<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 17:51:57 +0000</lastBuildDate>
    <item>
      <title>bdu:2021-04496</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-04496</link>
      <description>bdu:2021-04496</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-04496</guid>
    </item>
    <item>
      <title>certfr-2021-avi-599 — De multiples vulnérabilités ont été découvertes dans les produits
Siemens. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-599</link>
      <description>certfr-2021-avi-599</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-599</guid>
    </item>
    <item>
      <title>cnvd-2021-58798</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-58798</link>
      <description>cnvd-2021-58798</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-58798</guid>
    </item>
    <item>
      <title>EUVD-2026-27426</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-27426</link>
      <description>EUVD-2026-27426</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-27426</guid>
    </item>
    <item>
      <title>fkie_cve-2021-31401</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-31401</link>
      <description>&lt;p&gt;An issue was discovered in tcp_rcv() in nptcp.c in HCC embedded InterNiche 4.0.1. The TCP header processing code doesn&amp;#39;t sanitize the value of the IP total length field (header length + data length). With a crafted IP packet, an integer overflow occurs whenever the value of the IP data length is calculated by subtracting the length of the header from the total length of the IP packet.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered in tcp_rcv() in nptcp.c in HCC embedded InterNiche 4.0.1. The TCP header processing code doesn&amp;#39;t sanitize the value of the IP total length field (header length + data length). With a crafted IP packet, an integer overflow occurs whenever the value of the IP data length is calculated by subtracting the length of the header from the total length of the IP packet.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-31401</guid>
    </item>
    <item>
      <title>GHSA-jggm-qmcw-j5f5</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jggm-qmcw-j5f5</link>
      <description>&lt;p&gt;An issue was discovered in tcp_rcv() in nptcp.c in HCC embedded InterNiche 4.0.1. The TCP header processing code doesn&amp;#39;t sanitize the value of the IP total length field (header length + data length). With a crafted IP packet, an integer overflow occurs whenever the value of the IP data length is calculated by subtracting the length of the header from the total length of the IP packet.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered in tcp_rcv() in nptcp.c in HCC embedded InterNiche 4.0.1. The TCP header processing code doesn&amp;#39;t sanitize the value of the IP total length field (header length + data length). With a crafted IP packet, an integer overflow occurs whenever the value of the IP data length is calculated by subtracting the length of the header from the total length of the IP packet.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jggm-qmcw-j5f5</guid>
    </item>
    <item>
      <title>gsd-2021-31401</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-31401</link>
      <description>gsd-2021-31401</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-31401</guid>
    </item>
    <item>
      <title>ICSA-21-217-01 — HCC Embedded InterNiche TCP/IP stack, NicheLite (Update B)</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-21-217-01</link>
      <description>&lt;p&gt;When parsing DNS domain names, there are no checks on whether a domain name compression pointer is pointing within the bounds of the packet, which may result in an out-of-bounds read.CVE-2020-25767 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). The routine for parsing DNS response packets does not check the response data length field of individual DNS answers, which may cause an out-of-bounds read/write.CVE-2020-25928 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The number of queries or responses specified in the DNS packet header is not validated with the query/response data available in the DNS packet, leading to an out-of-bounds read.CVE-2020-25927 has been assigned to this vulnerability. A CVSS v3 base score of 8.2 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H). The DNS client does not sufficiently randomize transaction IDs, facilitating DNS cache poisoning attacks.CVE-2020-25926 has been assigned to this vulnerability. A CVSS v3 base score of 4.0 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N). The code that parses ICMP packets relies on an unchecked value of the IP payload size to compute the ICMP checksum, which may result in an out-of-bounds read.CVE-2020-35683 has been assigned…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;When parsing DNS domain names, there are no checks on whether a domain name compression pointer is pointing within the bounds of the packet, which may result in an out-of-bounds read.CVE-2020-25767 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). The routine for parsing DNS response packets does not check the response data length field of individual DNS answers, which may cause an out-of-bounds read/write.CVE-2020-25928 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The number of queries or responses specified in the DNS packet header is not validated with the query/response data available in the DNS packet, leading to an out-of-bounds read.CVE-2020-25927 has been assigned to this vulnerability. A CVSS v3 base score of 8.2 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H). The DNS client does not sufficiently randomize transaction IDs, facilitating DNS cache poisoning attacks.CVE-2020-25926 has been assigned to this vulnerability. A CVSS v3 base score of 4.0 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N). The code that parses ICMP packets relies on an unchecked value of the IP payload size to compute the ICMP checksum, which may result in an out-of-bounds read.CVE-2020-35683 has been assigned…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-21-217-01</guid>
    </item>
    <item>
      <title>SEVD-2021-217-01 — NicheStack TCP/IP Vulnerabilities (INFRA:HALT) in Lexium ILE, ILA, ILS, and Communication Option Boards for Altivar and…</title>
      <link>https://cve.radiocsirt.org/vuln/sevd-2021-217-01</link>
      <description>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities in HCC Embedded’s NicheStack TCP/IP third party component, which is integrated into Schneider Electric’s Lexium ILE, ILA, ILS, Altivar Profinet Communication Module (VW3A3627), Altivar and Lexium Ethernet TCP/IP Communication Module (VW3A3616), and Altivar Profinet - Communication Card (VW3A3327) products.
Failure to apply the mitigations provided below may risk denial of service of the drives.
February 2023 Update: A remediation is available for Altivar 32/320/340/600/900 Profinet communication module (VW3A3627)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities in HCC Embedded’s NicheStack TCP/IP third party component, which is integrated into Schneider Electric’s Lexium ILE, ILA, ILS, Altivar Profinet Communication Module (VW3A3627), Altivar and Lexium Ethernet TCP/IP Communication Module (VW3A3616), and Altivar Profinet - Communication Card (VW3A3327) products.
Failure to apply the mitigations provided below may risk denial of service of the drives.
February 2023 Update: A remediation is available for Altivar 32/320/340/600/900 Profinet communication module (VW3A3627)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sevd-2021-217-01</guid>
    </item>
    <item>
      <title>VDE-2021-009 — Pilz: Multiple products prone to Niche Ethernet Stack vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2021-009</link>
      <description>&lt;p&gt;Multiple products of PILZ utilise a third-party TCP/IP implementation - the &amp;#34;Niche Ethernet Stack&amp;#34;. This TCP/IP stack contains multiple vulnerabilities which are therefore affecting the products listed above.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple products of PILZ utilise a third-party TCP/IP implementation - the &amp;#34;Niche Ethernet Stack&amp;#34;. This TCP/IP stack contains multiple vulnerabilities which are therefore affecting the products listed above.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2021-009</guid>
    </item>
    <item>
      <title>VDE-2021-032 — PHOENIX CONTACT: Niche Ethernet Stack for ILC1x0, ILC1x1 and AXC 1050 Industrial controllers and CHARX control DC</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2021-032</link>
      <description>&lt;p&gt;An issue was discovered in HCC Nichestack 3.0. The code that generates Initial Sequence Numbers (ISNs) for TCP connections derives the ISN from an insufficiently random source. As a result, an attacker may be able to determine the ISN of current and future TCP connections and either hijack existing ones or spoof future ones. (Proper ISN generation should aim to follow at least the specifications outlined in RFC 6528.) An issue was discovered in tcp_rcv() in nptcp.c in HCC embedded InterNiche 4.0.1. The TCP header processing code doesn&amp;#39;t sanitize the value of the IP total length field (header length + data length). With a crafted IP packet, an integer overflow occurs whenever the value of the IP data length is calculated by subtracting the length of the header from the total length of the IP packet. An issue was discovered in tcp_pulloutofband() in tcp_in.c in HCC embedded InterNiche 4.0.1. The TCP out-of-band urgent-data processing function invokes a panic function if the pointer to the end of the out-of-band data points outside of the TCP segment&amp;#39;s data. If the panic function hadn&amp;#39;t a trap invocation removed, it will enter an infinite loop and therefore cause DoS (continuous loop or a device reset). An issue was discovered in HCC Nichestack 3.0. The code that parses TCP packets relies on an unchecked value of the IP payload size (extracted from the IP header) to compute the length of the TCP payload within the TCP checksum computation function. When the IP payload size is s…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered in HCC Nichestack 3.0. The code that generates Initial Sequence Numbers (ISNs) for TCP connections derives the ISN from an insufficiently random source. As a result, an attacker may be able to determine the ISN of current and future TCP connections and either hijack existing ones or spoof future ones. (Proper ISN generation should aim to follow at least the specifications outlined in RFC 6528.) An issue was discovered in tcp_rcv() in nptcp.c in HCC embedded InterNiche 4.0.1. The TCP header processing code doesn&amp;#39;t sanitize the value of the IP total length field (header length + data length). With a crafted IP packet, an integer overflow occurs whenever the value of the IP data length is calculated by subtracting the length of the header from the total length of the IP packet. An issue was discovered in tcp_pulloutofband() in tcp_in.c in HCC embedded InterNiche 4.0.1. The TCP out-of-band urgent-data processing function invokes a panic function if the pointer to the end of the out-of-band data points outside of the TCP segment&amp;#39;s data. If the panic function hadn&amp;#39;t a trap invocation removed, it will enter an infinite loop and therefore cause DoS (continuous loop or a device reset). An issue was discovered in HCC Nichestack 3.0. The code that parses TCP packets relies on an unchecked value of the IP payload size (extracted from the IP header) to compute the length of the TCP payload within the TCP checksum computation function. When the IP payload size is s…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2021-032</guid>
    </item>
    <item>
      <title>VDE-2021-042 — Weidmueller: Remote I/O fieldbus couplers (IP20) affected by INFRA:HALT vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2021-042</link>
      <description>&lt;p&gt;The Weidmueller Remote I/O (IP20) fieldbus couplers (u-remote) are affected by several vulnerabilities of the third-party TCP/IP Niche stack. An attacker may use crafted IP packets to cause a denial of service or breach of integrity of the affected products. Weidmueller recommends restricting network access from the internet and also locally to reduce the attack vector to a manageable minimum.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Weidmueller Remote I/O (IP20) fieldbus couplers (u-remote) are affected by several vulnerabilities of the third-party TCP/IP Niche stack. An attacker may use crafted IP packets to cause a denial of service or breach of integrity of the affected products. Weidmueller recommends restricting network access from the internet and also locally to reduce the attack vector to a manageable minimum.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2021-042</guid>
    </item>
  </channel>
</rss>
