<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T23:56:27.136060+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-24060</id>
    <title>CVE-2026-24060 — Automated Logic WebCTRL Premium Server Cleartext Transmission of Sensitive Information</title>
    <updated>2026-10-05T23:56:27.200132+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Automated Logic WebCTRL Premium Server</p>
<p>Service information is not encrypted when transmitted as BACnet packets 
over the wire, and can be sniffed, intercepted, and modified by an 
attacker. Valuable information such as the File Start Position and File 
Data can be sniffed from network traffic using Wireshark's BACnet 
dissector filter. The proprietary format used by WebCTRL to receive 
updates from the PLC can also be sniffed and reverse engineered.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-24060"/>
  </entry>
</feed>
