<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T05:40:23.009613+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/2nga002579</id>
    <title>2NGA002579 — ABB Arctic communication solution ARM600 Vulnerabilities</title>
    <updated>2026-10-03T05:40:23.493651+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ABB is aware of public reports of a vulnerabilities in product versions listed as affected in this advisory. An attacker who successfully exploited these vulnerabilities could cause the product to stop, make the product inacces-sible, take remote control of the product or insert and run arbitrary code.
As part of ABB product lifecycle policy, once a product transitions to end-of-life, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document, such as using a private APN cellular network between Arctic wireless gateways and ARM600 for establishing VPN tunnels, to mitigate security risks and avoid potential vulnerabilities.
As part of ABB product lifecycle policy, once a product transitions to Limited state, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document to mitigate security risks.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/2nga002579"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2015-09702</id>
    <title>bdu:2015-09702</title>
    <updated>2026-10-03T05:40:23.493764+00:00</updated>
    <content>bdu:2015-09702</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2015-09702"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certa-2013-avi-099</id>
    <title>certa-2013-avi-099 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;OpenSSL&lt;/span&gt;. Elles permettent à un attaquant…</title>
    <updated>2026-10-03T05:40:23.493783+00:00</updated>
    <content>certa-2013-avi-099</content>
    <link href="https://cve.radiocsirt.org/vuln/certa-2013-avi-099"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-104541</id>
    <title>EUVD-2026-104541</title>
    <updated>2026-10-03T05:40:23.493800+00:00</updated>
    <content>EUVD-2026-104541</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-104541"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2013-0169</id>
    <title>fkie_cve-2013-0169</title>
    <updated>2026-10-03T05:40:23.493812+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as used in OpenSSL, OpenJDK, PolarSSL, and other products, do not properly consider timing side-channel attacks on a MAC check requirement during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, aka the "Lucky Thirteen" issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2013-0169"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-pg96-42c4-p633</id>
    <title>GHSA-pg96-42c4-p633</title>
    <updated>2026-10-03T05:40:23.493837+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as used in OpenSSL, OpenJDK, PolarSSL, and other products, do not properly consider timing side-channel attacks on a MAC check requirement during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, aka the "Lucky Thirteen" issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-pg96-42c4-p633"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2013-0169</id>
    <title>gsd-2013-0169</title>
    <updated>2026-10-03T05:40:23.493854+00:00</updated>
    <content>gsd-2013-0169</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2013-0169"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-19-192-04</id>
    <title>ICSA-19-192-04 — ICSA-19-192-04 Siemens SIMATIC RF6XXR</title>
    <updated>2026-10-03T05:40:23.493864+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The SSL protocol encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses e.g. the HTML5 WebSocket API, the Java URLConnection API, or the Silverlight WebClient API, aka a "BEAST" attack. The security vulnerability could be exploited by an attacker with network access to the affected systems. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise confidentiality of the device. TLS, when used with a 64-bit block cipher, could allow remote attackers to obtain cleartext data by leveraging a birthday attack against a long-duration encrypted session, aka a "Sweet32" attack. The security vulnerability could be exploited by an attacker with network access to the affected systems. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise confidentiality of the device. TLS and DTLS versions 1.1 and 1.2, as used in the affected product, do not properly consider timing side-channel attacks on a MAC check requirement during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, aka the "Lucky Thirteen"…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-19-192-04"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10271-1</id>
    <title>openSUSE-SU-2024:10271-1 — libopenssl-devel-1.0.2j-2.2 on GA media</title>
    <updated>2026-10-03T05:40:23.493899+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libopenssl-devel-1.0.2j-2.2 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:10271-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2013:0273</id>
    <title>RHSA-2013:0273 — Red Hat Security Advisory: java-1.6.0-openjdk security update</title>
    <updated>2026-10-03T05:40:23.493976+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>SSL/TLS: CBC padding timing attack (lucky-13) OpenJDK: MBeanServer insufficient privilege restrictions (JMX, 8006446)</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2013:0273"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2015:0182-2</id>
    <title>SUSE-SU-2015:0182-2 — Security update for compat-openssl097g</title>
    <updated>2026-10-03T05:40:23.493995+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for compat-openssl097g</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2015:0182-2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2013-0169</id>
    <title>UBUNTU-CVE-2013-0169</title>
    <updated>2026-10-03T05:40:23.494022+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: openssl098</p>
<p>The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as used in OpenSSL, OpenJDK, PolarSSL, and other products, do not properly consider timing side-channel attacks on a MAC check requirement during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, aka the "Lucky Thirteen" issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2013-0169"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2021-027</id>
    <title>VDE-2021-027 — Pepperl+Fuchs: WirelessHART-Gateway - Vulnerability may allow remote attackers to cause a Denial Of Service</title>
    <updated>2026-10-03T05:40:23.494045+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Critical vulnerabilities have been discovered in the product and in the utilized components jQuery by jQuery Team and TLS Version 1.0/1.1.</p>
<p>The impact of the vulnerabilities on the affected device may result in</p>
<p>- denial of service
- remote code execution
- code exposure</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2021-027"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1435</id>
    <title>WID-SEC-W-2023-1435 — Hitachi Energy Relion: Mehrere Schwachstellen</title>
    <updated>2026-10-03T05:40:23.494072+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Hitachi Energy Relion ausnutzen, um einen Denial of Service Angriff durchzuführen und Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1435"/>
  </entry>
</feed>
