<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T17:36:08.443106+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2021-03140</id>
    <title>bdu:2021-03140</title>
    <updated>2026-10-02T17:36:08.623805+00:00</updated>
    <content>bdu:2021-03140</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2021-03140"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2016-avi-320</id>
    <title>certfr-2016-avi-320 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;OpenSSL&lt;/span&gt;. Certaines d'entre elles permett…</title>
    <updated>2026-10-02T17:36:08.623886+00:00</updated>
    <content>certfr-2016-avi-320</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2016-avi-320"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2016-06765</id>
    <title>cnvd-2016-06765</title>
    <updated>2026-10-02T17:36:08.623909+00:00</updated>
    <content>cnvd-2016-06765</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2016-06765"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-323019</id>
    <title>EUVD-2026-323019</title>
    <updated>2026-10-02T17:36:08.623923+00:00</updated>
    <content>EUVD-2026-323019</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-323019"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2016-2183</id>
    <title>fkie_cve-2016-2183</title>
    <updated>2026-10-02T17:36:08.623934+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a "Sweet32" attack.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2016-2183"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-w2rw-pv8p-h9c8</id>
    <title>GHSA-w2rw-pv8p-h9c8</title>
    <updated>2026-10-02T17:36:08.623966+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a "Sweet32" attack.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-w2rw-pv8p-h9c8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2016-2183</id>
    <title>gsd-2016-2183</title>
    <updated>2026-10-02T17:36:08.623983+00:00</updated>
    <content>gsd-2016-2183</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2016-2183"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-21-075-02</id>
    <title>ICSA-21-075-02 — GE UR Family (Update A)</title>
    <updated>2026-10-02T17:36:08.623994+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Prior to UR firmware Version 8.1x, UR supported various encryption and MAC algorithms for SSH communication, some of which are weak. The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a "Sweet32" attack. Prior to UR firmware Version 8.1x, UR supported various encryption and MAC algorithms for SSH communication, some of which are weak. The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large number of sessions that use the same plaintext. Prior to firmware Version 7.4x, UR supported only SSHv2. Starting from firmware Version 7.4x, UR added support to SSHv1. SSHv1 has known vulnerabilities (SSH protocol session key retrieval and insertion attack). SSH 1.2.25, 1.2.23, and other versions, when used in in CBC (Cipher Block Chaining) or CFB (Cipher Feedback 64 bits) modes, allows remote attackers to insert arbitrary data into an existing stream between an SSH client and server by using a known plaintext attack and computing a valid CRC-32 checksum for the packet, aka the "SSH insertion attack." GE U…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-21-075-02"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/jvndb-2023-000029</id>
    <title>jvndb-2023-000029</title>
    <updated>2026-10-02T17:36:08.624052+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>SkyBridge MB-A100/A110/A200/A130 SkySpider MB-R210 provided by Seiko Solutions Inc. contain multiple vulnerabilities listed below.
&lt;ul&gt;
&lt;li&gt;Exposure of sensitive information to an unauthorized actor (CWE-200) - CVE-2016-2183
&lt;li&gt;Command injection (CWE-77) - CVE-2022-36556
&lt;li&gt;Unrestricted upload of file with dangerous type (CWE-434) - CVE-2022-36557
&lt;li&gt;Use of hard-coded credentials (CWE-798) - CVE-2022-36558
&lt;li&gt;Command injection (CWE-77) - CVE-2022-36559
&lt;li&gt;Use of hard-coded credentials (CWE-798) - CVE-2022-36560
&lt;li&gt;Improper privilege management (CWE-269) - CVE-2023-22361
&lt;li&gt;Missing authentication for critical function (CWE-306) - CVE-2023-22441
&lt;li&gt;Improper access control (CWE-284) - CVE-2023-23578
&lt;li&gt;Improper following of a certificate's chain of trust (CWE-296) - CVE-2023-23901
&lt;li&gt;Missing authentication for critical function (CWE-306) - CVE-2023-23906
&lt;li&gt;Cleartext storage of sensitive information (CWE-312) - CVE-2023-24586
&lt;li&gt;Cleartext transmission of sensitive information (CWE-319) - CVE-2023-25070
&lt;li&gt;Use of weak credentials (CWE-1391) - CVE-2023-25072
&lt;li&gt;Use of weak credentials (CWE-1391) - CVE-2023-25184
&lt;/ul&gt;
The developer states that attacks exploiting CVE-2022-36556 have been observed.


CVE-2023-22441
MASAHIRO IIDA of LAC Co., Ltd. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

CVE-2016-2183, CVE-2022-36556, CVE-2022-36557, CVE-2022-36558, CVE-20…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/jvndb-2023-000029"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10247-1</id>
    <title>openSUSE-SU-2024:10247-1 — nodejs4-4.7.0-1.1 on GA media</title>
    <updated>2026-10-02T17:36:08.624083+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>nodejs4-4.7.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:10247-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2019:2581</id>
    <title>RHBA-2019:2581 — Red Hat Bug Fix Advisory: OpenShift Container Platform 3.11 images update</title>
    <updated>2026-10-02T17:36:08.624106+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>SSL/TLS: Birthday attack against 64-bit block ciphers (SWEET32)</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2019:2581"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2016:2387-1</id>
    <title>SUSE-SU-2016:2387-1 — Security update for openssl</title>
    <updated>2026-10-02T17:36:08.624124+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for openssl</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2016:2387-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2016-2183</id>
    <title>UBUNTU-CVE-2016-2183</title>
    <updated>2026-10-02T17:36:08.624144+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: nss, Ubuntu:14.04:LTS: openjdk-6, Ubuntu:14.04:LTS: openjdk-7, Ubuntu:14.04:LTS: openssl, Ubuntu:16.04:LTS: nss, Ubuntu:16.04:LTS: openjdk-8, Ubuntu:16.04:LTS: openssl</p>
<p>The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a "Sweet32" attack.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2016-2183"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2025-023</id>
    <title>VDE-2025-023 — Weidmueller: OpenSSL vulnerability in industrial ethernet switches</title>
    <updated>2026-10-02T17:36:08.624177+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Multiple Weidmueller products are affected by an OpenSSL vulnerability.</p>
<p>Weidmüller has released new firmwares of the affected products to fix the vulnerability.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2025-023"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2025-078</id>
    <title>VDE-2025-078 — TRUMPF: Remote support uses an outdated encryption algorithm</title>
    <updated>2026-10-02T17:36:08.624197+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The TRUMPF remote support infrastructure selects an outdated encryption algorithm when setting up communication channels for machines. This cannot be prevented for old machines. For most machines it is possible to change the encryption settings.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2025-078"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2026-013</id>
    <title>VDE-2026-013 — Helmholz: Use of a Broken or Risky Cryptographic Algorithm</title>
    <updated>2026-10-02T17:36:08.624214+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Vulnerabilities in PROFINET-Switch devices with firmware &lt;= V1.12.010 that allow an attacker to gain control over the device.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2026-013"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1955</id>
    <title>WID-SEC-W-2022-1955 — OpenSSL: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
    <updated>2026-10-02T17:36:08.624230+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in OpenSSL ausnutzen, um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1955"/>
  </entry>
</feed>
