Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.12% | — | Siemens Sinec Traffic Analyzer | 12/8/2025 | 17/6/2026 | A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions). The affected application uses a monitoring interface that is not operating in a strictly passive mode. This could allow an attacker to interact with the interface, leading to man-in-the-middle attacks. | |
| Aplazada | Alta (7.5) | 0.15% | — | Siemens Sinec Traffic AnalyzerAI | 12/8/2025 | 17/6/2026 | A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V3.0). The affected application uses a Content Security Policy that allows unsafe script execution methods. This could allow an attacker to execute unauthorized scripts, potentially leading to cross-site scripting… | |
| Analizada | Alta (7) | 0.14% | — | Siemens Sinec Traffic Analyzer | 12/8/2025 | 17/6/2026 | A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V3.0). The affected application exposes an internal service port to be accessible from outside the system. This could allow an unauthorized attacker to access the application. | |
| Analizada | Alta (8.8) | 0.13% | — | Siemens Sinec Traffic Analyzer | 12/8/2025 | 17/6/2026 | A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V3.0). The affected application runs docker containers without adequate security controls to enforce isolation. This could allow an attacker to gain elevated access, potentially accessing sensitive host system resources. | |
| Analizada | Media (6.8) | 0.18% | 💥 PoC | Siemens Sinec Traffic Analyzer | 12/8/2025 | 17/6/2026 | A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V3.0). The affected application runs docker containers without adequate resource and security limitations. This could allow an attacker to perform a denial-of-service (DoS) attack. | |
| Analizada | Baja (2.1) | 0.22% | — | Siemens Sinec Traffic Analyzer | 13/8/2024 | 17/6/2026 | A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application is missing general HTTP security headers in the web server. This could allow an attacker to make the servers more prone to clickjacking attack. | |
| Analizada | Media (6.3) | 0.23% | — | Siemens Sinec Traffic Analyzer | 13/8/2024 | 17/6/2026 | A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application does not properly handle cacheable HTTP responses in the web service. This could allow an attacker to read and modify data stored in the local cache. | |
| Analizada | Alta (7.6) | 0.30% | — | Siemens Sinec Traffic Analyzer | 13/8/2024 | 17/6/2026 | A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application do not have access control for accessing the files. This could allow an authenticated attacker with low privilege's to get access to sensitive information. | |
| Analizada | Alta (8.7) | 0.54% | — | Siemens Sinec Traffic Analyzer | 13/8/2024 | 17/6/2026 | A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application do not properly enforce restriction of excessive authentication attempts. This could allow an unauthenticated attacker to conduct brute force attacks against legitimate user credentials or… | |
| Analizada | Alta (7.5) | 0.39% | — | Siemens Sinec Traffic Analyzer | 13/8/2024 | 17/6/2026 | A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application mounts the container's root filesystem with read and write privileges. This could allow an attacker to alter the container's filesystem leading to unauthorized modifications and data… | |
| Modificada | Media (6.9) | 0.34% | — | Siemens Sinec Traffic Analyzer | 11/6/2024 | 17/6/2026 | A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected application lacks input validation due to which an attacker can gain access to the Database entries. | |
| Modificada | Media (6.8) | 0.22% | — | Siemens Sinec Traffic Analyzer | 11/6/2024 | 17/6/2026 | A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server, after a successful login, sets the session cookie on the browser, without applying any security attributes (such as “Secure”, “HttpOnly”, or “SameSite”). | |
| Modificada | Media (5.1) | 0.15% | — | Siemens Sinec Traffic Analyzer | 11/6/2024 | 17/6/2026 | A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server is not enforcing HSTS. This could allow an attacker to perform downgrade attacks exposing confidential information. | |
| Modificada | Media (6.9) | 0.32% | — | Siemens Sinec Traffic Analyzer | 11/6/2024 | 17/6/2026 | A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server is allowing HTTP methods like PUT and Delete. This could allow an attacker to modify unauthorized files. | |
| Modificada | Media (4.8) | 0.15% | — | Siemens Sinec Traffic Analyzer | 11/6/2024 | 17/6/2026 | A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server stored the password in cleartext. This could allow attacker in a privileged position to obtain access passwords. | |
| Modificada | Alta (8.5) | 0.15% | — | Siemens Sinec Traffic Analyzer | 11/6/2024 | 17/6/2026 | A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The web interface of the affected devices are vulnerable to Cross-Site Request Forgery(CSRF) attacks. By tricking an authenticated victim user to click a malicious link, an attacker could perform arbitrary actions… | |
| Modificada | Alta (8.5) | 0.33% | — | Siemens Sinec Traffic Analyzer | 11/6/2024 | 17/6/2026 | A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected application does not expire the session. This could allow an attacker to get unauthorized access. |