Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.0% | — | Pepperl-fuchs Wha-gw-f2d2-0-as-z2-eth FirmwarePepperl-fuchs Wha-gw-f2d2-0-as-z2-eth.eip Firmware | 31/8/2021 | 17/6/2026 | In PEPPERL+FUCHS WirelessHART-Gateway 3.0.7 to 3.0.9 the SSH and telnet services are active with hard-coded credentials. | |
| Modificada | Baja (3.3) | 0.24% | — | Pepperl-fuchs Wha-gw-f2d2-0-as-z2-eth FirmwarePepperl-fuchs Wha-gw-f2d2-0-as-z2-eth.eip Firmware | 31/8/2021 | 17/6/2026 | In PEPPERL+FUCHS WirelessHART-Gateway 3.0.8 and 3.0.9 the HttpOnly attribute is not set on a cookie. This allows the cookie's value to be read or set by client-side JavaScript. | |
| Modificada | Media (6.1) | 0.58% | — | Pepperl-fuchs Wha-gw-f2d2-0-as-z2-eth FirmwarePepperl-fuchs Wha-gw-f2d2-0-as-z2-eth.eip Firmware | 31/8/2021 | 17/6/2026 | In PEPPERL+FUCHS WirelessHART-Gateway 3.0.8 it is possible to inject arbitrary JavaScript into the application's response. | |
| Modificada | Alta (8.8) | 0.87% | — | Pepperl-fuchs Wha-gw-f2d2-0-as-z2-eth FirmwarePepperl-fuchs Wha-gw-f2d2-0-as-z2-eth.eip Firmware | 31/8/2021 | 17/6/2026 | In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 serious issue exists, if the application is not externally accessible or uses IP-based access restrictions. Attackers can use DNS Rebinding to bypass any IP or firewall based access restrictions that may be in place, by proxying through their target's browser. | |
| Modificada | Media (5.5) | 0.21% | — | Pepperl-fuchs Wha-gw-f2d2-0-as-z2-eth FirmwarePepperl-fuchs Wha-gw-f2d2-0-as-z2-eth.eip Firmware | 31/8/2021 | 17/6/2026 | In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.9 a form contains a password field with autocomplete enabled. The stored credentials can be captured by an attacker who gains control over the user's computer. Therefore the user must have logged in at least once. | |
| Modificada | Media (5.3) | 0.77% | — | Pepperl-fuchs Wha-gw-f2d2-0-as-z2-eth FirmwarePepperl-fuchs Wha-gw-f2d2-0-as-z2-eth.eip Firmware | 31/8/2021 | 17/6/2026 | In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 a vulnerability may allow remote attackers to rewrite links and URLs in cached pages to arbitrary strings. |