<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 17:36:04 +0000</lastBuildDate>
    <item>
      <title>bdu:2021-03140</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-03140</link>
      <description>bdu:2021-03140</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-03140</guid>
    </item>
    <item>
      <title>certfr-2016-avi-320 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;OpenSSL&lt;/span&gt;. Certaines d'entre elles permett…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2016-avi-320</link>
      <description>certfr-2016-avi-320</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2016-avi-320</guid>
    </item>
    <item>
      <title>cnvd-2016-06765</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2016-06765</link>
      <description>cnvd-2016-06765</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2016-06765</guid>
    </item>
    <item>
      <title>EUVD-2026-323019</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-323019</link>
      <description>EUVD-2026-323019</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-323019</guid>
    </item>
    <item>
      <title>fkie_cve-2016-2183</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2016-2183</link>
      <description>&lt;p&gt;The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a &amp;#34;Sweet32&amp;#34; attack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a &amp;#34;Sweet32&amp;#34; attack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2016-2183</guid>
    </item>
    <item>
      <title>GHSA-w2rw-pv8p-h9c8</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-w2rw-pv8p-h9c8</link>
      <description>&lt;p&gt;The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a &amp;#34;Sweet32&amp;#34; attack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a &amp;#34;Sweet32&amp;#34; attack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-w2rw-pv8p-h9c8</guid>
    </item>
    <item>
      <title>gsd-2016-2183</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2016-2183</link>
      <description>gsd-2016-2183</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2016-2183</guid>
    </item>
    <item>
      <title>ICSA-21-075-02 — GE UR Family (Update A)</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-21-075-02</link>
      <description>&lt;p&gt;Prior to UR firmware Version 8.1x, UR supported various encryption and MAC algorithms for SSH communication, some of which are weak. The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a &amp;#34;Sweet32&amp;#34; attack. Prior to UR firmware Version 8.1x, UR supported various encryption and MAC algorithms for SSH communication, some of which are weak. The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large number of sessions that use the same plaintext. Prior to firmware Version 7.4x, UR supported only SSHv2. Starting from firmware Version 7.4x, UR added support to SSHv1. SSHv1 has known vulnerabilities (SSH protocol session key retrieval and insertion attack). SSH 1.2.25, 1.2.23, and other versions, when used in in CBC (Cipher Block Chaining) or CFB (Cipher Feedback 64 bits) modes, allows remote attackers to insert arbitrary data into an existing stream between an SSH client and server by using a known plaintext attack and computing a valid CRC-32 checksum for the packet, aka the &amp;#34;SSH insertion attack.&amp;#34; GE U…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Prior to UR firmware Version 8.1x, UR supported various encryption and MAC algorithms for SSH communication, some of which are weak. The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a &amp;#34;Sweet32&amp;#34; attack. Prior to UR firmware Version 8.1x, UR supported various encryption and MAC algorithms for SSH communication, some of which are weak. The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large number of sessions that use the same plaintext. Prior to firmware Version 7.4x, UR supported only SSHv2. Starting from firmware Version 7.4x, UR added support to SSHv1. SSHv1 has known vulnerabilities (SSH protocol session key retrieval and insertion attack). SSH 1.2.25, 1.2.23, and other versions, when used in in CBC (Cipher Block Chaining) or CFB (Cipher Feedback 64 bits) modes, allows remote attackers to insert arbitrary data into an existing stream between an SSH client and server by using a known plaintext attack and computing a valid CRC-32 checksum for the packet, aka the &amp;#34;SSH insertion attack.&amp;#34; GE U…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-21-075-02</guid>
    </item>
    <item>
      <title>jvndb-2023-000029</title>
      <link>https://cve.radiocsirt.org/vuln/jvndb-2023-000029</link>
      <description>&lt;p&gt;SkyBridge MB-A100/A110/A200/A130 SkySpider MB-R210 provided by Seiko Solutions Inc. contain multiple vulnerabilities listed below.&#13;
&amp;lt;ul&amp;gt;&#13;
&amp;lt;li&amp;gt;Exposure of sensitive information to an unauthorized actor (CWE-200) - CVE-2016-2183&#13;
&amp;lt;li&amp;gt;Command injection (CWE-77) - CVE-2022-36556&#13;
&amp;lt;li&amp;gt;Unrestricted upload of file with dangerous type (CWE-434) - CVE-2022-36557&#13;
&amp;lt;li&amp;gt;Use of hard-coded credentials (CWE-798) - CVE-2022-36558&#13;
&amp;lt;li&amp;gt;Command injection (CWE-77) - CVE-2022-36559&#13;
&amp;lt;li&amp;gt;Use of hard-coded credentials (CWE-798) - CVE-2022-36560&#13;
&amp;lt;li&amp;gt;Improper privilege management (CWE-269) - CVE-2023-22361&#13;
&amp;lt;li&amp;gt;Missing authentication for critical function (CWE-306) - CVE-2023-22441&#13;
&amp;lt;li&amp;gt;Improper access control (CWE-284) - CVE-2023-23578&#13;
&amp;lt;li&amp;gt;Improper following of a certificate&amp;#39;s chain of trust (CWE-296) - CVE-2023-23901&#13;
&amp;lt;li&amp;gt;Missing authentication for critical function (CWE-306) - CVE-2023-23906&#13;
&amp;lt;li&amp;gt;Cleartext storage of sensitive information (CWE-312) - CVE-2023-24586&#13;
&amp;lt;li&amp;gt;Cleartext transmission of sensitive information (CWE-319) - CVE-2023-25070&#13;
&amp;lt;li&amp;gt;Use of weak credentials (CWE-1391) - CVE-2023-25072&#13;
&amp;lt;li&amp;gt;Use of weak credentials (CWE-1391) - CVE-2023-25184&#13;
&amp;lt;/ul&amp;gt;&#13;
The developer states that attacks exploiting CVE-2022-36556 have been observed.&#13;
&#13;
&#13;
CVE-2023-22441&#13;
MASAHIRO IIDA of LAC Co., Ltd. reported this vulnerability to IPA.&#13;
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.&#13;
&#13;
CVE-2016-2183, CVE-2022-36556, CVE-2022-36557, CVE-2022-36558, CVE-20…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SkyBridge MB-A100/A110/A200/A130 SkySpider MB-R210 provided by Seiko Solutions Inc. contain multiple vulnerabilities listed below.&#13;
&amp;lt;ul&amp;gt;&#13;
&amp;lt;li&amp;gt;Exposure of sensitive information to an unauthorized actor (CWE-200) - CVE-2016-2183&#13;
&amp;lt;li&amp;gt;Command injection (CWE-77) - CVE-2022-36556&#13;
&amp;lt;li&amp;gt;Unrestricted upload of file with dangerous type (CWE-434) - CVE-2022-36557&#13;
&amp;lt;li&amp;gt;Use of hard-coded credentials (CWE-798) - CVE-2022-36558&#13;
&amp;lt;li&amp;gt;Command injection (CWE-77) - CVE-2022-36559&#13;
&amp;lt;li&amp;gt;Use of hard-coded credentials (CWE-798) - CVE-2022-36560&#13;
&amp;lt;li&amp;gt;Improper privilege management (CWE-269) - CVE-2023-22361&#13;
&amp;lt;li&amp;gt;Missing authentication for critical function (CWE-306) - CVE-2023-22441&#13;
&amp;lt;li&amp;gt;Improper access control (CWE-284) - CVE-2023-23578&#13;
&amp;lt;li&amp;gt;Improper following of a certificate&amp;#39;s chain of trust (CWE-296) - CVE-2023-23901&#13;
&amp;lt;li&amp;gt;Missing authentication for critical function (CWE-306) - CVE-2023-23906&#13;
&amp;lt;li&amp;gt;Cleartext storage of sensitive information (CWE-312) - CVE-2023-24586&#13;
&amp;lt;li&amp;gt;Cleartext transmission of sensitive information (CWE-319) - CVE-2023-25070&#13;
&amp;lt;li&amp;gt;Use of weak credentials (CWE-1391) - CVE-2023-25072&#13;
&amp;lt;li&amp;gt;Use of weak credentials (CWE-1391) - CVE-2023-25184&#13;
&amp;lt;/ul&amp;gt;&#13;
The developer states that attacks exploiting CVE-2022-36556 have been observed.&#13;
&#13;
&#13;
CVE-2023-22441&#13;
MASAHIRO IIDA of LAC Co., Ltd. reported this vulnerability to IPA.&#13;
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.&#13;
&#13;
CVE-2016-2183, CVE-2022-36556, CVE-2022-36557, CVE-2022-36558, CVE-20…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/jvndb-2023-000029</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:10247-1 — nodejs4-4.7.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10247-1</link>
      <description>&lt;p&gt;nodejs4-4.7.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nodejs4-4.7.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:10247-1</guid>
    </item>
    <item>
      <title>RHBA-2019:2581 — Red Hat Bug Fix Advisory: OpenShift Container Platform 3.11 images update</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2019:2581</link>
      <description>&lt;p&gt;SSL/TLS: Birthday attack against 64-bit block ciphers (SWEET32)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SSL/TLS: Birthday attack against 64-bit block ciphers (SWEET32)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2019:2581</guid>
    </item>
    <item>
      <title>SUSE-SU-2016:2387-1 — Security update for openssl</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2016:2387-1</link>
      <description>&lt;p&gt;Security update for openssl&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for openssl&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2016:2387-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2016-2183</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2016-2183</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: nss, Ubuntu:14.04:LTS: openjdk-6, Ubuntu:14.04:LTS: openjdk-7, Ubuntu:14.04:LTS: openssl, Ubuntu:16.04:LTS: nss, Ubuntu:16.04:LTS: openjdk-8, Ubuntu:16.04:LTS: openssl&lt;/p&gt;
&lt;p&gt;The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a &amp;#34;Sweet32&amp;#34; attack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: nss, Ubuntu:14.04:LTS: openjdk-6, Ubuntu:14.04:LTS: openjdk-7, Ubuntu:14.04:LTS: openssl, Ubuntu:16.04:LTS: nss, Ubuntu:16.04:LTS: openjdk-8, Ubuntu:16.04:LTS: openssl&lt;/p&gt;
&lt;p&gt;The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a &amp;#34;Sweet32&amp;#34; attack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2016-2183</guid>
    </item>
    <item>
      <title>VDE-2025-023 — Weidmueller: OpenSSL vulnerability in industrial ethernet switches</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2025-023</link>
      <description>&lt;p&gt;Multiple Weidmueller products are affected by an OpenSSL vulnerability.&lt;/p&gt;
&lt;p&gt;Weidmüller has released new firmwares of the affected products to fix the vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple Weidmueller products are affected by an OpenSSL vulnerability.&lt;/p&gt;
&lt;p&gt;Weidmüller has released new firmwares of the affected products to fix the vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2025-023</guid>
    </item>
    <item>
      <title>VDE-2025-078 — TRUMPF: Remote support uses an outdated encryption algorithm</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2025-078</link>
      <description>&lt;p&gt;The TRUMPF remote support infrastructure selects an outdated encryption algorithm when setting up communication channels for machines. This cannot be prevented for old machines. For most machines it is possible to change the encryption settings.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The TRUMPF remote support infrastructure selects an outdated encryption algorithm when setting up communication channels for machines. This cannot be prevented for old machines. For most machines it is possible to change the encryption settings.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2025-078</guid>
    </item>
    <item>
      <title>VDE-2026-013 — Helmholz: Use of a Broken or Risky Cryptographic Algorithm</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2026-013</link>
      <description>&lt;p&gt;Vulnerabilities in PROFINET-Switch devices with firmware &amp;lt;= V1.12.010 that allow an attacker to gain control over the device.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Vulnerabilities in PROFINET-Switch devices with firmware &amp;lt;= V1.12.010 that allow an attacker to gain control over the device.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2026-013</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1955 — OpenSSL: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1955</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in OpenSSL ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in OpenSSL ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1955</guid>
    </item>
  </channel>
</rss>
