<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T07:06:08.542586+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2021-03844</id>
    <title>bdu:2021-03844</title>
    <updated>2026-10-03T07:06:08.547699+00:00</updated>
    <content>bdu:2021-03844</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2021-03844"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2020-avi-166</id>
    <title>certfr-2020-avi-166 — De multiples vulnérabilités ont été découvertes dans Schneider Electric
. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-03T07:06:08.547742+00:00</updated>
    <content>certfr-2020-avi-166</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2020-avi-166"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2020-23198</id>
    <title>cnvd-2020-23198</title>
    <updated>2026-10-03T07:06:08.547762+00:00</updated>
    <content>cnvd-2020-23198</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2020-23198"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-37914</id>
    <title>EUVD-2026-37914</title>
    <updated>2026-10-03T07:06:08.547775+00:00</updated>
    <content>EUVD-2026-37914</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-37914"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-7475</id>
    <title>fkie_cve-2020-7475</title>
    <updated>2026-10-03T07:06:08.547785+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), reflective DLL, vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20), Modicon M580 (all versions prior to V3.10), which, if exploited, could allow attackers to transfer malicious code to the controller.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-7475"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3mwf-xhc6-4rgf</id>
    <title>GHSA-3mwf-xhc6-4rgf</title>
    <updated>2026-10-03T07:06:08.547822+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), reflective DLL, vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20), Modicon M580 (all versions prior to V3.10), which, if exploited, could allow attackers to transfer malicious code to the controller.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3mwf-xhc6-4rgf"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-7475</id>
    <title>gsd-2020-7475</title>
    <updated>2026-10-03T07:06:08.547857+00:00</updated>
    <content>gsd-2020-7475</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-7475"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2020-080-01</id>
    <title>SEVD-2020-080-01 — Modicon Controllers, EcoStruxure™ Control Expert and Unity Pro Programming Software</title>
    <updated>2026-10-03T07:06:08.547875+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Researchers from Airbus Cybersecurity have made Schneider Electric aware of a vulnerability
in two versions of Schneider Electric's Modicon programmable controllers and its EcoStruxure 
Control Expert (formerly Unity Pro) programming software. 
Since alerting us to the vulnerability, Airbus Cybersecurity and Schneider Electric have 
collaborated to validate the research and to assess its true impact. Our mutual findings 
demonstrate that while the discovered vulnerability affects Schneider Electric offers, it equally 
impacts many other vendors and the global industrial automation market in general, especially 
when the baseline assumption of the attack technique Airbus Cybersecurity demonstrated is 
considered. Given certain conditions, and assuming an attacker has access to the network, 
many devices available from several different industrial control vendors are likewise vulnerable.
Details of the vulnerability and a remediation are included below. However, as a general 
guideline, Schneider Electric and Airbus Cybersecurity encourage all industrial companies to 
ensure they have implemented cybersecurity best practices across their operations and supply 
chains to reduce cyber risks. Where appropriate this includes locating industrial systems and 
remotely accessible devices behind firewalls; installing physical controls to prevent unauthorized
access; preventing mission-critical systems and devices from being accessed from outside 
networks; systematical…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2020-080-01"/>
  </entry>
</feed>
