<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T16:54:46.002582+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-03539</id>
    <title>bdu:2023-03539</title>
    <updated>2026-10-03T16:54:46.140317+00:00</updated>
    <content>bdu:2023-03539</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-03539"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2021-avi-443</id>
    <title>certfr-2021-avi-443 — De multiples vulnérabilités ont été découvertes dans les produits
Schneider Electric. Certaines d'entre elles permetten…</title>
    <updated>2026-10-03T16:54:46.140360+00:00</updated>
    <content>certfr-2021-avi-443</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2021-avi-443"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-231254</id>
    <title>EUVD-2026-231254</title>
    <updated>2026-10-03T16:54:46.140381+00:00</updated>
    <content>EUVD-2026-231254</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-231254"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-25178</id>
    <title>fkie_cve-2020-25178</title>
    <updated>2026-10-03T16:54:46.140394+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ISaGRAF Workbench communicates with Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x using TCP/IP. This communication protocol provides various file system operations, as well as the uploading of applications. Data is transferred over this protocol unencrypted, which could allow a remote unauthenticated attacker to upload, read, and delete files.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-25178"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9x5p-r7c6-hf92</id>
    <title>GHSA-9x5p-r7c6-hf92</title>
    <updated>2026-10-03T16:54:46.140425+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ISaGRAF Workbench communicates with Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x using TCP/IP. This communication protocol provides various file system operations, as well as the uploading of applications. Data is transferred over this protocol unencrypted, which could allow a remote unauthenticated attacker to upload, read, and delete files.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9x5p-r7c6-hf92"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-25178</id>
    <title>gsd-2020-25178</title>
    <updated>2026-10-03T16:54:46.140442+00:00</updated>
    <content>gsd-2020-25178</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-25178"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-20-280-01</id>
    <title>ICSA-20-280-01 — Rockwell Automation ISaGRAF5 Runtime (Update A)</title>
    <updated>2026-10-03T16:54:46.140454+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Some commands used by the ISaGRAF eXchange Layer (IXL) protocol perform various file operations in the file system. Since the parameter pointing to the file name is not checked for reserved characters, it is possible for a remote, unauthenticated attacker to traverse an application 's directory, which could lead to remote code execution.CVE-2020-25176 has been assigned to this vulnerability. A CVSS v3 base score of 9.1 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H). ISaGRAF Runtime stores the password in plaintext in a file that is in the same directory as the executable file. ISaGRAF Runtime reads the file and saves the data in a variable without any additional modification. A local, unauthenticated attacker could compromise the user passwords, resulting in information disclosure.CVE-2020-25184 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). ISaGRAF Workbench communicates with ISaGRAF Runtime using TCP/IP. This communication protocol provides various file system operations, as well as the uploading of applications. Data is transferred over this protocol unencrypted, which could allow a remote unauthenticated attacker to upload, read, and delete files.CVE-2020-25178 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H). ISaGRAF Runtim…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-20-280-01"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2021-159-04</id>
    <title>SEVD-2021-159-04 — ISaGRAF Vulnerabilities in IEC 61131-3 Programming and Engineering Tools</title>
    <updated>2026-10-03T16:54:46.140497+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>On June 8, 2021, Rockwell Automation disclosed multiple vulnerabilities in its ISaGRAF Workbench and ISaGRAF Runtime products. Multiple vendors, including Schneider Electric, embed ISaGRAF in their offers.
ISaGRAF Workbench is used to program applications for embedded devices using IEC 61131-3 languages and may be incorporated into larger programming and configuration tools. The ISaGRAF Runtime module executes the process control code created in ISaGRAF Workbench on embedded devices.
If successfully exploited, bad actors could execute a range of actions, including accessing and disclosing sensitive information, privilege escalation, and in some cases remote code execution.
Customers should immediately ensure they have implemented cybersecurity best practices across their operations to protect themselves from possible exploitation of these vulnerabilities. Where appropriate, this includes locating their industrial systems and remotely accessible devices behind firewalls; installing physical controls to prevent unauthorized access; preventing mission-critical systems and devices from being accessed from outside networks; and following the mitigations and general security recommendations below.
For additional information and support, please contact your Schneider Electric sales or service representative or Schneider Electric’s Customer Care Center.
Subscribe to the Schneider Electric security notification service to be informed of critical
updates to this notification, includin…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2021-159-04"/>
  </entry>
</feed>
