<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T08:55:48.283285+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-04985</id>
    <title>bdu:2023-04985</title>
    <updated>2026-10-02T08:55:48.302208+00:00</updated>
    <content>bdu:2023-04985</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-04985"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0733</id>
    <title>certfr-2023-avi-0733 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits Siemens&lt;/span&gt;. Certaines d'entr…</title>
    <updated>2026-10-02T08:55:48.302248+00:00</updated>
    <content>certfr-2023-avi-0733</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0733"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2023-69811</id>
    <title>cnvd-2023-69811</title>
    <updated>2026-10-02T08:55:48.302266+00:00</updated>
    <content>cnvd-2023-69811</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2023-69811"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-251093</id>
    <title>EUVD-2026-251093</title>
    <updated>2026-10-02T08:55:48.302279+00:00</updated>
    <content>EUVD-2026-251093</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-251093"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-3935</id>
    <title>fkie_cve-2023-3935</title>
    <updated>2026-10-02T08:55:48.302289+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-3935"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fsa-202305</id>
    <title>FSA-202305 — Festo: Vulnerable WIBU-SYSTEMS CodeMeter Runtime in several products</title>
    <updated>2026-10-02T08:55:48.302316+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability in the Wibu CodeMeter Runtime, which is part of the installation packages of several Festo products, was found. An attacker exploiting the vulnerability in WIBU CodeMeter Runtime in server mode could gain full access to the affected server via network access without any user interaction. This could lead to remote code execution and escalation of privileges giving full admin access on the host system for an already authenticated user (logged in locally to the PC).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fsa-202305"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-c9rf-qf73-r46f</id>
    <title>GHSA-c9rf-qf73-r46f</title>
    <updated>2026-10-02T08:55:48.302338+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-c9rf-qf73-r46f"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-3935</id>
    <title>gsd-2023-3935</title>
    <updated>2026-10-02T08:55:48.302352+00:00</updated>
    <content>gsd-2023-3935</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-3935"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-23-257-06</id>
    <title>ICSA-23-257-06 — Siemans WIBU Systems CodeMeter</title>
    <updated>2026-10-02T08:55:48.302361+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In CodeMeter Runtime versions up to 7.60b, there is a heap buffer overflow vulnerability which can potentially lead to a remote code execution. Currently, no PoC is known to us. To
exploit the heap overflow, additional protection mechanisms need to be broken. Remote access is only possible if CodeMeter is configured as a server. If CodeMeter is not configured as a server, the adversary would need to log in to the machine where the CodeMeter Runtime is running or trick the user into sending a malicious request to CodeMeter. This might result in an escalation of privilege. (WIBU-230704-01)</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-23-257-06"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sca-2023-0009</id>
    <title>SCA-2023-0009 — Vulnerability in Wibu-Systems CodeMeter Runtime affects multiple SICK products</title>
    <updated>2026-10-02T08:55:48.302379+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In CodeMeter Runtime versions up to 7.60b, there is a heap buffer overflow vulnerability which can potentially lead to a remote code execution. Currently, no PoC is known to us. To exploit the heap overflow, additional protection mechanisms need to be broken. Remote access is only possible if CodeMeter is configured as a server. If CodeMeter is not configured as a server, the adversary would need to log in to the machine where the CodeMeter Runtime is running or trick the user into sending a malicious request to CodeMeter. This might result in an escalation of privilege.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sca-2023-0009"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2023-030</id>
    <title>VDE-2023-030 — Phoenix Contact: Multiple products affected by WIBU Codemeter Vulnerability (Update A)</title>
    <updated>2026-10-02T08:55:48.302396+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A Vulnerability in WIBU-SYSTEMS CodeMeter Runtime affects multiple Phoenix Contact products.
Phoenix Contact devices using CodeMeter embedded are not affected by this vulnerability.
Update A, 2023-11-13
Removed CVE-2023-4701 because it was revoked.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2023-030"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2023-031</id>
    <title>VDE-2023-031 — Trumpf: Multiple Products affected by WIBU Codemeter Vulnerability</title>
    <updated>2026-10-02T08:55:48.302411+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>The TRUMPF CAD/CAM software tools mentioned above use the vulnerable CodeMeter Runtime (up to version 7.60b) application from WIBU-SYSTEMS AG to manage licenses within the component TRUMPF License Expert. This CodeMeter application contains new vulnerabilities, which may enable an attacker to gain full access to the server or workstation on which the TRUMPF License Expert has been installed on. A new version of the TRUMPF License Expert which fixes this vulnerability is available.Machines with a running and correctly installed mGuard hardware firewall cannot be exploited by this vulnerability if used as intended (according to the manual).</p>
<p>Update A, 2023-11-13
Removed CVE-2023-4701 because it was revoked.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2023-031"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2023-032</id>
    <title>VDE-2023-032 — Weidmueller: WIBU Vulnerability in multiple Products</title>
    <updated>2026-10-02T08:55:48.302431+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multiple Weidmueller products are affected by recent WIBU vulnerability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2023-032"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2023-033</id>
    <title>VDE-2023-033 — Pilz: WIBU Vulnerabilitiy in multiple Products</title>
    <updated>2026-10-02T08:55:48.302444+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Several Pilz products use the 3rd party component "CodeMeter Runtime" from WIBU-SYSTEM AG to manage software licenses. This component is affected by a vulnerability, which may enable an attacker to gain full control over the system running the software product. The vulnerability can be exploited locally or over the network.</p>
<p>Update A, 2023-12-05</p>
<p>changed affected version of "Software PASvisu &lt; 1.15.0" to "Software PASvisu &lt; 1.14.1"
removed CVE-2023-4701 because it was revoked.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2023-033"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2023-035</id>
    <title>VDE-2023-035 — CODESYS: Multiple products affected by WIBU Codemeter vulnerability</title>
    <updated>2026-10-02T08:55:48.302464+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Several CODESYS setups contain and install vulnerable versions of the WIBU CodeMeter Runtime.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2023-035"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2023-042</id>
    <title>VDE-2023-042 — Wago: Vulnerable WIBU-SYSTEMS Codemeter installed through e!COCKPIT and WAGO-I/O-Pro (UPDATE B)</title>
    <updated>2026-10-02T08:55:48.302478+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Critical vulnerability has been discovered in the utilized component PROFINET IO Device by Hilscher Gesellschaft für Systemautomation mbH.
The impact of the vulnerability on the affected device is that it can</p>
<p>no longer perform acyclic requests
may drop all established cyclic connections may
disappear completely from the network
For more information see advisory by Hilscher:</p>
<p>https://kb.hilscher.com/display/ISMS/2020-12-03+Denial+of+Service+vulnerability+in+PROFINET+IO+Device</p>
<p>Update 20.11.2024: Products have been added</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2023-042"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2025-105</id>
    <title>VDE-2025-105 — Endress+Hauser: Multiple products affected by Wibu-Systems CodeMeter Vulnerability</title>
    <updated>2026-10-02T08:55:48.302497+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability in Wibu-Systems CodeMeter (up to version 7.60b) affects multiple Endress+Hauser products. This flaw can lead to a heap buffer overflow, which may allow remote code execution under certain conditions.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2025-105"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2311</id>
    <title>WID-SEC-W-2023-2311 — Wibu-Systems CodeMeter: Schwachstelle ermöglicht Codeausführung und Privilegienerweiterung</title>
    <updated>2026-10-02T08:55:48.302511+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter anonymer Angreifer kann eine Schwachstelle in Wibu-Systems CodeMeter ausnutzen, um beliebigen Code auszuführen oder seine Privilegien zu erweitern.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2311"/>
  </entry>
</feed>
