<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:29:01 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-235497</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-235497</link>
      <description>EUVD-2026-235497</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-235497</guid>
    </item>
    <item>
      <title>fkie_cve-2022-3737</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-3737</link>
      <description>&lt;p&gt;In PHOENIX CONTACT Automationworx Software Suite up to version 1.89 memory can be read beyond the intended scope due to insufficient validation of input data. Availability, integrity, or confidentiality of an application programming workstation might be compromised by attacks using these vulnerabilities.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In PHOENIX CONTACT Automationworx Software Suite up to version 1.89 memory can be read beyond the intended scope due to insufficient validation of input data. Availability, integrity, or confidentiality of an application programming workstation might be compromised by attacks using these vulnerabilities.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-3737</guid>
    </item>
    <item>
      <title>GHSA-r2cg-cw4r-gcx4</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r2cg-cw4r-gcx4</link>
      <description>&lt;p&gt;In PHOENIX CONTACT Automationworx Software Suite up to version 1.89 memory can be read beyond the intended scope due to insufficient validation of input data. Availability, integrity, or confidentiality of an application programming workstation might be compromised by attacks using these vulnerabilities.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In PHOENIX CONTACT Automationworx Software Suite up to version 1.89 memory can be read beyond the intended scope due to insufficient validation of input data. Availability, integrity, or confidentiality of an application programming workstation might be compromised by attacks using these vulnerabilities.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r2cg-cw4r-gcx4</guid>
    </item>
    <item>
      <title>gsd-2022-3737</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-3737</link>
      <description>gsd-2022-3737</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-3737</guid>
    </item>
    <item>
      <title>ICSA-22-326-03 — Phoenix Contact Automation Worx</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-22-326-03</link>
      <description>&lt;p&gt;In Phoenix Contact Automation Worx Software Suite up to version 1.89, manipulated PC Worx or Config+ files could lead to a heap buffer overflow or a read access violation. Availability, integrity, or confidentiality of an application programming workstation could be compromised by attacks using these vulnerabilities.CVE-2022-3461 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). In Phoenix Contact Automation Worx Software Suite up to version 1.89, unauthorized users could read memory beyond the intended scope due to insufficient validation of input data. Availability, integrity, or confidentiality of an application programming workstation could be compromised by attacks using these vulnerabilities.CVE-2022-3737 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In Phoenix Contact Automation Worx Software Suite up to version 1.89, manipulated PC Worx or Config+ files could lead to a heap buffer overflow or a read access violation. Availability, integrity, or confidentiality of an application programming workstation could be compromised by attacks using these vulnerabilities.CVE-2022-3461 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). In Phoenix Contact Automation Worx Software Suite up to version 1.89, unauthorized users could read memory beyond the intended scope due to insufficient validation of input data. Availability, integrity, or confidentiality of an application programming workstation could be compromised by attacks using these vulnerabilities.CVE-2022-3737 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-22-326-03</guid>
    </item>
    <item>
      <title>VDE-2022-048 — PHOENIX CONTACT: Automationworx BCP File Parsing Vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2022-048</link>
      <description>&lt;p&gt;Manipulated PC Worx or Config+ files could lead to a heap buffer overflow, release of unallocated memory or a read access violation due to insufficient validation of input data.The attacker needs to get access to an original bus configuration file (*.bcp) to be able to manipulate data inside. After manipulation the attacker needs to exchange the original file by the manipulated one on the application programming workstation.&lt;/p&gt;
&lt;p&gt;Update A, 2022-11-14&lt;/p&gt;
&lt;p&gt;removed the sentence &amp;#34;Automated systems in operation which were programmed with one of the above-mentioned products are not affected.&amp;#34; from Impact.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Manipulated PC Worx or Config+ files could lead to a heap buffer overflow, release of unallocated memory or a read access violation due to insufficient validation of input data.The attacker needs to get access to an original bus configuration file (*.bcp) to be able to manipulate data inside. After manipulation the attacker needs to exchange the original file by the manipulated one on the application programming workstation.&lt;/p&gt;
&lt;p&gt;Update A, 2022-11-14&lt;/p&gt;
&lt;p&gt;removed the sentence &amp;#34;Automated systems in operation which were programmed with one of the above-mentioned products are not affected.&amp;#34; from Impact.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2022-048</guid>
    </item>
  </channel>
</rss>
