<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 13:11:34 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-07322</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-07322</link>
      <description>bdu:2022-07322</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-07322</guid>
    </item>
    <item>
      <title>certfr-2022-avi-1001 — De multiples vulnérabilités ont été découvertes dans les produits
Siemens. Certaines d'entre elles permettent à un atta…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-1001</link>
      <description>certfr-2022-avi-1001</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-1001</guid>
    </item>
    <item>
      <title>cnvd-2022-75540</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2022-75540</link>
      <description>cnvd-2022-75540</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2022-75540</guid>
    </item>
    <item>
      <title>EUVD-2026-262875</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-262875</link>
      <description>EUVD-2026-262875</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-262875</guid>
    </item>
    <item>
      <title>fkie_cve-2022-43439</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-43439</link>
      <description>&lt;p&gt;A vulnerability has been identified in POWER METER SICAM Q100 (7KG9501-0AA01-0AA1) (All versions &amp;lt; V2.50), POWER METER SICAM Q100 (7KG9501-0AA01-2AA1) (All versions &amp;lt; V2.50), POWER METER SICAM Q100 (7KG9501-0AA31-0AA1) (All versions &amp;lt; V2.50), POWER METER SICAM Q100 (7KG9501-0AA31-2AA1) (All versions &amp;lt; V2.50), SICAM P850 (7KG8500-0AA00-0AA0) (All versions &amp;lt; V3.10), SICAM P850 (7KG8500-0AA00-2AA0) (All versions &amp;lt; V3.10), SICAM P850 (7KG8500-0AA10-0AA0) (All versions &amp;lt; V3.10), SICAM P850 (7KG8500-0AA10-2AA0) (All versions &amp;lt; V3.10), SICAM P850 (7KG8500-0AA30-0AA0) (All versions &amp;lt; V3.10), SICAM P850 (7KG8500-0AA30-2AA0) (All versions &amp;lt; V3.10), SICAM P850 (7KG8501-0AA01-0AA0) (All versions &amp;lt; V3.10), SICAM P850 (7KG8501-0AA01-2AA0) (All versions &amp;lt; V3.10), SICAM P850 (7KG8501-0AA02-0AA0) (All versions &amp;lt; V3.10), SICAM P850 (7KG8501-0AA02-2AA0) (All versions &amp;lt; V3.10), SICAM P850 (7KG8501-0AA11-0AA0) (All versions &amp;lt; V3.10), SICAM P850 (7KG8501-0AA11-2AA0) (All versions &amp;lt; V3.10), SICAM P850 (7KG8501-0AA12-0AA0) (All versions &amp;lt; V3.10), SICAM P850 (7KG8501-0AA12-2AA0) (All versions &amp;lt; V3.10), SICAM P850 (7KG8501-0AA31-0AA0) (All versions &amp;lt; V3.10), SICAM P850 (7KG8501-0AA31-2AA0) (All versions &amp;lt; V3.10), SICAM P850 (7KG8501-0AA32-0AA0) (All versions &amp;lt; V3.10), SICAM P850 (7KG8501-0AA32-2AA0) (All versions &amp;lt; V3.10), SICAM P855 (7KG8550-0AA00-0AA0) (All versions &amp;lt; V3.10), SICAM P855 (7KG8550-0AA00-2AA0) (All versions &amp;lt; V3.10), SICAM P855 (7KG8550-0AA10-0AA0) (All versions &amp;lt; V3.10), SICAM P855 (…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability has been identified in POWER METER SICAM Q100 (7KG9501-0AA01-0AA1) (All versions &amp;lt; V2.50), POWER METER SICAM Q100 (7KG9501-0AA01-2AA1) (All versions &amp;lt; V2.50), POWER METER SICAM Q100 (7KG9501-0AA31-0AA1) (All versions &amp;lt; V2.50), POWER METER SICAM Q100 (7KG9501-0AA31-2AA1) (All versions &amp;lt; V2.50), SICAM P850 (7KG8500-0AA00-0AA0) (All versions &amp;lt; V3.10), SICAM P850 (7KG8500-0AA00-2AA0) (All versions &amp;lt; V3.10), SICAM P850 (7KG8500-0AA10-0AA0) (All versions &amp;lt; V3.10), SICAM P850 (7KG8500-0AA10-2AA0) (All versions &amp;lt; V3.10), SICAM P850 (7KG8500-0AA30-0AA0) (All versions &amp;lt; V3.10), SICAM P850 (7KG8500-0AA30-2AA0) (All versions &amp;lt; V3.10), SICAM P850 (7KG8501-0AA01-0AA0) (All versions &amp;lt; V3.10), SICAM P850 (7KG8501-0AA01-2AA0) (All versions &amp;lt; V3.10), SICAM P850 (7KG8501-0AA02-0AA0) (All versions &amp;lt; V3.10), SICAM P850 (7KG8501-0AA02-2AA0) (All versions &amp;lt; V3.10), SICAM P850 (7KG8501-0AA11-0AA0) (All versions &amp;lt; V3.10), SICAM P850 (7KG8501-0AA11-2AA0) (All versions &amp;lt; V3.10), SICAM P850 (7KG8501-0AA12-0AA0) (All versions &amp;lt; V3.10), SICAM P850 (7KG8501-0AA12-2AA0) (All versions &amp;lt; V3.10), SICAM P850 (7KG8501-0AA31-0AA0) (All versions &amp;lt; V3.10), SICAM P850 (7KG8501-0AA31-2AA0) (All versions &amp;lt; V3.10), SICAM P850 (7KG8501-0AA32-0AA0) (All versions &amp;lt; V3.10), SICAM P850 (7KG8501-0AA32-2AA0) (All versions &amp;lt; V3.10), SICAM P855 (7KG8550-0AA00-0AA0) (All versions &amp;lt; V3.10), SICAM P855 (7KG8550-0AA00-2AA0) (All versions &amp;lt; V3.10), SICAM P855 (7KG8550-0AA10-0AA0) (All versions &amp;lt; V3.10), SICAM P855 (…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-43439</guid>
    </item>
    <item>
      <title>GHSA-hj8w-fgm6-wx7w</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hj8w-fgm6-wx7w</link>
      <description>&lt;p&gt;A vulnerability has been identified in POWER METER SICAM Q100 (All versions &amp;lt; V2.50), POWER METER SICAM Q100 (All versions &amp;lt; V2.50). Affected devices do not properly validate the Language-parameter in requests to the web interface on port 443/tcp. This could allow an authenticated remote attacker to crash the device (followed by an automatic reboot) or to execute arbitrary code on the device.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability has been identified in POWER METER SICAM Q100 (All versions &amp;lt; V2.50), POWER METER SICAM Q100 (All versions &amp;lt; V2.50). Affected devices do not properly validate the Language-parameter in requests to the web interface on port 443/tcp. This could allow an authenticated remote attacker to crash the device (followed by an automatic reboot) or to execute arbitrary code on the device.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hj8w-fgm6-wx7w</guid>
    </item>
    <item>
      <title>gsd-2022-43439</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-43439</link>
      <description>gsd-2022-43439</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-43439</guid>
    </item>
    <item>
      <title>ICSA-22-286-09 — Siemens SICAM P850 and P855 Devices</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-22-286-09</link>
      <description>&lt;p&gt;Affected devices accept user defined session cookies and do not renew the session cookie after login/logout. This could allow an attacker to take over another user&amp;#39;s session after login. Affected devices do not properly validate the parameter of a specific GET request. This could allow an unauthenticated attacker to set the device to a denial of service state or to control the program counter and, thus, execute arbitrary code on the device. Affected devices do not properly validate the Language-parameter in requests to the web interface on port  443/tcp. This could allow an authenticated remote attacker to crash the device (followed by an automatic reboot) or to execute arbitrary code on the device. Affected devices do not properly validate the RecordType-parameter in requests to the web interface on port 443/tcp. This could allow an authenticated remote attacker to crash the device (followed by an automatic reboot) or to execute arbitrary code on the device. Affected devices do not properly validate the EndTime-parameter in requests to the web interface on port 443/tcp. This could allow an authenticated remote attacker to crash the device (followed by an automatic reboot) or to execute arbitrary code on the device.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Affected devices accept user defined session cookies and do not renew the session cookie after login/logout. This could allow an attacker to take over another user&amp;#39;s session after login. Affected devices do not properly validate the parameter of a specific GET request. This could allow an unauthenticated attacker to set the device to a denial of service state or to control the program counter and, thus, execute arbitrary code on the device. Affected devices do not properly validate the Language-parameter in requests to the web interface on port  443/tcp. This could allow an authenticated remote attacker to crash the device (followed by an automatic reboot) or to execute arbitrary code on the device. Affected devices do not properly validate the RecordType-parameter in requests to the web interface on port 443/tcp. This could allow an authenticated remote attacker to crash the device (followed by an automatic reboot) or to execute arbitrary code on the device. Affected devices do not properly validate the EndTime-parameter in requests to the web interface on port 443/tcp. This could allow an authenticated remote attacker to crash the device (followed by an automatic reboot) or to execute arbitrary code on the device.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-22-286-09</guid>
    </item>
    <item>
      <title>SSA-471761 — SSA-471761: Multiple Vulnerabilities in SICAM T Before V3.0</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-471761</link>
      <description>&lt;p&gt;Affected devices do not properly validate parameters of POST requests. This could allow an authenticated attacker to set the device to a denial of service state or to control the program counter and, thus, execute arbitrary code on the device. Affected devices do not properly validate parameters of certain GET and POST requests. This could allow an unauthenticated attacker to set the device to a denial of service state or to control the program counter and, thus, execute arbitrary code on the device. Affected devices do not encrypt web traffic with clients but communicate in cleartext via HTTP. This could allow an unauthenticated attacker to capture the traffic and interfere with the functionality of the device. Affected devices do not properly handle the input of a GET request parameter. The provided argument is directly reflected in the web server response. This could allow an unauthenticated attacker to perform reflected XSS attacks. Affected devices use a limited range for challenges that are sent during the unencrypted challenge-response communication. An unauthenticated attacker could capture a valid challenge-response pair generated by a legitimate user, and request the webpage repeatedly to wait for the same challenge to reappear for which the correct response is known. This could allow the attacker to access the management interface of the device. The web based management interface of affected devices does not employ special access protection for certain internal de…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Affected devices do not properly validate parameters of POST requests. This could allow an authenticated attacker to set the device to a denial of service state or to control the program counter and, thus, execute arbitrary code on the device. Affected devices do not properly validate parameters of certain GET and POST requests. This could allow an unauthenticated attacker to set the device to a denial of service state or to control the program counter and, thus, execute arbitrary code on the device. Affected devices do not encrypt web traffic with clients but communicate in cleartext via HTTP. This could allow an unauthenticated attacker to capture the traffic and interfere with the functionality of the device. Affected devices do not properly handle the input of a GET request parameter. The provided argument is directly reflected in the web server response. This could allow an unauthenticated attacker to perform reflected XSS attacks. Affected devices use a limited range for challenges that are sent during the unencrypted challenge-response communication. An unauthenticated attacker could capture a valid challenge-response pair generated by a legitimate user, and request the webpage repeatedly to wait for the same challenge to reappear for which the correct response is known. This could allow the attacker to access the management interface of the device. The web based management interface of affected devices does not employ special access protection for certain internal de…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-471761</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1974 — Siemens SICAM: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1974</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter  oder anonymer Angreifer kann mehrere Schwachstellen in Siemens SICAM ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsvorkehrungen zu umgehen oder einen Denial of Service zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter  oder anonymer Angreifer kann mehrere Schwachstellen in Siemens SICAM ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsvorkehrungen zu umgehen oder einen Denial of Service zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1974</guid>
    </item>
  </channel>
</rss>
