Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
–

19 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.58%—Opcfoundation UA .net Standard Stack10/2/202517/6/2026
Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application authentication when using HTTPS endpoints.
AnalizadaAlta (8.6)0.60%—Opcfoundation UA .net Standard Stack10/2/202517/6/2026
Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application authentication when the deprecated Basic128Rsa15 security policy is enabled.
AplazadaMedia (5.3)0.50%—Opcfoundation UA .net StandardAI22/10/202417/6/2026
An issue was discovered in OPC Foundation OPCFoundation/UA-.NETStandard through 1.5.374.78. A remote attacker can send requests with invalid credentials and cause the server performance to degrade gradually.
AnalizadaAlta (7.5)1.0%—Opcfoundation Ua-.netstandard7/5/202417/6/2026
OPC Foundation UA .NET Standard ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of OPC Foundation UA .NET Standard. Authentication is not required to exploit this vulnerability. The…
ModificadaMedia (5.3)0.79%—Opcfoundation Ua-.netstandard12/12/202317/6/2026
The OPC UA .NET Standard Reference Server before 1.4.371.86. places sensitive information into an error message that may be seen remotely.
ModificadaAlta (7.5)1.3%—Opcfoundation UA .net Standard Stack23/8/202217/6/2026
OPC UA .NET Standard Reference Server 1.04.368 allows a remote attacker to cause the application to access sensitive information.
ModificadaAlta (7.5)1.7%—Opcfoundation UA .net Standard Stack16/6/202217/6/2026
OPC UA .NET Standard Stack 1.04.368 allows a remote attacker to exhaust the memory resources of a server via a crafted request that triggers Uncontrolled Resource Consumption.
ModificadaAlta (7.5)2.0%—Opcfoundation UA .net Standard Stack16/6/202217/6/2026
OPC UA .NET Standard Stack 1.04.368 allows a remote attacker to cause a server to crash via a large number of messages that trigger Uncontrolled Resource Consumption.
ModificadaAlta (7.5)1.4%—Opcfoundation UA .net Standard Stack16/6/202217/6/2026
OPC UA .NET Standard Stack 1.04.368 allows remote attacker to cause a crash via a crafted message that triggers excessive memory allocation.
ModificadaAlta (7.5)1.7%—Opcfoundation UA .net Standard Stack16/6/202217/6/2026
OPC UA .NET Standard Stack allows a remote attacker to bypass the application authentication check via crafted fake credentials.
ModificadaAlta (7.5)1.6%—Opcfoundation UA .net Standard Stack16/6/202217/6/2026
An infinite loop in OPC UA .NET Standard Stack 1.04.368 allows a remote attackers to cause the application to hang via a crafted message.
ModificadaAlta (7.5)1.9%—Opcfoundation Ua-.net-legacyOpcfoundation UA .net Standard Stack20/5/202117/6/2026
OPC Foundation UA .NET Standard versions prior to 1.4.365.48 and OPC UA .NET Legacy are vulnerable to an uncontrolled recursion, which may allow an attacker to trigger a stack overflow.
ModificadaMedia (4.4)0.31%—Opcfoundation Ua-.netstandard16/2/202117/6/2026
A Privilege Elevation vulnerability in OPC UA .NET Standard Stack 1.4.363.107 could allow a rogue application to establish a secure connection.
ModificadaAlta (7.4)1.0%—Opcfoundation Netstandard.opc.uaOpcfoundation Ua-.netstandard16/3/202017/6/2026
In OPC Foundation OPC UA .NET Standard codebase 1.4.357.28, servers do not create sufficiently random numbers in OPCFoundation.NetStandard.Opc.Ua before 1.4.359.31, which allows man in the middle attackers to reuse encrypted user credentials sent over the network.
ModificadaMedia (5.3)0.29%—Opcfoundation Ua-.net-legacyOpcfoundation Ua-.netstandard3/10/201817/6/2026
Failure to validate certificates in OPC Foundation UA Client Applications communicating without security allows attackers with control over a piece of network infrastructure to decrypt passwords.
ModificadaAlta (8.2)1.6%—Opcfoundation Ua-.net-legacyOpcfoundation Ua-java14/9/201817/6/2026
An XXE vulnerability in the OPC UA Java and .NET Legacy Stack can allow remote attackers to trigger a denial of service.
ModificadaAlta (8.8)1.0%—Opcfoundation Ua-.net-legacy14/6/201817/6/2026
Unsigned versions of the DLLs distributed by the OPC Foundation may be replaced with malicious code.
ModificadaMedia (5.3)1.2%—Opcfoundation Ua-.net-legacyOpcfoundation Ua-.netstandard13/6/201817/6/2026
An issue was discovered in OPC UA .NET Standard Stack and Sample Code before GitHub commit 2018-04-12, and OPC UA .NET Legacy Stack and Sample Code before GitHub commit 2018-03-13. A vulnerability in OPC UA applications can allow a remote attacker to determine a Server's private key by sending carefully constructed…
ModificadaAlta (8.2)2.9%—Siemens Simatic Pcs7Siemens WinccOcpfoundation Local Discovery ServerOcpfoundation UA .net30/8/201717/6/2026
An XXE vulnerability has been identified in OPC Foundation UA .NET Sample Code before 2017-03-21 and Local Discovery Server (LDS) before 1.03.367. Among the affected products are Siemens SIMATIC PCS7 (All versions V8.1 and earlier), SIMATIC WinCC (All versions < V7.4 SP1), SIMATIC WinCC Runtime Professional (All…