Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2636▼ 212 respecto a la semana anterior
Críticas / altas1386▲ 155 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
–

68 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.1)0.50%—Embedded-solutions FreemodbusAI5/8/202626/8/2026
The LINUXTCP port of FreeModbus contains an off-by-one bounds check in xMBPortTCPPool (demo/LINUXTCP/port/porttcp.c). The check uses a strict greater-than comparison instead of greater-than-or-equal against the 263-byte MB_TCP_BUF_SIZE limit.
AplazadaCrítica (9.8)0.55%—NanomodbusAI5/8/202626/8/2026
nanoMODBUS through v1.23.0 contains an out-of-bounds stack read leading to a wild-pointer write in nmbs_read_device_identification_basic / recv_read_device_identification_res in nanomodbus.c. A fixed 3-element stack array order[3] = {0,1,2} maps object IDs to buffer indices. The server-supplied object_id field (0-255,…
AplazadaAlta (8.6)0.39%—NanomodbusAI5/8/202626/8/2026
nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus client-side recv_read_device_identification_res function (FC 0x2B/MEI 0x0E, Read Device Identification) in nanomodbus.c. The server-supplied object_length field (0-246) is validated only against the remaining PDU size (res_size_left) and is never…
AplazadaCrítica (9.8)0.55%—NanomodbusAI5/8/202626/8/2026
nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus server-side handle_read_file_record function (FC 0x14, Read File Record) in nanomodbus.c. The function validates that the total request size does not exceed 245 bytes and that each sub-request's record_length is at most 124, but it never…
AplazadaAlta (8.7)0.56%—Charx Modbus ServerAI30/7/202630/7/2026
A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by opening the port that CharxModbusServer is listening, an unauthenticated attacker can perform a Denial-of-Service attack.
AplazadaAlta (7.5)0.49%—LibmodbusAI13/7/202615/7/2026
A Denial of Service (DoS) vulnerability exists in the receive loop of libmodbus 3.1.12 when running on Windows. The issue stems from improper timeout management during network read operations.
Pendiente de análisisAlta (8.2)0.54%—Codesys Modbus TCP ServerAI12/5/202617/6/2026
An unauthenticated remote attacker may exhaust all available TCP connections in the CODESYS Modbus TCP Server stack if a race condition in connection handling is successfully exploited, preventing legitimate clients from establishing new connections.
AplazadaAlta (8.2)0.92%—NanomodbusAI8/5/202617/6/2026
nanoMODBUS through v1.22.0 has a stack-based buffer overflow in recv_read_registers_res() in nanomodbus.c. When a client calls nmbs_read_holding_registers() or nmbs_read_input_registers(), the library writes register data from the server response to the caller-provided buffer based on the response's byte_count field…
Pendiente de análisisCrítica (9.3)0.20%—3onedata Modbus Gateway Gw1101-1dAI4/5/202630/9/2026
3onedata modbus gateway device model GW1101-1D(RS-485)-TB-P (hardware version V2.2.0) allows authenticated users to execute arbitrary shell commands in the context of the root user by providing payload in the "IP address" field of the diagnosis test tools. This issue has been resolved in firmware version…
AplazadaAlta (7.5)0.51%—ModbusAI2/2/202617/6/2026
An unauthenticated remote attacker could potentially disrupt operations by switching between multiple configuration presets via Modbus (TCP).
AplazadaMedia (5.3)1.6%—ModbusAI14/10/202517/6/2026
An unauthanticated remote attacker can perform a DoS of the Modbus service by sending a specific function and sub-function code without affecting the core functionality.
AplazadaAlta (7.5)0.34%—Embedded-solutions FreemodbusAI14/8/202517/6/2026
An issue was discovered in the demo/LINUXTCP implementation of cwalter-at freemodbus v.2018-09-12 allowing attackers to reach an infinite loop via a crafted length value for a packet.
ModificadaCrítica (9.8)0.56%—Libmodbus27/2/20251/8/2026
Stack-based Buffer Overflow vulnerability in libmodbus v3.1.10 allows to overflow the buffer allocated for the Modbus response if the function tries to reply to a Modbus request with an unexpected length.
AplazadaAlta (8.8)0.68%—ModbusmechanicAI21/11/20245/7/2026
An arbitrary file upload vulnerability in ModbusMechanic v3.0 allows attackers to execute arbitrary code via uploading a crafted .xml file.
AnalizadaAlta (7.1)0.38%—Pepperl-fuchs Icdm-rx/tcp Socketserver FirmwarePepperl-fuchs Profinet FirmwarePepperl-fuchs Profinet/modbus FirmwarePepperl-fuchs Modbus Router Firmware+413/8/202417/6/2026
An unauthenticated remote attacker may use a reflected XSS vulnerability to obtain information from a user or reboot the affected device once.
AnalizadaAlta (7.1)0.34%—Pepperl-fuchs Icdm-rx/tcp Socketserver FirmwarePepperl-fuchs Profinet FirmwarePepperl-fuchs Profinet/modbus FirmwarePepperl-fuchs Modbus Router Firmware+413/8/202417/6/2026
An unauthenticated remote attacker may use stored XSS vulnerability to obtain information from a user or reboot the affected device once.
AnalizadaMedia (6.1)0.33%—Pepperl-fuchs Icdm-rx/tcp Socketserver FirmwarePepperl-fuchs Profinet FirmwarePepperl-fuchs Profinet/modbus FirmwarePepperl-fuchs Modbus Router Firmware+413/8/202417/6/2026
An unauthenticated remote attacker may use a HTML injection vulnerability with limited length to inject malicious HTML code and gain low-privileged access on the affected device.
ModificadaAlta (7.5)0.55%—Embedded-solutions Freemodbus8/7/202417/6/2026
Buffer Overflow vulnerability in SILA Embedded Solutions GmbH freemodbus v.2018-09-12 allows a remtoe attacker to cause a denial of service via the LINUXTCP server component.
ModificadaMedia (4.3)0.47%—Libmodbus31/5/202417/6/2026
An invalid pointer in the modbus_receive() function of libmodbus v3.1.6 allows attackers to cause a Denial of Service (DoS) via a crafted message sent to the unit-test-server.
ModificadaAlta (7.5)0.61%—Libmodbus31/5/202417/6/2026
libmodbus v3.1.6 was discovered to contain a use-after-free via the ctx->backend pointer. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted message sent to the unit-test-server.
ModificadaAlta (7.5)0.79%—Libmodbus31/5/202417/6/2026
libmodbus v3.1.6 was discovered to contain a heap overflow via the modbus_mapping_free() function.
AnalizadaAlta (7.5)0.52%—Libmodbus8/5/202417/6/2026
libmodbus v3.1.10 is vulnerable to Buffer Overflow via the modbus_write_bits function. This issue can be triggered when the function is fed with specially crafted input, which leads to out-of-bounds read and can potentially cause a crash or other unintended behaviors.
AnalizadaCrítica (9.8)0.73%—Libmodbus1/5/202417/6/2026
libmodbus v3.1.10 has a heap-based buffer overflow vulnerability in read_io_status function in src/modbus.c.
ModificadaAlta (7.5)1.2%—Opcfoundation UA Java LegacyProsysopc UA HistorianProsysopc UA Modbus ServerProsysopc UA Simulation Server15/5/202317/6/2026
The OPC UA Legacy Java Stack before 6f176f2 enables an attacker to block OPC UA server applications via uncontrolled resource consumption so that they can no longer serve client applications.
ModificadaMedia (4.3)0.85%—Rockwellautomation Modbus TCP Server ADD ON Instructions17/3/202317/6/2026
Rockwell Automation Modbus TCP Server AOI prior to 2.04.00 is vulnerable to an unauthorized user sending a malformed message that could cause the controller to respond with a copy of the most recent response to the last valid request. If exploited, an unauthorized user could read the connected device’s Modbus TCP…