<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:29:24.973803+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-235497</id>
    <title>EUVD-2026-235497</title>
    <updated>2026-10-02T19:29:25.006180+00:00</updated>
    <content>EUVD-2026-235497</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-235497"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-3737</id>
    <title>fkie_cve-2022-3737</title>
    <updated>2026-10-02T19:29:25.006218+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In PHOENIX CONTACT Automationworx Software Suite up to version 1.89 memory can be read beyond the intended scope due to insufficient validation of input data. Availability, integrity, or confidentiality of an application programming workstation might be compromised by attacks using these vulnerabilities.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-3737"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-r2cg-cw4r-gcx4</id>
    <title>GHSA-r2cg-cw4r-gcx4</title>
    <updated>2026-10-02T19:29:25.006251+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In PHOENIX CONTACT Automationworx Software Suite up to version 1.89 memory can be read beyond the intended scope due to insufficient validation of input data. Availability, integrity, or confidentiality of an application programming workstation might be compromised by attacks using these vulnerabilities.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-r2cg-cw4r-gcx4"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-3737</id>
    <title>gsd-2022-3737</title>
    <updated>2026-10-02T19:29:25.006270+00:00</updated>
    <content>gsd-2022-3737</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-3737"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-22-326-03</id>
    <title>ICSA-22-326-03 — Phoenix Contact Automation Worx</title>
    <updated>2026-10-02T19:29:25.006282+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In Phoenix Contact Automation Worx Software Suite up to version 1.89, manipulated PC Worx or Config+ files could lead to a heap buffer overflow or a read access violation. Availability, integrity, or confidentiality of an application programming workstation could be compromised by attacks using these vulnerabilities.CVE-2022-3461 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). In Phoenix Contact Automation Worx Software Suite up to version 1.89, unauthorized users could read memory beyond the intended scope due to insufficient validation of input data. Availability, integrity, or confidentiality of an application programming workstation could be compromised by attacks using these vulnerabilities.CVE-2022-3737 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-22-326-03"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2022-048</id>
    <title>VDE-2022-048 — PHOENIX CONTACT: Automationworx BCP File Parsing Vulnerabilities</title>
    <updated>2026-10-02T19:29:25.006309+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Manipulated PC Worx or Config+ files could lead to a heap buffer overflow, release of unallocated memory or a read access violation due to insufficient validation of input data.The attacker needs to get access to an original bus configuration file (*.bcp) to be able to manipulate data inside. After manipulation the attacker needs to exchange the original file by the manipulated one on the application programming workstation.</p>
<p>Update A, 2022-11-14</p>
<p>removed the sentence "Automated systems in operation which were programmed with one of the above-mentioned products are not affected." from Impact.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2022-048"/>
  </entry>
</feed>
