<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 22:06:24 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-08948</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-08948</link>
      <description>bdu:2023-08948</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-08948</guid>
    </item>
    <item>
      <title>EUVD-2026-6554</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-6554</link>
      <description>EUVD-2026-6554</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-6554</guid>
    </item>
    <item>
      <title>fkie_cve-2023-0757</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-0757</link>
      <description>&lt;p&gt;Incorrect Permission Assignment for Critical Resource vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote attacker to upload arbitrary malicious code and gain full access on the affected device.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Incorrect Permission Assignment for Critical Resource vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote attacker to upload arbitrary malicious code and gain full access on the affected device.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-0757</guid>
    </item>
    <item>
      <title>GHSA-j2r4-7r3h-j7m5</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-j2r4-7r3h-j7m5</link>
      <description>&lt;p&gt;Incorrect Permission Assignment for Critical Resource vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote attacker to upload arbitrary malicious code and gain full access on the affected device.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Incorrect Permission Assignment for Critical Resource vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote attacker to upload arbitrary malicious code and gain full access on the affected device.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-j2r4-7r3h-j7m5</guid>
    </item>
    <item>
      <title>gsd-2023-0757</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-0757</link>
      <description>gsd-2023-0757</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-0757</guid>
    </item>
    <item>
      <title>VDE-2023-051 — Phoenix Contact: MULTIPROG Engineering tool and ProConOS eCLR SDK prone to CWE-732</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2023-051</link>
      <description>&lt;p&gt;Increased Security attacks against OT infrastructure and research of Dragos makes it necessary to publish this advisory giving users hints according to basic security measures to support automation systems using existing devices based on ProConOS/ProConOS eCLR.&lt;/p&gt;
&lt;p&gt;ProConOS/ProConOS eCLR controller runtime system has been offered as a Software Development Kit (SDK) to automation suppliers that build their own automation devices.&lt;/p&gt;
&lt;p&gt;ProConOS/ProConOS eCLR is embedded into automation suppliers&amp;#39; hardware, real-time operating systems (RTOS), firmware, and I/O systems.The application (e.g.: logic files, executable logic, configurations) had been designed without integrity and authenticity check which was state of the art when developing the products.&lt;/p&gt;
&lt;p&gt;Logic files generated by MULTIPROG Engineering tool could be manipulated on the engineering station and loaded into the PLC without tamper detection. In addition, tampering can be done by specially designed attacks in such a way that it remains hidden, and the logic program modifies its own code, making it difficult to determine the impact of a malicious program.
Users need to check with their device vendors if they are affected by this attack vulnerability or if the specific device integration mitigates this attack vector.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Increased Security attacks against OT infrastructure and research of Dragos makes it necessary to publish this advisory giving users hints according to basic security measures to support automation systems using existing devices based on ProConOS/ProConOS eCLR.&lt;/p&gt;
&lt;p&gt;ProConOS/ProConOS eCLR controller runtime system has been offered as a Software Development Kit (SDK) to automation suppliers that build their own automation devices.&lt;/p&gt;
&lt;p&gt;ProConOS/ProConOS eCLR is embedded into automation suppliers&amp;#39; hardware, real-time operating systems (RTOS), firmware, and I/O systems.The application (e.g.: logic files, executable logic, configurations) had been designed without integrity and authenticity check which was state of the art when developing the products.&lt;/p&gt;
&lt;p&gt;Logic files generated by MULTIPROG Engineering tool could be manipulated on the engineering station and loaded into the PLC without tamper detection. In addition, tampering can be done by specially designed attacks in such a way that it remains hidden, and the logic program modifies its own code, making it difficult to determine the impact of a malicious program.
Users need to check with their device vendors if they are affected by this attack vulnerability or if the specific device integration mitigates this attack vector.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2023-051</guid>
    </item>
  </channel>
</rss>
