<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 06:49:00 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-02521</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-02521</link>
      <description>bdu:2024-02521</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-02521</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0119 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits Siemens&lt;/span&gt;. Certaines d'entr…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0119</link>
      <description>certfr-2024-avi-0119</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0119</guid>
    </item>
    <item>
      <title>EUVD-2026-16287</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-16287</link>
      <description>EUVD-2026-16287</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-16287</guid>
    </item>
    <item>
      <title>fkie_cve-2022-29862</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-29862</link>
      <description>&lt;p&gt;An infinite loop in OPC UA .NET Standard Stack 1.04.368 allows a remote attackers to cause the application to hang via a crafted message.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An infinite loop in OPC UA .NET Standard Stack 1.04.368 allows a remote attackers to cause the application to hang via a crafted message.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-29862</guid>
    </item>
    <item>
      <title>GHSA-5q2v-6j86-5h9v — Security Update for the OPC UA .NET Standard Stack</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5q2v-6j86-5h9v</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; NuGet: OPCFoundation.NetStandard.Opc.Ua.Core&lt;/p&gt;
&lt;p&gt;A vulnerability was discovered in OPC UA .NET Standard Stack that allows a malicious client or server to cause a peer to hang with a carefully crafted message sent during secure channel creation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; NuGet: OPCFoundation.NetStandard.Opc.Ua.Core&lt;/p&gt;
&lt;p&gt;A vulnerability was discovered in OPC UA .NET Standard Stack that allows a malicious client or server to cause a peer to hang with a carefully crafted message sent during secure channel creation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5q2v-6j86-5h9v</guid>
    </item>
    <item>
      <title>gsd-2022-29862</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-29862</link>
      <description>gsd-2022-29862</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-29862</guid>
    </item>
    <item>
      <title>ICSA-24-046-02 — Siemens SIDIS Prime</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-24-046-02</link>
      <description>&lt;p&gt;In OPC Foundation OPC UA .NET Standard codebase 1.4.357.28, servers do not create sufficiently random numbers in OPCFoundation.NetStandard.Opc.Ua before 1.4.359.31, which allows man in the middle attackers to reuse encrypted user credentials sent over the network. Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the &amp;#34;signature_algorithms_cert&amp;#34; TLS extension. The crash occurs if an invalid or unrecognised signature algorithm is received from the peer. This could be exploited by a malicious peer in a Denial of Service attack. The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both GENERAL_NAMEs contain an EDIPARTYNAME. A NULL pointer dereference and a crash may occur leading to a possible denial of service attack. OpenSSL itself uses the GENERAL_NAME_cmp function for two purposes: 1) Comparing CRL distribution point names between an available CRL and a CRL distribution point embedded in an X509 certificate 2) When verifying that a timestamp response token signer matches the timestamp authority name (exposed via the API functions TS_RESP_verify_response and TS_RESP_verify_token) If an atta…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In OPC Foundation OPC UA .NET Standard codebase 1.4.357.28, servers do not create sufficiently random numbers in OPCFoundation.NetStandard.Opc.Ua before 1.4.359.31, which allows man in the middle attackers to reuse encrypted user credentials sent over the network. Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the &amp;#34;signature_algorithms_cert&amp;#34; TLS extension. The crash occurs if an invalid or unrecognised signature algorithm is received from the peer. This could be exploited by a malicious peer in a Denial of Service attack. The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both GENERAL_NAMEs contain an EDIPARTYNAME. A NULL pointer dereference and a crash may occur leading to a possible denial of service attack. OpenSSL itself uses the GENERAL_NAME_cmp function for two purposes: 1) Comparing CRL distribution point names between an available CRL and a CRL distribution point embedded in an X509 certificate 2) When verifying that a timestamp response token signer matches the timestamp authority name (exposed via the API functions TS_RESP_verify_response and TS_RESP_verify_token) If an atta…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-24-046-02</guid>
    </item>
    <item>
      <title>VDE-2022-034 — TRUMPF: Products prone to Unified Automation vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2022-034</link>
      <description>&lt;p&gt;A number of TRUMPF software tools use the OPC UA Server in C++ based OPC UA SDK by Unified Automation. The application contains several vulnerabilities, which enable an attacker to send malicious data to the application, resulting in a Denial-of-Service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A number of TRUMPF software tools use the OPC UA Server in C++ based OPC UA SDK by Unified Automation. The application contains several vulnerabilities, which enable an attacker to send malicious data to the application, resulting in a Denial-of-Service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2022-034</guid>
    </item>
    <item>
      <title>VDE-2022-046 — PHOENIX CONTACT: Multiple Linux component vulnerabilities in PLCnext Firmware</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2022-046</link>
      <description>&lt;p&gt;UPDATE A: Two devices (ENERGY AXC PU, SMARTRTU AXC SG) added (24.11.2022) Update for PLCnext Firmware containing fixes for recent vulnerability findings in Linux components and security enhancements. PLCnext Control AXC F x152 is certified according to IEC 62443-4-1 and IEC 62443-4-2. This certification requires that all third-party components used in the firmware are regularly checked for known vulnerabilities.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;UPDATE A: Two devices (ENERGY AXC PU, SMARTRTU AXC SG) added (24.11.2022) Update for PLCnext Firmware containing fixes for recent vulnerability findings in Linux components and security enhancements. PLCnext Control AXC F x152 is certified according to IEC 62443-4-1 and IEC 62443-4-2. This certification requires that all third-party components used in the firmware are regularly checked for known vulnerabilities.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2022-046</guid>
    </item>
  </channel>
</rss>
