Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.89% | — | Schneider-electric Sage RTU Firmware | 12/6/2024 | 17/6/2026 | CWE-125: Out-of-bounds Read vulnerability exists that could cause denial of service of the device’s web interface when an attacker sends a specially crafted HTTP request. | |
| Modificada | Alta (8.1) | 0.39% | — | Schneider-electric Sage RTU Firmware | 12/6/2024 | 17/6/2026 | CWE-120: Buffer Copy without Checking Size of Input (‘Classic Buffer Overflow’) vulnerability exists that could allow a user with access to the device’s web interface to cause a fault on the device when sending a malformed HTTP request. | |
| Modificada | Alta (7.5) | 0.79% | — | Schneider-electric Sage RTU Firmware | 12/6/2024 | 17/6/2026 | CWE-252: Unchecked Return Value vulnerability exists that could cause denial of service of the device when an attacker sends a specially crafted HTTP request. | |
| Modificada | Alta (8.8) | 0.37% | — | Schneider-electric Sage RTU Firmware | 12/6/2024 | 17/6/2026 | CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated user with access to the device’s web interface to perform unauthorized file and firmware uploads when crafting custom web requests. | |
| Modificada | Alta (8.1) | 1.0% | — | Schneider-electric Sage RTU Firmware | 12/6/2024 | 17/6/2026 | CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability exists that could allow an authenticated user with access to the device’s web interface to corrupt files and impact device functionality when sending a crafted HTTP request. | |
| Modificada | Crítica (9.8) | 0.53% | — | Schneider-electric Sage RTU Firmware | 12/6/2024 | 17/6/2026 | CWE-787: Out-of-bounds Write vulnerability exists that could result in an authentication bypass when sending a malformed POST request and particular configuration parameters are set. |