<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T01:50:41.023883+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2021-avi-705</id>
    <title>certfr-2021-avi-705 — De multiples vulnérabilités ont été découvertes dans les produits
Schneider. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-03T01:50:41.128763+00:00</updated>
    <content>certfr-2021-avi-705</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2021-avi-705"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-23170</id>
    <title>EUVD-2026-23170</title>
    <updated>2026-10-03T01:50:41.128865+00:00</updated>
    <content>EUVD-2026-23170</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-23170"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-22797</id>
    <title>fkie_cve-2021-22797</title>
    <updated>2026-10-03T01:50:41.128898+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal) vulnerability exists that could cause malicious script to be deployed in an unauthorized location and may result in code execution on the engineering workstation when a malicious project file is loaded in the engineering software. Affected Product: EcoStruxure Control Expert (V15.0 SP1 and prior, including former Unity Pro), EcoStruxure Process Expert (2020 and prior, including former HDCS), SCADAPack RemoteConnect for x70 (All versions)</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-22797"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qqgr-6jmg-cwgv</id>
    <title>GHSA-qqgr-6jmg-cwgv</title>
    <updated>2026-10-03T01:50:41.128960+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal) vulnerability exists that could cause malicious script to be deployed in an unauthorized location and may result in code execution on the engineering workstation when a malicious project file is loaded in the engineering software. Affected Product: EcoStruxure Control Expert (V15.0 SP1 and prior, including former Unity Pro), EcoStruxure Process Expert (2020 and prior, including former HDCS), SCADAPack RemoteConnect for x70 (All versions)</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qqgr-6jmg-cwgv"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-22797</id>
    <title>gsd-2021-22797</title>
    <updated>2026-10-03T01:50:41.129003+00:00</updated>
    <content>gsd-2021-22797</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-22797"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-21-259-02</id>
    <title>ICSA-21-259-02 — Schneider Electric EcoStruxure and SCADAPack</title>
    <updated>2026-10-03T01:50:41.129029+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>When a malicious project file is loaded on the engineering workstation software, it deploys a malicious script to execute arbitrary code in unauthorized locations.CVE-2021-22797has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-21-259-02"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2021-257-01</id>
    <title>SEVD-2021-257-01 — EcoStruxureTM Control Expert, EcoStruxureTM Process Expert, SCADAPack RemoteConnect™ for x70</title>
    <updated>2026-10-03T01:50:41.129072+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Schneider Electric is aware of multiple vulnerabilities in its EcoStruxure™ Control Expert, EcoStruxure™ Process Expert, SCADAPack RemoteConnect™ for x70 software products.
EcoStruxure™ Control Expert is the common programming, debugging and operating software for Modicon M340, M580, M580S, Premium, Momentum and Quantum ranges.   
EcoStruxure™ Process Expert is the next-generation process automation system to engineer, operate and maintain an entire plant, a Distributed Control System (DCS), designed especially for water, mining, cement, power generation, consumer packaged goods, chemical, and oil and gas applications.  
The SCADAPack RemoteConnect™ for x70 product is a Windows-based application based on EcoStruxure™ Control Expert software components that provides a programming and configuration environment for the SCADAPack x70 RTU series, which is comprised of the SCADAPack 470, 474, 570, 574 and 575 Smart RTUs.
Failure to apply the remediations provided below may risk a Denial of Service attack, which could cause a disruption of communication between the Modicon controller and the engineering software.

June 2022 Update: Added SCADAPack RemoteConnect™ to the list of affected products, which is impacted on versions prior to R2.7.3 through the integration of EcoStruxure™ Control Expert.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2021-257-01"/>
  </entry>
</feed>
