Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
–

4 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.36%—Siemens Logo! Cmr2020 FirmwareSiemens Logo! Cmr2040 FirmwareSiemens Simatic Rtu3010c FirmwareSiemens Simatic Rtu3030c Firmware+214/9/202117/6/2026
A vulnerability has been identified in LOGO! CMR2020 (All versions < V2.2), LOGO! CMR2040 (All versions < V2.2), SIMATIC RTU3010C (All versions < V4.0.9), SIMATIC RTU3030C (All versions < V4.0.9), SIMATIC RTU3031C (All versions < V4.0.9), SIMATIC RTU3041C (All versions < V4.0.9). The underlying TCP/IP stack does not…
ModificadaAlta (7.5)1.1%—ARM Mbed TLSSiemens Logo! Cmr2020 FirmwareSiemens Logo! Cmr2040 FirmwareSiemens Simatic Rtu3031c Firmware+423/8/202117/6/2026
An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). A NULL algorithm parameters entry looks identical to an array of REAL (size zero) and thus the certificate is considered valid. However, if the parameters do not match in any way, then the certificate should be considered…
ModificadaAlta (7.5)1.9%—ARM Mbed TLSSiemens Logo! Cmr2020 FirmwareSiemens Logo! Cmr2040 FirmwareSiemens Simatic Rtu3031c Firmware+423/8/202117/6/2026
An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). The calculations performed by mbedtls_mpi_exp_mod are not limited; thus, supplying overly large parameters could lead to denial of service when generating Diffie-Hellman key pairs.
ModificadaBaja (3.7)6.3%—Haxx LibcurlFedoraproject FedoraDebian LinuxNetapp Cloud Backup+295/8/202117/6/2026
libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into account and it compared the involved paths *case insensitively*,which could lead to libcurl reusing…