<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 09:52:33 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-183886</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-183886</link>
      <description>EUVD-2026-183886</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-183886</guid>
    </item>
    <item>
      <title>fkie_cve-2022-31806</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-31806</link>
      <description>&lt;p&gt;In CODESYS V2 PLCWinNT and Runtime Toolkit 32 in versions prior to V2.4.7.57 password protection is not enabled by default and there is no information or prompt to enable password protection at login in case no password is set at the controller.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In CODESYS V2 PLCWinNT and Runtime Toolkit 32 in versions prior to V2.4.7.57 password protection is not enabled by default and there is no information or prompt to enable password protection at login in case no password is set at the controller.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-31806</guid>
    </item>
    <item>
      <title>FSA-202208 — Festo: Multiple Festo products contain an unsafe default Codesys configuration</title>
      <link>https://cve.radiocsirt.org/vuln/fsa-202208</link>
      <description>&lt;p&gt;The products are shipped with an unsafe configuration of the integrated CODESYS Runtime
environment. In this case no default password is set to the CODESYS PLC and therefore access
without authentication is possible.&lt;/p&gt;
&lt;p&gt;With a successful established connection to the CODESYS Runtime the PLC-Browser commands are
available. Thus granting the possibilities to e.g. read and modify the configuration file(s), start/stop
the application and reboot the device.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The products are shipped with an unsafe configuration of the integrated CODESYS Runtime
environment. In this case no default password is set to the CODESYS PLC and therefore access
without authentication is possible.&lt;/p&gt;
&lt;p&gt;With a successful established connection to the CODESYS Runtime the PLC-Browser commands are
available. Thus granting the possibilities to e.g. read and modify the configuration file(s), start/stop
the application and reboot the device.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fsa-202208</guid>
    </item>
    <item>
      <title>GHSA-796c-7jw3-fwpp</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-796c-7jw3-fwpp</link>
      <description>&lt;p&gt;In CODESYS V2 PLCWinNT and Runtime Toolkit 32 in versions prior to V2.4.7.57 password protection is not enabled by default and there is no information or prompt to enable password protection at login in case no password is set at the controller.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In CODESYS V2 PLCWinNT and Runtime Toolkit 32 in versions prior to V2.4.7.57 password protection is not enabled by default and there is no information or prompt to enable password protection at login in case no password is set at the controller.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-796c-7jw3-fwpp</guid>
    </item>
    <item>
      <title>gsd-2022-31806</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-31806</link>
      <description>gsd-2022-31806</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-31806</guid>
    </item>
    <item>
      <title>ICSA-25-329-05 — Festo Compact Vision System, Control Block, Controller, and Operator Unit products</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-25-329-05</link>
      <description>&lt;p&gt;A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime system to use the vulnerability in order to read and modify the configuration file(s) of the affected products. In CODESYS V2 PLCWinNT and Runtime Toolkit 32 in versions prior to V2.4.7.57 password protection is not enabled by default and there is no information or prompt to enable password protection at login in case no password is set at the controller.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime system to use the vulnerability in order to read and modify the configuration file(s) of the affected products. In CODESYS V2 PLCWinNT and Runtime Toolkit 32 in versions prior to V2.4.7.57 password protection is not enabled by default and there is no information or prompt to enable password protection at login in case no password is set at the controller.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-25-329-05</guid>
    </item>
    <item>
      <title>VDE-2022-040 — WAGO: Multiple Vulnerabilities in Controller with WAGO I/O-Pro / CODESYS 2.3 Runtime</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2022-040</link>
      <description>&lt;p&gt;UPDATE A: Solution has updated release datesUPDATE B: Solution has updated release datesThis Advisory is published with reference to:&lt;/p&gt;
&lt;p&gt;CODESYS Advisory 2022-11 (Security update for CODESYS Control V2)
CODESYS Advisory 2022-12 (Security update for CODESYS V2 password transport)
CODESYS Advisory 2022-13 (Security update for CODESYS Gateway V2)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;UPDATE A: Solution has updated release datesUPDATE B: Solution has updated release datesThis Advisory is published with reference to:&lt;/p&gt;
&lt;p&gt;CODESYS Advisory 2022-11 (Security update for CODESYS Control V2)
CODESYS Advisory 2022-12 (Security update for CODESYS V2 password transport)
CODESYS Advisory 2022-13 (Security update for CODESYS Gateway V2)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2022-040</guid>
    </item>
  </channel>
</rss>
