Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.2% | — | Schneider-electric Ecostruxure Control ExpertSchneider-electric Ecostruxure Process ExpertSchneider-electric Modicon M340 Bmxp341000 FirmwareSchneider-electric Modicon M340 Bmxp342000 Firmware+51 | 30/1/2023 | 17/6/2026 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when a malicious project file is loaded onto the controller. Affected Products: EcoStruxure Control Expert (All Versions),… | |
| Modificada | Alta (7.5) | 0.75% | — | Schneider-electric Modicon M340 BMX P34-2010 FirmwareSchneider-electric Modicon M340 BMX P34-2030 FirmwareSchneider-electric Modicon M580 Bmeh582040 FirmwareSchneider-electric Modicon M580 Bmeh582040c Firmware+44 | 22/11/2022 | 17/6/2026 | A CWE-191: Integer Underflow (Wrap or Wraparound) vulnerability exists that could cause a denial of service of the controller due to memory access violations when using the Modbus TCP protocol. Affected products: Modicon M340 CPU (part numbers BMXP34*)(V3.40 and prior), Modicon M580 CPU (part numbers BMEP* and… | |
| Modificada | Alta (7.5) | 0.94% | — | Schneider-electric Modicon M340 Bmxp341000Schneider-electric Modicon M340 Bmxp342010Schneider-electric Modicon M340 Bmxp342020Schneider-electric Modicon M340 Bmxp342030+45 | 2/9/2021 | 17/6/2026 | A CWE-476: NULL Pointer Dereference vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP* and BMEH*, all versions), Modicon M340 CPU (part numbers… | |
| Modificada | Media (6.5) | 0.84% | — | Schneider-electric Modicon M340 Bmxp341000Schneider-electric Modicon M340 Bmxp342010Schneider-electric Modicon M340 Bmxp342020Schneider-electric Modicon M340 Bmxp342030+45 | 2/9/2021 | 17/6/2026 | A CWE-787: Out-of-bounds Write vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP* and BMEH*, all versions), Modicon M340 CPU (part numbers BMXP34*, all… | |
| Modificada | Media (6.5) | 0.84% | — | Schneider-electric Modicon M340 Bmxp341000Schneider-electric Modicon M340 Bmxp342010Schneider-electric Modicon M340 Bmxp342020Schneider-electric Modicon M340 Bmxp342030+45 | 2/9/2021 | 17/6/2026 | A CWE-125: Out-of-bounds Read vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP* and BMEH*, all versions), Modicon M340 CPU (part numbers BMXP34*, all… | |
| Modificada | Media (6.5) | 0.84% | — | Schneider-electric Modicon M340 Bmxp341000Schneider-electric Modicon M340 Bmxp342010Schneider-electric Modicon M340 Bmxp342020Schneider-electric Modicon M340 Bmxp342030+45 | 2/9/2021 | 17/6/2026 | A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP* and BMEH*, all… |