Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
–

8 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.82%—Motorola Moscad IP Gateway FirmwareMotorola ACE IP Gateway (4600) Firmware26/7/202217/6/2026
The Motorola MOSCAD and ACE line of RTUs through 2022-05-02 omit an authentication requirement. They feature IP Gateway modules which allow for interfacing between Motorola Data Link Communication (MDLC) networks (potentially over a variety of serial, RF and/or Ethernet links) and TCP/IP networks. Communication with…
ModificadaAlta (7.2)3.8%—Gira Tks-ip-gateway Firmware7/5/202017/6/2026
Gira TKS-IP-Gateway 4.0.7.7 is vulnerable to authenticated remote code execution via the backup functionality of the web frontend. This can be combined with CVE-2020-10794 for remote root access.
ModificadaCrítica (9.8)1.4%—Gira Tks-ip-gateway Firmware7/5/202017/6/2026
Gira TKS-IP-Gateway 4.0.7.7 is vulnerable to unauthenticated path traversal that allows an attacker to download the application database. This can be combined with CVE-2020-10795 for remote root access.
ModificadaCrítica (9.8)1.7%—ABB IP Gateway Firmware6/6/201817/6/2026
In ABB IP GATEWAY 3.39 and prior, some configuration files contain passwords stored in plain-text, which may allow an attacker to gain unauthorized access.
ModificadaCrítica (9.8)2.5%—ABB IP Gateway Firmware6/6/201817/6/2026
In ABB IP GATEWAY 3.39 and prior, by accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access the configuration files and application pages without authentication.
ModificadaAlta (8.8)0.66%—ABB IP Gateway Firmware6/6/201817/6/2026
In ABB IP GATEWAY 3.39 and prior, the web server does not sufficiently verify that a request was performed by the authenticated user, which may allow an attacker to launch a request impersonating that user.
ModificadaAlta (7.5)0.64%—Motorola Moscad IP Gateway Firmware23/12/201517/6/2026
Cross-site request forgery (CSRF) vulnerability in Motorola Solutions MOSCAD IP Gateway allows remote attackers to hijack the authentication of administrators for requests that modify a password.
ModificadaAlta (7.5)1.5%—Motorola Moscad IP Gateway Firmware23/12/201517/6/2026
Motorola Solutions MOSCAD IP Gateway allows remote attackers to read arbitrary files via unspecified vectors.