<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:35:05.480746+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2021-03155</id>
    <title>bdu:2021-03155</title>
    <updated>2026-10-02T19:35:07.829271+00:00</updated>
    <content>bdu:2021-03155</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2021-03155"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2021-avi-622</id>
    <title>certfr-2021-avi-622 — De multiples vulnérabilités ont été découvertes dans les produits
Schneider Electric. Certaines d'entre elles permetten…</title>
    <updated>2026-10-02T19:35:07.829333+00:00</updated>
    <content>certfr-2021-avi-622</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2021-avi-622"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2021-37673</id>
    <title>cnvd-2021-37673</title>
    <updated>2026-10-02T19:35:07.829367+00:00</updated>
    <content>cnvd-2021-37673</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2021-37673"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-26671</id>
    <title>EUVD-2026-26671</title>
    <updated>2026-10-02T19:35:07.829389+00:00</updated>
    <content>EUVD-2026-26671</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-26671"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-30188</id>
    <title>fkie_cve-2021-30188</title>
    <updated>2026-10-02T19:35:07.829408+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>CODESYS V2 runtime system SP before 2.4.7.55 has a Stack-based Buffer Overflow.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-30188"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fsa-202601</id>
    <title>FSA-202601 — Several CODESYS vulnerabilities in Festo Automation Suite</title>
    <updated>2026-10-02T19:35:07.829447+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Starting with Festo Automation Suite (FAS) version 2.8.0.138, the suite is delivered only with a connector to Codesys, rather than including Codesys directly. Prior to this version, Codesys was bundled within the FAS installation. From version 2.8.0.138 onwards, customers are required to download and install Codesys independently.</p>
<p>This change impacts the handling of security vulnerabilities (CVEs) related to Codesys. Any Codesys-related security issues must now be addressed by the customer through their separate Codesys installation. The FAS itself includes only the connector component, which is maintained and updated within the suite.</p>
<p>Please ensure that Codesys is kept up to date independently to mitigate any potential security risks associated with the Codesys software.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fsa-202601"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vcv5-xrh2-qgqx</id>
    <title>GHSA-vcv5-xrh2-qgqx</title>
    <updated>2026-10-02T19:35:07.829619+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>CODESYS V2 runtime system SP before 2.4.7.55 has a Stack-based Buffer Overflow.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vcv5-xrh2-qgqx"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-30188</id>
    <title>gsd-2021-30188</title>
    <updated>2026-10-02T19:35:07.829651+00:00</updated>
    <content>gsd-2021-30188</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-30188"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-21-173-03</id>
    <title>ICSA-21-173-03 — CODESYS Control V2 communication</title>
    <updated>2026-10-02T19:35:07.829674+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A crafted request may cause a heap-based buffer overflow in the affected CODESYS products, resulting in a denial-of-service condition.CVE-2021-30186 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). A crafted request may cause a stack-based buffer overflow in the affected CODESYS products, resulting in a denial-of-service condition or remote code execution.CVE-2021-30188 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). A crafted request may cause a buffer over-read in the affected CODESYS products, resulting in a denial-of-service condition.CVE-2021-30195 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-21-173-03"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2021-222-06</id>
    <title>SEVD-2021-222-06 — CODESYS V2 Vulnerabilities in Programmable Automation Controller (PacDrive) M</title>
    <updated>2026-10-02T19:35:07.829715+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Schneider Electric is aware of multiple vulnerabilities disclosed by Codesys on CODESYS V2 runtime for industrial control systems, which is used in its Programmable Automation Controller (PacDrive) M products.
The Programmable Automation Controller (PacDrive) M products are legacy logic motion technology for packaging and production machines.
Failure to apply the mitigations provided below may risk buffer overflow attacks, which could result in potential denial of service condition or arbitrary remote code execution.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2021-222-06"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2021-014</id>
    <title>VDE-2021-014 — WAGO: Multiple Vulnerabilities in CODESYS Runtime 2.3</title>
    <updated>2026-10-02T19:35:07.829751+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multiple vulnerabilities were reported in CODESYS 2.3 Runtime. The CODESYS 2.3 Runtime is an essential component in several WAGO PLC's.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2021-014"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2021-048</id>
    <title>VDE-2021-048 — Lenze: Multiple Vulnerabilities in CODESYS Control V2 communication</title>
    <updated>2026-10-02T19:35:07.829793+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>The affected products contain a CODESYS Control runtime system in version V2. They are therefore affected by the
vulnerability described in CODESYS Advisory 2021-06. It provides a communication server for the communication with clients like the CODESYS Development System.</p>
<p>The 9400 servo inverters is only affected if the communication Path via the inserted EtherNet Module E94AYCEN on slot MXI1 or MXI2 is used. If the Module E94AYCEN is used, the following Versions are affected.</p>
<p>Product Identification: E94xSHxxx (Single Drive, High Line)
Product Identification: E94xMHxxx (Multi Drive, High Line)</p>
<p>Remark: If the product identification of your 9400 product does not fit to the above mentioned identification, please contact Lenze at Security.de@Lenze.com.</p>
<p>The Versions P (power supply module) and R (regenerative power supply module) are not affected. Furthermore, the Variant P (PLC) and the Variant S (StateLine) are not affected. The communication paths via the diagnostic interface X6, the system bus (CAN) X1 or the field buses (other than the named Ethernet module) that can be plugged into the module slots MXI1 or MXI2 are not affected.</p>
<p>The focus is therefore on 9400 servo inverters with the product-identification E94x{S/M}{H}... with a plugged in Ethernet module E94AYCEN... in module slot MXI1 or MXI2 and communication with the Engineer-Tools via exactly this channel.</p>
<p>In addition to the standard tool Engineer, there is also a special Version of the PLC Designer (Version 0.x)…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2021-048"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2021-054</id>
    <title>VDE-2021-054 — Pilz: Multiple vulnerabilities in CODESYS V2 and V3 runtime system</title>
    <updated>2026-10-02T19:35:07.829869+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Several Pilz products use Versions V2 and V3 of the CODESYS runtime system from CODESYS GmbH, which enables the execution of IEC 61131-3 PLC programs. These runtime environments contain several vulnerabilities, which an attacker can exploit via the network. Successful exploitation of the vulnerabilities results in reduced availability and, in a worst case, to the insertion of program code.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2021-054"/>
  </entry>
</feed>
