Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2628▼ 312 respecto a la semana anterior
Críticas / altas1351▲ 89 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.74% | — | Siemens Simatic S7-plcsim Advanced FirmwareSiemens Simatic S7-1200 CPU 1211c FirmwareSiemens Simatic S7-1200 CPU 1212c FirmwareSiemens Simatic S7-1200 CPU 1212fc Firmware+92 | 13/12/2022 | 17/6/2026 | Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device. | |
| Modificada | Alta (7.5) | 0.63% | — | Siemens Simatic S7-plcsim Advanced FirmwareSiemens Simatic S7-1200 CPU 1211c FirmwareSiemens Simatic S7-1200 CPU 1212c FirmwareSiemens Simatic S7-1200 CPU 1212fc Firmware+88 | 13/12/2022 | 17/6/2026 | Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device. | |
| Modificada | Alta (7.5) | 0.74% | — | Siemens Simatic S7-plcsim Advanced FirmwareSiemens Simatic S7-1200 CPU 1211c FirmwareSiemens Simatic S7-1200 CPU 1212c FirmwareSiemens Simatic S7-1200 CPU 1212fc Firmware+92 | 13/12/2022 | 17/6/2026 | Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device. | |
| Modificada | Alta (7.5) | 0.90% | — | Siemens Simatic S7-plcsim Advanced FirmwareSiemens Simatic S7-1200 CPU 1211c FirmwareSiemens Simatic S7-1200 CPU 1212c FirmwareSiemens Simatic S7-1200 CPU 1212fc Firmware+92 | 13/12/2022 | 17/6/2026 | Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device. | |
| Modificada | Baja (3.5) | 0.31% | — | Siemens Simatic S7-1500 Software ControllerSiemens Simatic S7-plcsim AdvancedSiemens Simatic Wincc RuntimeSiemens 6es7154-8fb01-0ab0 Firmware+109 | 8/11/2022 | 17/6/2026 | The login endpoint /FormLogin in affected web services does not apply proper origin checking. This could allow authenticated remote attackers to track the activities of other users via a login cross-site request forgery attack. | |
| Modificada | Alta (7.5) | 1.6% | — | Siemens Simatic Drive Controller CPU 1504d TF FirmwareSiemens Simatic Drive Controller CPU 1507d TF FirmwareSiemens Simatic ET 200sp Open Controller CPU 1515sp PC2 FirmwareSiemens Simatic S7-plcsim Advanced Firmware+44 | 9/2/2022 | 17/6/2026 | A vulnerability has been identified in SIMATIC Drive Controller family (All versions >= V2.9.2 < V2.9.4), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions >= V21.9 < V21.9.4), SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (All versions >= V4.5.0 < V4.5.2), SIMATIC S7-1500 CPU… | |
| Modificada | Alta (7.5) | 2.2% | — | Siemens Simatic Drive Controller CPU 1504d TF FirmwareSiemens Simatic Drive Controller CPU 1507d TF FirmwareSiemens Simatic ET 200sp Open Controller CPU 1515sp PC2 FirmwareSiemens Simatic S7-plcsim Advanced Firmware+44 | 9/2/2022 | 17/6/2026 | A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC Drive Controller family (All versions >= V2.9.2 < V2.9.4), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants) (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS… | |
| Modificada | Alta (7.5) | 2.1% | — | Siemens Simatic Drive Controller CPU 1504d TF FirmwareSiemens Simatic Drive Controller CPU 1507d TF FirmwareSiemens Simatic ET 200sp Open Controller CPU 1515sp PC2 FirmwareSiemens Simatic S7-plcsim Advanced Firmware+44 | 9/2/2022 | 17/6/2026 | A vulnerability has been identified in SIMATIC Drive Controller family (All versions >= V2.9.2 < V2.9.4), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions >= V21.9 < V21.9.4), SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (All versions >= V4.5.0 < V4.5.2), SIMATIC S7-1500 CPU… | |
| Modificada | Media (5.3) | 0.75% | — | Siemens CPU 1504d TF FirmwareSiemens CPU 1507d TF FirmwareSiemens CPU 1515sp PC2 TF FirmwareSiemens Simatic S7 Plcsim Advanced Firmware+52 | 10/8/2021 | 17/6/2026 | A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions < V21.9), SIMATIC S7 PLCSIM Advanced (All versions > V2 < V4), SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (Version V4.4), SIMATIC… | |
| Modificada | Media (5.9) | 64% | — | OpensslDebian LinuxFreebsdNetapp Active IQ Unified Manager+102 | 25/3/2021 | 17/6/2026 | An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer… | |
| Modificada | Alta (7.5) | 1.7% | — | Siemens S7-1200 CPU 1211c FirmwareSiemens S7-1200 CPU 1212c FirmwareSiemens S7-1200 CPU 1214c FirmwareSiemens S7-1200 CPU 1215c Firmware+20 | 11/2/2020 | 17/6/2026 | A vulnerability has been identified in SIMATIC ET 200pro IM154-8 PN/DP CPU (All versions < V3.X.17), SIMATIC ET 200pro IM154-8F PN/DP CPU (All versions < V3.X.17), SIMATIC ET 200pro IM154-8FX PN/DP CPU (All versions < V3.X.17), SIMATIC ET 200S IM151-8 PN/DP CPU (All versions < V3.X.17), SIMATIC ET 200S IM151-8F PN/DP… | |
| Modificada | Alta (7.8) | 2.4% | — | Siemens Simatic S7-1200 FirmwareSiemens Simatic S7-1200 CPU 1211c FirmwareSiemens Simatic S7-1200 CPU 1212c FirmwareSiemens Simatic S7-1200 CPU 1212fc Firmware+5 | 22/4/2013 | 16/6/2026 | Siemens SIMATIC S7-1200 PLCs 2.x and 3.x allow remote attackers to cause a denial of service (defect-mode transition and control outage) via crafted packets to UDP port 161 (aka the SNMP port). | |
| Modificada | Alta (7.8) | 2.4% | — | Siemens Simatic S7-1200 FirmwareSiemens Simatic S7-1200 CPU 1211c FirmwareSiemens Simatic S7-1200 CPU 1212c FirmwareSiemens Simatic S7-1200 CPU 1212fc Firmware+5 | 22/4/2013 | 16/6/2026 | Siemens SIMATIC S7-1200 PLCs 2.x and 3.x allow remote attackers to cause a denial of service (defect-mode transition and control outage) via crafted packets to TCP port 102 (aka the ISO-TSAP port). | |
| Modificada | Media (4.3) | 2.6% | — | Siemens Simatic S7-1200 FirmwareSiemens Simatic S7-1200 CPU 1211c FirmwareSiemens Simatic S7-1200 CPU 1212c FirmwareSiemens Simatic S7-1200 CPU 1212fc Firmware+5 | 10/10/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the web server on Siemens SIMATIC S7-1200 PLCs 2.x through 3.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URI. | |
| Modificada | Media (4.3) | 1.5% | — | Siemens Simatic S7-1200 FirmwareSiemens Simatic S7-1200 CPU 1211c FirmwareSiemens Simatic S7-1200 CPU 1212c FirmwareSiemens Simatic S7-1200 CPU 1212fc Firmware+5 | 25/9/2012 | 16/6/2026 | The Siemens SIMATIC S7-1200 2.x PLC does not properly protect the private key of the SIMATIC CONTROLLER Certification Authority certificate, which allows remote attackers to spoof the S7-1200 web server by using this key to create a forged certificate. |