<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:40:24 +0000</lastBuildDate>
    <item>
      <title>certfr-2023-avi-1015 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits Siemens&lt;/span&gt;. Certaines d'entr…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-1015</link>
      <description>certfr-2023-avi-1015</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-1015</guid>
    </item>
    <item>
      <title>cnvd-2023-97252</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2023-97252</link>
      <description>cnvd-2023-97252</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2023-97252</guid>
    </item>
    <item>
      <title>EUVD-2026-10026</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-10026</link>
      <description>EUVD-2026-10026</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-10026</guid>
    </item>
    <item>
      <title>fkie_cve-2023-48431</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-48431</link>
      <description>&lt;p&gt;A vulnerability has been identified in SINEC INS (All versions &amp;lt; V1.0 SP2 Update 2). Affected software does not correctly validate the response received by an UMC server. An attacker can use this to crash the affected software by providing and configuring a malicious UMC server or by manipulating the traffic from a legitimate UMC server (i.e. leveraging CVE-2023-48427).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability has been identified in SINEC INS (All versions &amp;lt; V1.0 SP2 Update 2). Affected software does not correctly validate the response received by an UMC server. An attacker can use this to crash the affected software by providing and configuring a malicious UMC server or by manipulating the traffic from a legitimate UMC server (i.e. leveraging CVE-2023-48427).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-48431</guid>
    </item>
    <item>
      <title>GHSA-gv5r-5x6r-p8j8</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gv5r-5x6r-p8j8</link>
      <description>&lt;p&gt;A vulnerability has been identified in SINEC INS (All versions &amp;lt; V1.0 SP2 Update 2). Affected software does not correctly validate the response received by an UMC server. An attacker can use this to crash the affected software by providing and configuring a malicious UMC server or by manipulating the traffic from a legitimate UMC server (i.e. leveraging CVE-2023-48427).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability has been identified in SINEC INS (All versions &amp;lt; V1.0 SP2 Update 2). Affected software does not correctly validate the response received by an UMC server. An attacker can use this to crash the affected software by providing and configuring a malicious UMC server or by manipulating the traffic from a legitimate UMC server (i.e. leveraging CVE-2023-48427).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gv5r-5x6r-p8j8</guid>
    </item>
    <item>
      <title>gsd-2023-48431</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-48431</link>
      <description>gsd-2023-48431</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-48431</guid>
    </item>
    <item>
      <title>ICSA-23-348-16 — Siemens SINEC INS</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-23-348-16</link>
      <description>&lt;p&gt;A security vulnerability has been identified in all supported versions of OpenSSL related to the verification of X.509 certificate chains that include policy constraints. Attackers may be able to exploit this vulnerability by creating a malicious certificate chain that triggers exponential use of computational resources, leading to a denial-of-service (DoS) attack on affected systems.&#13;
&#13;
Policy processing is disabled by default but can be enabled by passing the `-policy` argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()` function. libcurl would reuse a previously created connection even when an SSH related option had been changed that should have prohibited reuse. libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, two SSH settings were left out from the configuration match checks, making them match too easily. Affected products do not properly validate the certificate of the configured UMC server. This could allow an attacker to intercept credentials that are sent to the UMC server as well as to manipulate responses, potentially allowing an attacker to escalate privileges. The radius configuration mechanism of affected products does not correctly check uploaded certificates. A malicious admin could upload a crafted certificate resulting in a denial-of-service condition or potentially issue commands on system level. The Web UI of affected devices…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A security vulnerability has been identified in all supported versions of OpenSSL related to the verification of X.509 certificate chains that include policy constraints. Attackers may be able to exploit this vulnerability by creating a malicious certificate chain that triggers exponential use of computational resources, leading to a denial-of-service (DoS) attack on affected systems.&#13;
&#13;
Policy processing is disabled by default but can be enabled by passing the `-policy` argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()` function. libcurl would reuse a previously created connection even when an SSH related option had been changed that should have prohibited reuse. libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, two SSH settings were left out from the configuration match checks, making them match too easily. Affected products do not properly validate the certificate of the configured UMC server. This could allow an attacker to intercept credentials that are sent to the UMC server as well as to manipulate responses, potentially allowing an attacker to escalate privileges. The radius configuration mechanism of affected products does not correctly check uploaded certificates. A malicious admin could upload a crafted certificate resulting in a denial-of-service condition or potentially issue commands on system level. The Web UI of affected devices…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-23-348-16</guid>
    </item>
  </channel>
</rss>
