<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T23:20:58.668165+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2018-01158</id>
    <title>bdu:2018-01158</title>
    <updated>2026-10-02T23:20:58.772960+00:00</updated>
    <content>bdu:2018-01158</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2018-01158"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2018-avi-146</id>
    <title>certfr-2018-avi-146 — De multiples vulnérabilités ont été découvertes dans SCADA Schneider
Electric Modicon. Certaines d'entre elles permette…</title>
    <updated>2026-10-02T23:20:58.773000+00:00</updated>
    <content>certfr-2018-avi-146</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2018-avi-146"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2018-06519</id>
    <title>cnvd-2018-06519</title>
    <updated>2026-10-02T23:20:58.773021+00:00</updated>
    <content>cnvd-2018-06519</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2018-06519"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-63102</id>
    <title>EUVD-2026-63102</title>
    <updated>2026-10-02T23:20:58.773034+00:00</updated>
    <content>EUVD-2026-63102</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-63102"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2018-7242</id>
    <title>fkie_cve-2018-7242</title>
    <updated>2026-10-02T23:20:58.773045+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Vulnerable hash algorithms exists in Schneider Electric's Modicon Premium, Modicon Quantum, Modicon M340, and BMXNOR0200 controllers in all versions of the communication modules. The algorithm used to encrypt the password is vulnerable to hash collision attacks.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2018-7242"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4cgj-crgg-xwgf</id>
    <title>GHSA-4cgj-crgg-xwgf</title>
    <updated>2026-10-02T23:20:58.773074+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Vulnerable hash algorithms exists in Schneider Electric's Modicon Premium, Modicon Quantum, Modicon M340, and BMXNOR0200 controllers in all versions of the communication modules. The algorithm used to encrypt the password is vulnerable to hash collision attacks.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4cgj-crgg-xwgf"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2018-7242</id>
    <title>gsd-2018-7242</title>
    <updated>2026-10-02T23:20:58.773091+00:00</updated>
    <content>gsd-2018-7242</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2018-7242"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-18-086-01</id>
    <title>ICSA-18-086-01 — Schneider Electric Modicon Premium, Modicon Quantum, Modicon M340, and Modicon BMXNOR0200</title>
    <updated>2026-10-02T23:20:58.773102+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The FTP server does not limit the length of a command parameter which may cause a buffer overflow condition. CVE-2018-7240 has been assigned to this vulnerability. A CVSS v3 base score of 4.8 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H). The FTP servers contain a hard-coded account, which could allow unauthorized access. CVE-2018-7241 has been assigned to this vulnerability. A CVSS v3 base score of 5.9 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H). The FTP server does not limit the length of a command parameter, which may cause a buffer overflow condition. CVE-2018-7242 has been assigned to this vulnerability. A CVSS v3 base score of 5.9 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-18-086-01"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2018-081-01</id>
    <title>SEVD-2018-081-01 — Embedded FTP Servers for Modicon PAC Controllers</title>
    <updated>2026-10-02T23:20:58.773126+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Schneider Electric is aware of multiple vulnerabilities in the FTP servers of its Modicon PAC controllers.

Modicon PACs (Programmable Automation Controllers) control and monitor industrial operations in a sustainable, flexible, efficient, and protected way. Our PLCs and PACs supply edge technology, augmenting it with Ethernet connectivity, built-in cybersecurity, and processing power needed to handle Big Data analysis and protect against new vulnerabilities among connected industrial assets, across devices or into the cloud.

Failure to address these vulnerabilities could result in unauthorized access to your PLC and a denial of service or other malicious activity.

March 2023 Update: Remediation for the Modicon M580 CPU is available for download</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2018-081-01"/>
  </entry>
</feed>
