<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T09:21:24.245161+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2020-12517</id>
    <title>CVE-2020-12517 — Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS: An authenticated low privileged user could embed ma…</title>
    <updated>2026-10-05T09:21:24.302661+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Phoenix Contact AXC F 1152 (1151412), Phoenix Contact AXC F 2152 (2404267), Phoenix Contact AXC F 3152 (1069208), Phoenix Contact RFC 4072S (1051328, Phoenix Contact AXC F 2152 Starterkit (1046568), Phoenix Contact PLCnext Technology Starterkit (1188165)</p>
<p>On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an authenticated low privileged user could embed malicious Javascript code to gain admin rights when the admin user visits the vulnerable website (local privilege escalation).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2020-12517"/>
  </entry>
</feed>
