<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T09:52:47.804125+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-00986</id>
    <title>bdu:2022-00986</title>
    <updated>2026-10-02T09:52:47.922782+00:00</updated>
    <content>bdu:2022-00986</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-00986"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2020-avi-550</id>
    <title>certfr-2020-avi-550 — De multiples vulnérabilités ont été découvertes dans les produits
Siemens. Certaines d'entre elles permettent à un atta…</title>
    <updated>2026-10-02T09:52:47.922820+00:00</updated>
    <content>certfr-2020-avi-550</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2020-avi-550"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2020-51242</id>
    <title>cnvd-2020-51242</title>
    <updated>2026-10-02T09:52:47.922839+00:00</updated>
    <content>cnvd-2020-51242</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2020-51242"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-42505</id>
    <title>EUVD-2026-42505</title>
    <updated>2026-10-02T09:52:47.922851+00:00</updated>
    <content>EUVD-2026-42505</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-42505"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-14517</id>
    <title>fkie_cve-2020-14517</title>
    <updated>2026-10-02T09:52:47.922862+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Protocol encryption can be easily broken for CodeMeter (All versions prior to 6.90 are affected, including Version 6.90 or newer only if CodeMeter Runtime is running as server) and the server accepts external connections, which may allow an attacker to remotely communicate with the CodeMeter API.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-14517"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fsa-202601</id>
    <title>FSA-202601 — Several CODESYS vulnerabilities in Festo Automation Suite</title>
    <updated>2026-10-02T09:52:47.922900+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Starting with Festo Automation Suite (FAS) version 2.8.0.138, the suite is delivered only with a connector to Codesys, rather than including Codesys directly. Prior to this version, Codesys was bundled within the FAS installation. From version 2.8.0.138 onwards, customers are required to download and install Codesys independently.</p>
<p>This change impacts the handling of security vulnerabilities (CVEs) related to Codesys. Any Codesys-related security issues must now be addressed by the customer through their separate Codesys installation. The FAS itself includes only the connector component, which is maintained and updated within the suite.</p>
<p>Please ensure that Codesys is kept up to date independently to mitigate any potential security risks associated with the Codesys software.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fsa-202601"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hqvx-g6jw-22pw</id>
    <title>GHSA-hqvx-g6jw-22pw</title>
    <updated>2026-10-02T09:52:47.923031+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Protocol encryption can be easily broken for CodeMeter (All versions prior to 6.90 are affected, including Version 6.90 or newer only if CodeMeter Runtime is running as server) and the server accepts external connections, which may allow an attacker to remotely communicate with the CodeMeter API.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hqvx-g6jw-22pw"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-14517</id>
    <title>gsd-2020-14517</title>
    <updated>2026-10-02T09:52:47.923047+00:00</updated>
    <content>gsd-2020-14517</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-14517"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-20-203-01</id>
    <title>ICSA-20-203-01 — Wibu-Systems CodeMeter (Update F)</title>
    <updated>2026-10-02T09:52:47.923058+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multiple memory corruption vulnerabilities exist where the packet parser mechanism does not verify length fields. An attacker could send specially crafted packets to exploit these vulnerabilities.CVE-2020-14509 has been assigned to this vulnerability. A CVSS v3 base score of 10.0 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). Protocol encryption can be easily broken and the server accepts external connections, which may allow an attacker to remotely communicate with the CodeMeter API.CVE-2020-14517 has been assigned to this vulnerability. A CVSS v3 base score of 9.4 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H). This vulnerability allows an attacker to use the internal WebSockets API via a specifically crafted Java Script payload, which may allow alteration or creation of license files when combined with CVE-2020-14515.CVE-2020-14519 has been assigned to this vulnerability. A CVSS v3 base score of 8.1 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H). CodeMeter and the software using it may crash while processing a specifically crafted license file due to unverified length fields.CVE-2020-14513 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). There is an issue in the license-file signature checking mechanism, which allows attackers to build arbitrary license f…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-20-203-01"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2020-287-02</id>
    <title>SEVD-2020-287-02 — Wibu-Systems CodeMeter Vulnerabilities</title>
    <updated>2026-10-02T09:52:47.923092+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Schneider Electric is aware of multiple vulnerabilities disclosed by Wibu-Systems in the 
CodeMeter licensing manager product which is used by some Schneider Electric and Eurotherm 
offers.
Failure to apply the remediations provided below may risk various types of attack on 
CodeMeter, which could allow an attacker to alter and forge a license file, cause a denial-ofservice condition, potentially attain remote code execution, read heap data, and prevent normal 
operation of third-party software dependent on the CodeMeter. 
December 2020 update: The CodeMeter V7.10a fix qualification is confirmed for EcoStruxure
Machine SCADA Expert.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2020-287-02"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2020-031</id>
    <title>VDE-2020-031 — Endress+Hauser: Multiple products prone to WIBU CodeMeter vulnerabilities</title>
    <updated>2026-10-02T09:52:47.923117+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>For further Information please refer to WIBU Advisories directly at https://wibu.com/support/security-advisories.html and the aforementioned CVE-IDs.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2020-031"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2020-032</id>
    <title>VDE-2020-032 — WAGO: Vulnerable WIBU-SYSTEMS Codemeter installed through e!COCKPIT</title>
    <updated>2026-10-02T09:52:47.923136+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multiple vulnerabilties were reported in WIBU-SYSTEMS Codemeter. WIBU-SYSTEMS Codemeter is installed by default during e!COCKPIT installation. All currently existing e!COCKPIT installation bundles contain vulnerable versions of WIBU-SYSTEMS Codemeter.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2020-032"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2020-033</id>
    <title>VDE-2020-033 — Pilz: Multiple products prone to WIBU-SYSTEMS CodeMeter vulnerabilities</title>
    <updated>2026-10-02T09:52:47.923155+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A number of Pilz software tools use the Software CodeMeter Runtime application from WIBU-SYSTEMS AG to manage licences. This application contains a number of vulnerabilities, which enable an attacker to change and falsify a licence file, prevent normal operation of Code- Meter (Denial-of-Service) and potentially execute arbitrary code.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2020-033"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2020-034</id>
    <title>VDE-2020-034 — Pepperl+Fuchs: VMT MSS and VMT IS - Several vulnerabilities in products utilizing WIBU-SYSTEMS CodeMeter components</title>
    <updated>2026-10-02T09:52:47.923174+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Several vulnerabilities have been discovered in the utilized component WIBU-SYSTEMS CodeMeter Runtime.
For detailed information please refer to WIBU-SYSTEMS original Advisories at https://wibu.com/support/security-advisories.html</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2020-034"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2020-039</id>
    <title>VDE-2020-039 — TRUMPF: Multiple products prone to WIBU CodeMeter vulnerabilities</title>
    <updated>2026-10-02T09:52:47.923193+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A number of TRUMPF CAD/CAM software tools use the CodeMeter Runtime application from WIBU-SYSTEMS AG to manage licences. This application contains a number of vulnerabilities, which enable an attacker to prevent normal operation of CodeMeter, resulting in a Denial-of-Service and potentially execute arbitrary code.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2020-039"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2020-041</id>
    <title>VDE-2020-041 — Weidmueller: u-create studio &lt; 1.20.2 affected by WIBU-SYSTEMS CodeMeter vulnerabilities</title>
    <updated>2026-10-02T09:52:47.923212+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>WIBU-SYSTEMS report multiple vulnerabilities in their CodeMeter Runtime software. As part of the Weidmüller u-create studio installation the WIBU-SYSTEMS CodeMeter is installed by default. As the u-create studio installation bundle contains vulnerable versions of WIBU-SYSTEMS CodeMeter, the u-create studio is affected by a subset of these vulnerabilities. For details refer to section "Impact".</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2020-041"/>
  </entry>
</feed>
