<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T04:39:54.761749+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2021-01783</id>
    <title>bdu:2021-01783</title>
    <updated>2026-10-04T04:39:54.865928+00:00</updated>
    <content>bdu:2021-01783</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2021-01783"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-322653</id>
    <title>EUVD-2026-322653</title>
    <updated>2026-10-04T04:39:54.865964+00:00</updated>
    <content>EUVD-2026-322653</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-322653"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-28209</id>
    <title>fkie_cve-2020-28209</title>
    <updated>2026-10-04T04:39:54.865979+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A CWE-428 Windows Unquoted Search Path vulnerability exists in EcoStruxure Building Operation Enterprise Server installer V1.9 - V3.1 and Enterprise Central installer V2.0 - V3.1 that could cause any local Windows user who has write permission on at least one of the subfolders of the Connect Agent service binary path, being able to gain the privilege of the user who started the service. By default, the Enterprise Server and Enterprise Central is always installed at a location requiring Administrator privileges so the vulnerability is only valid if the application has been installed on a non-secure location.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-28209"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-v6vj-vcw7-qf3c</id>
    <title>GHSA-v6vj-vcw7-qf3c</title>
    <updated>2026-10-04T04:39:54.866012+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A CWE-428 Windows Unquoted Search Path vulnerability exists in EcoStruxure Building Operation Enterprise Server installer V1.9 - V3.1 and Enterprise Central installer V2.0 - V3.1 that could cause any local Windows user who has write permission on at least one of the subfolders of the Connect Agent service binary path, being able to gain the privilege of the user who started the service. By default, the Enterprise Server and Enterprise Central is always installed at a location requiring Administrator privileges so the vulnerability is only valid if the application has been installed on a non-secure location.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-v6vj-vcw7-qf3c"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-28209</id>
    <title>gsd-2020-28209</title>
    <updated>2026-10-04T04:39:54.866031+00:00</updated>
    <content>gsd-2020-28209</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-28209"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-21-063-02</id>
    <title>ICSA-21-063-02 — ICSA-21-063-02_Schneider Electric EcoStruxure Building Operation (EBO)</title>
    <updated>2026-10-04T04:39:54.866043+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An unrestricted upload of a file with dangerous type vulnerability could allow an authenticated remote user to upload arbitrary files due to incorrect verification of user supplied files and achieve remote code execution.CVE-2020-7569 has been assigned to this vulnerability. A CVSS v3 base score of 4.6 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L). An improper neutralization of an input during webpage generation vulnerability could allow an authenticated remote user to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data and achieve a stored cross-site scripting attack against other WebReport users.CVE-2020-7570 has been assigned to this vulnerability. A CVSS v3 base score of 6.4 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L). Multiple improper neutralizations of an input during webpage generation vulnerabilities could allow a remote attacker to inject arbitrary web script or HTML due to incorrect sanitization of user supplied data and achieve a reflected cross-site scripting attack against other WebReport users.CVE-2020-7571 has been assigned to this vulnerability. A CVSS v3 base score of 6.1 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). An improper restriction of XML external entity reference vulnerability could allow an authenticated remote user to inject arbitrary XML code and obtain disclosure of confidential data, cause…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-21-063-02"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2020-315-04</id>
    <title>SEVD-2020-315-04 — EcoStruxure Building Operation (EBO)</title>
    <updated>2026-10-04T04:39:54.866082+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Schneider Electric is aware of multiple vulnerabilities in its EcoStruxure Building Operation
(EBO) product offerings. More information on the product line can be found at the following link:
https://www.se.com/ww/en/product-range-presentation/62111-ecostruxure%E2%84%A2-
building-operation/?parent-subcategory-id=1210&amp;filter=business-2-building-automation-andcontrol#tabs-top
Failure to apply the mitigations/remediations provided below may risk various types of attacks 
and cause various types of impact (see information below for each vulnerability).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2020-315-04"/>
  </entry>
</feed>
