<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 01:57:08 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-03244</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-03244</link>
      <description>bdu:2022-03244</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-03244</guid>
    </item>
    <item>
      <title>certfr-2022-avi-435 — De multiples vulnérabilités ont été découvertes dans les produits
Siemens. Certaines d'entre elles permettent à un atta…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-435</link>
      <description>certfr-2022-avi-435</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-435</guid>
    </item>
    <item>
      <title>cnvd-2022-36397</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2022-36397</link>
      <description>cnvd-2022-36397</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2022-36397</guid>
    </item>
    <item>
      <title>EUVD-2026-262863</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-262863</link>
      <description>EUVD-2026-262863</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-262863</guid>
    </item>
    <item>
      <title>fkie_cve-2022-29873</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-29873</link>
      <description>&lt;p&gt;A vulnerability has been identified in SICAM T (All versions &amp;lt; V3.0). Affected devices do not properly validate parameters of certain GET and POST requests. This could allow an unauthenticated attacker to set the device to a denial of service state or to control the program counter and, thus, execute arbitrary code on the device.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability has been identified in SICAM T (All versions &amp;lt; V3.0). Affected devices do not properly validate parameters of certain GET and POST requests. This could allow an unauthenticated attacker to set the device to a denial of service state or to control the program counter and, thus, execute arbitrary code on the device.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-29873</guid>
    </item>
    <item>
      <title>GHSA-v36v-c6xp-cpv3</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v36v-c6xp-cpv3</link>
      <description>&lt;p&gt;A vulnerability has been identified in SICAM P850 (All versions &amp;lt; V3.00), SICAM P850 (All versions &amp;lt; V3.00), SICAM P850 (All versions &amp;lt; V3.00), SICAM P850 (All versions &amp;lt; V3.00), SICAM P850 (All versions &amp;lt; V3.00), SICAM P850 (All versions &amp;lt; V3.00), SICAM P850 (All versions &amp;lt; V3.00), SICAM P850 (All versions &amp;lt; V3.00), SICAM P850 (All versions &amp;lt; V3.00), SICAM P850 (All versions &amp;lt; V3.00), SICAM P850 (All versions &amp;lt; V3.00), SICAM P850 (All versions &amp;lt; V3.00), SICAM P850 (All versions &amp;lt; V3.00), SICAM P850 (All versions &amp;lt; V3.00), SICAM P850 (All versions &amp;lt; V3.00), SICAM P850 (All versions &amp;lt; V3.00), SICAM P850 (All versions &amp;lt; V3.00), SICAM P850 (All versions &amp;lt; V3.00), SICAM P855 (All versions &amp;lt; V3.00), SICAM P855 (All versions &amp;lt; V3.00), SICAM P855 (All versions &amp;lt; V3.00), SICAM P855 (All versions &amp;lt; V3.00), SICAM P855 (All versions &amp;lt; V3.00), SICAM P855 (All versions &amp;lt; V3.00), SICAM P855 (All versions &amp;lt; V3.00), SICAM P855 (All versions &amp;lt; V3.00), SICAM P855 (All versions &amp;lt; V3.00), SICAM P855 (All versions &amp;lt; V3.00), SICAM P855 (All versions &amp;lt; V3.00), SICAM P855 (All versions &amp;lt; V3.00), SICAM P855 (All versions &amp;lt; V3.00), SICAM P855 (All versions &amp;lt; V3.00), SICAM P855 (All versions &amp;lt; V3.00), SICAM P855 (All versions &amp;lt; V3.00), SICAM P855 (All versions &amp;lt; V3.00), SICAM P855 (All versions &amp;lt; V3.00). Affected devices do not properly validate parameters of certain GET and POST requests. This could allow an unauthenticated attacker to set the device to a denial of service state or to control the pro…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability has been identified in SICAM P850 (All versions &amp;lt; V3.00), SICAM P850 (All versions &amp;lt; V3.00), SICAM P850 (All versions &amp;lt; V3.00), SICAM P850 (All versions &amp;lt; V3.00), SICAM P850 (All versions &amp;lt; V3.00), SICAM P850 (All versions &amp;lt; V3.00), SICAM P850 (All versions &amp;lt; V3.00), SICAM P850 (All versions &amp;lt; V3.00), SICAM P850 (All versions &amp;lt; V3.00), SICAM P850 (All versions &amp;lt; V3.00), SICAM P850 (All versions &amp;lt; V3.00), SICAM P850 (All versions &amp;lt; V3.00), SICAM P850 (All versions &amp;lt; V3.00), SICAM P850 (All versions &amp;lt; V3.00), SICAM P850 (All versions &amp;lt; V3.00), SICAM P850 (All versions &amp;lt; V3.00), SICAM P850 (All versions &amp;lt; V3.00), SICAM P850 (All versions &amp;lt; V3.00), SICAM P855 (All versions &amp;lt; V3.00), SICAM P855 (All versions &amp;lt; V3.00), SICAM P855 (All versions &amp;lt; V3.00), SICAM P855 (All versions &amp;lt; V3.00), SICAM P855 (All versions &amp;lt; V3.00), SICAM P855 (All versions &amp;lt; V3.00), SICAM P855 (All versions &amp;lt; V3.00), SICAM P855 (All versions &amp;lt; V3.00), SICAM P855 (All versions &amp;lt; V3.00), SICAM P855 (All versions &amp;lt; V3.00), SICAM P855 (All versions &amp;lt; V3.00), SICAM P855 (All versions &amp;lt; V3.00), SICAM P855 (All versions &amp;lt; V3.00), SICAM P855 (All versions &amp;lt; V3.00), SICAM P855 (All versions &amp;lt; V3.00), SICAM P855 (All versions &amp;lt; V3.00), SICAM P855 (All versions &amp;lt; V3.00), SICAM P855 (All versions &amp;lt; V3.00). Affected devices do not properly validate parameters of certain GET and POST requests. This could allow an unauthenticated attacker to set the device to a denial of service state or to control the pro…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v36v-c6xp-cpv3</guid>
    </item>
    <item>
      <title>gsd-2022-29873</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-29873</link>
      <description>gsd-2022-29873</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-29873</guid>
    </item>
    <item>
      <title>ICSA-22-132-07 — Siemens SICAM P850 and SICAM P855</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-22-132-07</link>
      <description>&lt;p&gt;Affected devices do not properly validate parameters of POST requests. This could allow an authenticated attacker to set the device to a denial of service state or to control the program counter and, thus, execute arbitrary code on the device. Affected devices do not properly validate parameters of certain GET and POST requests. This could allow an unauthenticated attacker to set the device to a denial of service state or to control the program counter and, thus, execute arbitrary code on the device. Affected devices do not encrypt web traffic with clients but communicate in cleartext via HTTP. This could allow an unauthenticated attacker to capture the traffic and interfere with the functionality of the device. Affected devices do not properly handle the input of a GET request parameter. The provided argument is directly reflected in the web server response. This could allow an unauthenticated attacker to perform reflected XSS attacks. Affected devices allow unauthenticated access to the web interface configuration area. This could allow an attacker to extract internal configuration details or to reconfigure network settings. However, the reconfigured settings cannot be activated unless the role of an authenticated administrator user. Affected devices use a limited range for challenges that are sent during the unencrypted challenge-response communication. An unauthenticated attacker could capture a valid challenge-response pair generated by a legitimate user, and request th…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Affected devices do not properly validate parameters of POST requests. This could allow an authenticated attacker to set the device to a denial of service state or to control the program counter and, thus, execute arbitrary code on the device. Affected devices do not properly validate parameters of certain GET and POST requests. This could allow an unauthenticated attacker to set the device to a denial of service state or to control the program counter and, thus, execute arbitrary code on the device. Affected devices do not encrypt web traffic with clients but communicate in cleartext via HTTP. This could allow an unauthenticated attacker to capture the traffic and interfere with the functionality of the device. Affected devices do not properly handle the input of a GET request parameter. The provided argument is directly reflected in the web server response. This could allow an unauthenticated attacker to perform reflected XSS attacks. Affected devices allow unauthenticated access to the web interface configuration area. This could allow an attacker to extract internal configuration details or to reconfigure network settings. However, the reconfigured settings cannot be activated unless the role of an authenticated administrator user. Affected devices use a limited range for challenges that are sent during the unencrypted challenge-response communication. An unauthenticated attacker could capture a valid challenge-response pair generated by a legitimate user, and request th…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-22-132-07</guid>
    </item>
    <item>
      <title>SSA-471761 — SSA-471761: Multiple Vulnerabilities in SICAM T Before V3.0</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-471761</link>
      <description>&lt;p&gt;Affected devices do not properly validate parameters of POST requests. This could allow an authenticated attacker to set the device to a denial of service state or to control the program counter and, thus, execute arbitrary code on the device. Affected devices do not properly validate parameters of certain GET and POST requests. This could allow an unauthenticated attacker to set the device to a denial of service state or to control the program counter and, thus, execute arbitrary code on the device. Affected devices do not encrypt web traffic with clients but communicate in cleartext via HTTP. This could allow an unauthenticated attacker to capture the traffic and interfere with the functionality of the device. Affected devices do not properly handle the input of a GET request parameter. The provided argument is directly reflected in the web server response. This could allow an unauthenticated attacker to perform reflected XSS attacks. Affected devices use a limited range for challenges that are sent during the unencrypted challenge-response communication. An unauthenticated attacker could capture a valid challenge-response pair generated by a legitimate user, and request the webpage repeatedly to wait for the same challenge to reappear for which the correct response is known. This could allow the attacker to access the management interface of the device. The web based management interface of affected devices does not employ special access protection for certain internal de…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Affected devices do not properly validate parameters of POST requests. This could allow an authenticated attacker to set the device to a denial of service state or to control the program counter and, thus, execute arbitrary code on the device. Affected devices do not properly validate parameters of certain GET and POST requests. This could allow an unauthenticated attacker to set the device to a denial of service state or to control the program counter and, thus, execute arbitrary code on the device. Affected devices do not encrypt web traffic with clients but communicate in cleartext via HTTP. This could allow an unauthenticated attacker to capture the traffic and interfere with the functionality of the device. Affected devices do not properly handle the input of a GET request parameter. The provided argument is directly reflected in the web server response. This could allow an unauthenticated attacker to perform reflected XSS attacks. Affected devices use a limited range for challenges that are sent during the unencrypted challenge-response communication. An unauthenticated attacker could capture a valid challenge-response pair generated by a legitimate user, and request the webpage repeatedly to wait for the same challenge to reappear for which the correct response is known. This could allow the attacker to access the management interface of the device. The web based management interface of affected devices does not employ special access protection for certain internal de…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-471761</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2767 — Siemens SICAM: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2767</link>
      <description>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Siemens SICAM ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen und einen Cross-Site-Scripting Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Siemens SICAM ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen und einen Cross-Site-Scripting Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2767</guid>
    </item>
  </channel>
</rss>
