Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
–

14 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.6)0.62%—Siemens Cpci85AISiemens SicoreAI9/7/20269/7/2026
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application contains insufficient validation of authentication credentials when processing administrative account modifications through the web API. This…
Pendiente de análisisMedia (6.3)0.23%—Siemens Cpci85AISiemens Sicore Base SystemAI9/7/20269/7/2026
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application ships with a default configuration that disables all OPC UA security mechanisms. This could allow an attacker to gain unauthorized access and…
Pendiente de análisisAlta (8.4)0.18%—Siemens Cpci85AISiemens SicoreAI9/7/20269/7/2026
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application contains a vulnerability in its firmware update mechanism's signature validation process. This could allow an attacker to install malicious…
Pendiente de análisisAlta (7.1)0.41%—Siemens Cpci85AISiemens SicoreAI9/7/20269/7/2026
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application includes a debugging interface that is accessible through HTTP endpoints. This could allow an authenticated attacker to disrupt the system by…
Pendiente de análisisAlta (8.7)0.51%—Siemens Cpci85AISiemens SicoreAI26/3/202617/6/2026
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.10), SICORE Base system (All versions < V26.10.0). The affected application contains an out-of-bounds write vulnerability while parsing specially crafted XML inputs. This could allow an unauthenticated attacker to…
Pendiente de análisisAlta (7.1)0.29%—Phoenixcontact Cpci85AIPhoenixcontact Rtum85AI26/3/202617/6/2026
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.10), RTUM85 RTU Base (All versions < V26.10). The affected application contains denial-of-service (DoS) vulnerability. The remote operation mode is susceptible to a resource exhaustion condition when subjected to a high…
AplazadaMedia (5.1)0.29%—Cpci85 Central Processing CommunicationAI10/12/202417/6/2026
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V05.30). The affected devices contain a secure element which is connected via an unencrypted SPI bus. This could allow an attacker with physical access to the SPI bus to observe the password used for the secure element…
AplazadaAlta (7.1)0.52%—Phoenixcontact Cpci85AIPhoenixcontact SicoreAI22/7/202417/6/2026
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.40), SICORE Base system (All versions < V1.4.0). Affected devices allow a remote authenticated user or an unauthenticated user with physical access to downgrade the firmware of the device. This could allow an attacker to…
AplazadaCrítica (9.3)0.45%—Beckhoff Cpci85AIBeckhoff SicoreAI22/7/202417/6/2026
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.40), SICORE Base system (All versions < V1.4.0). The password of administrative accounts of the affected applications can be reset without requiring the knowledge of the current password, given the auto login is enabled.…
AplazadaAlta (8.6)2.4%—Phoenixcontact Cpci85AIPhoenixcontact SicoreAI14/5/202417/6/2026
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.30), SICORE Base system (All versions < V1.3.0). The web interface of affected devices is vulnerable to command injection due to missing server side input sanitation. This could allow an authenticated privileged remote…
AplazadaAlta (7.3)0.47%—Siemens Cpc80AISiemens Cpci85AISiemens Cpcx26AISiemens Eta4AI+214/5/202417/6/2026
A vulnerability has been identified in CPC80 Central Processing/Communication (All versions < V16.41), CPCI85 Central Processing/Communication (All versions < V5.30), CPCX26 Central Processing/Communication (All versions < V06.02), ETA4 Ethernet Interface IEC60870-5-104 (All versions < V10.46), ETA5 Ethernet Int.…
ModificadaMedia (6.8)0.39%—Siemens Cpci85 Firmware13/6/202317/6/2026
A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). The affected devices contain an exposed UART console login interface. An attacker with direct physical access could try to bruteforce or crack the root password to login to the…
ModificadaMedia (6.8)0.36%—Siemens Cpci85 Firmware13/6/202317/6/2026
A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). The affected devices contain the hash of the root password in a hard-coded form, which could be exploited for UART console login to the device. An attacker with direct physical…
ModificadaAlta (7.2)48%—Siemens Cpci85 Firmware13/6/202317/6/2026
A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). The web interface of affected devices is vulnerable to command injection due to missing server side input sanitation. This could allow an authenticated privileged remote attacker…