<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 13:00:24 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-00987</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-00987</link>
      <description>bdu:2022-00987</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-00987</guid>
    </item>
    <item>
      <title>certfr-2020-avi-550 — De multiples vulnérabilités ont été découvertes dans les produits
Siemens. Certaines d'entre elles permettent à un atta…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2020-avi-550</link>
      <description>certfr-2020-avi-550</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2020-avi-550</guid>
    </item>
    <item>
      <title>cnvd-2020-51240</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-51240</link>
      <description>cnvd-2020-51240</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-51240</guid>
    </item>
    <item>
      <title>EUVD-2026-43389</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-43389</link>
      <description>EUVD-2026-43389</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-43389</guid>
    </item>
    <item>
      <title>fkie_cve-2020-16233</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-16233</link>
      <description>&lt;p&gt;An attacker could send a specially crafted packet that could have CodeMeter (All versions prior to 7.10) send back packets containing data from the heap.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An attacker could send a specially crafted packet that could have CodeMeter (All versions prior to 7.10) send back packets containing data from the heap.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-16233</guid>
    </item>
    <item>
      <title>FSA-202601 — Several CODESYS vulnerabilities in Festo Automation Suite</title>
      <link>https://cve.radiocsirt.org/vuln/fsa-202601</link>
      <description>&lt;p&gt;Starting with Festo Automation Suite (FAS) version 2.8.0.138, the suite is delivered only with a connector to Codesys, rather than including Codesys directly. Prior to this version, Codesys was bundled within the FAS installation. From version 2.8.0.138 onwards, customers are required to download and install Codesys independently.&lt;/p&gt;
&lt;p&gt;This change impacts the handling of security vulnerabilities (CVEs) related to Codesys. Any Codesys-related security issues must now be addressed by the customer through their separate Codesys installation. The FAS itself includes only the connector component, which is maintained and updated within the suite.&lt;/p&gt;
&lt;p&gt;Please ensure that Codesys is kept up to date independently to mitigate any potential security risks associated with the Codesys software.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Starting with Festo Automation Suite (FAS) version 2.8.0.138, the suite is delivered only with a connector to Codesys, rather than including Codesys directly. Prior to this version, Codesys was bundled within the FAS installation. From version 2.8.0.138 onwards, customers are required to download and install Codesys independently.&lt;/p&gt;
&lt;p&gt;This change impacts the handling of security vulnerabilities (CVEs) related to Codesys. Any Codesys-related security issues must now be addressed by the customer through their separate Codesys installation. The FAS itself includes only the connector component, which is maintained and updated within the suite.&lt;/p&gt;
&lt;p&gt;Please ensure that Codesys is kept up to date independently to mitigate any potential security risks associated with the Codesys software.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fsa-202601</guid>
    </item>
    <item>
      <title>GHSA-8xr9-2r57-gg3h</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8xr9-2r57-gg3h</link>
      <description>&lt;p&gt;An attacker could send a specially crafted packet that could have CodeMeter (All versions prior to 7.10) send back packets containing data from the heap.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An attacker could send a specially crafted packet that could have CodeMeter (All versions prior to 7.10) send back packets containing data from the heap.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8xr9-2r57-gg3h</guid>
    </item>
    <item>
      <title>gsd-2020-16233</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-16233</link>
      <description>gsd-2020-16233</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-16233</guid>
    </item>
    <item>
      <title>ICSA-20-203-01 — Wibu-Systems CodeMeter (Update F)</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-20-203-01</link>
      <description>&lt;p&gt;Multiple memory corruption vulnerabilities exist where the packet parser mechanism does not verify length fields. An attacker could send specially crafted packets to exploit these vulnerabilities.CVE-2020-14509 has been assigned to this vulnerability. A CVSS v3 base score of 10.0 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). Protocol encryption can be easily broken and the server accepts external connections, which may allow an attacker to remotely communicate with the CodeMeter API.CVE-2020-14517 has been assigned to this vulnerability. A CVSS v3 base score of 9.4 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H). This vulnerability allows an attacker to use the internal WebSockets API via a specifically crafted Java Script payload, which may allow alteration or creation of license files when combined with CVE-2020-14515.CVE-2020-14519 has been assigned to this vulnerability. A CVSS v3 base score of 8.1 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H). CodeMeter and the software using it may crash while processing a specifically crafted license file due to unverified length fields.CVE-2020-14513 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). There is an issue in the license-file signature checking mechanism, which allows attackers to build arbitrary license f…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple memory corruption vulnerabilities exist where the packet parser mechanism does not verify length fields. An attacker could send specially crafted packets to exploit these vulnerabilities.CVE-2020-14509 has been assigned to this vulnerability. A CVSS v3 base score of 10.0 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). Protocol encryption can be easily broken and the server accepts external connections, which may allow an attacker to remotely communicate with the CodeMeter API.CVE-2020-14517 has been assigned to this vulnerability. A CVSS v3 base score of 9.4 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H). This vulnerability allows an attacker to use the internal WebSockets API via a specifically crafted Java Script payload, which may allow alteration or creation of license files when combined with CVE-2020-14515.CVE-2020-14519 has been assigned to this vulnerability. A CVSS v3 base score of 8.1 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H). CodeMeter and the software using it may crash while processing a specifically crafted license file due to unverified length fields.CVE-2020-14513 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). There is an issue in the license-file signature checking mechanism, which allows attackers to build arbitrary license f…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-20-203-01</guid>
    </item>
    <item>
      <title>SEVD-2020-287-02 — Wibu-Systems CodeMeter Vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/sevd-2020-287-02</link>
      <description>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities disclosed by Wibu-Systems in the &#13;
CodeMeter licensing manager product which is used by some Schneider Electric and Eurotherm &#13;
offers.&#13;
Failure to apply the remediations provided below may risk various types of attack on &#13;
CodeMeter, which could allow an attacker to alter and forge a license file, cause a denial-ofservice condition, potentially attain remote code execution, read heap data, and prevent normal &#13;
operation of third-party software dependent on the CodeMeter. &#13;
December 2020 update: The CodeMeter V7.10a fix qualification is confirmed for EcoStruxure&#13;
Machine SCADA Expert.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities disclosed by Wibu-Systems in the &#13;
CodeMeter licensing manager product which is used by some Schneider Electric and Eurotherm &#13;
offers.&#13;
Failure to apply the remediations provided below may risk various types of attack on &#13;
CodeMeter, which could allow an attacker to alter and forge a license file, cause a denial-ofservice condition, potentially attain remote code execution, read heap data, and prevent normal &#13;
operation of third-party software dependent on the CodeMeter. &#13;
December 2020 update: The CodeMeter V7.10a fix qualification is confirmed for EcoStruxure&#13;
Machine SCADA Expert.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sevd-2020-287-02</guid>
    </item>
    <item>
      <title>VDE-2020-030 — PHOENIX CONTACT: Products utilizing WIBU-SYSTEMS CodeMeter components</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2020-030</link>
      <description>&lt;p&gt;Several vulnerabilities have been discovered in WIBU-SYSTEMS CodeMeter and published 08 September 2020. Phoenix Contact is only affected by a subset of these vulnerabilities.&lt;/p&gt;
&lt;p&gt;Phoenix Contact products are not affected by vulnerabilities WIBU-200521-01 (CVE-2020- 14513), WIBU-200521-04 (CVE-2020-14517, and WIBU-200521-06 (CVE-2020-14515). For further Information please refer to WIBU Advisories directly at https://wibu.com/support/security-advisories.html&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Several vulnerabilities have been discovered in WIBU-SYSTEMS CodeMeter and published 08 September 2020. Phoenix Contact is only affected by a subset of these vulnerabilities.&lt;/p&gt;
&lt;p&gt;Phoenix Contact products are not affected by vulnerabilities WIBU-200521-01 (CVE-2020- 14513), WIBU-200521-04 (CVE-2020-14517, and WIBU-200521-06 (CVE-2020-14515). For further Information please refer to WIBU Advisories directly at https://wibu.com/support/security-advisories.html&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2020-030</guid>
    </item>
    <item>
      <title>VDE-2020-031 — Endress+Hauser: Multiple products prone to WIBU CodeMeter vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2020-031</link>
      <description>&lt;p&gt;For further Information please refer to WIBU Advisories directly at https://wibu.com/support/security-advisories.html and the aforementioned CVE-IDs.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;For further Information please refer to WIBU Advisories directly at https://wibu.com/support/security-advisories.html and the aforementioned CVE-IDs.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2020-031</guid>
    </item>
    <item>
      <title>VDE-2020-032 — WAGO: Vulnerable WIBU-SYSTEMS Codemeter installed through e!COCKPIT</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2020-032</link>
      <description>&lt;p&gt;Multiple vulnerabilties were reported in WIBU-SYSTEMS Codemeter. WIBU-SYSTEMS Codemeter is installed by default during e!COCKPIT installation. All currently existing e!COCKPIT installation bundles contain vulnerable versions of WIBU-SYSTEMS Codemeter.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilties were reported in WIBU-SYSTEMS Codemeter. WIBU-SYSTEMS Codemeter is installed by default during e!COCKPIT installation. All currently existing e!COCKPIT installation bundles contain vulnerable versions of WIBU-SYSTEMS Codemeter.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2020-032</guid>
    </item>
    <item>
      <title>VDE-2020-033 — Pilz: Multiple products prone to WIBU-SYSTEMS CodeMeter vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2020-033</link>
      <description>&lt;p&gt;A number of Pilz software tools use the Software CodeMeter Runtime application from WIBU-SYSTEMS AG to manage licences. This application contains a number of vulnerabilities, which enable an attacker to change and falsify a licence file, prevent normal operation of Code- Meter (Denial-of-Service) and potentially execute arbitrary code.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A number of Pilz software tools use the Software CodeMeter Runtime application from WIBU-SYSTEMS AG to manage licences. This application contains a number of vulnerabilities, which enable an attacker to change and falsify a licence file, prevent normal operation of Code- Meter (Denial-of-Service) and potentially execute arbitrary code.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2020-033</guid>
    </item>
    <item>
      <title>VDE-2020-034 — Pepperl+Fuchs: VMT MSS and VMT IS - Several vulnerabilities in products utilizing WIBU-SYSTEMS CodeMeter components</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2020-034</link>
      <description>&lt;p&gt;Several vulnerabilities have been discovered in the utilized component WIBU-SYSTEMS CodeMeter Runtime.
For detailed information please refer to WIBU-SYSTEMS original Advisories at https://wibu.com/support/security-advisories.html&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Several vulnerabilities have been discovered in the utilized component WIBU-SYSTEMS CodeMeter Runtime.
For detailed information please refer to WIBU-SYSTEMS original Advisories at https://wibu.com/support/security-advisories.html&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2020-034</guid>
    </item>
    <item>
      <title>VDE-2020-039 — TRUMPF: Multiple products prone to WIBU CodeMeter vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2020-039</link>
      <description>&lt;p&gt;A number of TRUMPF CAD/CAM software tools use the CodeMeter Runtime application from WIBU-SYSTEMS AG to manage licences. This application contains a number of vulnerabilities, which enable an attacker to prevent normal operation of CodeMeter, resulting in a Denial-of-Service and potentially execute arbitrary code.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A number of TRUMPF CAD/CAM software tools use the CodeMeter Runtime application from WIBU-SYSTEMS AG to manage licences. This application contains a number of vulnerabilities, which enable an attacker to prevent normal operation of CodeMeter, resulting in a Denial-of-Service and potentially execute arbitrary code.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2020-039</guid>
    </item>
    <item>
      <title>VDE-2020-041 — Weidmueller: u-create studio &lt; 1.20.2 affected by WIBU-SYSTEMS CodeMeter vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2020-041</link>
      <description>&lt;p&gt;WIBU-SYSTEMS report multiple vulnerabilities in their CodeMeter Runtime software. As part of the Weidmüller u-create studio installation the WIBU-SYSTEMS CodeMeter is installed by default. As the u-create studio installation bundle contains vulnerable versions of WIBU-SYSTEMS CodeMeter, the u-create studio is affected by a subset of these vulnerabilities. For details refer to section &amp;#34;Impact&amp;#34;.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;WIBU-SYSTEMS report multiple vulnerabilities in their CodeMeter Runtime software. As part of the Weidmüller u-create studio installation the WIBU-SYSTEMS CodeMeter is installed by default. As the u-create studio installation bundle contains vulnerable versions of WIBU-SYSTEMS CodeMeter, the u-create studio is affected by a subset of these vulnerabilities. For details refer to section &amp;#34;Impact&amp;#34;.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2020-041</guid>
    </item>
  </channel>
</rss>
