Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2540▼ 352 respecto a la semana anterior
Críticas / altas1339▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

10 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.7)0.24%—Siemens Sinumerik 828d Ppu.4AISiemens Sinumerik 828d Ppu.5AISiemens Sinumerik 840d SLAISiemens Sinumerik MCAI+112/8/202517/6/2026
A vulnerability has been identified in SINUMERIK 828D PPU.4 (All versions < V4.95 SP5), SINUMERIK 828D PPU.5 (All versions < V5.25 SP1), SINUMERIK 840D sl (All versions < V4.95 SP5), SINUMERIK MC (All versions < V1.25 SP1), SINUMERIK MC V1.15 (All versions < V1.15 SP5), SINUMERIK ONE (All versions < V6.25 SP1),…
AplazadaMedia (6.8)0.15%—Siemens Sinumerik 828dAISiemens Sinumerik 840d SLAISiemens Sinumerik ONEAISiemens Create MyconfigAI10/9/202417/6/2026
A vulnerability has been identified in SINUMERIK 828D V4 (All versions < V4.95 SP3), SINUMERIK 840D sl V4 (All versions < V4.95 SP3 in connection with using Create MyConfig (CMC) <= V4.8 SP1 HF6), SINUMERIK ONE (All versions < V6.23 in connection with using Create MyConfig (CMC) <= V6.6), SINUMERIK ONE (All versions <…
AplazadaCrítica (9.3)0.14%—Siemens Sinumerik 828dAISiemens Sinumerik 840d SLAISiemens Sinumerik ONEAI10/9/202417/6/2026
A vulnerability has been identified in SINUMERIK 828D V4 (All versions), SINUMERIK 828D V5 (All versions < V5.24), SINUMERIK 840D sl V4 (All versions), SINUMERIK ONE (All versions < V6.24). Affected devices do not properly enforce access restrictions to scripts that are regularly executed by the system with elevated…
AplazadaAlta (8.2)0.26%—Siemens Security Configuration ToolAISiemens Simatic Automation ToolAISiemens Simatic BatchAISiemens Simatic NET PC SoftwareAI+1514/5/202417/6/2026
A vulnerability has been identified in Security Configuration Tool (SCT) (All versions), SIMATIC Automation Tool (All versions < V5.0 SP2), SIMATIC BATCH V9.1 (All versions < V9.1 SP2 Upd5), SIMATIC NET PC Software V16 (All versions < V16 Update 8), SIMATIC NET PC Software V17 (All versions), SIMATIC NET PC Software…
ModificadaAlta (7.5)1.2%—Siemens Simatic Drive Controller CPU 1504d TF FirmwareSiemens Simatic Drive Controller CPU 1507d TF FirmwareSiemens Simatic ET 200sp Open Control 1515sp PC2 FirmwareSiemens Simatic S7-1500 CPU 1510sp F-1 PN Firmware+6912/12/202317/6/2026
Affected devices improperly handle specially crafted packets sent to port 102/tcp. This could allow an attacker to create a denial of service condition. A restart is needed to restore normal operations.
ModificadaBaja (3.5)0.31%—Siemens Simatic S7-1500 Software ControllerSiemens Simatic S7-plcsim AdvancedSiemens Simatic Wincc RuntimeSiemens 6es7154-8fb01-0ab0 Firmware+1098/11/202217/6/2026
The login endpoint /FormLogin in affected web services does not apply proper origin checking. This could allow authenticated remote attackers to track the activities of other users via a login cross-site request forgery attack.
ModificadaAlta (7.8)0.21%—Siemens Sinumerik MC FirmwareSiemens Sinumerik ONE Firmware8/3/202217/6/2026
A vulnerability has been identified in SINUMERIK MC (All versions < V1.15 SP1), SINUMERIK ONE (All versions < V6.15 SP1). The sc SUID binary on affected devices provides several commands that are used to execute system commands or modify system files. A specific set of operations using sc could allow local attackers…
ModificadaAlta (7.5)3.2%—Lldpd Project LldpdOpenvswitchRedhat Openshift Container PlatformRedhat Openstack+1318/3/202117/6/2026
A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.
AnalizadaMedia (6.8)0.38%—Intel Converged Security AND Manageability EngineIntel Trusted Execution TechnologySiemens Simatic Drive Controller FirmwareSiemens Simatic Et200sp 1515sp PC2 Firmware+1812/11/202017/6/2026
Insufficient control flow management in subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25 , Intel(R) TXE versions before 3.1.80 and 4.0.30 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
ModificadaMedia (6.7)0.46%—Siemens Simatic Automatic ToolSiemens Simatic NET PCSiemens Simatic PCS 7Siemens Simatic PCS NEO+1310/6/202017/6/2026
A vulnerability has been identified in SIMATIC Automation Tool (All versions < V4 SP2), SIMATIC NET PC Software V14 (All versions < V14 SP1 Update 14), SIMATIC NET PC Software V15 (All versions), SIMATIC NET PC Software V16 (All versions < V16 Upd3), SIMATIC PCS neo (All versions < V3.0 SP1), SIMATIC ProSave (All…