<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 23:53:29 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-291059</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-291059</link>
      <description>EUVD-2026-291059</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-291059</guid>
    </item>
    <item>
      <title>fkie_cve-2024-1573</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-1573</link>
      <description>&lt;p&gt;Missing Authentication for Critical Function vulnerability in the mobile monitoring feature of Mitsubishi Electric GENESIS64 versions 10.97.2 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.2 and prior, Mitsubishi Electric Hyper Historian versions 10.97.2 and prior, Mitsubishi Electric AnalytiX versions 10.97.2 and prior, Mitsubishi Electric MobileHMI versions 10.97.2 and prior, Mitsubishi Electric IoTWorX version 10.95, Mitsubishi Electric MC Works64 all versions, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97.2 and prior, Mitsubishi Electric Iconics Digital Solutions ICONICS Suite versions 10.97.2 and prior, Mitsubishi Electric Iconics Digital Solutions Hyper Historian versions 10.97.2 and prior, Mitsubishi Electric Iconics Digital Solutions AnalytiX versions 10.97.2 and prior, Mitsubishi Electric Iconics Digital Solutions MobileHMI versions 10.97.2 and prior, and Mitsubishi Electric Iconics Digital Solutions IoTWorX version 10.95 allows a remote unauthenticated attacker to bypass proper authentication and log in to the system when all of the following conditions are met: (1) Active Directory is used in the security setting (2) &amp;#34;Automatic log in&amp;#34; option is enabled in the security setting (3) The IcoAnyGlass IIS Application Pool is running under an Active Directory Domain Account. (4) The IcoAnyGlass IIS Application Pool account is included in GENESIS64, ICONCIS Suite, and MC Works64 Security and has permission to log in.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Missing Authentication for Critical Function vulnerability in the mobile monitoring feature of Mitsubishi Electric GENESIS64 versions 10.97.2 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.2 and prior, Mitsubishi Electric Hyper Historian versions 10.97.2 and prior, Mitsubishi Electric AnalytiX versions 10.97.2 and prior, Mitsubishi Electric MobileHMI versions 10.97.2 and prior, Mitsubishi Electric IoTWorX version 10.95, Mitsubishi Electric MC Works64 all versions, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97.2 and prior, Mitsubishi Electric Iconics Digital Solutions ICONICS Suite versions 10.97.2 and prior, Mitsubishi Electric Iconics Digital Solutions Hyper Historian versions 10.97.2 and prior, Mitsubishi Electric Iconics Digital Solutions AnalytiX versions 10.97.2 and prior, Mitsubishi Electric Iconics Digital Solutions MobileHMI versions 10.97.2 and prior, and Mitsubishi Electric Iconics Digital Solutions IoTWorX version 10.95 allows a remote unauthenticated attacker to bypass proper authentication and log in to the system when all of the following conditions are met: (1) Active Directory is used in the security setting (2) &amp;#34;Automatic log in&amp;#34; option is enabled in the security setting (3) The IcoAnyGlass IIS Application Pool is running under an Active Directory Domain Account. (4) The IcoAnyGlass IIS Application Pool account is included in GENESIS64, ICONCIS Suite, and MC Works64 Security and has permission to log in.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-1573</guid>
    </item>
    <item>
      <title>GHSA-34qf-4246-phgf</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-34qf-4246-phgf</link>
      <description>&lt;p&gt;Improper Authentication vulnerability in the mobile monitoring feature of ICONICS GENESIS64 versions 10.97 to 10.97.2, Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.2 and Mitsubishi Electric MC Works64 all versions allows a remote unauthenticated attacker to bypass proper authentication and log in to the system when all of the following conditions are met:  *  Active Directory is used in the security setting.
  *  “Automatic log in” option is enabled in the security setting.
  *  The IcoAnyGlass IIS Application Pool is running under an Active Directory Domain Account.
  *  The IcoAnyGlass IIS Application Pool account is included in GENESIS64TM and MC Works64 Security and has permission to log in.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Improper Authentication vulnerability in the mobile monitoring feature of ICONICS GENESIS64 versions 10.97 to 10.97.2, Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.2 and Mitsubishi Electric MC Works64 all versions allows a remote unauthenticated attacker to bypass proper authentication and log in to the system when all of the following conditions are met:  *  Active Directory is used in the security setting.
  *  “Automatic log in” option is enabled in the security setting.
  *  The IcoAnyGlass IIS Application Pool is running under an Active Directory Domain Account.
  *  The IcoAnyGlass IIS Application Pool account is included in GENESIS64TM and MC Works64 Security and has permission to log in.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-34qf-4246-phgf</guid>
    </item>
    <item>
      <title>gsd-2024-1573</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-1573</link>
      <description>gsd-2024-1573</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-1573</guid>
    </item>
    <item>
      <title>ICSA-24-184-03 — Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric Products (Update E)</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-24-184-03</link>
      <description>&lt;p&gt;When the BACnet Secure Connect feature is enabled in the affected products, a temporary denial-of-service vulnerability due to allocation of resources without limits or throttling exists in the OpenSSL library integrated into the products, during data validation. This vulnerability allows a remote attacker to cause a denial-of-service condition on the affected products by sending a certificate that contains a specially crafted ANS 1 OBJECT IDENTIFIER. When running on X86_64 CPUs supporting AVX512-IFMA instructions and the BACnet Secure Connect feature is enabled in the affected products, a denial-of-service vulnerability due to improper verification of cryptographic signature exists in the Message Authentication Code (MAC) implementation in OpenSSL library integrated into the products. This vulnerability allows a remote attacker to cause a denial-of-service condition on the affected products by sending messages that contain specially crafted Message Authentication Code (MAC). When the affected products are installed with the Pager agent in the multi-agent notification feature, an arbitrary code execution vulnerability due to uncontrolled search path element exists in the feature. This vulnerability allows a local attacker to execute an arbitrary code by storing a specially crafted DLL in a specific folder. An authentication bypass vulnerability due to missing authentication for critical function exists in the mobile monitoring feature of the affected products when all of the…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;When the BACnet Secure Connect feature is enabled in the affected products, a temporary denial-of-service vulnerability due to allocation of resources without limits or throttling exists in the OpenSSL library integrated into the products, during data validation. This vulnerability allows a remote attacker to cause a denial-of-service condition on the affected products by sending a certificate that contains a specially crafted ANS 1 OBJECT IDENTIFIER. When running on X86_64 CPUs supporting AVX512-IFMA instructions and the BACnet Secure Connect feature is enabled in the affected products, a denial-of-service vulnerability due to improper verification of cryptographic signature exists in the Message Authentication Code (MAC) implementation in OpenSSL library integrated into the products. This vulnerability allows a remote attacker to cause a denial-of-service condition on the affected products by sending messages that contain specially crafted Message Authentication Code (MAC). When the affected products are installed with the Pager agent in the multi-agent notification feature, an arbitrary code execution vulnerability due to uncontrolled search path element exists in the feature. This vulnerability allows a local attacker to execute an arbitrary code by storing a specially crafted DLL in a specific folder. An authentication bypass vulnerability due to missing authentication for critical function exists in the mobile monitoring feature of the affected products when all of the…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-24-184-03</guid>
    </item>
  </channel>
</rss>
