Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.2% | — | Siemens Simatic Drive Controller CPU 1504d TF FirmwareSiemens Simatic Drive Controller CPU 1507d TF FirmwareSiemens Simatic ET 200sp Open Control 1515sp PC2 FirmwareSiemens Simatic S7-1500 CPU 1510sp F-1 PN Firmware+69 | 12/12/2023 | 17/6/2026 | Affected devices improperly handle specially crafted packets sent to port 102/tcp. This could allow an attacker to create a denial of service condition. A restart is needed to restore normal operations. | |
| Modificada | Alta (8.7) | 1.1% | — | Siemens Simatic Cloud Connect 7 Cc712 FirmwareSiemens Simatic Cloud Connect 7 Cc716 FirmwareSiemens Simatic Drive Controller CPU 1504d TF FirmwareSiemens Simatic Drive Controller CPU 1507d TF Firmware+74 | 12/9/2023 | 17/6/2026 | The OPC UA implementations (ANSI C and C++) in affected products contain an integer overflow vulnerability that could cause the application to run into an infinite loop during certificate validation. This could allow an unauthenticated remote attacker to create a denial of service condition by sending a specially… | |
| Modificada | Media (6.8) | 0.29% | — | Siemens Simatic Drive Controller CPU 1504d TF FirmwareSiemens Simatic Drive Controller CPU 1507d TF FirmwareSiemens Simatic S7-1500 CPU 1510sp F-1 PN FirmwareSiemens Simatic S7-1500 CPU 1510sp-1 PN Firmware+66 | 10/1/2023 | 17/6/2026 | Affected devices do not contain an Immutable Root of Trust in Hardware. With this the integrity of the code executed on the device can not be validated during load-time. An attacker with physical access to the device could use this to replace the boot image of the device and execute arbitrary code. | |
| Modificada | Alta (7.5) | 0.74% | — | Siemens Simatic S7-plcsim Advanced FirmwareSiemens Simatic S7-1200 CPU 1211c FirmwareSiemens Simatic S7-1200 CPU 1212c FirmwareSiemens Simatic S7-1200 CPU 1212fc Firmware+92 | 13/12/2022 | 17/6/2026 | Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device. | |
| Modificada | Alta (7.5) | 0.63% | — | Siemens Simatic S7-plcsim Advanced FirmwareSiemens Simatic S7-1200 CPU 1211c FirmwareSiemens Simatic S7-1200 CPU 1212c FirmwareSiemens Simatic S7-1200 CPU 1212fc Firmware+88 | 13/12/2022 | 17/6/2026 | Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device. | |
| Modificada | Alta (7.5) | 0.74% | — | Siemens Simatic S7-plcsim Advanced FirmwareSiemens Simatic S7-1200 CPU 1211c FirmwareSiemens Simatic S7-1200 CPU 1212c FirmwareSiemens Simatic S7-1200 CPU 1212fc Firmware+92 | 13/12/2022 | 17/6/2026 | Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device. | |
| Modificada | Alta (7.5) | 0.90% | — | Siemens Simatic S7-plcsim Advanced FirmwareSiemens Simatic S7-1200 CPU 1211c FirmwareSiemens Simatic S7-1200 CPU 1212c FirmwareSiemens Simatic S7-1200 CPU 1212fc Firmware+92 | 13/12/2022 | 17/6/2026 | Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device. | |
| Modificada | Baja (3.5) | 0.31% | — | Siemens Simatic S7-1500 Software ControllerSiemens Simatic S7-plcsim AdvancedSiemens Simatic Wincc RuntimeSiemens 6es7154-8fb01-0ab0 Firmware+109 | 8/11/2022 | 17/6/2026 | The login endpoint /FormLogin in affected web services does not apply proper origin checking. This could allow authenticated remote attackers to track the activities of other users via a login cross-site request forgery attack. | |
| Modificada | Media (5.3) | 0.75% | — | Siemens CPU 1504d TF FirmwareSiemens CPU 1507d TF FirmwareSiemens CPU 1515sp PC2 TF FirmwareSiemens Simatic S7 Plcsim Advanced Firmware+52 | 10/8/2021 | 17/6/2026 | A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions < V21.9), SIMATIC S7 PLCSIM Advanced (All versions > V2 < V4), SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (Version V4.4), SIMATIC… | |
| Modificada | Alta (7.5) | 1.7% | — | Siemens KTK Ate530s FirmwareSiemens Sidoor Atd430w FirmwareSiemens Sidoor Ate530s Coated FirmwareSiemens Sidoor Ate531s Firmware+29 | 14/4/2020 | 17/6/2026 | A vulnerability has been identified in Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200, Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200P, KTK ATE530S, SIDOOR ATD430W, SIDOOR ATE530S COATED, SIDOOR ATE531S, SIMATIC ET 200AL IM 157-1 PN (6ES7157-1AB00-0AB0), SIMATIC ET 200eco PN, AI 8xRTD/TC, M12-L… |