<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 11:28:37 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-02717</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-02717</link>
      <description>bdu:2023-02717</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-02717</guid>
    </item>
    <item>
      <title>certfr-2021-avi-517 — De multiples vulnérabilités ont été découvertes dans les produits
Schneider. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-517</link>
      <description>certfr-2021-avi-517</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-517</guid>
    </item>
    <item>
      <title>EUVD-2026-23147</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-23147</link>
      <description>EUVD-2026-23147</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-23147</guid>
    </item>
    <item>
      <title>fkie_cve-2021-22781</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-22781</link>
      <description>&lt;p&gt;Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), and SCADAPack RemoteConnect for x70, all versions, that could cause a leak of SMTP credential used for mailbox authentication when an attacker can access a project file.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), and SCADAPack RemoteConnect for x70, all versions, that could cause a leak of SMTP credential used for mailbox authentication when an attacker can access a project file.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-22781</guid>
    </item>
    <item>
      <title>GHSA-734p-mcvf-5whm</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-734p-mcvf-5whm</link>
      <description>&lt;p&gt;Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), and SCADAPack RemoteConnect for x70, all versions, that could cause a leak of SMTP credential used for mailbox authentication when an attacker can access a project file.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), and SCADAPack RemoteConnect for x70, all versions, that could cause a leak of SMTP credential used for mailbox authentication when an attacker can access a project file.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-734p-mcvf-5whm</guid>
    </item>
    <item>
      <title>gsd-2021-22781</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-22781</link>
      <description>gsd-2021-22781</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-22781</guid>
    </item>
    <item>
      <title>ICSA-21-194-02 — Schneider Electric Modicon Controllers and Software (Update A)</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-21-194-02</link>
      <description>&lt;p&gt;An insufficiently protected credentials vulnerability exists that could cause protected derived function blocks to be read or modified by unauthorized users when accessing a project file. CVE-2021-22778 has been assigned to this vulnerability. A CVSS v3 base score of 8.6 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).. --------- Begin Update A Part 2 of 2 --------CVE-2021-22778 has been assigned to this vulnerability. A CVSS v3 base score of 8.6 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H). An authentication bypass by spoofing vulnerability exists that could cause unauthorized access in read and write mode to the controller by spoofing the Modbus communication between the engineering software and the controller. CVE-2021-22779 has been assigned to this vulnerability. A CVSS v3 base score of 9.8has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).. --------- End Update A Part 2 of 2 --------CVE-2021-22779 has been assigned to this vulnerability. A CVSS v3 base score of 9.8has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). M&amp;amp;M Software fdtCONTAINER component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage.
Note: This vulnerability could cause local code execution on the engineering workstation when a malicious project file is loaded into the engine…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An insufficiently protected credentials vulnerability exists that could cause protected derived function blocks to be read or modified by unauthorized users when accessing a project file. CVE-2021-22778 has been assigned to this vulnerability. A CVSS v3 base score of 8.6 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).. --------- Begin Update A Part 2 of 2 --------CVE-2021-22778 has been assigned to this vulnerability. A CVSS v3 base score of 8.6 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H). An authentication bypass by spoofing vulnerability exists that could cause unauthorized access in read and write mode to the controller by spoofing the Modbus communication between the engineering software and the controller. CVE-2021-22779 has been assigned to this vulnerability. A CVSS v3 base score of 9.8has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).. --------- End Update A Part 2 of 2 --------CVE-2021-22779 has been assigned to this vulnerability. A CVSS v3 base score of 9.8has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). M&amp;amp;M Software fdtCONTAINER component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage.
Note: This vulnerability could cause local code execution on the engineering workstation when a malicious project file is loaded into the engine…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-21-194-02</guid>
    </item>
    <item>
      <title>SEVD-2021-194-01 — EcoStruxureTM Control Expert, EcoStruxureTM Process Expert, SCADAPack RemoteConnect™ x70, and Modicon Controllers M580…</title>
      <link>https://cve.radiocsirt.org/vuln/sevd-2021-194-01</link>
      <description>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities in its EcoStruxure™ Control Expert , EcoStruxure™ Process Expert, SCADAPack RemoteConnect™ x70, and Modicon M580 and M340 control products. These vulnerabilities pose several risks, primary among these is the possibility of arbitrary code execution and loss of confidentiality and integrity of the project file.
With all products affected an attack would first involve an authenticated user gaining access to the engineering station; or an unauthenticated user gaining access to a project file or to the process control network.
Our findings demonstrate that while the discovered vulnerabilities affect Schneider Electric offers, it is possible to mitigate the potential impacts by following standard guidance, specific instructions; and in some cases, the fixes provided by Schneider Electric to remove the vulnerabilities.
Please ensure that if you are an EcoStruxure™ Control Expert user to apply the latest security updates provided below. For users of any of the mentioned products see the mitigation section in this security notice for further information on how to help protect your system from possible attack.
Schneider Electric encourages all industrial companies to ensure they have implemented cybersecurity best practices across their operations and supply chains to reduce cyber risks. Where appropriate this includes locating industrial systems and remotely accessible devices behind firewalls; installing physical controls to p…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities in its EcoStruxure™ Control Expert , EcoStruxure™ Process Expert, SCADAPack RemoteConnect™ x70, and Modicon M580 and M340 control products. These vulnerabilities pose several risks, primary among these is the possibility of arbitrary code execution and loss of confidentiality and integrity of the project file.
With all products affected an attack would first involve an authenticated user gaining access to the engineering station; or an unauthenticated user gaining access to a project file or to the process control network.
Our findings demonstrate that while the discovered vulnerabilities affect Schneider Electric offers, it is possible to mitigate the potential impacts by following standard guidance, specific instructions; and in some cases, the fixes provided by Schneider Electric to remove the vulnerabilities.
Please ensure that if you are an EcoStruxure™ Control Expert user to apply the latest security updates provided below. For users of any of the mentioned products see the mitigation section in this security notice for further information on how to help protect your system from possible attack.
Schneider Electric encourages all industrial companies to ensure they have implemented cybersecurity best practices across their operations and supply chains to reduce cyber risks. Where appropriate this includes locating industrial systems and remotely accessible devices behind firewalls; installing physical controls to p…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sevd-2021-194-01</guid>
    </item>
  </channel>
</rss>
