<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 11:35:39 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-03215</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-03215</link>
      <description>bdu:2022-03215</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-03215</guid>
    </item>
    <item>
      <title>certfr-2022-avi-435 — De multiples vulnérabilités ont été découvertes dans les produits
Siemens. Certaines d'entre elles permettent à un atta…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-435</link>
      <description>certfr-2022-avi-435</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-435</guid>
    </item>
    <item>
      <title>EUVD-2026-33211</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-33211</link>
      <description>EUVD-2026-33211</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-33211</guid>
    </item>
    <item>
      <title>fkie_cve-2021-45117</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-45117</link>
      <description>&lt;p&gt;The OPC autogenerated ANSI C stack stubs (in the NodeSets) do not handle all error cases. This can lead to a NULL pointer dereference.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The OPC autogenerated ANSI C stack stubs (in the NodeSets) do not handle all error cases. This can lead to a NULL pointer dereference.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-45117</guid>
    </item>
    <item>
      <title>GHSA-v4v7-f2qj-8939</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v4v7-f2qj-8939</link>
      <description>&lt;p&gt;The OPC autogenerated ANSI C stack stubs (in the NodeSets) do not handle all error cases. This can lead to a NULL pointer dereference.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The OPC autogenerated ANSI C stack stubs (in the NodeSets) do not handle all error cases. This can lead to a NULL pointer dereference.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v4v7-f2qj-8939</guid>
    </item>
    <item>
      <title>gsd-2021-45117</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-45117</link>
      <description>gsd-2021-45117</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-45117</guid>
    </item>
    <item>
      <title>ICSA-22-132-08 — Siemens Industrial Products with OPC UA</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-22-132-08</link>
      <description>&lt;p&gt;The OPC UA ANSIC Stack (also called Legacy C-Stack) was reported to crash when an unexpected OPC UA Response message status code was accessed via the synchronous Client API. The vulnerability was found in generated code of the OPC Foundation C-Stack. An unexpected status code in response message will dereference Null pointer leading to crash, ping of death (PoD). This affects a client, but it might also affect a server when it uses OpcUa_ClientApi_RegisterServer (e.g. register at LDS). A specially crafted UA server, or Man in the Middle attacker, can cause the OPC UA application to crash by sending uncertain status code in response message.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The OPC UA ANSIC Stack (also called Legacy C-Stack) was reported to crash when an unexpected OPC UA Response message status code was accessed via the synchronous Client API. The vulnerability was found in generated code of the OPC Foundation C-Stack. An unexpected status code in response message will dereference Null pointer leading to crash, ping of death (PoD). This affects a client, but it might also affect a server when it uses OpcUa_ClientApi_RegisterServer (e.g. register at LDS). A specially crafted UA server, or Man in the Middle attacker, can cause the OPC UA application to crash by sending uncertain status code in response message.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-22-132-08</guid>
    </item>
    <item>
      <title>VDE-2022-003 — BECKHOFF: Null Pointer Dereference vulnerability in products with OPC UA technology</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2022-003</link>
      <description>&lt;p&gt;By tricking clients of the mentioned products into contacting malicious OPC UA servers and thereby acting as OPC UA clients, a crash of the component can be provoked.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;By tricking clients of the mentioned products into contacting malicious OPC UA servers and thereby acting as OPC UA clients, a crash of the component can be provoked.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2022-003</guid>
    </item>
    <item>
      <title>VDE-2022-010 — PHOENIX CONTACT: Multiple Linux component vulnerabilities fixed in latest AXC F x152 LTS release</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2022-010</link>
      <description>&lt;p&gt;PLCnext Control AXC F x152 is certified according to IEC 62443-4-1 and IEC 62443-4-2.
This certification requires that all third-party components used in the firmware are regularly checked for known vulnerabilities.&lt;/p&gt;
&lt;p&gt;Firmware components in version 2021.06 had already been updated. For the 2022.0 LTS version more firmware components have been updated implicitly fixing the vulnerabilities listed. The vulnerabilities listed above have not been individually verified in terms of actual impact and/or limitations in combination with the affected products listed. The current LTS release 2022.0 LTS contains updates of integrated third-party libraries, SDKs and other third-party software to address these issues nevertheless.&lt;/p&gt;
&lt;p&gt;UPDATE A (April 4th, 2022): Added RFC 4072 (Art. No. 1051328) and fixed affected version of AXC F 3152&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;PLCnext Control AXC F x152 is certified according to IEC 62443-4-1 and IEC 62443-4-2.
This certification requires that all third-party components used in the firmware are regularly checked for known vulnerabilities.&lt;/p&gt;
&lt;p&gt;Firmware components in version 2021.06 had already been updated. For the 2022.0 LTS version more firmware components have been updated implicitly fixing the vulnerabilities listed. The vulnerabilities listed above have not been individually verified in terms of actual impact and/or limitations in combination with the affected products listed. The current LTS release 2022.0 LTS contains updates of integrated third-party libraries, SDKs and other third-party software to address these issues nevertheless.&lt;/p&gt;
&lt;p&gt;UPDATE A (April 4th, 2022): Added RFC 4072 (Art. No. 1051328) and fixed affected version of AXC F 3152&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2022-010</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-2603 — Siemens SICAM: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2603</link>
      <description>&lt;p&gt;Ein entfernter, anonymer oder lokaler Angreifer kann mehrere Schwachstellen in Siemens SICAM ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand auszulösen, seine Privilegien zu erweitern und Daten zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer oder lokaler Angreifer kann mehrere Schwachstellen in Siemens SICAM ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand auszulösen, seine Privilegien zu erweitern und Daten zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2603</guid>
    </item>
  </channel>
</rss>
