Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3028▼ 62 respecto a la semana anterior
Críticas / altas1422▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

3 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.90%—Siemens Simatic CFU DIQ FirmwareSiemens Simatic CFU PA FirmwareSiemens Simatic S7-300 CPU FirmwareSiemens Simatic S7-400h V6 Firmware+812/4/202217/6/2026
The PROFINET (PNIO) stack, when integrated with the Interniche IP stack, improperly handles internal resources for TCP segments where the minimum TCP-Header length is less than defined. This could allow an attacker to create a denial of service condition for TCP services on affected devices by sending specially…
ModificadaAlta (8.7)1.9%—Siemens DK Standard Ethernet Controller Evaluation KIT FirmwareSiemens Ek-ertec 200 Evaulation KIT FirmwareSiemens Ek-ertec 200p Evaluation KIT FirmwareSiemens Ruggedcom Rm1224 Firmware+7513/7/202117/6/2026
Affected devices contain a vulnerability that allows an unauthenticated attacker to trigger a denial of service condition. The vulnerability can be triggered if a large amount of DCP reset packets are sent to the device.
ModificadaAlta (7.5)2.1%—Siemens DK Standard Ethernet Controller FirmwareSiemens Ek-ertec 200 FirmwareSiemens Ek-ertec 200p FirmwareSiemens Simatic CFU PA Firmware+6210/10/201917/6/2026
Affected devices improperly handle large amounts of specially crafted UDP packets. This could allow an unauthenticated remote attacker to trigger a denial of service condition.