Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
27 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.7) | 0.11% | — | Siemens Scalance Lpe9403 Firmware | 13/5/2025 | 8/9/2026 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge Client installed). Affected devices do transmit sensitive information in cleartext. This could allow a privileged local attacker to retrieve this sensitive information. | |
| Modificada | Alta (8.5) | 0.18% | — | Siemens Scalance Lpe9403 Firmware | 13/5/2025 | 8/9/2026 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge Client installed). Affected devices do not properly sanitize configuration parameters. This could allow a non-privileged local attacker to execute root commands on the device. | |
| Modificada | Alta (8.4) | 0.15% | — | Siemens Scalance Lpe9403 Firmware | 13/5/2025 | 8/9/2026 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge Client installed). Affected devices are vulnerable to an authentication bypass. This could allow a non-privileged local attacker to bypass the authentication of the SINEMA Remote… | |
| Modificada | Media (5.4) | 0.16% | — | Siemens Scalance Lpe9403 Firmware | 13/5/2025 | 17/6/2026 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices are vulnerable to a stack-based buffer overflow. This could allow a non-privileged local attacker to execute arbitrary code on the device or to cause a denial of service condition. | |
| Modificada | Media (5.4) | 0.16% | — | Siemens Scalance Lpe9403 Firmware | 13/5/2025 | 17/6/2026 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices are vulnerable to a stack-based buffer overflow. This could allow a non-privileged local attacker to execute arbitrary code on the device or to cause a denial of service condition. | |
| Analizada | Media (5.3) | 0.27% | — | Siemens Scalance Lpe9403 Firmware | 13/5/2025 | 17/6/2026 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions). Affected devices do not properly handle multiple incoming Profinet packets received in rapid succession. An unauthenticated remote attacker can exploit this flaw by sending multiple packets in a very short time frame, which… | |
| Modificada | Media (5.3) | 0.27% | — | Siemens Scalance Lpe9403 Firmware | 13/5/2025 | 17/6/2026 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices do not properly validate incoming Profinet packets. An unauthenticated remote attacker can exploit this flaw by sending a specially crafted malicious packet, which leads to a crash of the dcpd… | |
| Modificada | Media (5.3) | 0.27% | — | Siemens Scalance Lpe9403 Firmware | 13/5/2025 | 17/6/2026 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices do not properly validate incoming Profinet packets. An unauthenticated remote attacker can exploit this flaw by sending a specially crafted malicious packet, which leads to a crash of the dcpd… | |
| Modificada | Media (5.3) | 0.46% | — | Siemens Scalance Lpe9403 Firmware | 13/5/2025 | 17/6/2026 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices do not properly validate incoming Profinet packets. An unauthenticated remote attacker can exploit this flaw by sending a specially crafted malicious packet, which leads to a crash of the dcpd… | |
| Modificada | Alta (8.5) | 0.14% | — | Siemens Scalance Lpe9403 Firmware | 13/5/2025 | 17/6/2026 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices do not properly assign permissions to critical ressources. This could allow a non-privileged local attacker to interact with the backupmanager service. | |
| Modificada | Media (6.7) | 0.17% | — | Siemens Scalance Lpe9403 Firmware | 13/5/2025 | 17/6/2026 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices are vulnerable to path traversal attacks. This could allow a privileged local attacker to restore backups that are outside the backup folder. | |
| Modificada | Media (6.8) | 0.14% | — | Siemens Scalance Lpe9403 Firmware | 13/5/2025 | 17/6/2026 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices do not properly assign permissions to critical ressources. This could allow a non-privileged local attacker to access sensitive information stored on the device. | |
| Analizada | Baja (2.1) | 0.34% | — | Siemens Scalance Lpe9403 Firmware | 11/3/2025 | 17/6/2026 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0). Affected devices do not properly neutralize special characters when interpreting user controlled log paths. This could allow an authenticated highly-privileged remote attacker to execute a limited set of binaries that… | |
| Analizada | Media (5.1) | 0.41% | — | Siemens Scalance Lpe9403 Firmware | 11/3/2025 | 17/6/2026 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0). Affected devices do not properly limit user controlled paths to which logs are written and from where they are read. This could allow an authenticated highly-privileged remote attacker to read and write arbitrary files… | |
| Analizada | Alta (8.7) | 0.44% | — | Siemens Scalance Lpe9403 Firmware | 11/3/2025 | 17/6/2026 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0). Affected devices do not properly limit the elevation of privileges required to perform certain valid functionality. This could allow an authenticated lowly-privileged remote attacker to escalate their privileges. | |
| Analizada | Alta (8.6) | 0.66% | — | Siemens Scalance Lpe9403 Firmware | 11/3/2025 | 17/6/2026 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0). Affected devices do not properly limit the scope of files accessible through and the privileges of the SFTP functionality. This could allow an authenticated highly-privileged remote attacker to read and write arbitrary… | |
| Analizada | Alta (8.6) | 0.73% | — | Siemens Scalance Lpe9403 Firmware | 11/3/2025 | 17/6/2026 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0). Affected devices do not properly sanitize user input when creating new SNMP users. This could allow an authenticated highly-privileged remote attacker to execute arbitrary code on the device. | |
| Analizada | Alta (8.6) | 0.73% | — | Siemens Scalance Lpe9403 Firmware | 11/3/2025 | 17/6/2026 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0). Affected devices do not properly sanitize user input when creating new users. This could allow an authenticated highly-privileged remote attacker to execute arbitrary code on the device. | |
| Analizada | Alta (8.6) | 0.73% | — | Siemens Scalance Lpe9403 Firmware | 11/3/2025 | 17/6/2026 | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0). Affected devices do not properly sanitize user input when creating new VXLAN configurations. This could allow an authenticated highly-privileged remote attacker to execute arbitrary code on the device. | |
| Modificada | Baja (2.7) | 0.56% | — | Siemens Scalance Lpe9403 Firmware | 9/5/2023 | 17/6/2026 | A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). A heap-based buffer overflow vulnerability was found in the `edgebox_web_app` binary. The binary will crash if supplied with a backup password longer than 255 characters. This could allow an authenticated privileged attacker to cause a… | |
| Modificada | Baja (3.3) | 0.17% | — | Siemens Scalance Lpe9403 Firmware | 9/5/2023 | 17/6/2026 | A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). A path traversal vulnerability was found in the `deviceinfo` binary via the `mac` parameter. This could allow an authenticated attacker with access to the SSH interface on the affected device to read the contents of any file named `address`. | |
| Modificada | Baja (3.3) | 0.17% | — | Siemens Scalance Lpe9403 Firmware | 9/5/2023 | 17/6/2026 | A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). The `i2c` mutex file is created with the permissions bits of `-rw-rw-rw-`. This file is used as a mutex for multiple applications interacting with i2c. This could allow an authenticated attacker with access to the SSH interface on the… | |
| Modificada | Crítica (9.9) | 1.3% | — | Siemens Scalance Lpe9403 Firmware | 9/5/2023 | 17/6/2026 | A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). The web based management of affected device does not properly validate user input, making it susceptible to command injection. This could allow an authenticated remote attacker to access the underlying operating system as the root user. | |
| Analizada | Alta (7.8) | 93% | ⚠ Explotación activa | Linux KernelFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux EUS+25 | 10/3/2022 | 17/6/2026 | A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read… | |
| Analizada | Alta (7.8) | 94% | ⚠ Explotación activa | Polkit Project PolkitRedhat Enterprise Linux Server Update Services FOR SAP SolutionsRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+26 | 28/1/2022 | 15/8/2026 | A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends… |