Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2567▼ 296 respecto a la semana anterior
Críticas / altas1351▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.6) | 0.62% | — | Siemens Cpci85AISiemens SicoreAI | 9/7/2026 | 9/7/2026 | A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application contains insufficient validation of authentication credentials when processing administrative account modifications through the web API. This… | |
| Pendiente de análisis | Media (6.3) | 0.23% | — | Siemens Cpci85AISiemens Sicore Base SystemAI | 9/7/2026 | 9/7/2026 | A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application ships with a default configuration that disables all OPC UA security mechanisms. This could allow an attacker to gain unauthorized access and… | |
| Pendiente de análisis | Alta (8.4) | 0.18% | — | Siemens Cpci85AISiemens SicoreAI | 9/7/2026 | 9/7/2026 | A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application contains a vulnerability in its firmware update mechanism's signature validation process. This could allow an attacker to install malicious… | |
| Pendiente de análisis | Alta (7.1) | 0.41% | — | Siemens Cpci85AISiemens SicoreAI | 9/7/2026 | 9/7/2026 | A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application includes a debugging interface that is accessible through HTTP endpoints. This could allow an authenticated attacker to disrupt the system by… | |
| Pendiente de análisis | Alta (8.7) | 0.51% | — | Siemens Cpci85AISiemens SicoreAI | 26/3/2026 | 17/6/2026 | A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.10), SICORE Base system (All versions < V26.10.0). The affected application contains an out-of-bounds write vulnerability while parsing specially crafted XML inputs. This could allow an unauthenticated attacker to… | |
| Aplazada | Alta (7.1) | 0.52% | — | Phoenixcontact Cpci85AIPhoenixcontact SicoreAI | 22/7/2024 | 17/6/2026 | A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.40), SICORE Base system (All versions < V1.4.0). Affected devices allow a remote authenticated user or an unauthenticated user with physical access to downgrade the firmware of the device. This could allow an attacker to… | |
| Aplazada | Crítica (9.3) | 0.45% | — | Beckhoff Cpci85AIBeckhoff SicoreAI | 22/7/2024 | 17/6/2026 | A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.40), SICORE Base system (All versions < V1.4.0). The password of administrative accounts of the affected applications can be reset without requiring the knowledge of the current password, given the auto login is enabled.… | |
| Aplazada | Alta (8.6) | 2.4% | — | Phoenixcontact Cpci85AIPhoenixcontact SicoreAI | 14/5/2024 | 17/6/2026 | A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.30), SICORE Base system (All versions < V1.3.0). The web interface of affected devices is vulnerable to command injection due to missing server side input sanitation. This could allow an authenticated privileged remote… |