Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 1.1% | — | Weidmueller Ie-wl-bl-ap-cl-eu FirmwareWeidmueller Ie-wlt-bl-ap-cl-eu FirmwareWeidmueller Ie-wl-bl-ap-cl-us FirmwareWeidmueller Ie-wlt-bl-ap-cl-us Firmware+4 | 25/6/2021 | 17/6/2026 | In Weidmueller Industrial WLAN devices in multiple versions an exploitable authentication bypass vulnerability exists in the hostname processing. A specially configured device hostname can cause the device to interpret selected remote traffic as local traffic, resulting in a bypass of web authentication. An attacker… | |
| Modificada | Alta (8.8) | 1.0% | — | Weidmueller Ie-wl-bl-ap-cl-eu FirmwareWeidmueller Ie-wlt-bl-ap-cl-eu FirmwareWeidmueller Ie-wl-bl-ap-cl-us FirmwareWeidmueller Ie-wlt-bl-ap-cl-us Firmware+4 | 25/6/2021 | 17/6/2026 | In Weidmueller Industrial WLAN devices in multiple versions an exploitable improper access control vulnerability exists in the iw_webs account settings functionality. A specially crafted user name entry can cause the overwrite of an existing user account password, resulting in remote shell access to the device as that… | |
| Modificada | Alta (8.8) | 1.6% | — | Weidmueller Ie-wl-bl-ap-cl-eu FirmwareWeidmueller Ie-wlt-bl-ap-cl-eu FirmwareWeidmueller Ie-wl-bl-ap-cl-us FirmwareWeidmueller Ie-wlt-bl-ap-cl-us Firmware+4 | 25/6/2021 | 17/6/2026 | In Weidmueller Industrial WLAN devices in multiple versions an exploitable remote code execution vulnerability exists in the iw_webs configuration parsing functionality. A specially crafted user name entry can cause an overflow of an error message buffer, resulting in remote code execution. An attacker can send… | |
| Modificada | Alta (7.5) | 1.0% | — | Weidmueller Ie-wl-bl-ap-cl-eu FirmwareWeidmueller Ie-wlt-bl-ap-cl-eu FirmwareWeidmueller Ie-wl-bl-ap-cl-us FirmwareWeidmueller Ie-wlt-bl-ap-cl-us Firmware+4 | 25/6/2021 | 17/6/2026 | In Weidmueller Industrial WLAN devices in multiple versions an exploitable denial-of-service vulnerability exists in ServiceAgent functionality. A specially crafted packet can cause an integer underflow, triggering a large memcpy that will access unmapped or out-of-bounds memory. An attacker can send this packet while… | |
| Modificada | Alta (8.8) | 1.6% | — | Weidmueller Ie-wl-bl-ap-cl-eu FirmwareWeidmueller Ie-wlt-bl-ap-cl-eu FirmwareWeidmueller Ie-wl-bl-ap-cl-us FirmwareWeidmueller Ie-wlt-bl-ap-cl-us Firmware+4 | 25/6/2021 | 17/6/2026 | In Weidmueller Industrial WLAN devices in multiple versions an exploitable format string vulnerability exists in the iw_console conio_writestr functionality. A specially crafted time server entry can cause an overflow of the time server buffer, resulting in remote code execution. An attacker can send commands while… | |
| Modificada | Alta (7.2) | 2.1% | — | Weidmueller Ie-wl-bl-ap-cl-eu FirmwareWeidmueller Ie-wlt-bl-ap-cl-eu FirmwareWeidmueller Ie-wl-bl-ap-cl-us FirmwareWeidmueller Ie-wlt-bl-ap-cl-us Firmware+4 | 25/6/2021 | 17/6/2026 | In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the hostname functionality. A specially crafted entry to network configuration information can cause execution of arbitrary system commands, resulting in full control of the device. An attacker can send… | |
| Modificada | Alta (8.8) | 1.7% | — | Weidmueller Ie-wl-bl-ap-cl-eu FirmwareWeidmueller Ie-wlt-bl-ap-cl-eu FirmwareWeidmueller Ie-wl-bl-ap-cl-us FirmwareWeidmueller Ie-wlt-bl-ap-cl-us Firmware+4 | 25/6/2021 | 17/6/2026 | In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the iw_webs functionality. A specially crafted iw_serverip parameter can cause user input to be reflected in a subsequent iw_system call, resulting in remote control over the device. An attacker can… | |
| Modificada | Alta (8.8) | 1.7% | — | Weidmueller Ie-wl-bl-ap-cl-eu FirmwareWeidmueller Ie-wlt-bl-ap-cl-eu FirmwareWeidmueller Ie-wl-bl-ap-cl-us FirmwareWeidmueller Ie-wlt-bl-ap-cl-us Firmware+4 | 25/6/2021 | 17/6/2026 | In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the iw_webs functionality. A specially crafted diagnostic script file name can cause user input to be reflected in a subsequent iw_system call, resulting in remote control over the device. An attacker… | |
| Modificada | Alta (8.8) | 0.72% | — | Weidmueller Ie-wl-bl-ap-cl-eu FirmwareWeidmueller Ie-wlt-bl-ap-cl-eu FirmwareWeidmueller Ie-wl-bl-ap-cl-us FirmwareWeidmueller Ie-wlt-bl-ap-cl-us Firmware+4 | 25/6/2021 | 17/6/2026 | In Weidmueller Industrial WLAN devices in multiple versions an exploitable use of hard-coded credentials vulnerability exists in multiple iw_* utilities. The device operating system contains an undocumented encryption password, allowing for the creation of custom diagnostic scripts. An attacker can send diagnostic… | |
| Modificada | Alta (8.8) | 1.7% | — | Weidmueller Ie-wl-bl-ap-cl-eu FirmwareWeidmueller Ie-wlt-bl-ap-cl-eu FirmwareWeidmueller Ie-wl-bl-ap-cl-us FirmwareWeidmueller Ie-wlt-bl-ap-cl-us Firmware+4 | 25/6/2021 | 17/6/2026 | In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in encrypted diagnostic script functionality of the devices. A specially crafted diagnostic script file can cause arbitrary busybox commands to be executed, resulting in remote control over the device. An… | |
| Modificada | Alta (7.5) | 0.93% | — | Weidmueller Ie-wl-bl-ap-cl-eu FirmwareWeidmueller Ie-wlt-bl-ap-cl-eu FirmwareWeidmueller Ie-wl-bl-ap-cl-us FirmwareWeidmueller Ie-wlt-bl-ap-cl-us Firmware+4 | 25/6/2021 | 17/6/2026 | In Weidmueller Industrial WLAN devices in multiple versions the usage of hard-coded cryptographic keys within the service agent binary allows for the decryption of captured traffic across the network from or to the device. | |
| Modificada | Alta (8.8) | 1.1% | — | Weidmueller Ie-wl-bl-ap-cl-eu FirmwareWeidmueller Ie-wlt-bl-ap-cl-eu FirmwareWeidmueller Ie-wl-bl-ap-cl-us FirmwareWeidmueller Ie-wlt-bl-ap-cl-us Firmware+4 | 25/6/2021 | 17/6/2026 | In Weidmueller Industrial WLAN devices in multiple versions an exploitable privilege escalation vulnerability exists in the iw_console functionality. A specially crafted menu selection string can cause an escape from the restricted console, resulting in system access as the root user. An attacker can send commands… |