<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 04:39:58 +0000</lastBuildDate>
    <item>
      <title>bdu:2021-01783</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-01783</link>
      <description>bdu:2021-01783</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-01783</guid>
    </item>
    <item>
      <title>EUVD-2026-322653</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-322653</link>
      <description>EUVD-2026-322653</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-322653</guid>
    </item>
    <item>
      <title>fkie_cve-2020-28209</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-28209</link>
      <description>&lt;p&gt;A CWE-428 Windows Unquoted Search Path vulnerability exists in EcoStruxure Building Operation Enterprise Server installer V1.9 - V3.1 and Enterprise Central installer V2.0 - V3.1 that could cause any local Windows user who has write permission on at least one of the subfolders of the Connect Agent service binary path, being able to gain the privilege of the user who started the service. By default, the Enterprise Server and Enterprise Central is always installed at a location requiring Administrator privileges so the vulnerability is only valid if the application has been installed on a non-secure location.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A CWE-428 Windows Unquoted Search Path vulnerability exists in EcoStruxure Building Operation Enterprise Server installer V1.9 - V3.1 and Enterprise Central installer V2.0 - V3.1 that could cause any local Windows user who has write permission on at least one of the subfolders of the Connect Agent service binary path, being able to gain the privilege of the user who started the service. By default, the Enterprise Server and Enterprise Central is always installed at a location requiring Administrator privileges so the vulnerability is only valid if the application has been installed on a non-secure location.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-28209</guid>
    </item>
    <item>
      <title>GHSA-v6vj-vcw7-qf3c</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v6vj-vcw7-qf3c</link>
      <description>&lt;p&gt;A CWE-428 Windows Unquoted Search Path vulnerability exists in EcoStruxure Building Operation Enterprise Server installer V1.9 - V3.1 and Enterprise Central installer V2.0 - V3.1 that could cause any local Windows user who has write permission on at least one of the subfolders of the Connect Agent service binary path, being able to gain the privilege of the user who started the service. By default, the Enterprise Server and Enterprise Central is always installed at a location requiring Administrator privileges so the vulnerability is only valid if the application has been installed on a non-secure location.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A CWE-428 Windows Unquoted Search Path vulnerability exists in EcoStruxure Building Operation Enterprise Server installer V1.9 - V3.1 and Enterprise Central installer V2.0 - V3.1 that could cause any local Windows user who has write permission on at least one of the subfolders of the Connect Agent service binary path, being able to gain the privilege of the user who started the service. By default, the Enterprise Server and Enterprise Central is always installed at a location requiring Administrator privileges so the vulnerability is only valid if the application has been installed on a non-secure location.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v6vj-vcw7-qf3c</guid>
    </item>
    <item>
      <title>gsd-2020-28209</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-28209</link>
      <description>gsd-2020-28209</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-28209</guid>
    </item>
    <item>
      <title>ICSA-21-063-02 — ICSA-21-063-02_Schneider Electric EcoStruxure Building Operation (EBO)</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-21-063-02</link>
      <description>&lt;p&gt;An unrestricted upload of a file with dangerous type vulnerability could allow an authenticated remote user to upload arbitrary files due to incorrect verification of user supplied files and achieve remote code execution.CVE-2020-7569 has been assigned to this vulnerability. A CVSS v3 base score of 4.6 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L). An improper neutralization of an input during webpage generation vulnerability could allow an authenticated remote user to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data and achieve a stored cross-site scripting attack against other WebReport users.CVE-2020-7570 has been assigned to this vulnerability. A CVSS v3 base score of 6.4 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L). Multiple improper neutralizations of an input during webpage generation vulnerabilities could allow a remote attacker to inject arbitrary web script or HTML due to incorrect sanitization of user supplied data and achieve a reflected cross-site scripting attack against other WebReport users.CVE-2020-7571 has been assigned to this vulnerability. A CVSS v3 base score of 6.1 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). An improper restriction of XML external entity reference vulnerability could allow an authenticated remote user to inject arbitrary XML code and obtain disclosure of confidential data, cause…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An unrestricted upload of a file with dangerous type vulnerability could allow an authenticated remote user to upload arbitrary files due to incorrect verification of user supplied files and achieve remote code execution.CVE-2020-7569 has been assigned to this vulnerability. A CVSS v3 base score of 4.6 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L). An improper neutralization of an input during webpage generation vulnerability could allow an authenticated remote user to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data and achieve a stored cross-site scripting attack against other WebReport users.CVE-2020-7570 has been assigned to this vulnerability. A CVSS v3 base score of 6.4 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L). Multiple improper neutralizations of an input during webpage generation vulnerabilities could allow a remote attacker to inject arbitrary web script or HTML due to incorrect sanitization of user supplied data and achieve a reflected cross-site scripting attack against other WebReport users.CVE-2020-7571 has been assigned to this vulnerability. A CVSS v3 base score of 6.1 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). An improper restriction of XML external entity reference vulnerability could allow an authenticated remote user to inject arbitrary XML code and obtain disclosure of confidential data, cause…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-21-063-02</guid>
    </item>
    <item>
      <title>SEVD-2020-315-04 — EcoStruxure Building Operation (EBO)</title>
      <link>https://cve.radiocsirt.org/vuln/sevd-2020-315-04</link>
      <description>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities in its EcoStruxure Building Operation&#13;
(EBO) product offerings. More information on the product line can be found at the following link:&#13;
https://www.se.com/ww/en/product-range-presentation/62111-ecostruxure%E2%84%A2-&#13;
building-operation/?parent-subcategory-id=1210&amp;amp;filter=business-2-building-automation-andcontrol#tabs-top&#13;
Failure to apply the mitigations/remediations provided below may risk various types of attacks &#13;
and cause various types of impact (see information below for each vulnerability).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities in its EcoStruxure Building Operation&#13;
(EBO) product offerings. More information on the product line can be found at the following link:&#13;
https://www.se.com/ww/en/product-range-presentation/62111-ecostruxure%E2%84%A2-&#13;
building-operation/?parent-subcategory-id=1210&amp;amp;filter=business-2-building-automation-andcontrol#tabs-top&#13;
Failure to apply the mitigations/remediations provided below may risk various types of attacks &#13;
and cause various types of impact (see information below for each vulnerability).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sevd-2020-315-04</guid>
    </item>
  </channel>
</rss>
