<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T10:02:42.920470+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2021-103631</id>
    <title>cnvd-2021-103631</title>
    <updated>2026-10-03T10:02:42.936427+00:00</updated>
    <content>cnvd-2021-103631</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2021-103631"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-27950</id>
    <title>EUVD-2026-27950</title>
    <updated>2026-10-03T10:02:42.936459+00:00</updated>
    <content>EUVD-2026-27950</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-27950"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-32497</id>
    <title>fkie_cve-2021-32497</title>
    <updated>2026-10-03T10:02:42.936474+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>SICK SOPAS ET before version 4.8.0 allows attackers to wrap any executable file into an SDD and provide this to a SOPAS ET user. When a user starts the emulator the executable is run without further checks.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-32497"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mj9r-rw22-xm89</id>
    <title>GHSA-mj9r-rw22-xm89</title>
    <updated>2026-10-03T10:02:42.936502+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>SICK SOPAS ET before version 4.8.0 allows attackers to wrap any executable file into an SDD and provide this to a SOPAS ET user. When a user starts the emulator the executable is run without further checks.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mj9r-rw22-xm89"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-32497</id>
    <title>gsd-2021-32497</title>
    <updated>2026-10-03T10:02:42.936519+00:00</updated>
    <content>gsd-2021-32497</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-32497"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sca-2021-0004</id>
    <title>SCA-2021-0004 — Vulnerabilities in SICK SOPAS ET</title>
    <updated>2026-10-03T10:02:42.936530+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>SDD files might contain an executable file that will be listed as the Emulators inside SOPAS ET. When 
a user starts the emulator, the executable is run without further checks. Attackers could wrap any 
executable file into an SDD and provide this to a SOPAS ET user. When installing the SDD the user 
may not be aware about the executable inside of the SDD. When an SDD contains an emulator, the emulator location is part of the SDD manifest. Attackers could manipulate this location and use path traversal to target an arbitrary executable located on the host system. When the user starts the emulator from SOPAS ET, the corresponding executable will be started instead of the emulator. The command line arguments that are passed to an emulator when starting it via SOPAS ET, are part 
of the SDD manifest. Attackers could manipulate the arguments to pass in any value to the 
executable. In combination with CVE-2021-32498 the attacker could target an arbitrary executable 
with any arguments on the host system.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sca-2021-0004"/>
  </entry>
</feed>
