<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T13:25:22.608859+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-01586</id>
    <title>bdu:2023-01586</title>
    <updated>2026-10-05T13:25:22.615355+00:00</updated>
    <content>bdu:2023-01586</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-01586"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2021-avi-517</id>
    <title>certfr-2021-avi-517 — De multiples vulnérabilités ont été découvertes dans les produits
Schneider. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-05T13:25:22.615387+00:00</updated>
    <content>certfr-2021-avi-517</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2021-avi-517"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-23108</id>
    <title>EUVD-2026-23108</title>
    <updated>2026-10-05T13:25:22.615405+00:00</updated>
    <content>EUVD-2026-23108</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-23108"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-22778</id>
    <title>fkie_cve-2021-22778</title>
    <updated>2026-10-05T13:25:22.615417+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), and SCADAPack RemoteConnect for x70, all versions, that could cause protected derived function blocks to be read or modified by unauthorized users when accessing a project file.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-22778"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-cpxg-749c-f5cf</id>
    <title>GHSA-cpxg-749c-f5cf</title>
    <updated>2026-10-05T13:25:22.615444+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), and SCADAPack RemoteConnect for x70, all versions, that could cause protected derived function blocks to be read or modified by unauthorized users when accessing a project file.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-cpxg-749c-f5cf"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-22778</id>
    <title>gsd-2021-22778</title>
    <updated>2026-10-05T13:25:22.615468+00:00</updated>
    <content>gsd-2021-22778</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-22778"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-21-194-02</id>
    <title>ICSA-21-194-02 — Schneider Electric Modicon Controllers and Software (Update A)</title>
    <updated>2026-10-05T13:25:22.615479+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An insufficiently protected credentials vulnerability exists that could cause protected derived function blocks to be read or modified by unauthorized users when accessing a project file. CVE-2021-22778 has been assigned to this vulnerability. A CVSS v3 base score of 8.6 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).. --------- Begin Update A Part 2 of 2 --------CVE-2021-22778 has been assigned to this vulnerability. A CVSS v3 base score of 8.6 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H). An authentication bypass by spoofing vulnerability exists that could cause unauthorized access in read and write mode to the controller by spoofing the Modbus communication between the engineering software and the controller. CVE-2021-22779 has been assigned to this vulnerability. A CVSS v3 base score of 9.8has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).. --------- End Update A Part 2 of 2 --------CVE-2021-22779 has been assigned to this vulnerability. A CVSS v3 base score of 9.8has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). M&amp;M Software fdtCONTAINER component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage.
Note: This vulnerability could cause local code execution on the engineering workstation when a malicious project file is loaded into the engine…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-21-194-02"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2021-194-01</id>
    <title>SEVD-2021-194-01 — EcoStruxureTM Control Expert, EcoStruxureTM Process Expert, SCADAPack RemoteConnect™ x70, and Modicon Controllers M580…</title>
    <updated>2026-10-05T13:25:22.615517+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Schneider Electric is aware of multiple vulnerabilities in its EcoStruxure™ Control Expert , EcoStruxure™ Process Expert, SCADAPack RemoteConnect™ x70, and Modicon M580 and M340 control products. These vulnerabilities pose several risks, primary among these is the possibility of arbitrary code execution and loss of confidentiality and integrity of the project file.
With all products affected an attack would first involve an authenticated user gaining access to the engineering station; or an unauthenticated user gaining access to a project file or to the process control network.
Our findings demonstrate that while the discovered vulnerabilities affect Schneider Electric offers, it is possible to mitigate the potential impacts by following standard guidance, specific instructions; and in some cases, the fixes provided by Schneider Electric to remove the vulnerabilities.
Please ensure that if you are an EcoStruxure™ Control Expert user to apply the latest security updates provided below. For users of any of the mentioned products see the mitigation section in this security notice for further information on how to help protect your system from possible attack.
Schneider Electric encourages all industrial companies to ensure they have implemented cybersecurity best practices across their operations and supply chains to reduce cyber risks. Where appropriate this includes locating industrial systems and remotely accessible devices behind firewalls; installing physical controls to p…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2021-194-01"/>
  </entry>
</feed>
