<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T21:39:45.603653+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-182139</id>
    <title>EUVD-2026-182139</title>
    <updated>2026-10-02T21:39:45.689999+00:00</updated>
    <content>EUVD-2026-182139</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-182139"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2018-10612</id>
    <title>fkie_cve-2018-10612</title>
    <updated>2026-10-02T21:39:45.690046+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In 3S-Smart Software Solutions GmbH CODESYS Control V3 products prior to version 3.5.14.0, user access management and communication encryption is not enabled by default, which could allow an attacker access to the device and sensitive information, including user credentials.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2018-10612"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fsa-202202</id>
    <title>FSA-202202 — Festo: Controller CECC-S,LK,D family &lt;= 2.3.8.1 - multiple vulnerabilities in CODESYS V3 runtime system</title>
    <updated>2026-10-02T21:39:45.690083+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Festo controller CECC product family is affected by multiple vulnerabilities in the CODESYS V3 runtime.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fsa-202202"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hvp9-xhr6-2xm4</id>
    <title>GHSA-hvp9-xhr6-2xm4</title>
    <updated>2026-10-02T21:39:45.690126+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In 3S-Smart Software Solutions GmbH CODESYS Control V3 products prior to version 3.5.14.0, user access management and communication encryption is not enabled by default, which could allow an attacker access to the device and sensitive information, including user credentials.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hvp9-xhr6-2xm4"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2018-10612</id>
    <title>gsd-2018-10612</title>
    <updated>2026-10-02T21:39:45.690144+00:00</updated>
    <content>gsd-2018-10612</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2018-10612"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-18-352-03</id>
    <title>ICSA-18-352-03 — 3S-Smart Software Solutions GmbH CODESYS Control V3 Products</title>
    <updated>2026-10-02T21:39:45.690156+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>User access management and communication encryption is not enabled by default, which could allow an attacker access to the device and sensitive information, including user credentials. CVE-2018-10612 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-18-352-03"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2021-033</id>
    <title>VDE-2021-033 — TRUMPF Laser GmbH: multiple products prone to codesys runtime vulnerabilities</title>
    <updated>2026-10-02T21:39:45.690175+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>The TruControl laser control software (versions 1.04 to 3.0.0) uses CODESYS runtime versions affected by multiple CVEs:</p>
<p>**CVE list:**</p>
<p>- CVE-2021-29242
- CVE-2021-29241
- CVE-2019-5105
- CVE-2020-7052
- CVE-2019-9012
- CVE-2019-9010
- CVE-2019-9009
- CVE-2018-10612</p>
<p>In addition to the CVEs listed above, the affected products are also vulnerable to the following issues without a CVE ID:</p>
<p>---</p>
<p>### **CODESYS Advisory 2018-07**</p>
<p>A crafted communication request may cause an access violation in the affected CODESYS products and may result in a denial-of-service condition.</p>
<p>- **CVSS v3.0 base score:** 6.5  
- **CVSS v3.0 vector:** `CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H`</p>
<p>🔗 [Link to advisory](https://customers.codesys.com/index.php?eID=dumpFile&amp;t=f&amp;f=12928&amp;token=6d1dcea05a15aeef7ad48eadc64c8eca5d4f07b2&amp;download=)</p>
<p>---</p>
<p>### **CODESYS Advisory 2018-04**</p>
<p>The CODESYS runtime system allows access to files outside the restricted working directory of the controller by online services.</p>
<p>- **CVSS v3.0 base score:** 9.9  
- **CVSS v3.0 vector:** `CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H`</p>
<p>🔗 [Link to advisory](https://customers.codesys.com/index.php?eID=dumpFile&amp;t=f&amp;f=12925&amp;token=50e7240fa947ea215311e3db441f82152f1109b6&amp;download=)</p>
<p>---</p>
<p>### **CODESYS Advisory 2017-03**</p>
<p>A crafted request may cause an access violation in the affected CODESYS products and may result in a denial-of-service condition.</p>
<p>- **CVSS v3.0 base score:** 7.5  
- **CVSS v3.0 vector:** `CVSS:3.0/AV:N/AC:L/PR:N/…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2021-033"/>
  </entry>
</feed>
