Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
3 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.59% | — | Jtekt Pc10g-cpu Tcc-6353 FirmwareJtekt Pc10ge Tcc-6464 FirmwareJtekt Pc10p Tcc-6372 FirmwareJtekt Pc10p-dp Tcc-6726 Firmware+13 | 26/7/2022 | 17/6/2026 | JTEKT TOYOPUC PLCs through 2022-04-29 do not ensure data integrity. They utilize the unauthenticated CMPLink/TCP protocol for engineering purposes, including downloading projects and control logic to the PLC. Control logic is downloaded to the PLC on a block-by-block basis with a given memory address and a blob of… | |
| Modificada | Crítica (9.1) | 1.3% | — | Jtekt Pc10g-cpu Tcc-6353 FirmwareJtekt Pc10ge Tcc-6464 FirmwareJtekt Pc10p Tcc-6372 FirmwareJtekt Pc10p-dp Tcc-6726 Firmware+13 | 26/7/2022 | 17/6/2026 | JTEKT TOYOPUC PLCs through 2022-04-29 mishandle authentication. They utilize the CMPLink/TCP protocol (configurable on ports 1024-65534 on either TCP or UDP) for a wide variety of engineering purposes such as starting and stopping the PLC, downloading and uploading projects, and changing configuration settings. This… | |
| Modificada | Media (4.3) | 0.41% | — | Jtekt Pc10g-cpu Tcc-6353 FirmwareJtekt Pc10ge Tcc-6464 FirmwareJtekt Pc10p Tcc-6372 FirmwareJtekt Pc10p-dp Tcc-6726 Firmware+23 | 10/9/2021 | 17/6/2026 | All versions of the afffected TOYOPUC-PC10 Series,TOYOPUC-Plus Series,TOYOPUC-PC3J/PC2J Series, TOYOPUC-Nano Series products may not be able to properly process an ICMP flood, which may allow an attacker to deny Ethernet communications between affected devices. |