<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T19:12:59.980687+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2025-40569</id>
    <title>CVE-2025-40569</title>
    <updated>2026-10-10T19:12:59.982593+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Siemens RUGGEDCOM RST2428P, Siemens SCALANCE XCH328, Siemens SCALANCE XCM324, Siemens SCALANCE XCM328, Siemens SCALANCE XCM332, Siemens SCALANCE XRH334 (24 V DC, 8xFO, CC), Siemens SCALANCE XRM334 (230 V AC, 12xFO), Siemens SCALANCE XRM334 (230 V AC, 8xFO), Siemens SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+), Siemens SCALANCE XRM334 (24 V DC, 12xFO) and 5 more</p>
<p>A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions &lt; V3.2), SCALANCE XCH328 (6GK5328-4TS01-2EC2) (All versions &lt; V3.2), SCALANCE XCM324 (6GK5324-8TS01-2AC2) (All versions &lt; V3.2), SCALANCE XCM328 (6GK5328-4TS01-2AC2) (All versions &lt; V3.2), SCALANCE XCM332 (6GK5332-0GA01-2AC2) (All versions &lt; V3.2), SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3) (All versions &lt; V3.2), SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3) (All versions &lt; V3.2), SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3) (All versions &lt; V3.2), SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3) (All versions &lt; V3.2), SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3) (All versions &lt; V3.2), SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3) (All versions &lt; V3.2), SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3) (All versions &lt; V3.2), SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3) (All versions &lt; V3.2), SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3) (All versions &lt; V3.2), SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3) (All versions &lt; V3.2). The "Load Configuration from Local PC" functionality in the web interface of affected products contains a race condition vulnerability. This could allow an authenticated remote attacker to make the affected product load an attacker controlled configuration instead of the legitimate one. Successful exploitation requires that a legitim…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2025-40569"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-693776</id>
    <title>SSA-693776 — SSA-693776: Multiple Vulnerabilities in Industrial Communication Devices based on SINEC OS before V3.2</title>
    <updated>2026-10-10T19:12:59.982684+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The "Load Rollback" functionality in the web interface of affected products contains an incorrect authorization check vulnerability. This could allow an authenticated remote attacker with "guest" role to make the affected product roll back configuration changes made by privileged users. An internal session termination functionality in the web interface of affected products contains an incorrect authorization check vulnerability. This could allow an authenticated remote attacker with "guest" role to terminate legitimate users' sessions. The "Load Configuration from Local PC" functionality in the web interface of affected products contains a race condition vulnerability. This could allow an authenticated remote attacker to make the affected product load an attacker controlled configuration instead of the legitimate one. Successful exploitation requires that a legitimate administrator invokes the functionality and the attacker wins the race condition.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-693776"/>
  </entry>
</feed>
