Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.96% | — | Siemens Scalance M-800 FirmwareSiemens Scalance S615 FirmwareSiemens Scalance Sc-600 FirmwareSiemens Scalance Sc622-2c Firmware+86 | 10/8/2022 | 17/6/2026 | Affected devices do not properly sanitize data introduced by an user when rendering the web interface. This could allow an authenticated remote attacker with administrative privileges to inject code and lead to a DOM-based XSS. | |
| Modificada | Alta (7.5) | 1.7% | — | Siemens Scalance M-800 FirmwareSiemens Scalance S615 FirmwareSiemens Scalance W700 Ieee 802.11ax FirmwareSiemens Scalance W700 Ieee 802.11n Firmware+80 | 10/8/2022 | 17/6/2026 | Affected devices do not properly handle the renegotiation of SSL/TLS parameters. This could allow an unauthenticated remote attacker to bypass the TCP brute force prevention and lead to a denial of service condition for the duration of the attack. | |
| Modificada | Alta (7.2) | 1.8% | — | Siemens Scalance M-800 FirmwareSiemens Scalance S615 FirmwareSiemens Scalance Sc-600 FirmwareSiemens Scalance Sc622-2c Firmware+86 | 10/8/2022 | 17/6/2026 | Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with administrative privileges to inject code or spawn a system root shell. | |
| Modificada | Alta (7.5) | 1.6% | — | Siemens Scalance Xm-400 FirmwareSiemens Scalance Xr524 FirmwareSiemens Scalance Xr526 FirmwareSiemens Scalance Xr528 Firmware+7 | 12/5/2021 | 17/6/2026 | An unauthenticated remote attacker could create a permanent denial-of-service condition by sending specially crafted OSPF packets. Successful exploitation requires OSPF to be enabled on an affected device on the SCALANCE XM-400, XR-500 (All versions prior to v6.4). | |
| Modificada | Alta (7.5) | 1.5% | — | Siemens DK Standard Ethernet ControllerSiemens Profinet DriverSiemens Simatic IPC SupportSiemens Ek-ertec 200 Firmware+48 | 11/2/2020 | 17/6/2026 | Profinet-IO (PNIO) stack versions prior V06.00 do not properly limit internal resource allocation when multiple legitimate diagnostic package requests are sent to the DCE-RPC interface. This could lead to a denial of service condition due to lack of memory for devices that include a vulnerable version of the stack.… |