<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 23:13:01 +0000</lastBuildDate>
    <item>
      <title>cnvd-2018-18592</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2018-18592</link>
      <description>cnvd-2018-18592</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2018-18592</guid>
    </item>
    <item>
      <title>EUVD-2026-324151</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-324151</link>
      <description>EUVD-2026-324151</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-324151</guid>
    </item>
    <item>
      <title>fkie_cve-2018-8851</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2018-8851</link>
      <description>&lt;p&gt;Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. The devices store passwords in plaintext, which may allow an attacker with access to the configuration file to log into the SmartServer web user interface.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. The devices store passwords in plaintext, which may allow an attacker with access to the configuration file to log into the SmartServer web user interface.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2018-8851</guid>
    </item>
    <item>
      <title>GHSA-37x4-rhq4-f92v</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-37x4-rhq4-f92v</link>
      <description>&lt;p&gt;Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. The devices store passwords in plaintext, which may allow an attacker with access to the configuration file to log into the SmartServer web user interface.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. The devices store passwords in plaintext, which may allow an attacker with access to the configuration file to log into the SmartServer web user interface.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-37x4-rhq4-f92v</guid>
    </item>
    <item>
      <title>gsd-2018-8851</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2018-8851</link>
      <description>gsd-2018-8851</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2018-8851</guid>
    </item>
    <item>
      <title>ICSA-18-200-03 — Echelon SmartServer 1, SmartServer 2, SmartServer 3, i.LON 100, i.LON 600 (Update A)</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-18-200-03</link>
      <description>&lt;p&gt;An attacker can use the SOAP API to retrieve and change sensitive configuration items such as the usernames and passwords for the Web and FTP servers. This vulnerability does not affect the i.LON 600 product.CVE-2018-10627 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). An attacker can bypass the required authentication specified in the security configuration file by including extra characters in the directory name when specifying the directory to be accessed.CVE-2018-8859 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The devices store passwords in plaintext, which may allow an attacker with access to the configuration file to log into the SmartServer web user interface.CVE-2018-8851 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The devices allow unencrypted Web connections by default, and devices can receive configuration and firmware updates by unsecure FTP.CVE-2018-8855 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An attacker can use the SOAP API to retrieve and change sensitive configuration items such as the usernames and passwords for the Web and FTP servers. This vulnerability does not affect the i.LON 600 product.CVE-2018-10627 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). An attacker can bypass the required authentication specified in the security configuration file by including extra characters in the directory name when specifying the directory to be accessed.CVE-2018-8859 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The devices store passwords in plaintext, which may allow an attacker with access to the configuration file to log into the SmartServer web user interface.CVE-2018-8851 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The devices allow unencrypted Web connections by default, and devices can receive configuration and firmware updates by unsecure FTP.CVE-2018-8855 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-18-200-03</guid>
    </item>
  </channel>
</rss>
