Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
–

55 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisCrítica (9.2)0.43%—Siemens Simatic S7-1500 Software Controller 5370AISiemens Simatic S7-1500 Software Controller 5570AI14/7/202629/9/2026
A denial-of-service issue exists in 5370/5570 controllers. This vulnerability could potentially allow a remote user to load an invalid project, causing the device to enter a major non-recoverable fault (MNRF).
AnalizadaAlta (7.8)3.4%⚠ Explotación activaLinux KernelRedhat Openshift Container PlatformRedhat Enterprise LinuxRedhat Enterprise Linux AUS+4422/4/20268/9/2026
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different…
AnalizadaMedia (5.5)1.3%⚠ Explotación activaLinux KernelSiemens Simatic S7-1500 CPU 1518-4 Pn/dp MFP FirmwareSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP Firmware13/10/202519/9/2026
In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal…
AnalizadaMedia (5.5)0.81%⚠ Explotación activaGoogle AndroidDebian LinuxSiemens Simatic S7-1500 TM MFP FirmwareSiemens Sinec OS+119/11/202417/6/2026
In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by all kinds of drivers in various ways, let's zero-initialize it during allocation to make sure that it can't be ever used to leak kernel memory via specially-crafted report.
ModificadaAlta (7.8)0.33%—Siemens Simatic S7-1500 TM MFP FirmwareDebian LinuxLinux KernelSiemens Sinec OS21/10/20244/8/2026
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix index out of bounds in degamma hardware format translation Fixes index out of bounds issue in `cm_helper_translate_curve_to_degamma_hw_format` function. The issue could occur when the index 'i' exceeds the number of transfer…
ModificadaAlta (7.5)1.2%—Siemens Simatic Drive Controller CPU 1504d TF FirmwareSiemens Simatic Drive Controller CPU 1507d TF FirmwareSiemens Simatic ET 200sp Open Control 1515sp PC2 FirmwareSiemens Simatic S7-1500 CPU 1510sp F-1 PN Firmware+6912/12/202317/6/2026
Affected devices improperly handle specially crafted packets sent to port 102/tcp. This could allow an attacker to create a denial of service condition. A restart is needed to restore normal operations.
AnalizadaAlta (7.5)100%⚠ Explotación activaSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+16110/10/202311/8/2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
AnalizadaAlta (7.8)64%⚠ Explotación activaNetapp Bootstrap OSSiemens Simatic S7-1500 CPU 1518-4 Pn/dp MFP FirmwareSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Siplus S7-1500 CPU 1518-4 Pn/dp MFP Firmware+353/10/202317/6/2026
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated…
ModificadaAlta (8.7)1.1%—Siemens Simatic Cloud Connect 7 Cc712 FirmwareSiemens Simatic Cloud Connect 7 Cc716 FirmwareSiemens Simatic Drive Controller CPU 1504d TF FirmwareSiemens Simatic Drive Controller CPU 1507d TF Firmware+7412/9/202317/6/2026
The OPC UA implementations (ANSI C and C++) in affected products contain an integer overflow vulnerability that could cause the application to run into an infinite loop during certificate validation. This could allow an unauthenticated remote attacker to create a denial of service condition by sending a specially…
ModificadaMedia (6.8)0.29%—Siemens Simatic Drive Controller CPU 1504d TF FirmwareSiemens Simatic Drive Controller CPU 1507d TF FirmwareSiemens Simatic S7-1500 CPU 1510sp F-1 PN FirmwareSiemens Simatic S7-1500 CPU 1510sp-1 PN Firmware+6610/1/202317/6/2026
Affected devices do not contain an Immutable Root of Trust in Hardware. With this the integrity of the code executed on the device can not be validated during load-time. An attacker with physical access to the device could use this to replace the boot image of the device and execute arbitrary code.
ModificadaAlta (7.5)0.74%—Siemens Simatic S7-plcsim Advanced FirmwareSiemens Simatic S7-1200 CPU 1211c FirmwareSiemens Simatic S7-1200 CPU 1212c FirmwareSiemens Simatic S7-1200 CPU 1212fc Firmware+9213/12/202217/6/2026
Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device.
ModificadaAlta (7.5)0.63%—Siemens Simatic S7-plcsim Advanced FirmwareSiemens Simatic S7-1200 CPU 1211c FirmwareSiemens Simatic S7-1200 CPU 1212c FirmwareSiemens Simatic S7-1200 CPU 1212fc Firmware+8813/12/202217/6/2026
Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device.
ModificadaAlta (7.5)0.74%—Siemens Simatic S7-plcsim Advanced FirmwareSiemens Simatic S7-1200 CPU 1211c FirmwareSiemens Simatic S7-1200 CPU 1212c FirmwareSiemens Simatic S7-1200 CPU 1212fc Firmware+9213/12/202217/6/2026
Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device.
ModificadaAlta (7.5)0.90%—Siemens Simatic S7-plcsim Advanced FirmwareSiemens Simatic S7-1200 CPU 1211c FirmwareSiemens Simatic S7-1200 CPU 1212c FirmwareSiemens Simatic S7-1200 CPU 1212fc Firmware+9213/12/202217/6/2026
Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device.
ModificadaBaja (3.5)0.31%—Siemens Simatic S7-1500 Software ControllerSiemens Simatic S7-plcsim AdvancedSiemens Simatic Wincc RuntimeSiemens 6es7154-8fb01-0ab0 Firmware+1098/11/202217/6/2026
The login endpoint /FormLogin in affected web services does not apply proper origin checking. This could allow authenticated remote attackers to track the activities of other users via a login cross-site request forgery attack.
ModificadaAlta (7.8)0.23%—Siemens Simatic ET 200 SP Open Controller CPU 1515sp PC2 FirmwareSiemens Simatic ET 200 SP Open Controller CPU 1515sp PC FirmwareSiemens Simatic Drive Controller CPU 1504d TF FirmwareSiemens Simatic Drive Controller CPU 1507d TF Firmware+4111/10/202217/6/2026
A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants) (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions < V21.9), SIMATIC S7-1200 CPU family (incl. SIPLUS…
ModificadaAlta (7.5)0.90%—Siemens Simatic CFU DIQ FirmwareSiemens Simatic CFU PA FirmwareSiemens Simatic S7-300 CPU FirmwareSiemens Simatic S7-400h V6 Firmware+812/4/202217/6/2026
The PROFINET (PNIO) stack, when integrated with the Interniche IP stack, improperly handles internal resources for TCP segments where the minimum TCP-Header length is less than defined. This could allow an attacker to create a denial of service condition for TCP services on affected devices by sending specially…
ModificadaAlta (7.5)1.6%—Siemens Simatic Drive Controller CPU 1504d TF FirmwareSiemens Simatic Drive Controller CPU 1507d TF FirmwareSiemens Simatic ET 200sp Open Controller CPU 1515sp PC2 FirmwareSiemens Simatic S7-plcsim Advanced Firmware+449/2/202217/6/2026
A vulnerability has been identified in SIMATIC Drive Controller family (All versions >= V2.9.2 < V2.9.4), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions >= V21.9 < V21.9.4), SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (All versions >= V4.5.0 < V4.5.2), SIMATIC S7-1500 CPU…
ModificadaAlta (7.5)2.2%—Siemens Simatic Drive Controller CPU 1504d TF FirmwareSiemens Simatic Drive Controller CPU 1507d TF FirmwareSiemens Simatic ET 200sp Open Controller CPU 1515sp PC2 FirmwareSiemens Simatic S7-plcsim Advanced Firmware+449/2/202217/6/2026
A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC Drive Controller family (All versions >= V2.9.2 < V2.9.4), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants) (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS…
ModificadaAlta (7.5)2.1%—Siemens Simatic Drive Controller CPU 1504d TF FirmwareSiemens Simatic Drive Controller CPU 1507d TF FirmwareSiemens Simatic ET 200sp Open Controller CPU 1515sp PC2 FirmwareSiemens Simatic S7-plcsim Advanced Firmware+449/2/202217/6/2026
A vulnerability has been identified in SIMATIC Drive Controller family (All versions >= V2.9.2 < V2.9.4), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions >= V21.9 < V21.9.4), SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (All versions >= V4.5.0 < V4.5.2), SIMATIC S7-1500 CPU…
ModificadaMedia (5.3)0.75%—Siemens CPU 1504d TF FirmwareSiemens CPU 1507d TF FirmwareSiemens CPU 1515sp PC2 TF FirmwareSiemens Simatic S7 Plcsim Advanced Firmware+5210/8/202117/6/2026
A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions < V21.9), SIMATIC S7 PLCSIM Advanced (All versions > V2 < V4), SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (Version V4.4), SIMATIC…
ModificadaCrítica (9.8)5.2%—Siemens Simatic Driver Controller FirmwareSiemens S7-1200 CPU FirmwareSiemens S7-1500 CPU FirmwareSiemens Simatic S7-1500 Software Controller+228/5/202117/6/2026
A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants) (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions < V21.9), SIMATIC S7-1200 CPU family (incl. SIPLUS…
ModificadaMedia (5.9)64%—OpensslDebian LinuxFreebsdNetapp Active IQ Unified Manager+10225/3/202117/6/2026
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer…
ModificadaAlta (7.5)1.6%—Siemens Simatic ET 200sp Open Controller FirmwareSiemens Simatic S7-1500 Software Controller Firmware14/12/202017/6/2026
A vulnerability has been identified in SIMATIC ET 200SP Open Controller (incl. SIPLUS variants) (V20.8), SIMATIC S7-1500 Software Controller (V20.8). The web server of the affected products contains a vulnerability that could allow a remote attacker to trigger a denial-of-service condition by sending a specially…
ModificadaAlta (7.8)0.36%—Intel Converged Security AND Management EngineIntel Server Platform ServicesIntel Trusted Execution EngineSiemens Simatic S7-1518-4 Pn/dp MFP Firmware+212/11/202017/6/2026
Improper initialization in subsystem for Intel(R) CSME versions before12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE versions before 4.0.30 Intel(R) SPS versions before E3_05.01.04.200 may allow a privileged user to potentially enable escalation of privilege via local access.