<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 14:49:55 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-04388</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-04388</link>
      <description>bdu:2023-04388</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-04388</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0526 — De multiples vulnérabilités ont été découvertes dans les produits
Siemens. Certaines d'entre elles permettent à un atta…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0526</link>
      <description>certfr-2023-avi-0526</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0526</guid>
    </item>
    <item>
      <title>cnvd-2023-60612</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2023-60612</link>
      <description>cnvd-2023-60612</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2023-60612</guid>
    </item>
    <item>
      <title>EUVD-2026-204724</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-204724</link>
      <description>EUVD-2026-204724</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-204724</guid>
    </item>
    <item>
      <title>fkie_cve-2023-36749</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-36749</link>
      <description>&lt;p&gt;A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions &amp;lt; V2.16.0), RUGGEDCOM ROX MX5000RE (All versions &amp;lt; V2.16.0), RUGGEDCOM ROX RX1400 (All versions &amp;lt; V2.16.0), RUGGEDCOM ROX RX1500 (All versions &amp;lt; V2.16.0), RUGGEDCOM ROX RX1501 (All versions &amp;lt; V2.16.0), RUGGEDCOM ROX RX1510 (All versions &amp;lt; V2.16.0), RUGGEDCOM ROX RX1511 (All versions &amp;lt; V2.16.0), RUGGEDCOM ROX RX1512 (All versions &amp;lt; V2.16.0), RUGGEDCOM ROX RX1524 (All versions &amp;lt; V2.16.0), RUGGEDCOM ROX RX1536 (All versions &amp;lt; V2.16.0), RUGGEDCOM ROX RX5000 (All versions &amp;lt; V2.16.0). The webserver of the affected devices support insecure TLS 1.0 protocol. An attacker could achieve a man-in-the-middle attack and compromise confidentiality and integrity of data.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions &amp;lt; V2.16.0), RUGGEDCOM ROX MX5000RE (All versions &amp;lt; V2.16.0), RUGGEDCOM ROX RX1400 (All versions &amp;lt; V2.16.0), RUGGEDCOM ROX RX1500 (All versions &amp;lt; V2.16.0), RUGGEDCOM ROX RX1501 (All versions &amp;lt; V2.16.0), RUGGEDCOM ROX RX1510 (All versions &amp;lt; V2.16.0), RUGGEDCOM ROX RX1511 (All versions &amp;lt; V2.16.0), RUGGEDCOM ROX RX1512 (All versions &amp;lt; V2.16.0), RUGGEDCOM ROX RX1524 (All versions &amp;lt; V2.16.0), RUGGEDCOM ROX RX1536 (All versions &amp;lt; V2.16.0), RUGGEDCOM ROX RX5000 (All versions &amp;lt; V2.16.0). The webserver of the affected devices support insecure TLS 1.0 protocol. An attacker could achieve a man-in-the-middle attack and compromise confidentiality and integrity of data.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-36749</guid>
    </item>
    <item>
      <title>GHSA-pcw9-vp4g-qgm6</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pcw9-vp4g-qgm6</link>
      <description>&lt;p&gt;A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions &amp;lt; V2.16.0), RUGGEDCOM ROX MX5000RE (All versions &amp;lt; V2.16.0), RUGGEDCOM ROX RX1400 (All versions &amp;lt; V2.16.0), RUGGEDCOM ROX RX1500 (All versions &amp;lt; V2.16.0), RUGGEDCOM ROX RX1501 (All versions &amp;lt; V2.16.0), RUGGEDCOM ROX RX1510 (All versions &amp;lt; V2.16.0), RUGGEDCOM ROX RX1511 (All versions &amp;lt; V2.16.0), RUGGEDCOM ROX RX1512 (All versions &amp;lt; V2.16.0), RUGGEDCOM ROX RX1524 (All versions &amp;lt; V2.16.0), RUGGEDCOM ROX RX1536 (All versions &amp;lt; V2.16.0), RUGGEDCOM ROX RX5000 (All versions &amp;lt; V2.16.0). The webserver of the affected devices support insecure TLS 1.0 protocol. An attacker could achieve a man-in-the-middle attack and compromise confidentiality and integrity of data.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions &amp;lt; V2.16.0), RUGGEDCOM ROX MX5000RE (All versions &amp;lt; V2.16.0), RUGGEDCOM ROX RX1400 (All versions &amp;lt; V2.16.0), RUGGEDCOM ROX RX1500 (All versions &amp;lt; V2.16.0), RUGGEDCOM ROX RX1501 (All versions &amp;lt; V2.16.0), RUGGEDCOM ROX RX1510 (All versions &amp;lt; V2.16.0), RUGGEDCOM ROX RX1511 (All versions &amp;lt; V2.16.0), RUGGEDCOM ROX RX1512 (All versions &amp;lt; V2.16.0), RUGGEDCOM ROX RX1524 (All versions &amp;lt; V2.16.0), RUGGEDCOM ROX RX1536 (All versions &amp;lt; V2.16.0), RUGGEDCOM ROX RX5000 (All versions &amp;lt; V2.16.0). The webserver of the affected devices support insecure TLS 1.0 protocol. An attacker could achieve a man-in-the-middle attack and compromise confidentiality and integrity of data.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pcw9-vp4g-qgm6</guid>
    </item>
    <item>
      <title>gsd-2023-36749</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-36749</link>
      <description>gsd-2023-36749</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-36749</guid>
    </item>
    <item>
      <title>ICSA-23-194-01 — Siemens RUGGEDCOM ROX</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-23-194-01</link>
      <description>&lt;p&gt;A user can tell curl &amp;gt;= 7.20.0 and &amp;lt;= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLUSESSL_ALL` withlibcurl). This requirement could be bypassed if the server would return a properly crafted but perfectly legitimate response.This flaw would then make curl silently continue its operations **withoutTLS** contrary to the instructions and expectations, exposing possibly sensitive data in clear text over the network. The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022-1292 was fixed it was not discovered that there are other places in the script where the file names of certificates being hashed were possibly passed to a command executed through the shell. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A user can tell curl &amp;gt;= 7.20.0 and &amp;lt;= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLUSESSL_ALL` withlibcurl). This requirement could be bypassed if the server would return a properly crafted but perfectly legitimate response.This flaw would then make curl silently continue its operations **withoutTLS** contrary to the instructions and expectations, exposing possibly sensitive data in clear text over the network. The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022-1292 was fixed it was not discovered that there are other places in the script where the file names of certificates being hashed were possibly passed to a command executed through the shell. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-23-194-01</guid>
    </item>
  </channel>
</rss>
