<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 13:24:45 +0000</lastBuildDate>
    <item>
      <title>certfr-2021-avi-517 — De multiples vulnérabilités ont été découvertes dans les produits
Schneider. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-517</link>
      <description>certfr-2021-avi-517</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-517</guid>
    </item>
    <item>
      <title>EUVD-2026-175626</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-175626</link>
      <description>EUVD-2026-175626</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-175626</guid>
    </item>
    <item>
      <title>fkie_cve-2020-12525</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-12525</link>
      <description>&lt;p&gt;M&amp;amp;M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;M&amp;amp;M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-12525</guid>
    </item>
    <item>
      <title>GHSA-v82r-x75j-xwxm</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v82r-x75j-xwxm</link>
      <description>&lt;p&gt;M&amp;amp;M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;M&amp;amp;M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v82r-x75j-xwxm</guid>
    </item>
    <item>
      <title>gsd-2020-12525</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-12525</link>
      <description>gsd-2020-12525</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-12525</guid>
    </item>
    <item>
      <title>ICSA-21-021-05 — WAGO M&amp;M Software fdtCONTAINER (Update C)</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-21-021-05</link>
      <description>&lt;p&gt;A vulnerability has been discovered in the fdtCONTAINER component issued by M&amp;amp;M Software and used by other products, including RTIS and PACTware. An attacker could exploit this vulnerability on the workstation by supplying/providing a manipulated project file. If that manipulated project file is loaded, malicious code could be executed without notice.CVE-2020-12525 has been assigned to this vulnerability. A CVSS v3 base score of 7.3 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability has been discovered in the fdtCONTAINER component issued by M&amp;amp;M Software and used by other products, including RTIS and PACTware. An attacker could exploit this vulnerability on the workstation by supplying/providing a manipulated project file. If that manipulated project file is loaded, malicious code could be executed without notice.CVE-2020-12525 has been assigned to this vulnerability. A CVSS v3 base score of 7.3 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-21-021-05</guid>
    </item>
    <item>
      <title>SEVD-2020-252-01 — SCADAPack x70 Remote Connect and SCADAPack x70 Security Administrator</title>
      <link>https://cve.radiocsirt.org/vuln/sevd-2020-252-01</link>
      <description>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities in the SCADAPack x70 Remote Connect&#13;
and the SCADAPack x70 Security Administrator applications.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities in the SCADAPack x70 Remote Connect&#13;
and the SCADAPack x70 Security Administrator applications.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sevd-2020-252-01</guid>
    </item>
    <item>
      <title>VDE-2020-048 — M&amp;M Software (WAGO): Deserialisation of untrusted data in fdtContainer</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2020-048</link>
      <description>&lt;p&gt;The fdtCONTAINER component is integrated into an application (host application). The fdtCONTAINER application is a specific host application which integrates the fdtCONTAINER component.&lt;/p&gt;
&lt;p&gt;The fdtCONTAINER component exchanges binary data blobs with such a host application. Typically, the host application saves these binary data blobs into a project storage (project file or a project database).&lt;/p&gt;
&lt;p&gt;To manipulate the data inside the project storage, the attacker needs write access to this project storage. Additionally, the manipulated project needs to be opened by the host application. It depends on the host application whether opening the project requires a user action or not. In
fdtCONTAINER applications, the user has to open the manipulated project file manually.&lt;/p&gt;
&lt;p&gt;In the case of opening a stored project, the deserialization of the manipulated data can be exploited.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The fdtCONTAINER component is integrated into an application (host application). The fdtCONTAINER application is a specific host application which integrates the fdtCONTAINER component.&lt;/p&gt;
&lt;p&gt;The fdtCONTAINER component exchanges binary data blobs with such a host application. Typically, the host application saves these binary data blobs into a project storage (project file or a project database).&lt;/p&gt;
&lt;p&gt;To manipulate the data inside the project storage, the attacker needs write access to this project storage. Additionally, the manipulated project needs to be opened by the host application. It depends on the host application whether opening the project requires a user action or not. In
fdtCONTAINER applications, the user has to open the manipulated project file manually.&lt;/p&gt;
&lt;p&gt;In the case of opening a stored project, the deserialization of the manipulated data can be exploited.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2020-048</guid>
    </item>
    <item>
      <title>VDE-2021-001 — Pepperl+Fuchs: Vulnerability allowing code-excution in PACTware &lt;=5.0.5.31</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2021-001</link>
      <description>&lt;p&gt;A critical vulnerability has been discovered in the fdtCONTAINER component by M&amp;amp;M Software GmbH used by PACTware.
While de-serializing PACTware 5 project files (loading PW5 files) the vulnerability can be exploited to execute arbitrary code.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A critical vulnerability has been discovered in the fdtCONTAINER component by M&amp;amp;M Software GmbH used by PACTware.
While de-serializing PACTware 5 project files (loading PW5 files) the vulnerability can be exploited to execute arbitrary code.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2021-001</guid>
    </item>
    <item>
      <title>VDE-2021-002 — Weidmueller: WI Manager affected by fdtContainer vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2021-002</link>
      <description>&lt;p&gt;A vulnerability has been discovered in the fdtCONTAINER component and application by M&amp;amp;M Software GmbH.
As this software is part of the Weidmüller FDT/DTM Software with WI Manager, this Weidmueller software is affected by the above vulnerability as well.&lt;/p&gt;
&lt;p&gt;The fdtCONTAINER component exchanges binary data blobs with the WI Manager. The WI Manager saves these binary data blobs into a project file.&lt;/p&gt;
&lt;p&gt;If an attacker gets write access to the project file, the project file can be manipulated to contain malicious code.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability has been discovered in the fdtCONTAINER component and application by M&amp;amp;M Software GmbH.
As this software is part of the Weidmüller FDT/DTM Software with WI Manager, this Weidmueller software is affected by the above vulnerability as well.&lt;/p&gt;
&lt;p&gt;The fdtCONTAINER component exchanges binary data blobs with the WI Manager. The WI Manager saves these binary data blobs into a project file.&lt;/p&gt;
&lt;p&gt;If an attacker gets write access to the project file, the project file can be manipulated to contain malicious code.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2021-002</guid>
    </item>
    <item>
      <title>VDE-2021-005 — Endress+Hauser: Multiple Devices affected by fdtContainer vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2021-005</link>
      <description>&lt;p&gt;The fdtCONTAINER component is integrated into an application (host application). The fdtCONTAINER application is a specific host application which integrates the fdtCONTAINER component.&lt;/p&gt;
&lt;p&gt;The fdtCONTAINER component exchanges binary data blobs with such a host application. Typically, the host application saves these binary data blobs into a project storage (project file or a project database).&lt;/p&gt;
&lt;p&gt;To manipulate the data inside the project storage, the attacker needs write access to this project storage. Additionally, the manipulated project needs to be opened by the host application. It depends on the host application whether opening the project requires a user action or not. In
fdtCONTAINER applications, the user has to open the manipulated project file manually.&lt;/p&gt;
&lt;p&gt;In the case of opening a stored project, the deserialization of the manipulated data can be exploited.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The fdtCONTAINER component is integrated into an application (host application). The fdtCONTAINER application is a specific host application which integrates the fdtCONTAINER component.&lt;/p&gt;
&lt;p&gt;The fdtCONTAINER component exchanges binary data blobs with such a host application. Typically, the host application saves these binary data blobs into a project storage (project file or a project database).&lt;/p&gt;
&lt;p&gt;To manipulate the data inside the project storage, the attacker needs write access to this project storage. Additionally, the manipulated project needs to be opened by the host application. It depends on the host application whether opening the project requires a user action or not. In
fdtCONTAINER applications, the user has to open the manipulated project file manually.&lt;/p&gt;
&lt;p&gt;In the case of opening a stored project, the deserialization of the manipulated data can be exploited.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2021-005</guid>
    </item>
  </channel>
</rss>
