Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2023-1834

Publication date:
11/05/2023
<br /> Rockwell Automation was made aware that Kinetix 5500 drives, manufactured between May 2022 and January 2023, and are running v7.13 may have the telnet and FTP ports open by default.  This could potentially allow attackers unauthorized access to the device through the open ports.
Severity CVSS v4.0: Pending analysis
Last modification:
22/05/2023

CVE-2023-2444

Publication date:
11/05/2023
<br /> A cross site request forgery vulnerability exists in Rockwell Automation&amp;#39;s FactoryTalk Vantagepoint. This vulnerability can be exploited in two ways. If an attacker sends a malicious link to a computer that is on the same domain as the FactoryTalk Vantagepoint server and a user clicks the link, the attacker could impersonate the legitimate user and send requests to the affected product.  Additionally, if an attacker sends an untrusted link to a computer that is not on the same domain as the server and a user opens the FactoryTalk Vantagepoint website, enters credentials for the FactoryTalk Vantagepoint server, and clicks on the malicious link a cross site request forgery attack would be successful as well.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
20/05/2023

CVE-2023-2443

Publication date:
11/05/2023
<br /> Rockwell Automation ThinManager product allows the use of medium strength ciphers.  If the client requests an insecure cipher, a malicious actor could potentially decrypt traffic sent between the client and server API.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
20/05/2023

CVE-2023-29023

Publication date:
11/05/2023
<br /> A cross site scripting vulnerability was discovered in Rockwell Automation&amp;#39;s ArmorStart ST product that could potentially allow a malicious user to view and modify sensitive data or make the web page unavailable. User interaction, such as a phishing attack, is required for successful exploitation of this vulnerability.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
20/12/2023

CVE-2023-29025

Publication date:
11/05/2023
<br /> A cross site scripting vulnerability was discovered in Rockwell Automation&amp;#39;s ArmorStart ST product <br /> <br /> that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the availability of the web page.<br /> <br /> <br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
20/12/2023

CVE-2023-29026

Publication date:
11/05/2023
<br /> A cross site scripting vulnerability was discovered in Rockwell Automation&amp;#39;s ArmorStart ST product <br /> <br /> that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the availability of the web page.<br /> <br /> <br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
24/01/2025

CVE-2023-29028

Publication date:
11/05/2023
<br /> A cross site scripting vulnerability was discovered in Rockwell Automation&amp;#39;s ArmorStart ST product <br /> <br /> that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the availability of the web page.<br /> <br /> <br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
24/01/2025

CVE-2023-29027

Publication date:
11/05/2023
<br /> A cross site scripting vulnerability was discovered in Rockwell Automation&amp;#39;s ArmorStart ST product <br /> <br /> that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the availability of the web page.<br /> <br /> <br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
24/01/2025

CVE-2023-29029

Publication date:
11/05/2023
<br /> A cross site scripting vulnerability was discovered in Rockwell Automation&amp;#39;s ArmorStart ST product <br /> <br /> that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the availability of the web page.<br /> <br /> <br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
24/01/2025

CVE-2023-29030

Publication date:
11/05/2023
<br /> A cross site scripting vulnerability was discovered in Rockwell Automation&amp;#39;s ArmorStart ST product that could potentially allow a malicious user to view and modify sensitive data or make the web page unavailable. User interaction, such as a phishing attack, is required for successful exploitation of this vulnerability.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
20/12/2023

CVE-2023-29031

Publication date:
11/05/2023
<br /> A cross site scripting vulnerability was discovered in Rockwell Automation&amp;#39;s ArmorStart ST product that could potentially allow a malicious user to view and modify sensitive data or make the web page unavailable. User interaction, such as a phishing attack, is required for successful exploitation of this vulnerability.<br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
20/12/2023

CVE-2023-29022

Publication date:
11/05/2023
<br /> A cross site scripting vulnerability was discovered in Rockwell Automation&amp;#39;s ArmorStart ST product <br /> <br /> that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the availability of the web page.<br /> <br /> <br /> <br />
Severity CVSS v4.0: Pending analysis
Last modification:
24/01/2025