Vulnerabilities

Summary — last 7 days

New vulnerabilities3,335▲ 417 vs. last week
Critical / high1,494▲ 172 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)579▲ 105 vs. last week
–

3 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedHigh (8.8)0.23%—Siemens Simatic PCS 7 FirmwareSiemens Simatic PDM FirmwareSiemens Simatic Step 7 FirmwareSiemens Sinamics Starter Firmware7/13/20216/17/2026
A vulnerability has been identified in SIMATIC PCS 7 V8.2 and earlier (All versions), SIMATIC PCS 7 V9.X (All versions < V9.1 SP2), SIMATIC PDM (All versions < V9.2 SP2), SIMATIC STEP 7 V5.X (All versions < V5.7), SINAMICS STARTER (containing STEP 7 OEM version) (All versions < V5.4 SP2 HF1). A directory containing…
ModifiedHigh (7.8)0.56%—Siemens Simatic PCS FirmwareSiemens Simatic PDM FirmwareSiemens Simatic Step 7 FirmwareSiemens Sinamics Starter Firmware7/13/20216/17/2026
A vulnerability has been identified in SIMATIC PCS 7 V8.2 and earlier (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3), SIMATIC PDM (All versions < V9.2), SIMATIC STEP 7 V5.X (All versions < V5.6 SP2 HF3), SINAMICS STARTER (containing STEP 7 OEM version) (All versions < V5.4 HF2). The affected software…
ModifiedMedium (5.9)64%—OpensslDebian LinuxFreebsdNetapp Active IQ Unified Manager+1023/25/20216/17/2026
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer…