Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.1% | — | Sick Ftmg-esd20axx FirmwareSick Ftmg-esd25axx FirmwareSick Ftmg-esn40sxx FirmwareSick Ftmg-esn50sxx Firmware+3 | 15/5/2023 | 17/6/2026 | Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an remote attacker to influence the availability of the webserver by invocing a Slowloris style attack via HTTP requests. | |
| Modificada | Alta (7.5) | 0.43% | — | Sick Ftmg-esd20axx FirmwareSick Ftmg-esd25axx FirmwareSick Ftmg-esn40sxx FirmwareSick Ftmg-esn50sxx Firmware+3 | 15/5/2023 | 17/6/2026 | Cleartext Storage of Sensitive Information in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to potentially steal user credentials that are stored in the user’s browsers local storage via cross-site-scripting attacks. | |
| Modificada | Crítica (9.8) | 0.71% | — | Sick Ftmg-esd20axx FirmwareSick Ftmg-esd25axx FirmwareSick Ftmg-esn40sxx FirmwareSick Ftmg-esn50sxx Firmware+3 | 15/5/2023 | 17/6/2026 | Use of Password Hash Instead of Password for Authentication in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to use a password hash instead of an actual password to login to a valid user account via the REST interface. | |
| Modificada | Media (5.3) | 0.78% | — | Sick Ftmg-esd20axx FirmwareSick Ftmg-esd25axx FirmwareSick Ftmg-esn40sxx FirmwareSick Ftmg-esn50sxx Firmware+3 | 15/5/2023 | 17/6/2026 | Observable Response Discrepancy in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to gain information about valid usernames by analyzing challenge responses from the server via the REST interface. | |
| Modificada | Media (5.3) | 0.79% | — | Sick Ftmg-esd20axx FirmwareSick Ftmg-esd25axx FirmwareSick Ftmg-esn40sxx FirmwareSick Ftmg-esn50sxx Firmware+3 | 15/5/2023 | 17/6/2026 | Inclusion of Sensitive Information in Source Code in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to gain information about valid usernames via analysis of source code. | |
| Modificada | Alta (7.5) | 1.1% | — | Sick Ftmg-esd20axx FirmwareSick Ftmg-esd25axx FirmwareSick Ftmg-esn40sxx FirmwareSick Ftmg-esn50sxx Firmware+3 | 15/5/2023 | 17/6/2026 | Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to influence the availability of the webserver by invocing several open file requests via the REST interface. | |
| Modificada | Alta (7.5) | 0.90% | — | Sick Ftmg-esd20axx FirmwareSick Ftmg-esd25axx FirmwareSick Ftmg-esn40sxx FirmwareSick Ftmg-esn50sxx Firmware+3 | 15/5/2023 | 17/6/2026 | Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to download files by using a therefore unpriviledged account via the REST interface. | |
| Modificada | Alta (7.5) | 0.66% | — | Sick Ftmg-esd20axx FirmwareSick Ftmg-esd25axx FirmwareSick Ftmg-esn40sxx FirmwareSick Ftmg-esn50sxx Firmware+3 | 15/5/2023 | 17/6/2026 | Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to gain unauthorized access to data fields by using a therefore unpriviledged account via the REST interface. |