server of the affected CP devices could allow Cross-Site Scripting (XSS) attacks if unsuspecting users are tricked into following a malicious link. User interaction is required for a successful exploitation. At… | |
| Modificada | Crítica (9.1) | 1.8% | — | Siemens CP 1604 FirmwareSiemens CP 1616 Firmware | 17/4/2019 | 17/6/2026 | A vulnerability has been identified in CP 1604 (All versions), CP 1616 (All versions). An attacker with network access to port 23/tcp could extract internal communication data or cause a Denial-of-Service condition. Successful exploitation requires network access to a vulnerable device. At the time of advisory… | |
| Modificada | Alta (7.1) | 0.91% | — | Siemens Simatic CP 343-1 STD FirmwareSiemens Simatic CP 343-1 Lean FirmwareSiemens Simatic CP 343-1 ADV FirmwareSiemens Simatic CP 443-1 STD Firmware+75 | 11/5/2017 | 17/6/2026 | Specially crafted PROFINET DCP packets sent on a local Ethernet segment (Layer 2) to an affected product could cause a denial of service condition of that product. Human interaction is required to recover the system. PROFIBUS interfaces are not affected. | |
| Modificada | Alta (7.1) | 1.1% | — | Siemens Simatic CP 343-1 STD FirmwareSiemens Simatic CP 343-1 Lean FirmwareSiemens Simatic CP 343-1 ADV FirmwareSiemens Simatic CP 443-1 STD Firmware+89 | 11/5/2017 | 17/6/2026 | Specially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affected products on a local Ethernet segment (Layer 2). Human interaction is required to recover the systems. PROFIBUS interfaces are not affected. | |
| Modificada | Alta (10) | 5.9% | — | Siemens CP 1604 FirmwareSiemens CP 1616 FirmwareSiemens CP 1604Siemens CP 1616 | 1/4/2013 | 16/6/2026 | The debugging feature on the Siemens CP 1604 and CP 1616 interface cards with firmware before 2.5.2 allows remote attackers to execute arbitrary code via a crafted packet to UDP port 17185. |