Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2888▼ 169 respecto a la semana anterior
Críticas / altas1285▼ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
34 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.7) | 0.41% | — | Kioxia CM6 FirmwareKioxia PM7 FirmwareKioxia PM6 Firmware | 20/12/2024 | 17/6/2026 | There exists an unauthenticated accessible JTAG port on the Kioxia PM6, PM7 and CM6 devices - On the Kioxia CM6, PM6 and PM7 disk drives it was discovered that the 2 main CPU cores of the SoC can be accessed via an open JTAG debug port that is exposed on the drive’s circuit board. Due to the wide cutout of the… | |
| Modificada | Media (5.5) | 1.9% | — | Fujitsu Esprimo D556/2 FirmwareFujitsu Esprimo D6011 FirmwareFujitsu Esprimo D6012 FirmwareFujitsu Esprimo D7010 Firmware+183 | 7/12/2023 | 17/6/2026 | A LogoFAIL issue was discovered in BmpDecoderDxe in Insyde InsydeH2O with kernel 5.2 before 05.28.47, 5.3 before 05.37.47, 5.4 before 05.45.47, 5.5 before 05.53.47, and 5.6 before 05.60.47 for certain Lenovo devices. Image parsing of crafted BMP logo files can copy data to a specific address during the DXE phase of… | |
| Modificada | Alta (7.8) | 0.36% | — | Fiio M6 Firmware | 8/5/2023 | 17/6/2026 | A buffer overflow in the component /proc/ftxxxx-debug of FiiO M6 Build Number v1.0.4 allows attackers to escalate privileges to root. | |
| Modificada | Alta (8.2) | 0.33% | — | Insydeh2oSiemens Simatic Field PG M5 FirmwareSiemens Simatic Field PG M6 FirmwareSiemens Simatic Ipc127e Firmware+12 | 3/2/2022 | 11/8/2026 | An issue was discovered in Insyde InsydeH2O with Kernel 5.0 before 05.08.42, Kernel 5.1 before 05.16.42, Kernel 5.2 before 05.26.42, Kernel 5.3 before 05.35.42, Kernel 5.4 before 05.42.51, and Kernel 5.5 before 05.50.51. An SMM memory corruption vulnerability in FvbServicesRuntimeDxe allows a possible attacker to… | |
| Modificada | Media (6.7) | 0.35% | — | Insydeh2oSiemens Simatic Field PG M5 FirmwareSiemens Simatic Field PG M6 FirmwareSiemens Simatic Ipc127e Firmware+11 | 3/2/2022 | 11/8/2026 | An issue was discovered in Insyde InsydeH2O Kernel 5.0 before 05.08.41, Kernel 5.1 before 05.16.41, Kernel 5.2 before 05.26.41, Kernel 5.3 before 05.35.41, and Kernel 5.4 before 05.42.20. A stack-based buffer overflow leads toarbitrary code execution in UEFI DisplayTypeDxe DXE driver. | |
| Modificada | Alta (8.2) | 0.30% | — | Insydeh2oSiemens Simatic Field PG M5 FirmwareSiemens Simatic Field PG M6 FirmwareSiemens Simatic Ipc127e Firmware+11 | 3/2/2022 | 11/8/2026 | An issue was discovered in SdHostDriver in the kernel 5.0 through 5.5 in Insyde InsydeH2O. There is an SMM callout that allows an attacker to access the System Management Mode and execute arbitrary code. This occurs because of a Numeric Range Comparison Without a Minimum Check. | |
| Modificada | Alta (8.2) | 0.28% | — | Insydeh2oSiemens Simatic Field PG M5 FirmwareSiemens Simatic Field PG M6 FirmwareSiemens Simatic Ipc127e Firmware+11 | 3/2/2022 | 11/8/2026 | An issue was discovered in AhciBusDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. Because of an Untrusted Pointer Dereference that causes SMM memory corruption, an attacker may be able to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM. | |
| Modificada | Alta (8.2) | 0.33% | — | Insydeh2oSiemens Simatic Field PG M5 FirmwareSiemens Simatic Field PG M6 FirmwareSiemens Simatic Ipc127e Firmware+11 | 3/2/2022 | 11/8/2026 | An issue was discovered in Insyde InsydeH2O Kernel 5.0 before 05.09.11, 5.1 before 05.17.11, 5.2 before 05.27.11, 5.3 before 05.36.11, 5.4 before 05.44.11, and 5.5 before 05.52.11 affecting FwBlockServiceSmm. Software SMI services that use the Communicate() function of the EFI_SMM_COMMUNICATION_PROTOCOL do not check… | |
| Modificada | Alta (7.5) | 0.32% | — | Insydeh2oNetapp Fas/aff BiosSiemens Ruggedcom Ape1808 FirmwareSiemens Simatic Field PG M5 Firmware+14 | 3/2/2022 | 11/8/2026 | An issue was discovered in Kernel 5.x in Insyde InsydeH2O, affecting HddPassword. Software SMI services that use the Communicate() function of the EFI_SMM_COMMUNICATION_PROTOCOL do not check whether the address of the buffer is valid, which allows use of SMRAM, MMIO, or OS kernel addresses. | |
| Modificada | Alta (7.5) | 0.28% | — | Insydeh2oSiemens Ruggedcom Ape1808 FirmwareSiemens Simatic Field PG M6 FirmwareSiemens Simatic Ipc127e Firmware+13 | 3/2/2022 | 11/8/2026 | A vulnerability exists in System Management Interrupt (SWSMI) handler of InsydeH2O UEFI Firmware code located in SWSMI handler that dereferences gRT (EFI_RUNTIME_SERVICES) pointer to call a GetVariable service, which is located outside of SMRAM. This can result in code execution in SMM (escalating privilege from ring… | |
| Modificada | Alta (8.1) | 0.92% | — | Kalkitech Sync241-m1 FirmwareKalkitech Sync241-m2 FirmwareKalkitech Sync241-m4 FirmwareKalkitech Sync261-m1 Firmware+16 | 6/1/2022 | 17/6/2026 | A security vulnerability originally reported in the SYNC2101 product, and applicable to specific sub-families of SYNC devices, allows an attacker to download the configuration file used in the device and apply a modified configuration file back to the device. The attack requires network access to the SYNC device and… | |
| Modificada | Alta (7.8) | 0.31% | — | Insydeh2oSiemens Ruggedcom Apr1808 FirmwareSiemens Simatic Field PG M5 FirmwareSiemens Simatic Field PG M6 Firmware+13 | 1/10/2021 | 11/8/2026 | A vulnerability exists in SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently check or validate the allocated buffer pointer(QWORD values for CommBuffer). This can be used by an attacker to corrupt data in SMRAM memory and even lead to arbitrary code execution. | |
| Modificada | Media (6.7) | 0.32% | — | Insydeh2oSiemens Ruggedcom Apr1808 FirmwareSiemens Simatic Field PG M5 FirmwareSiemens Simatic Field PG M6 Firmware+13 | 16/6/2021 | 11/8/2026 | In the kernel in Insyde InsydeH2O 5.x, certain SMM drivers did not correctly validate the CommBuffer and CommBufferSize parameters, allowing callers to corrupt either the firmware or the OS memory. The fixed versions for this issue in the AhciBusDxe, IdeBusDxe, NvmExpressDxe, SdHostDriverDxe, and SdMmcDeviceDxe… | |
| Modificada | Media (6.4) | 0.21% | — | Intel Local Manageability ServiceSiemens Simatic Field PG M5 FirmwareSiemens Simatic Field PG M6 FirmwareSiemens Simatic Ipc427e Firmware+9 | 9/6/2021 | 17/6/2026 | Race condition in a subsystem in the Intel(R) LMS versions before 2039.1.0.0 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.33% | — | Intel Converged Security AND Manageability EngineNetapp Cloud BackupSiemens Simatic Field PG M6 FirmwareSiemens Simatic Field PG M5 Firmware+10 | 9/6/2021 | 17/6/2026 | Improper buffer restrictions in a subsystem in the Intel(R) CSME versions before 11.8.86, 11.12.86, 11.22.86, 12.0.81, 13.0.47, 13.30.17, 14.1.53, 14.5.32 and 15.0.22 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.4) | 0.27% | — | Intel BiosSiemens Simatic Field PG M6 FirmwareSiemens Simatic Ipc427e FirmwareSiemens Simatic Ipc477e Firmware+14 | 9/6/2021 | 17/6/2026 | Race condition in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (4.4) | 0.28% | — | Intel Converged Security AND Manageability EngineSiemens Simatic Field PG M6 FirmwareSiemens Simatic Ipc427e FirmwareSiemens Simatic Ipc477e Firmware+9 | 9/6/2021 | 17/6/2026 | Improper initialization in a subsystem in the Intel(R) CSME versions before 11.8.86, 11.12.86, 11.22.86, 12.0.81, 13.0.47, 13.30.17, 14.1.53, 14.5.32, 13.50.11 and 15.0.22 may allow a privileged user to potentially enable information disclosure via local access. | |
| Modificada | Media (4.4) | 0.28% | — | Intel Converged Security AND Manageability EngineSiemens Simatic Field PG M6 FirmwareSiemens Simatic Ipc627e FirmwareSiemens Simatic Ipc647e Firmware+2 | 9/6/2021 | 17/6/2026 | Out of bound read in a subsystem in the Intel(R) CSME versions before 12.0.81, 13.0.47, 13.30.17, 14.1.53 and 14.5.32 may allow a privileged user to potentially enable information disclosure via local access. | |
| Modificada | Media (6.7) | 0.35% | — | Intel BiosNetapp Cloud BackupNetapp AFF BiosNetapp E-series Bios+15 | 9/6/2021 | 17/6/2026 | Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.1) | 0.83% | — | Cisco Integrated Management ControllerCisco UCS ManagerCisco Encs 5100 FirmwareCisco Encs 5400 Firmware+21 | 6/5/2021 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of the parameters in an HTTP request. An attacker could… | |
| Analizada | Media (6.8) | 0.38% | — | Intel Converged Security AND Manageability EngineIntel Trusted Execution TechnologySiemens Simatic Drive Controller FirmwareSiemens Simatic Et200sp 1515sp PC2 Firmware+18 | 12/11/2020 | 17/6/2026 | Insufficient control flow management in subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25 , Intel(R) TXE versions before 3.1.80 and 4.0.30 may allow an unauthenticated user to potentially enable escalation of privilege via physical access. | |
| Modificada | Media (5.5) | 0.52% | — | Intel MicrocodeNetapp Clustered Data OntapNetapp HCI Compute Node BiosNetapp HCI Storage Node Bios+13 | 12/11/2020 | 17/6/2026 | Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Media (5.5) | 0.54% | — | Intel Celeron 1000mIntel Celeron 1005mIntel Celeron 1007uIntel Celeron 1017u+690 | 15/6/2020 | 17/6/2026 | Incomplete cleanup from specific special register read operations in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Media (5.5) | 0.84% | — | Huawei Honor V10 FirmwareHuawei P30 FirmwareHuawei Enjoy 7S FirmwareHuawei Mate 20 Firmware+5 | 13/12/2019 | 17/6/2026 | There is a path traversal vulnerability in several Huawei smartphones. The system does not sufficiently validate certain pathnames from the application. An attacker could trick the user into installing, backing up and restoring a malicious application. Successful exploit could cause information disclosure. | |
| Modificada | Media (6.8) | 0.34% | — | Lenovo 20f1 FirmwareLenovo 20f2 FirmwareLenovo 20jq FirmwareLenovo 20jr Firmware+144 | 19/8/2019 | 17/6/2026 | A vulnerability was reported in various BIOS versions of older ThinkPad systems that could allow a user with administrative privileges or physical access the ability to update the Embedded Controller with unsigned firmware. |