<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T12:08:14.558189+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-1015</id>
    <title>certfr-2023-avi-1015 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits Siemens&lt;/span&gt;. Certaines d'entr…</title>
    <updated>2026-10-02T12:08:14.630160+00:00</updated>
    <content>certfr-2023-avi-1015</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-1015"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2023-97255</id>
    <title>cnvd-2023-97255</title>
    <updated>2026-10-02T12:08:14.630199+00:00</updated>
    <content>cnvd-2023-97255</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2023-97255"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-270602</id>
    <title>EUVD-2026-270602</title>
    <updated>2026-10-02T12:08:14.630230+00:00</updated>
    <content>EUVD-2026-270602</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-270602"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-48428</id>
    <title>fkie_cve-2023-48428</title>
    <updated>2026-10-02T12:08:14.630244+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability has been identified in SINEC INS (All versions &lt; V1.0 SP2 Update 2). The radius configuration mechanism of affected products does not correctly check uploaded certificates. A malicious admin could upload a crafted certificate resulting in a denial-of-service condition or potentially issue commands on system level.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-48428"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3727-x5w3-xwrr</id>
    <title>GHSA-3727-x5w3-xwrr</title>
    <updated>2026-10-02T12:08:14.630274+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability has been identified in SINEC INS (All versions &lt; V1.0 SP2 Update 2). The radius configuration mechanism of affected products does not correctly check uploaded certificates. A malicious admin could upload a crafted certificate resulting in a denial-of-service condition or potentially issue commands on system level.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3727-x5w3-xwrr"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-48428</id>
    <title>gsd-2023-48428</title>
    <updated>2026-10-02T12:08:14.630291+00:00</updated>
    <content>gsd-2023-48428</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-48428"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-23-348-16</id>
    <title>ICSA-23-348-16 — Siemens SINEC INS</title>
    <updated>2026-10-02T12:08:14.630302+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A security vulnerability has been identified in all supported versions of OpenSSL related to the verification of X.509 certificate chains that include policy constraints. Attackers may be able to exploit this vulnerability by creating a malicious certificate chain that triggers exponential use of computational resources, leading to a denial-of-service (DoS) attack on affected systems.

Policy processing is disabled by default but can be enabled by passing the `-policy` argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()` function. libcurl would reuse a previously created connection even when an SSH related option had been changed that should have prohibited reuse. libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, two SSH settings were left out from the configuration match checks, making them match too easily. Affected products do not properly validate the certificate of the configured UMC server. This could allow an attacker to intercept credentials that are sent to the UMC server as well as to manipulate responses, potentially allowing an attacker to escalate privileges. The radius configuration mechanism of affected products does not correctly check uploaded certificates. A malicious admin could upload a crafted certificate resulting in a denial-of-service condition or potentially issue commands on system level. The Web UI of affected devices…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-23-348-16"/>
  </entry>
</feed>
