Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

5 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.0%—Schneider-electric Modicon M218 Firmware11/2/202217/6/2026
A CWE-20: Improper Input Validation vulnerability exists that could cause a Denial of Service when a crafted packet is sent to the controller over network port 1105/TCP. Affected Product: Modicon M218 Logic Controller (V5.1.0.6 and prior)
ModificadaAlta (7.5)1.4%—Schneider-electric Modicon M218 Firmware31/8/202017/6/2026
Out-of-bounds Write vulnerability exists in Modicon M218 Logic Controller (V5.0.0.7 and prior) which could cause Denial of Service when sending specific crafted IPV4 packet to the controller: Sending a specific IPv4 protocol package to Schneider Electric Modicon M218 Logic Controller can cause IPv4 devices to go down.…
ModificadaAlta (7.5)1.5%—Schneider-electric Modicon M218 Firmware16/6/202017/6/2026
A CWE-787: Out-of-bounds Write vulnerability exists in Modicon M218 Logic Controller (Firmware version 4.3 and prior), which may cause a Denial of Service when specific TCP/IP crafted packets are sent to the Modicon M218 Logic Controller.
ModificadaAlta (7.5)0.88%—Schneider-electric Ecostruxure Machine ExpertSchneider-electric SomachineSchneider-electric Somachine MotionSchneider-electric Modicon M218 Firmware+322/4/202017/6/2026
A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists which could leak sensitive information transmitted between the software and the Modicon M218, M241, M251, and M258 controllers.
ModificadaCrítica (9.8)0.69%—Schneider-electric Ecostruxure Machine ExpertSchneider-electric SomachineSchneider-electric Somachine MotionSchneider-electric Modicon M218 Firmware+322/4/202017/6/2026
A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists which could allow the attacker to execute malicious code on the Modicon M218, M241, M251, and M258 controllers.