Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

11 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.6)0.38%—Siemens Scalance Xb208 (e/ip) FirmwareSiemens Scalance Xb208 (pn) FirmwareSiemens Scalance Xb216 (e/ip) FirmwareSiemens Scalance Xb216 (pn) Firmware+6514/11/202317/6/2026
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V7.2.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V7.2.2), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V7.2.2), SCALANCE M812-1 ADSL-Router (6GK5812-1AA00-2AA2) (All versions <…
ModificadaMedia (5.1)0.72%—Siemens Ruggedcom Rm1224 Lte(4g) EU FirmwareSiemens Ruggedcom Rm1224 Lte(4g) NAM FirmwareSiemens Scalance M804pb FirmwareSiemens Scalance M812-1 Adsl-router Firmware+9713/12/202217/6/2026
Affected devices do not check the TFTP blocksize correctly. This could allow an authenticated attacker to read from an uninitialized buffer that potentially contains previously allocated data.
ModificadaMedia (5.2)0.27%—Siemens Ruggedcom Rm1224 Lte(4g) EU FirmwareSiemens Ruggedcom Rm1224 Lte(4g) NAM FirmwareSiemens Scalance M804pb FirmwareSiemens Scalance M812-1 Adsl-router Firmware+9713/12/202217/6/2026
Affected devices store the CLI user passwords encrypted in flash memory. Attackers with physical access to the device could retrieve the file and decrypt the CLI user passwords.
ModificadaAlta (7.1)0.24%—Siemens Ruggedcom Rm1224 Lte(4g) EU FirmwareSiemens Ruggedcom Rm1224 Lte(4g) NAM FirmwareSiemens Scalance M804pb FirmwareSiemens Scalance M812-1 Adsl-router Firmware+9713/12/202217/6/2026
Affected devices use a weak encryption scheme to encrypt the debug zip file. This could allow an authenticated attacker to decrypt the contents of the file and retrieve debug information about the system.
ModificadaMedia (4.8)0.96%—Siemens Scalance M-800 FirmwareSiemens Scalance S615 FirmwareSiemens Scalance Sc-600 FirmwareSiemens Scalance Sc622-2c Firmware+8610/8/202217/6/2026
Affected devices do not properly sanitize data introduced by an user when rendering the web interface. This could allow an authenticated remote attacker with administrative privileges to inject code and lead to a DOM-based XSS.
ModificadaAlta (7.5)1.7%—Siemens Scalance M-800 FirmwareSiemens Scalance S615 FirmwareSiemens Scalance W700 Ieee 802.11ax FirmwareSiemens Scalance W700 Ieee 802.11n Firmware+8010/8/202217/6/2026
Affected devices do not properly handle the renegotiation of SSL/TLS parameters. This could allow an unauthenticated remote attacker to bypass the TCP brute force prevention and lead to a denial of service condition for the duration of the attack.
ModificadaAlta (7.2)1.8%—Siemens Scalance M-800 FirmwareSiemens Scalance S615 FirmwareSiemens Scalance Sc-600 FirmwareSiemens Scalance Sc622-2c Firmware+8610/8/202217/6/2026
Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with administrative privileges to inject code or spawn a system root shell.
ModificadaMedia (5.9)1.1%—Siemens Scalance X200-4pirt FirmwareSiemens Scalance X201-3pirt FirmwareSiemens Scalance X202-2irt FirmwareSiemens Scalance X202-2pirt Firmware+6212/1/202117/6/2026
A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.5.0), SCALANCE X-200RNA switch family (All versions < V3.2.7). Devices create a new unique key upon factory reset,…
ModificadaCrítica (9.8)1.7%—Siemens Scalance X200-4pirt FirmwareSiemens Scalance X201-3pirt FirmwareSiemens Scalance X202-2irt FirmwareSiemens Scalance X202-2pirt Firmware+6212/1/202117/6/2026
A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.5.0). The web server of the affected devices contains a vulnerability that may lead to a buffer overflow condition. An…
ModificadaCrítica (9.8)1.7%—Siemens Scalance X200-4pirt FirmwareSiemens Scalance X201-3pirt FirmwareSiemens Scalance X202-2irt FirmwareSiemens Scalance X202-2pirt Firmware+6212/1/202117/6/2026
A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.5.0), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions < V4.1.0). The webserver of the…
ModificadaMedia (6.5)1.1%—Siemens Scalance X200-4pirt FirmwareSiemens Scalance X201-3pirt FirmwareSiemens Scalance X202-2irt FirmwareSiemens Scalance X202-2pirt Firmware+6212/1/202117/6/2026
A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.5.0). The vulnerability could allow an unauthenticated attacker to reboot the device over the network by using special…
Orbitaley — Vulnerabilidades