<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 22:06:39 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-04238</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-04238</link>
      <description>bdu:2022-04238</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-04238</guid>
    </item>
    <item>
      <title>certfr-2022-avi-435 — De multiples vulnérabilités ont été découvertes dans les produits
Siemens. Certaines d'entre elles permettent à un atta…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-435</link>
      <description>certfr-2022-avi-435</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-435</guid>
    </item>
    <item>
      <title>cnvd-2022-36378</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2022-36378</link>
      <description>cnvd-2022-36378</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2022-36378</guid>
    </item>
    <item>
      <title>EUVD-2026-14005</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-14005</link>
      <description>EUVD-2026-14005</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-14005</guid>
    </item>
    <item>
      <title>fkie_cve-2022-24040</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-24040</link>
      <description>&lt;p&gt;A vulnerability has been identified in Desigo DXR2 (All versions &amp;lt; V01.21.142.5-22), Desigo PXC3 (All versions &amp;lt; V01.21.142.4-18), Desigo PXC4 (All versions &amp;lt; V02.20.142.10-10884), Desigo PXC5 (All versions &amp;lt; V02.20.142.10-10884). The web application fails to enforce an upper bound to the cost factor of the PBKDF2 derived key during the creation or update of an account. An attacker with the user profile access privilege could cause a denial of service (DoS) condition through CPU consumption by setting a PBKDF2 derived key with a remarkably high cost effort and then attempting a login to the so-modified account.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability has been identified in Desigo DXR2 (All versions &amp;lt; V01.21.142.5-22), Desigo PXC3 (All versions &amp;lt; V01.21.142.4-18), Desigo PXC4 (All versions &amp;lt; V02.20.142.10-10884), Desigo PXC5 (All versions &amp;lt; V02.20.142.10-10884). The web application fails to enforce an upper bound to the cost factor of the PBKDF2 derived key during the creation or update of an account. An attacker with the user profile access privilege could cause a denial of service (DoS) condition through CPU consumption by setting a PBKDF2 derived key with a remarkably high cost effort and then attempting a login to the so-modified account.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-24040</guid>
    </item>
    <item>
      <title>GHSA-gvmv-rhmr-mw99</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gvmv-rhmr-mw99</link>
      <description>&lt;p&gt;A vulnerability has been identified in Desigo DXR2 (All versions &amp;lt; V01.21.142.5-22), Desigo PXC3 (All versions &amp;lt; V01.21.142.4-18), Desigo PXC4 (All versions &amp;lt; V02.20.142.10-10884), Desigo PXC5 (All versions &amp;lt; V02.20.142.10-10884). The web application fails to enforce an upper bound to the cost factor of the PBKDF2 derived key during the creation or update of an account. An attacker with the user profile access privilege could cause a denial of service (DoS) condition through CPU consumption by setting a PBKDF2 derived key with a remarkably high cost effort and then attempting a login to the so-modified account.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability has been identified in Desigo DXR2 (All versions &amp;lt; V01.21.142.5-22), Desigo PXC3 (All versions &amp;lt; V01.21.142.4-18), Desigo PXC4 (All versions &amp;lt; V02.20.142.10-10884), Desigo PXC5 (All versions &amp;lt; V02.20.142.10-10884). The web application fails to enforce an upper bound to the cost factor of the PBKDF2 derived key during the creation or update of an account. An attacker with the user profile access privilege could cause a denial of service (DoS) condition through CPU consumption by setting a PBKDF2 derived key with a remarkably high cost effort and then attempting a login to the so-modified account.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gvmv-rhmr-mw99</guid>
    </item>
    <item>
      <title>gsd-2022-24040</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-24040</link>
      <description>gsd-2022-24040</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-24040</guid>
    </item>
    <item>
      <title>ICSA-22-132-10 — Siemens Desigo PXC and DXR Devices</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-22-132-10</link>
      <description>&lt;p&gt;The addCell JavaScript function fails to properly sanitize user-controllable input before including it into the generated XML body of the XLS report document as it is possible to inject arbitrary content (e.g., XML tags) into the generated file. An attacker with restricted privileges could corrupt the content used to generate XLS reports to leverage the application to deliver malicious files against higher-privileged users and obtain remote code execution (RCE) against the administrator &amp;#39;s workstation.CVE-2022-24039 has been assigned to this vulnerability. A CVSS v3 base score of 9.0 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H). The web application fails to enforce an upper bound to the cost factor of the PBKDF2 derived key during the creation or update of an account. An attacker with the user profile access privilege could cause a denial-of-service condition through CPU consumption by setting a PBKDF2 derived key with a high-cost effort, followed by a login attempt to the modified account.CVE-2022-24040 has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). The web application stores the PBKDF2 derived key of user &amp;#39;s passwords with a low iteration count. An attacker with user profile access privilege can retrieve the stored password hashes of other accounts and then successfully perform an offline cracking attack and recover the plainte…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The addCell JavaScript function fails to properly sanitize user-controllable input before including it into the generated XML body of the XLS report document as it is possible to inject arbitrary content (e.g., XML tags) into the generated file. An attacker with restricted privileges could corrupt the content used to generate XLS reports to leverage the application to deliver malicious files against higher-privileged users and obtain remote code execution (RCE) against the administrator &amp;#39;s workstation.CVE-2022-24039 has been assigned to this vulnerability. A CVSS v3 base score of 9.0 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H). The web application fails to enforce an upper bound to the cost factor of the PBKDF2 derived key during the creation or update of an account. An attacker with the user profile access privilege could cause a denial-of-service condition through CPU consumption by setting a PBKDF2 derived key with a high-cost effort, followed by a login attempt to the modified account.CVE-2022-24040 has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). The web application stores the PBKDF2 derived key of user &amp;#39;s passwords with a low iteration count. An attacker with user profile access privilege can retrieve the stored password hashes of other accounts and then successfully perform an offline cracking attack and recover the plainte…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-22-132-10</guid>
    </item>
  </channel>
</rss>
