<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 07:05:48 +0000</lastBuildDate>
    <item>
      <title>bdu:2021-03844</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-03844</link>
      <description>bdu:2021-03844</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-03844</guid>
    </item>
    <item>
      <title>certfr-2020-avi-166 — De multiples vulnérabilités ont été découvertes dans Schneider Electric
. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2020-avi-166</link>
      <description>certfr-2020-avi-166</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2020-avi-166</guid>
    </item>
    <item>
      <title>cnvd-2020-23198</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-23198</link>
      <description>cnvd-2020-23198</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-23198</guid>
    </item>
    <item>
      <title>EUVD-2026-37914</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-37914</link>
      <description>EUVD-2026-37914</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-37914</guid>
    </item>
    <item>
      <title>fkie_cve-2020-7475</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-7475</link>
      <description>&lt;p&gt;A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component (&amp;#39;Injection&amp;#39;), reflective DLL, vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20), Modicon M580 (all versions prior to V3.10), which, if exploited, could allow attackers to transfer malicious code to the controller.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component (&amp;#39;Injection&amp;#39;), reflective DLL, vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20), Modicon M580 (all versions prior to V3.10), which, if exploited, could allow attackers to transfer malicious code to the controller.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-7475</guid>
    </item>
    <item>
      <title>GHSA-3mwf-xhc6-4rgf</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3mwf-xhc6-4rgf</link>
      <description>&lt;p&gt;A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component (&amp;#39;Injection&amp;#39;), reflective DLL, vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20), Modicon M580 (all versions prior to V3.10), which, if exploited, could allow attackers to transfer malicious code to the controller.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component (&amp;#39;Injection&amp;#39;), reflective DLL, vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20), Modicon M580 (all versions prior to V3.10), which, if exploited, could allow attackers to transfer malicious code to the controller.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3mwf-xhc6-4rgf</guid>
    </item>
    <item>
      <title>gsd-2020-7475</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-7475</link>
      <description>gsd-2020-7475</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-7475</guid>
    </item>
    <item>
      <title>SEVD-2020-080-01 — Modicon Controllers, EcoStruxure™ Control Expert and Unity Pro Programming Software</title>
      <link>https://cve.radiocsirt.org/vuln/sevd-2020-080-01</link>
      <description>&lt;p&gt;Researchers from Airbus Cybersecurity have made Schneider Electric aware of a vulnerability&#13;
in two versions of Schneider Electric&amp;#39;s Modicon programmable controllers and its EcoStruxure &#13;
Control Expert (formerly Unity Pro) programming software. &#13;
Since alerting us to the vulnerability, Airbus Cybersecurity and Schneider Electric have &#13;
collaborated to validate the research and to assess its true impact. Our mutual findings &#13;
demonstrate that while the discovered vulnerability affects Schneider Electric offers, it equally &#13;
impacts many other vendors and the global industrial automation market in general, especially &#13;
when the baseline assumption of the attack technique Airbus Cybersecurity demonstrated is &#13;
considered. Given certain conditions, and assuming an attacker has access to the network, &#13;
many devices available from several different industrial control vendors are likewise vulnerable.&#13;
Details of the vulnerability and a remediation are included below. However, as a general &#13;
guideline, Schneider Electric and Airbus Cybersecurity encourage all industrial companies to &#13;
ensure they have implemented cybersecurity best practices across their operations and supply &#13;
chains to reduce cyber risks. Where appropriate this includes locating industrial systems and &#13;
remotely accessible devices behind firewalls; installing physical controls to prevent unauthorized&#13;
access; preventing mission-critical systems and devices from being accessed from outside &#13;
networks; systematical…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Researchers from Airbus Cybersecurity have made Schneider Electric aware of a vulnerability&#13;
in two versions of Schneider Electric&amp;#39;s Modicon programmable controllers and its EcoStruxure &#13;
Control Expert (formerly Unity Pro) programming software. &#13;
Since alerting us to the vulnerability, Airbus Cybersecurity and Schneider Electric have &#13;
collaborated to validate the research and to assess its true impact. Our mutual findings &#13;
demonstrate that while the discovered vulnerability affects Schneider Electric offers, it equally &#13;
impacts many other vendors and the global industrial automation market in general, especially &#13;
when the baseline assumption of the attack technique Airbus Cybersecurity demonstrated is &#13;
considered. Given certain conditions, and assuming an attacker has access to the network, &#13;
many devices available from several different industrial control vendors are likewise vulnerable.&#13;
Details of the vulnerability and a remediation are included below. However, as a general &#13;
guideline, Schneider Electric and Airbus Cybersecurity encourage all industrial companies to &#13;
ensure they have implemented cybersecurity best practices across their operations and supply &#13;
chains to reduce cyber risks. Where appropriate this includes locating industrial systems and &#13;
remotely accessible devices behind firewalls; installing physical controls to prevent unauthorized&#13;
access; preventing mission-critical systems and devices from being accessed from outside &#13;
networks; systematical…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sevd-2020-080-01</guid>
    </item>
  </channel>
</rss>
