<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 08:58:55 +0000</lastBuildDate>
    <item>
      <title>bdu:2021-03153</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-03153</link>
      <description>bdu:2021-03153</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-03153</guid>
    </item>
    <item>
      <title>certfr-2021-avi-622 — De multiples vulnérabilités ont été découvertes dans les produits
Schneider Electric. Certaines d'entre elles permetten…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-622</link>
      <description>certfr-2021-avi-622</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-622</guid>
    </item>
    <item>
      <title>cnvd-2021-37672</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-37672</link>
      <description>cnvd-2021-37672</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-37672</guid>
    </item>
    <item>
      <title>EUVD-2026-26676</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-26676</link>
      <description>EUVD-2026-26676</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-26676</guid>
    </item>
    <item>
      <title>fkie_cve-2021-30195</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-30195</link>
      <description>&lt;p&gt;CODESYS V2 runtime system before 2.4.7.55 has Improper Input Validation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;CODESYS V2 runtime system before 2.4.7.55 has Improper Input Validation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-30195</guid>
    </item>
    <item>
      <title>FSA-202601 — Several CODESYS vulnerabilities in Festo Automation Suite</title>
      <link>https://cve.radiocsirt.org/vuln/fsa-202601</link>
      <description>&lt;p&gt;Starting with Festo Automation Suite (FAS) version 2.8.0.138, the suite is delivered only with a connector to Codesys, rather than including Codesys directly. Prior to this version, Codesys was bundled within the FAS installation. From version 2.8.0.138 onwards, customers are required to download and install Codesys independently.&lt;/p&gt;
&lt;p&gt;This change impacts the handling of security vulnerabilities (CVEs) related to Codesys. Any Codesys-related security issues must now be addressed by the customer through their separate Codesys installation. The FAS itself includes only the connector component, which is maintained and updated within the suite.&lt;/p&gt;
&lt;p&gt;Please ensure that Codesys is kept up to date independently to mitigate any potential security risks associated with the Codesys software.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Starting with Festo Automation Suite (FAS) version 2.8.0.138, the suite is delivered only with a connector to Codesys, rather than including Codesys directly. Prior to this version, Codesys was bundled within the FAS installation. From version 2.8.0.138 onwards, customers are required to download and install Codesys independently.&lt;/p&gt;
&lt;p&gt;This change impacts the handling of security vulnerabilities (CVEs) related to Codesys. Any Codesys-related security issues must now be addressed by the customer through their separate Codesys installation. The FAS itself includes only the connector component, which is maintained and updated within the suite.&lt;/p&gt;
&lt;p&gt;Please ensure that Codesys is kept up to date independently to mitigate any potential security risks associated with the Codesys software.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fsa-202601</guid>
    </item>
    <item>
      <title>GHSA-67hh-p488-99r8</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-67hh-p488-99r8</link>
      <description>&lt;p&gt;CODESYS V2 runtime system before 2.4.7.55 has Improper Input Validation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;CODESYS V2 runtime system before 2.4.7.55 has Improper Input Validation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-67hh-p488-99r8</guid>
    </item>
    <item>
      <title>gsd-2021-30195</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-30195</link>
      <description>gsd-2021-30195</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-30195</guid>
    </item>
    <item>
      <title>ICSA-21-173-03 — CODESYS Control V2 communication</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-21-173-03</link>
      <description>&lt;p&gt;A crafted request may cause a heap-based buffer overflow in the affected CODESYS products, resulting in a denial-of-service condition.CVE-2021-30186 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). A crafted request may cause a stack-based buffer overflow in the affected CODESYS products, resulting in a denial-of-service condition or remote code execution.CVE-2021-30188 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). A crafted request may cause a buffer over-read in the affected CODESYS products, resulting in a denial-of-service condition.CVE-2021-30195 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A crafted request may cause a heap-based buffer overflow in the affected CODESYS products, resulting in a denial-of-service condition.CVE-2021-30186 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). A crafted request may cause a stack-based buffer overflow in the affected CODESYS products, resulting in a denial-of-service condition or remote code execution.CVE-2021-30188 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). A crafted request may cause a buffer over-read in the affected CODESYS products, resulting in a denial-of-service condition.CVE-2021-30195 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-21-173-03</guid>
    </item>
    <item>
      <title>SEVD-2021-222-06 — CODESYS V2 Vulnerabilities in Programmable Automation Controller (PacDrive) M</title>
      <link>https://cve.radiocsirt.org/vuln/sevd-2021-222-06</link>
      <description>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities disclosed by Codesys on CODESYS V2 runtime for industrial control systems, which is used in its Programmable Automation Controller (PacDrive) M products.&#13;
The Programmable Automation Controller (PacDrive) M products are legacy logic motion technology for packaging and production machines.&#13;
Failure to apply the mitigations provided below may risk buffer overflow attacks, which could result in potential denial of service condition or arbitrary remote code execution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities disclosed by Codesys on CODESYS V2 runtime for industrial control systems, which is used in its Programmable Automation Controller (PacDrive) M products.&#13;
The Programmable Automation Controller (PacDrive) M products are legacy logic motion technology for packaging and production machines.&#13;
Failure to apply the mitigations provided below may risk buffer overflow attacks, which could result in potential denial of service condition or arbitrary remote code execution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sevd-2021-222-06</guid>
    </item>
    <item>
      <title>VDE-2021-014 — WAGO: Multiple Vulnerabilities in CODESYS Runtime 2.3</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2021-014</link>
      <description>&lt;p&gt;Multiple vulnerabilities were reported in CODESYS 2.3 Runtime. The CODESYS 2.3 Runtime is an essential component in several WAGO PLC&amp;#39;s.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities were reported in CODESYS 2.3 Runtime. The CODESYS 2.3 Runtime is an essential component in several WAGO PLC&amp;#39;s.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2021-014</guid>
    </item>
    <item>
      <title>VDE-2021-048 — Lenze: Multiple Vulnerabilities in CODESYS Control V2 communication</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2021-048</link>
      <description>&lt;p&gt;The affected products contain a CODESYS Control runtime system in version V2. They are therefore affected by the
vulnerability described in CODESYS Advisory 2021-06. It provides a communication server for the communication with clients like the CODESYS Development System.&lt;/p&gt;
&lt;p&gt;The 9400 servo inverters is only affected if the communication Path via the inserted EtherNet Module E94AYCEN on slot MXI1 or MXI2 is used. If the Module E94AYCEN is used, the following Versions are affected.&lt;/p&gt;
&lt;p&gt;Product Identification: E94xSHxxx (Single Drive, High Line)
Product Identification: E94xMHxxx (Multi Drive, High Line)&lt;/p&gt;
&lt;p&gt;Remark: If the product identification of your 9400 product does not fit to the above mentioned identification, please contact Lenze at Security.de@Lenze.com.&lt;/p&gt;
&lt;p&gt;The Versions P (power supply module) and R (regenerative power supply module) are not affected. Furthermore, the Variant P (PLC) and the Variant S (StateLine) are not affected. The communication paths via the diagnostic interface X6, the system bus (CAN) X1 or the field buses (other than the named Ethernet module) that can be plugged into the module slots MXI1 or MXI2 are not affected.&lt;/p&gt;
&lt;p&gt;The focus is therefore on 9400 servo inverters with the product-identification E94x{S/M}{H}... with a plugged in Ethernet module E94AYCEN... in module slot MXI1 or MXI2 and communication with the Engineer-Tools via exactly this channel.&lt;/p&gt;
&lt;p&gt;In addition to the standard tool Engineer, there is also a special Version of the PLC Designer (Version 0.x)…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The affected products contain a CODESYS Control runtime system in version V2. They are therefore affected by the
vulnerability described in CODESYS Advisory 2021-06. It provides a communication server for the communication with clients like the CODESYS Development System.&lt;/p&gt;
&lt;p&gt;The 9400 servo inverters is only affected if the communication Path via the inserted EtherNet Module E94AYCEN on slot MXI1 or MXI2 is used. If the Module E94AYCEN is used, the following Versions are affected.&lt;/p&gt;
&lt;p&gt;Product Identification: E94xSHxxx (Single Drive, High Line)
Product Identification: E94xMHxxx (Multi Drive, High Line)&lt;/p&gt;
&lt;p&gt;Remark: If the product identification of your 9400 product does not fit to the above mentioned identification, please contact Lenze at Security.de@Lenze.com.&lt;/p&gt;
&lt;p&gt;The Versions P (power supply module) and R (regenerative power supply module) are not affected. Furthermore, the Variant P (PLC) and the Variant S (StateLine) are not affected. The communication paths via the diagnostic interface X6, the system bus (CAN) X1 or the field buses (other than the named Ethernet module) that can be plugged into the module slots MXI1 or MXI2 are not affected.&lt;/p&gt;
&lt;p&gt;The focus is therefore on 9400 servo inverters with the product-identification E94x{S/M}{H}... with a plugged in Ethernet module E94AYCEN... in module slot MXI1 or MXI2 and communication with the Engineer-Tools via exactly this channel.&lt;/p&gt;
&lt;p&gt;In addition to the standard tool Engineer, there is also a special Version of the PLC Designer (Version 0.x)…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2021-048</guid>
    </item>
    <item>
      <title>VDE-2021-054 — Pilz: Multiple vulnerabilities in CODESYS V2 and V3 runtime system</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2021-054</link>
      <description>&lt;p&gt;Several Pilz products use Versions V2 and V3 of the CODESYS runtime system from CODESYS GmbH, which enables the execution of IEC 61131-3 PLC programs. These runtime environments contain several vulnerabilities, which an attacker can exploit via the network. Successful exploitation of the vulnerabilities results in reduced availability and, in a worst case, to the insertion of program code.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Several Pilz products use Versions V2 and V3 of the CODESYS runtime system from CODESYS GmbH, which enables the execution of IEC 61131-3 PLC programs. These runtime environments contain several vulnerabilities, which an attacker can exploit via the network. Successful exploitation of the vulnerabilities results in reduced availability and, in a worst case, to the insertion of program code.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2021-054</guid>
    </item>
  </channel>
</rss>
