<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:30:40 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-06599</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-06599</link>
      <description>bdu:2025-06599</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-06599</guid>
    </item>
    <item>
      <title>certfr-2022-avi-1001 — De multiples vulnérabilités ont été découvertes dans les produits
Siemens. Certaines d'entre elles permettent à un atta…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-1001</link>
      <description>certfr-2022-avi-1001</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-1001</guid>
    </item>
    <item>
      <title>EUVD-2026-215888</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-215888</link>
      <description>EUVD-2026-215888</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-215888</guid>
    </item>
    <item>
      <title>fkie_cve-2002-20001</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2002-20001</link>
      <description>&lt;p&gt;The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network bandwidth. The attack may be more disruptive in cases where a client can require a server to select its largest supported key size. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network bandwidth. The attack may be more disruptive in cases where a client can require a server to select its largest supported key size. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2002-20001</guid>
    </item>
    <item>
      <title>GHSA-jx4r-qc68-xjr5</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jx4r-qc68-xjr5</link>
      <description>&lt;p&gt;The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)ater attack. The client needs very little CPU resources and network bandwidth. The attack may be more disruptive in cases where a client can require a server to select its largest supported key size. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)ater attack. The client needs very little CPU resources and network bandwidth. The attack may be more disruptive in cases where a client can require a server to select its largest supported key size. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jx4r-qc68-xjr5</guid>
    </item>
    <item>
      <title>gsd-2002-20001</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2002-20001</link>
      <description>gsd-2002-20001</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2002-20001</guid>
    </item>
    <item>
      <title>ICSA-22-314-10 — Siemens SCALANCE W1750D</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-22-314-10</link>
      <description>&lt;p&gt;The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)ater attack. The client needs very little CPU resources and network bandwidth. The attack may be more disruptive in cases where a client can require a server to select its largest supported key size. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE. (ATLWL-266) A buffer overflow vulnerability in an underlying service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI UDP port (8211). (ATLWL-253) A buffer overflow vulnerability in an underlying service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI UDP port (8211). (ATLWL-254) A buffer overflow vulnerability in an underlying service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI UDP port (8211). (ATLWL-299) A buffer overflow vulnerability in an underlying service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI UDP port (8211). (ATLWL-300) A buffer overflow vulnerability in an underlying service could lead to unauthenticated remote code execution by sending spec…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)ater attack. The client needs very little CPU resources and network bandwidth. The attack may be more disruptive in cases where a client can require a server to select its largest supported key size. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE. (ATLWL-266) A buffer overflow vulnerability in an underlying service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI UDP port (8211). (ATLWL-253) A buffer overflow vulnerability in an underlying service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI UDP port (8211). (ATLWL-254) A buffer overflow vulnerability in an underlying service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI UDP port (8211). (ATLWL-299) A buffer overflow vulnerability in an underlying service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI UDP port (8211). (ATLWL-300) A buffer overflow vulnerability in an underlying service could lead to unauthenticated remote code execution by sending spec…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-22-314-10</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:11905-1 — libopenssl-1_1-devel-1.1.1m-4.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11905-1</link>
      <description>&lt;p&gt;libopenssl-1_1-devel-1.1.1m-4.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libopenssl-1_1-devel-1.1.1m-4.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:11905-1</guid>
    </item>
    <item>
      <title>VDE-2023-001 — PHOENIX CONTACT: Multiple Vulnerabilities in PLCnext Firmware</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2023-001</link>
      <description>&lt;p&gt;A new LTS Firmware release fixes known vulnerabilities in used open-source libraries.
In addition, the following improvements have been implemented:
HMI
- Hardening against DoS attacks. - Hardening against memory leak problems in case of network attacks.
WBM
- Umlauts in the password of the &amp;#39;User Manager&amp;#39; were not handled correctly. The password rule for upper and lower case was not followed. This could lead to unintentionally weaker passwords.- Hardening of WBM against Cross-Site-Scripting.
User Manager
- In security notifications &amp;#39;SecurityToken&amp;#39; was always displayed as &amp;#39;0000000&amp;#39; when creating or modifying users.- Hardening of Trust and Identity Stores.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A new LTS Firmware release fixes known vulnerabilities in used open-source libraries.
In addition, the following improvements have been implemented:
HMI
- Hardening against DoS attacks. - Hardening against memory leak problems in case of network attacks.
WBM
- Umlauts in the password of the &amp;#39;User Manager&amp;#39; were not handled correctly. The password rule for upper and lower case was not followed. This could lead to unintentionally weaker passwords.- Hardening of WBM against Cross-Site-Scripting.
User Manager
- In security notifications &amp;#39;SecurityToken&amp;#39; was always displayed as &amp;#39;0000000&amp;#39; when creating or modifying users.- Hardening of Trust and Identity Stores.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2023-001</guid>
    </item>
    <item>
      <title>VDE-2024-017 — Pepperl+Fuchs: ICE2- * and ICE3- * are affected by multiple vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2024-017</link>
      <description>&lt;p&gt;Critical vulnerabilities have been discovered in the product due to outdated software components.The impact of the vulnerabilities on the affected device may result in&lt;/p&gt;
&lt;p&gt;Denial of service
Bypassing of authentication
Information disclosure&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Critical vulnerabilities have been discovered in the product due to outdated software components.The impact of the vulnerabilities on the affected device may result in&lt;/p&gt;
&lt;p&gt;Denial of service
Bypassing of authentication
Information disclosure&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2024-017</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-2251 — Aruba ClearPass Policy Manager: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2251</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Aruba ClearPass Policy Manager ausnutzen, um SQL Injection- und Cross Site Scripting Angriffe durchzuführen, Code zur Ausführung zu bringen, seine Rechte zu erweitern oder Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Aruba ClearPass Policy Manager ausnutzen, um SQL Injection- und Cross Site Scripting Angriffe durchzuführen, Code zur Ausführung zu bringen, seine Rechte zu erweitern oder Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2251</guid>
    </item>
  </channel>
</rss>
