<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T20:52:29.276704+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-06609</id>
    <title>bdu:2025-06609</title>
    <updated>2026-10-04T20:52:29.285261+00:00</updated>
    <content>bdu:2025-06609</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-06609"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0397</id>
    <title>certfr-2025-avi-0397 — De multiples vulnérabilités ont été découvertes dans les produits Siemens. Certaines d'entre elles permettent à un atta…</title>
    <updated>2026-10-04T20:52:29.285294+00:00</updated>
    <content>certfr-2025-avi-0397</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0397"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-239146</id>
    <title>EUVD-2026-239146</title>
    <updated>2026-10-04T20:52:29.285313+00:00</updated>
    <content>EUVD-2026-239146</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-239146"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-23815</id>
    <title>fkie_cve-2024-23815</title>
    <updated>2026-10-04T20:52:29.285325+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability has been identified in Desigo CC (All versions if access from Installed Clients to Desigo CC server is allowed from networks outside of a highly protected zone), Desigo CC (All versions if access from Installed Clients to Desigo CC server is only allowed within highly protected zones). The affected server application fails to authenticate specific client requests. Modification of the client binary could allow an unauthenticated remote attacker to execute arbitrary SQL queries on the server database via the event port (default: 4998/tcp)</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-23815"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xgrg-cw4v-4h6g</id>
    <title>GHSA-xgrg-cw4v-4h6g</title>
    <updated>2026-10-04T20:52:29.285354+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability has been identified in Desigo CC (All versions if access from Installed Clients to Desigo CC server is allowed from networks outside of a highly protected zone), Desigo CC (All versions if access from Installed Clients to Desigo CC server is only allowed within highly protected zones). The affected server application fails to authenticate specific client requests. Modification of the client binary could allow an unauthenticated remote attacker to execute arbitrary SQL queries on the server database via the event port (default: 4998/tcp)</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xgrg-cw4v-4h6g"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-23815</id>
    <title>gsd-2024-23815</title>
    <updated>2026-10-04T20:52:29.285371+00:00</updated>
    <content>gsd-2024-23815</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-23815"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-25-135-04</id>
    <title>ICSA-25-135-04 — Siemens Desigo</title>
    <updated>2026-10-04T20:52:29.285382+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The affected server application fails to authenticate specific client requests. Modification of the client binary could allow an unauthenticated remote attacker to execute arbitrary SQL queries on the server database via the event port (default: 4998/tcp) If access from Installed Clients to Desigo CC server is only allowed within highly protected zones:
Exploitation of this issue requires an attacker to get access to an Installed Client application in the "highly protected zone" (i.e. a physically separated private network), and bypass the hardening measures as described by Desigo CC Cybersecurity Guideline.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-25-135-04"/>
  </entry>
</feed>
