<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 21:18:24 +0000</lastBuildDate>
    <item>
      <title>cnvd-2020-17488</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-17488</link>
      <description>cnvd-2020-17488</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-17488</guid>
    </item>
    <item>
      <title>EUVD-2026-49961</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-49961</link>
      <description>EUVD-2026-49961</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-49961</guid>
    </item>
    <item>
      <title>fkie_cve-2019-5106</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2019-5106</link>
      <description>&lt;p&gt;A hard-coded encryption key vulnerability exists in the authentication functionality of WAGO e!Cockpit version 1.5.1.1. An attacker with access to communications between e!Cockpit and CoDeSyS Gateway can trivially recover the password of any user attempting to log in, in plain text.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A hard-coded encryption key vulnerability exists in the authentication functionality of WAGO e!Cockpit version 1.5.1.1. An attacker with access to communications between e!Cockpit and CoDeSyS Gateway can trivially recover the password of any user attempting to log in, in plain text.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2019-5106</guid>
    </item>
    <item>
      <title>GHSA-f98g-j2jx-44x5</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-f98g-j2jx-44x5</link>
      <description>&lt;p&gt;A hard-coded encryption key vulnerability exists in the authentication functionality of WAGO e!Cockpit version 1.5.1.1. An attacker with access to communications between e!Cockpit and CoDeSyS Gateway can trivially recover the password of any user attempting to log in, in plain text.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A hard-coded encryption key vulnerability exists in the authentication functionality of WAGO e!Cockpit version 1.5.1.1. An attacker with access to communications between e!Cockpit and CoDeSyS Gateway can trivially recover the password of any user attempting to log in, in plain text.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-f98g-j2jx-44x5</guid>
    </item>
    <item>
      <title>gsd-2019-5106</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2019-5106</link>
      <description>gsd-2019-5106</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2019-5106</guid>
    </item>
    <item>
      <title>VDE-2020-004 — WAGO: e!Cockpit cleartext communication and hardcoded key</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2020-004</link>
      <description>&lt;p&gt;The communication between e!Cockpit and the programmable logic controller is not encrypted. The broken cryptographic algorithm allows an attacker to decode the password for the e!Cockpit communication and with this to manipulate the application.&lt;/p&gt;
&lt;p&gt;The password used by e!Cockpit for authentication against the PLC is encrypted with a hard-coded key. An attacker is able to decrypt the password by listening to the network traffic.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The communication between e!Cockpit and the programmable logic controller is not encrypted. The broken cryptographic algorithm allows an attacker to decode the password for the e!Cockpit communication and with this to manipulate the application.&lt;/p&gt;
&lt;p&gt;The password used by e!Cockpit for authentication against the PLC is encrypted with a hard-coded key. An attacker is able to decrypt the password by listening to the network traffic.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2020-004</guid>
    </item>
  </channel>
</rss>
