Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.71% | — | Solar-log 1000AISolar-log 200AISolar-log 500AISolar-log 250AI+5 | 26/7/2024 | 17/6/2026 | Incorrect access control in Solar-Log 1000 before v2.8.2 and build 52- 23.04.2013 allows attackers to obtain Administrative privileges via connecting to the web administration server. Not existing for SL 200, 500, 1000 / fixed in 4.2.8 for SL 250, 300, 1200, 2000, SL 50 Gateway / fixed in 5.1.2 / 6.0.0 for SL Base. | |
| Modificada | Crítica (9.8) | 1.2% | — | Solar-log 250 FirmwareSolar-log 300 FirmwareSolar-log 500 FirmwareSolar-log 800e Firmware+5 | 26/1/2023 | 17/6/2026 | A backdoor in Solar-Log Gateway products allows remote access via web panel gaining super administration privileges to the attacker. This affects Solar-Log devices that use firmware version v4.2.7 up to v5.1.1 (included). This does not exist in SL 200, 500, 1000 / fixed in 4.2.8 for SL 250, 300, 1200, 2000, SL 50… | |
| Modificada | Crítica (9.8) | 1.1% | — | Solar-log 250 FirmwareSolar-log 300 FirmwareSolar-log 500 FirmwareSolar-log 800e Firmware+4 | 9/6/2022 | 17/6/2026 | A vulnerability was found in Solare Solar-Log 2.8.4-56/3.5.2-85. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Flash Memory. The manipulation leads to privilege escalation. The attack can be launched remotely. Upgrading to version 3.5.3-86 is able to… | |
| Modificada | Alta (7.5) | 1.2% | — | Solar-log 250 FirmwareSolar-log 300 FirmwareSolar-log 500 FirmwareSolar-log 800e Firmware+4 | 9/6/2022 | 17/6/2026 | A vulnerability was found in Solare Solar-Log 2.8.4-56/3.5.2-85. It has been classified as problematic. Affected is an unknown function. The manipulation leads to denial of service. It is possible to launch the attack remotely. Upgrading to version 3.5.3-86 is able to address this issue. It is recommended to upgrade… | |
| Modificada | Crítica (9.8) | 0.85% | — | Solar-log 250 FirmwareSolar-log 300 FirmwareSolar-log 500 FirmwareSolar-log 800e Firmware+4 | 9/6/2022 | 17/6/2026 | A vulnerability was found in Solare Solar-Log 2.8.4-56/3.5.2-85 and classified as critical. This issue affects some unknown processing of the component Network Config. The manipulation leads to privilege escalation. The attack may be initiated remotely. Upgrading to version 3.5.3-86 is able to address this issue. It… | |
| Modificada | Alta (7.5) | 1.4% | — | Solar-log 250 FirmwareSolar-log 300 FirmwareSolar-log 500 FirmwareSolar-log 800e Firmware+4 | 9/6/2022 | 17/6/2026 | A vulnerability has been found in Solare Solar-Log 2.8.4-56/3.5.2-85 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to information disclosure. The attack can be initiated remotely. Upgrading to version 3.5.3-86 is able to address this issue. It is recommended to upgrade… | |
| Modificada | Crítica (9.8) | 1.0% | — | Solar-log 250 FirmwareSolar-log 300 FirmwareSolar-log 500 FirmwareSolar-log 800e Firmware+4 | 9/6/2022 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Solare Solar-Log 2.8.4-56/3.5.2-85. This affects an unknown part of the component File Upload. The manipulation leads to privilege escalation. It is possible to initiate the attack remotely. Upgrading to version 3.5.3-86 is able to address this issue. It… | |
| Modificada | Alta (8.8) | 0.40% | — | Solar-log 250 FirmwareSolar-log 300 FirmwareSolar-log 500 FirmwareSolar-log 800e Firmware+4 | 9/6/2022 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Solare Solar-Log 2.8.4-56/3.5.2-85. Affected by this issue is some unknown functionality. The manipulation leads to cross site request forgery. The attack may be launched remotely. Upgrading to version 3.5.3-86 is able to address this issue. It is… | |
| Modificada | Alta (7.5) | 1.0% | — | Solar-log 250 FirmwareSolar-log 300 FirmwareSolar-log 500 FirmwareSolar-log 800e Firmware+4 | 9/6/2022 | 17/6/2026 | A vulnerability classified as problematic was found in Solare Solar-Log 2.8.4-56/3.5.2-85. Affected by this vulnerability is an unknown functionality of the component Config Handler. The manipulation leads to information disclosure. The attack can be launched remotely. Upgrading to version 3.5.3-86 is able to address… | |
| Modificada | Media (6.5) | 1.0% | — | BKW Solar-log 500 Firmware | 7/12/2021 | 17/6/2026 | An issue was discovered in Solar-Log 500 before 2.8.2 Build 52 23.04.2013. In /export.html, email.html, and sms.html, cleartext passwords are stored. This may allow sensitive information to be read by someone with access to the device. Fixed with 3.0.0-60 11.10.2013 for SL 200, 500, 1000 / not existing for SL 250,… | |
| Modificada | Alta (7.5) | 3.0% | — | BKW Solar-log 500 Firmware | 7/12/2021 | 17/6/2026 | The web administration server in Solar-Log 500 before 2.8.2 Build 52 does not require authentication, which allows remote attackers to gain administrative privileges by connecting to the server. As a result, the attacker can modify configuration files and change the system status. Fixed with 3.0.0-60 11.10.2013 for SL… |