<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 08:57:24 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-04486</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-04486</link>
      <description>bdu:2023-04486</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-04486</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0525 — De multiples vulnérabilités ont été découvertes dans les produits
Schneider Electric. Certaines d'entre elles permetten…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0525</link>
      <description>certfr-2023-avi-0525</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0525</guid>
    </item>
    <item>
      <title>EUVD-2026-220695</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-220695</link>
      <description>EUVD-2026-220695</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-220695</guid>
    </item>
    <item>
      <title>fkie_cve-2022-47388</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-47388</link>
      <description>&lt;p&gt;An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-47388</guid>
    </item>
    <item>
      <title>FSA-202401 — Festo: Multiple products contain CoDe16 vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/fsa-202401</link>
      <description>&lt;p&gt;Several high severity vulnerabilities in CODESYS V3 affecting Festo products could lead to Remote Code Execution or Denial of Service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Several high severity vulnerabilities in CODESYS V3 affecting Festo products could lead to Remote Code Execution or Denial of Service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fsa-202401</guid>
    </item>
    <item>
      <title>GHSA-8gxg-qx47-fx77</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8gxg-qx47-fx77</link>
      <description>&lt;p&gt;An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8gxg-qx47-fx77</guid>
    </item>
    <item>
      <title>gsd-2022-47388</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-47388</link>
      <description>gsd-2022-47388</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-47388</guid>
    </item>
    <item>
      <title>ICSA-24-030-07 — Rockwell Automation LP30/40/50 and BM40 Operator Interface</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-24-030-07</link>
      <description>&lt;p&gt;After successful authentication, specifically crafted communication requests with inconsistent content can cause the CmpFiletransfer component to read internally from an invalid address, potentially leading to a denial-of-service condition.  After successful authentication, specifically crafted communication requests can cause the CmpApp component to write threat actor-controlled data to memory, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.  After successful authentication, specifically crafted communication requests can cause the CmpApp component to write threat actor-controlled data to stack, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.  After successful authentication, specifically crafted communication requests can cause the CmpApp component to write threat actor-controlled data to stack, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.  After successful authentication, specifically crafted communication requests can cause the CmpTraceMgr component to write threat actor-controlled data to stack, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.  After successful authentication, specifically crafted communication requests can cause the CmpTraceMgr component to write threat actor-controlled data to stack, which can lead to a denial-of-service condition, memory overwriting, or remote cod…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;After successful authentication, specifically crafted communication requests with inconsistent content can cause the CmpFiletransfer component to read internally from an invalid address, potentially leading to a denial-of-service condition.  After successful authentication, specifically crafted communication requests can cause the CmpApp component to write threat actor-controlled data to memory, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.  After successful authentication, specifically crafted communication requests can cause the CmpApp component to write threat actor-controlled data to stack, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.  After successful authentication, specifically crafted communication requests can cause the CmpApp component to write threat actor-controlled data to stack, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.  After successful authentication, specifically crafted communication requests can cause the CmpTraceMgr component to write threat actor-controlled data to stack, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.  After successful authentication, specifically crafted communication requests can cause the CmpTraceMgr component to write threat actor-controlled data to stack, which can lead to a denial-of-service condition, memory overwriting, or remote cod…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-24-030-07</guid>
    </item>
    <item>
      <title>SEVD-2023-192-04 — CODESYS Runtime Vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/sevd-2023-192-04</link>
      <description>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities disclosed on CODESYS runtime system V3 communication server. Many vendors, including Schneider Electric, embed CODESYS in their offers. &#13;
&#13;
If successfully exploited, these vulnerabilities could result in a denial of service or, in some cases, in remote code execution on PacDrive controllers, Modicon Controllers M241 / M251 / M262 / M258 / LMC058 / LMC078 / M218 ,  HMISCU, the Simulation Runtime SoftSPS from EcoStruxure Machine Expert and EcoStruxure Microgrid Operation products. &#13;
&#13;
Failure to apply the mitigations provided below may result in denial of service and/or arbitrary remote code execution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities disclosed on CODESYS runtime system V3 communication server. Many vendors, including Schneider Electric, embed CODESYS in their offers. &#13;
&#13;
If successfully exploited, these vulnerabilities could result in a denial of service or, in some cases, in remote code execution on PacDrive controllers, Modicon Controllers M241 / M251 / M262 / M258 / LMC058 / LMC078 / M218 ,  HMISCU, the Simulation Runtime SoftSPS from EcoStruxure Machine Expert and EcoStruxure Microgrid Operation products. &#13;
&#13;
Failure to apply the mitigations provided below may result in denial of service and/or arbitrary remote code execution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sevd-2023-192-04</guid>
    </item>
    <item>
      <title>VDE-2023-026 — WAGO: Multiple products prone to multiple vulnerabilities in e!Runtime / CODESYS V3 Runtime</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2023-026</link>
      <description>&lt;p&gt;Multiple WAGO devices are prone to vulnerabilites in the used CODESYS V3 framework.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple WAGO devices are prone to vulnerabilites in the used CODESYS V3 framework.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2023-026</guid>
    </item>
    <item>
      <title>VDE-2026-003 — Endress+Hauser: Multiple products prone to multiple vulnerabilities in e!Runtime and CODESYS V3 Runtime</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2026-003</link>
      <description>&lt;p&gt;Multiple Endress+Hauser devices are prone to vulnerabilities found in e!Runtime and the CODESYS V3 framework.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple Endress+Hauser devices are prone to vulnerabilities found in e!Runtime and the CODESYS V3 framework.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2026-003</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-2270 — Codesys V3: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2270</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Codesys V3 ausnutzen, um beliebigen Programmcode auszuführen, Speicher zu überschreiben oder einen Denial of Service zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Codesys V3 ausnutzen, um beliebigen Programmcode auszuführen, Speicher zu überschreiben oder einen Denial of Service zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2270</guid>
    </item>
  </channel>
</rss>
