Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2636▼ 301 respecto a la semana anterior
Críticas / altas1348▲ 73 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
87 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.25% | — | Siemens Sinema Remote Connect Server | 9/12/2025 | 17/6/2026 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP4). Affected applications do not properly validate license restrictions against the database, allowing direct modification of the system_ticketinfo table to bypass license limitations without proper enforcement checks. This… | |
| Analizada | Baja (3.3) | 0.10% | — | Siemens Sinema Remote Connect Server | 9/12/2025 | 17/6/2026 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP4). Affected applications contain private SSL/TLS keys on the server that are not properly protected allowing any user with server access to read these keys. This could allow an authenticated attacker to impersonate the server… | |
| Analizada | Alta (8.7) | 0.62% | — | Siemens Simatic PCS NEOSiemens Sinec NMSSiemens Sinema Remote ConnectSiemens Totally Integrated Automation Portal+1 | 13/5/2025 | 17/6/2026 | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC NMS (All versions < V4.0), SINEMA Remote Connect (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All… | |
| Analizada | Alta (8.7) | 0.62% | — | Siemens Simatic PCS NEOSiemens Sinec NMSSiemens Sinema Remote ConnectSiemens Totally Integrated Automation Portal+1 | 13/5/2025 | 17/6/2026 | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC NMS (All versions < V4.0), SINEMA Remote Connect (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All… | |
| Analizada | Alta (8.7) | 0.62% | — | Siemens Sinec NMSSiemens Sinema Remote ConnectSiemens Totally Integrated Automation PortalSiemens User Management Component | 13/5/2025 | 17/6/2026 | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC NMS (All versions < V4.0), SINEMA Remote Connect (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All… | |
| Analizada | Media (5.3) | 0.34% | — | Siemens Sinema Remote Connect Server | 10/9/2024 | 17/6/2026 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP2). The affected application does not properly handle user session establishment and invalidation. This could allow a remote attacker to circumvent the additional multi factor authentication for user session establishment. | |
| Analizada | Media (4.8) | 0.15% | — | Siemens Sinema Remote Connect Client | 10/9/2024 | 17/6/2026 | A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 SP2). The affected application inserts sensitive information into a log file which is readable by all legitimate users of the underlying system. This could allow an authenticated attacker to compromise the confidentiality of other… | |
| Aplazada | Crítica (9.3) | 1.1% | — | Siemens Opcenter QualityAISiemens Opcenter RdnlAISiemens Simatic PCS NEOAISiemens Sinec NMSAI+2 | 10/9/2024 | 17/6/2026 | A vulnerability has been identified in Opcenter Quality (All versions < V2406), Opcenter RDnL (All versions < V2410), SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Update 2), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1), SINEC NMS (All versions), SINEMA Remote Connect Client… | |
| Analizada | Media (5.3) | 0.29% | — | Siemens Sinema Remote Connect Client | 10/9/2024 | 17/6/2026 | A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 SP2). The affected application does not expire the user session on reboot without logout. This could allow an attacker to bypass Multi-Factor Authentication. | |
| Modificada | Media (5.3) | 0.21% | — | Siemens Sinema Remote Connect Server | 9/7/2024 | 17/6/2026 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected applications do not properly handle log rotation. This could allow an unauthenticated remote attacker to cause a denial of service condition through resource exhaustion on the device. | |
| Modificada | Media (5.3) | 0.26% | — | Siemens Sinema Remote Connect Server | 9/7/2024 | 17/6/2026 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application allows authenticated, low privilege users with the 'Manage own remote connections' permission to retrieve details about other users and group memberships. | |
| Modificada | Alta (8.7) | 0.41% | — | Siemens Sinema Remote Connect Server | 9/7/2024 | 17/6/2026 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application does not properly implement brute force protection against user credentials in its Client Communication component. This could allow an attacker to learn user credentials that are vulnerable to brute… | |
| Modificada | Alta (8.7) | 0.45% | — | Siemens Sinema Remote Connect Server | 9/7/2024 | 17/6/2026 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application does not properly implement brute force protection against user credentials in its web API. This could allow an attacker to learn user credentials that are vulnerable to brute force attacks. | |
| Modificada | Crítica (9.3) | 0.47% | — | Siemens Sinema Remote Connect Server | 9/7/2024 | 17/6/2026 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application does not properly assign rights to temporary files created during its update process. This could allow an authenticated attacker with the 'Manage firmware updates' role to escalate their privileges… | |
| Modificada | Media (5.3) | 0.22% | — | Siemens Sinema Remote Connect Server | 9/7/2024 | 17/6/2026 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected applications do not properly separate the rights to edit device settings and to edit settings for communication relations. This could allow an authenticated attacker with the permission to manage devices to gain… | |
| Modificada | Alta (7.1) | 0.25% | — | Siemens Sinema Remote Connect Server | 9/7/2024 | 17/6/2026 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected applications can be configured to allow users to manage own users. A local authenticated user with this privilege could use this modify users outside of their own scope as well as to escalate privileges. | |
| Modificada | Alta (7.1) | 0.28% | — | Siemens Sinema Remote Connect Server | 9/7/2024 | 17/6/2026 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected products allow to upload certificates. An authenticated attacker could upload a crafted certificates leading to a permanent denial-of-service situation. In order to recover from such an attack, the offending… | |
| Modificada | Alta (7.2) | 0.36% | — | Siemens Sinema Remote Connect Server | 9/7/2024 | 17/6/2026 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected devices do not properly validate the authentication when performing certain actions in the web interface allowing an unauthenticated attacker to access and edit VxLAN configuration information of networks for which… | |
| Modificada | Alta (7.2) | 0.36% | — | Siemens Sinema Remote Connect Server | 9/7/2024 | 17/6/2026 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected devices do not properly validate the authentication when performing certain actions in the web interface allowing an unauthenticated attacker to access and edit device configuration information of devices for which… | |
| Modificada | Alta (8.7) | 0.24% | — | Siemens Sinema Remote Connect Server | 9/7/2024 | 17/6/2026 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application allows users to upload encrypted backup files. This could allow an attacker with access to the backup encryption key and with the right to upload backup files to create a user with administrative… | |
| Modificada | Alta (8.7) | 0.45% | — | Siemens Sinema Remote Connect Server | 9/7/2024 | 17/6/2026 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application allows users to upload encrypted backup files. As part of this backup, files can be restored without correctly checking the path of the restored file. This could allow an attacker with access to the… | |
| Modificada | Alta (8.7) | 1.3% | — | Siemens Sinema Remote Connect Server | 9/7/2024 | 17/6/2026 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 HF1). Affected applications are vulnerable to command injection due to missing server side input sanitation when loading SNMP configurations. This could allow an attacker with the right to modify the SNMP configuration to execute… | |
| Modificada | Alta (8.7) | 1.4% | — | Siemens Sinema Remote Connect Server | 9/7/2024 | 17/6/2026 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 HF1). Affected applications are vulnerable to command injection due to missing server side input sanitation when loading VxLAN configurations. This could allow an authenticated attacker to execute arbitrary code with root… | |
| Modificada | Alta (7.5) | 1.0% | — | Siemens Sinema Remote Connect Client | 9/7/2024 | 17/6/2026 | A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 HF1). The system service of affected applications is vulnerable to command injection due to missing server side input sanitation when loading VPN configurations. This could allow an administrative remote attacker running a… | |
| Modificada | Alta (8.5) | 0.90% | — | Siemens Sinema Remote Connect Client | 9/7/2024 | 17/6/2026 | A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 HF1). The system service of affected applications is vulnerable to command injection due to missing server side input sanitation when loading proxy configurations. This could allow an authenticated local attacker to execute… |