<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T11:38:14.124488+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-178238</id>
    <title>EUVD-2026-178238</title>
    <updated>2026-10-02T11:38:14.129058+00:00</updated>
    <content>EUVD-2026-178238</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-178238"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-31802</id>
    <title>fkie_cve-2022-31802</title>
    <updated>2026-10-02T11:38:14.129090+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In CODESYS Gateway Server V2 for versions prior to V2.3.9.38 only a part of the the specified password is been compared to the real CODESYS Gateway password. An attacker may perform authentication by specifying a small password that matches the corresponding part of the longer real CODESYS Gateway password.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-31802"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fsa-202406</id>
    <title>FSA-202406 — Several Codesys Gateway v2 vulnerabilities in Codesys provided by Festo</title>
    <updated>2026-10-02T11:38:14.129120+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>An unauthenticated attacker would be able to send crafted requests to cause the CODESYS Gateway Server V2 to allocate excessive memory or consume all available TCP client connections. Besides, passwords are insufficiently checked during login.</p>
<p>All versions of the following CODESYS V2 product prior version V2.3.9.38 are affected:</p>
<p>• CODESYS Gateway Server</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fsa-202406"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jp8v-m2cx-q392</id>
    <title>GHSA-jp8v-m2cx-q392</title>
    <updated>2026-10-02T11:38:14.129148+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In CODESYS Gateway Server V2 for versions prior to V2.3.9.38 only a part of the the specified password is been compared to the real CODESYS Gateway password. An attacker may perform authentication by specifying a small password that matches the corresponding part of the longer real CODESYS Gateway password.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jp8v-m2cx-q392"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-31802</id>
    <title>gsd-2022-31802</title>
    <updated>2026-10-02T11:38:14.129164+00:00</updated>
    <content>gsd-2022-31802</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-31802"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-25-182-03</id>
    <title>ICSA-25-182-03 — FESTO CODESYS</title>
    <updated>2026-10-02T11:38:14.129176+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>An unauthenticated attacker would be able to send crafted requests to cause the CODESYS Gateway Server V2 to allocate excessive memory or consume all available TCP client connections. Besides, passwords are insufficiently checked during login.</p>
<p>All versions of the following CODESYS V2 product prior version V2.3.9.38 are affected:</p>
<p>• CODESYS Gateway Server</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-25-182-03"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2022-040</id>
    <title>VDE-2022-040 — WAGO: Multiple Vulnerabilities in Controller with WAGO I/O-Pro / CODESYS 2.3 Runtime</title>
    <updated>2026-10-02T11:38:14.129197+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>UPDATE A: Solution has updated release datesUPDATE B: Solution has updated release datesThis Advisory is published with reference to:</p>
<p>CODESYS Advisory 2022-11 (Security update for CODESYS Control V2)
CODESYS Advisory 2022-12 (Security update for CODESYS V2 password transport)
CODESYS Advisory 2022-13 (Security update for CODESYS Gateway V2)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2022-040"/>
  </entry>
</feed>
