<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T15:20:29.003838+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-04754</id>
    <title>bdu:2022-04754</title>
    <updated>2026-10-03T15:20:29.105638+00:00</updated>
    <content>bdu:2022-04754</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-04754"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-896</id>
    <title>certfr-2022-avi-896 — De multiples vulnérabilités ont été découvertes dans les produits
Schneider Electric. Certaines d'entre elles permetten…</title>
    <updated>2026-10-03T15:20:29.105703+00:00</updated>
    <content>certfr-2022-avi-896</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-896"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-231185</id>
    <title>EUVD-2026-231185</title>
    <updated>2026-10-03T15:20:29.105724+00:00</updated>
    <content>EUVD-2026-231185</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-231185"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-2465</id>
    <title>fkie_cve-2022-2465</title>
    <updated>2026-10-03T15:20:29.105738+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Deserialization of Untrusted Data vulnerability. ISaGRAF Workbench does not limit the objects that can be deserialized. This vulnerability allows attackers to craft a malicious serialized object that, if opened by a local user in ISaGRAF Workbench, may result in remote code execution. This vulnerability requires user interaction to be successfully exploited.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-2465"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g35v-78wx-r6fx</id>
    <title>GHSA-g35v-78wx-r6fx</title>
    <updated>2026-10-03T15:20:29.105791+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Deserialization of Untrusted Data vulnerability. ISaGRAF Workbench does not limit the objects that can be deserialized. This vulnerability allows attackers to craft a malicious serialized object that, if opened by a local user in ISaGRAF Workbench, may result in remote code execution. This vulnerability requires user interaction to be successfully exploited.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g35v-78wx-r6fx"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-2465</id>
    <title>gsd-2022-2465</title>
    <updated>2026-10-03T15:20:29.105822+00:00</updated>
    <content>gsd-2022-2465</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-2465"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-22-202-03</id>
    <title>ICSA-22-202-03 — Rockwell Automation ISaGRAF Workbench</title>
    <updated>2026-10-03T15:20:29.105833+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A crafted malicious .7z exchange file may allow an attacker to gain the privileges of the ISaGRAF Workbench software when opened. If the software is running at the SYSTEM level, then the attacker will gain admin level privileges. User interaction is required for this exploit to be successful.CVE-2022-2463 has been assigned to this vulnerability. A CVSS v3 base score of 6.1 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L). Crafted malicious files can allow an attacker to traverse the file system when opened by ISaGRAF Workbench. If successfully exploited, an attacker could overwrite existing files and create additional files with the same permissions of the ISaGRAF Workbench software. User interaction is required for this exploit to be successful.CVE-2022-2464 has been assigned to this vulnerability. A CVSS v3 base score of 7.7 has been calculated; the CVSS vector string is (AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H). ISaGRAF Workbench does not limit the objects that can be deserialized. This vulnerability allows attackers to craft a malicious serialized object that, if opened by a local user in ISaGRAF Workbench, may result in remote code execution. This vulnerability requires user interaction to be successfully exploited.CVE-2022-2465 has been assigned to this vulnerability. A CVSS v3 base score of 8.6 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-22-202-03"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2022-284-03</id>
    <title>SEVD-2022-284-03 — ISaGRAF Workbench for SAGE RTU</title>
    <updated>2026-10-03T15:20:29.105861+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Schneider Electric is aware of multiple vulnerabilities in the third party ISaGRAF Workbench software used by SAGE RTU products.
The SAGE RTU products are hardware devices that collect utility substation information from different devices and passes it along to a SCADA software platform.
Failure to apply the mitigations provided below may risk remote code execution, which could result in privilege escalation that will allow an attacker to gain the privileges of the software. If the software is running at SYSTEM level, an attacker may gain admin level privileges. These vulnerabilities can only be exploited when users open the TCP listening ports on the RTU and connect with ISaGRAF Workbench.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2022-284-03"/>
  </entry>
</feed>
