<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 08:55:39 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-04985</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-04985</link>
      <description>bdu:2023-04985</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-04985</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0733 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits Siemens&lt;/span&gt;. Certaines d'entr…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0733</link>
      <description>certfr-2023-avi-0733</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0733</guid>
    </item>
    <item>
      <title>cnvd-2023-69811</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2023-69811</link>
      <description>cnvd-2023-69811</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2023-69811</guid>
    </item>
    <item>
      <title>EUVD-2026-251093</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-251093</link>
      <description>EUVD-2026-251093</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-251093</guid>
    </item>
    <item>
      <title>fkie_cve-2023-3935</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-3935</link>
      <description>&lt;p&gt;A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-3935</guid>
    </item>
    <item>
      <title>FSA-202305 — Festo: Vulnerable WIBU-SYSTEMS CodeMeter Runtime in several products</title>
      <link>https://cve.radiocsirt.org/vuln/fsa-202305</link>
      <description>&lt;p&gt;A vulnerability in the Wibu CodeMeter Runtime, which is part of the installation packages of several Festo products, was found. An attacker exploiting the vulnerability in WIBU CodeMeter Runtime in server mode could gain full access to the affected server via network access without any user interaction. This could lead to remote code execution and escalation of privileges giving full admin access on the host system for an already authenticated user (logged in locally to the PC).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in the Wibu CodeMeter Runtime, which is part of the installation packages of several Festo products, was found. An attacker exploiting the vulnerability in WIBU CodeMeter Runtime in server mode could gain full access to the affected server via network access without any user interaction. This could lead to remote code execution and escalation of privileges giving full admin access on the host system for an already authenticated user (logged in locally to the PC).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fsa-202305</guid>
    </item>
    <item>
      <title>GHSA-c9rf-qf73-r46f</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-c9rf-qf73-r46f</link>
      <description>&lt;p&gt;A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-c9rf-qf73-r46f</guid>
    </item>
    <item>
      <title>gsd-2023-3935</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-3935</link>
      <description>gsd-2023-3935</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-3935</guid>
    </item>
    <item>
      <title>ICSA-23-257-06 — Siemans WIBU Systems CodeMeter</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-23-257-06</link>
      <description>&lt;p&gt;In CodeMeter Runtime versions up to 7.60b, there is a heap buffer overflow vulnerability which can potentially lead to a remote code execution. Currently, no PoC is known to us. To&#13;
exploit the heap overflow, additional protection mechanisms need to be broken. Remote access is only possible if CodeMeter is configured as a server. If CodeMeter is not configured as a server, the adversary would need to log in to the machine where the CodeMeter Runtime is running or trick the user into sending a malicious request to CodeMeter. This might result in an escalation of privilege. (WIBU-230704-01)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In CodeMeter Runtime versions up to 7.60b, there is a heap buffer overflow vulnerability which can potentially lead to a remote code execution. Currently, no PoC is known to us. To&#13;
exploit the heap overflow, additional protection mechanisms need to be broken. Remote access is only possible if CodeMeter is configured as a server. If CodeMeter is not configured as a server, the adversary would need to log in to the machine where the CodeMeter Runtime is running or trick the user into sending a malicious request to CodeMeter. This might result in an escalation of privilege. (WIBU-230704-01)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-23-257-06</guid>
    </item>
    <item>
      <title>SCA-2023-0009 — Vulnerability in Wibu-Systems CodeMeter Runtime affects multiple SICK products</title>
      <link>https://cve.radiocsirt.org/vuln/sca-2023-0009</link>
      <description>&lt;p&gt;In CodeMeter Runtime versions up to 7.60b, there is a heap buffer overflow vulnerability which can potentially lead to a remote code execution. Currently, no PoC is known to us. To exploit the heap overflow, additional protection mechanisms need to be broken. Remote access is only possible if CodeMeter is configured as a server. If CodeMeter is not configured as a server, the adversary would need to log in to the machine where the CodeMeter Runtime is running or trick the user into sending a malicious request to CodeMeter. This might result in an escalation of privilege.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In CodeMeter Runtime versions up to 7.60b, there is a heap buffer overflow vulnerability which can potentially lead to a remote code execution. Currently, no PoC is known to us. To exploit the heap overflow, additional protection mechanisms need to be broken. Remote access is only possible if CodeMeter is configured as a server. If CodeMeter is not configured as a server, the adversary would need to log in to the machine where the CodeMeter Runtime is running or trick the user into sending a malicious request to CodeMeter. This might result in an escalation of privilege.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sca-2023-0009</guid>
    </item>
    <item>
      <title>VDE-2023-030 — Phoenix Contact: Multiple products affected by WIBU Codemeter Vulnerability (Update A)</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2023-030</link>
      <description>&lt;p&gt;A Vulnerability in WIBU-SYSTEMS CodeMeter Runtime affects multiple Phoenix Contact products.
Phoenix Contact devices using CodeMeter embedded are not affected by this vulnerability.
Update A, 2023-11-13
Removed CVE-2023-4701 because it was revoked.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A Vulnerability in WIBU-SYSTEMS CodeMeter Runtime affects multiple Phoenix Contact products.
Phoenix Contact devices using CodeMeter embedded are not affected by this vulnerability.
Update A, 2023-11-13
Removed CVE-2023-4701 because it was revoked.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2023-030</guid>
    </item>
    <item>
      <title>VDE-2023-031 — Trumpf: Multiple Products affected by WIBU Codemeter Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2023-031</link>
      <description>&lt;p&gt;The TRUMPF CAD/CAM software tools mentioned above use the vulnerable CodeMeter Runtime (up to version 7.60b) application from WIBU-SYSTEMS AG to manage licenses within the component TRUMPF License Expert. This CodeMeter application contains new vulnerabilities, which may enable an attacker to gain full access to the server or workstation on which the TRUMPF License Expert has been installed on. A new version of the TRUMPF License Expert which fixes this vulnerability is available.Machines with a running and correctly installed mGuard hardware firewall cannot be exploited by this vulnerability if used as intended (according to the manual).&lt;/p&gt;
&lt;p&gt;Update A, 2023-11-13
Removed CVE-2023-4701 because it was revoked.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The TRUMPF CAD/CAM software tools mentioned above use the vulnerable CodeMeter Runtime (up to version 7.60b) application from WIBU-SYSTEMS AG to manage licenses within the component TRUMPF License Expert. This CodeMeter application contains new vulnerabilities, which may enable an attacker to gain full access to the server or workstation on which the TRUMPF License Expert has been installed on. A new version of the TRUMPF License Expert which fixes this vulnerability is available.Machines with a running and correctly installed mGuard hardware firewall cannot be exploited by this vulnerability if used as intended (according to the manual).&lt;/p&gt;
&lt;p&gt;Update A, 2023-11-13
Removed CVE-2023-4701 because it was revoked.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2023-031</guid>
    </item>
    <item>
      <title>VDE-2023-032 — Weidmueller: WIBU Vulnerability in multiple Products</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2023-032</link>
      <description>&lt;p&gt;Multiple Weidmueller products are affected by recent WIBU vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple Weidmueller products are affected by recent WIBU vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2023-032</guid>
    </item>
    <item>
      <title>VDE-2023-033 — Pilz: WIBU Vulnerabilitiy in multiple Products</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2023-033</link>
      <description>&lt;p&gt;Several Pilz products use the 3rd party component &amp;#34;CodeMeter Runtime&amp;#34; from WIBU-SYSTEM AG to manage software licenses. This component is affected by a vulnerability, which may enable an attacker to gain full control over the system running the software product. The vulnerability can be exploited locally or over the network.&lt;/p&gt;
&lt;p&gt;Update A, 2023-12-05&lt;/p&gt;
&lt;p&gt;changed affected version of &amp;#34;Software PASvisu &amp;lt; 1.15.0&amp;#34; to &amp;#34;Software PASvisu &amp;lt; 1.14.1&amp;#34;
removed CVE-2023-4701 because it was revoked.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Several Pilz products use the 3rd party component &amp;#34;CodeMeter Runtime&amp;#34; from WIBU-SYSTEM AG to manage software licenses. This component is affected by a vulnerability, which may enable an attacker to gain full control over the system running the software product. The vulnerability can be exploited locally or over the network.&lt;/p&gt;
&lt;p&gt;Update A, 2023-12-05&lt;/p&gt;
&lt;p&gt;changed affected version of &amp;#34;Software PASvisu &amp;lt; 1.15.0&amp;#34; to &amp;#34;Software PASvisu &amp;lt; 1.14.1&amp;#34;
removed CVE-2023-4701 because it was revoked.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2023-033</guid>
    </item>
    <item>
      <title>VDE-2023-035 — CODESYS: Multiple products affected by WIBU Codemeter vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2023-035</link>
      <description>&lt;p&gt;Several CODESYS setups contain and install vulnerable versions of the WIBU CodeMeter Runtime.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Several CODESYS setups contain and install vulnerable versions of the WIBU CodeMeter Runtime.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2023-035</guid>
    </item>
    <item>
      <title>VDE-2023-042 — Wago: Vulnerable WIBU-SYSTEMS Codemeter installed through e!COCKPIT and WAGO-I/O-Pro (UPDATE B)</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2023-042</link>
      <description>&lt;p&gt;Critical vulnerability has been discovered in the utilized component PROFINET IO Device by Hilscher Gesellschaft für Systemautomation mbH.
The impact of the vulnerability on the affected device is that it can&lt;/p&gt;
&lt;p&gt;no longer perform acyclic requests
may drop all established cyclic connections may
disappear completely from the network
For more information see advisory by Hilscher:&lt;/p&gt;
&lt;p&gt;https://kb.hilscher.com/display/ISMS/2020-12-03+Denial+of+Service+vulnerability+in+PROFINET+IO+Device&lt;/p&gt;
&lt;p&gt;Update 20.11.2024: Products have been added&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Critical vulnerability has been discovered in the utilized component PROFINET IO Device by Hilscher Gesellschaft für Systemautomation mbH.
The impact of the vulnerability on the affected device is that it can&lt;/p&gt;
&lt;p&gt;no longer perform acyclic requests
may drop all established cyclic connections may
disappear completely from the network
For more information see advisory by Hilscher:&lt;/p&gt;
&lt;p&gt;https://kb.hilscher.com/display/ISMS/2020-12-03+Denial+of+Service+vulnerability+in+PROFINET+IO+Device&lt;/p&gt;
&lt;p&gt;Update 20.11.2024: Products have been added&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2023-042</guid>
    </item>
    <item>
      <title>VDE-2025-105 — Endress+Hauser: Multiple products affected by Wibu-Systems CodeMeter Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2025-105</link>
      <description>&lt;p&gt;A vulnerability in Wibu-Systems CodeMeter (up to version 7.60b) affects multiple Endress+Hauser products. This flaw can lead to a heap buffer overflow, which may allow remote code execution under certain conditions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in Wibu-Systems CodeMeter (up to version 7.60b) affects multiple Endress+Hauser products. This flaw can lead to a heap buffer overflow, which may allow remote code execution under certain conditions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2025-105</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-2311 — Wibu-Systems CodeMeter: Schwachstelle ermöglicht Codeausführung und Privilegienerweiterung</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2311</link>
      <description>&lt;p&gt;Ein entfernter anonymer Angreifer kann eine Schwachstelle in Wibu-Systems CodeMeter ausnutzen, um beliebigen Code auszuführen oder seine Privilegien zu erweitern.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter anonymer Angreifer kann eine Schwachstelle in Wibu-Systems CodeMeter ausnutzen, um beliebigen Code auszuführen oder seine Privilegien zu erweitern.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2311</guid>
    </item>
  </channel>
</rss>
