<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 16:22:30 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-09671</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-09671</link>
      <description>bdu:2024-09671</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-09671</guid>
    </item>
    <item>
      <title>cnvd-2024-40029</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2024-40029</link>
      <description>cnvd-2024-40029</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2024-40029</guid>
    </item>
    <item>
      <title>EUVD-2026-275241</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-275241</link>
      <description>EUVD-2026-275241</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-275241</guid>
    </item>
    <item>
      <title>fkie_cve-2024-47562</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-47562</link>
      <description>&lt;p&gt;A vulnerability has been identified in SINEC Security Monitor (All versions &amp;lt; V4.9.0). The affected application does not properly neutralize special elements in user input to the ```ssmctl-client``` command.&#13;
This could allow an authenticated, lowly privileged local attacker to execute privileged commands in the underlying OS.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability has been identified in SINEC Security Monitor (All versions &amp;lt; V4.9.0). The affected application does not properly neutralize special elements in user input to the ```ssmctl-client``` command.&#13;
This could allow an authenticated, lowly privileged local attacker to execute privileged commands in the underlying OS.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-47562</guid>
    </item>
    <item>
      <title>GHSA-hq54-fc5j-p5hh</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hq54-fc5j-p5hh</link>
      <description>&lt;p&gt;A vulnerability has been identified in Siemens SINEC Security Monitor (All versions &amp;lt; V4.9.0). The affected application does not properly neutralize special elements in user input to the ```ssmctl-client``` command.
This could allow an authenticated, lowly privileged local attacker to execute privileged commands in the underlying OS.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability has been identified in Siemens SINEC Security Monitor (All versions &amp;lt; V4.9.0). The affected application does not properly neutralize special elements in user input to the ```ssmctl-client``` command.
This could allow an authenticated, lowly privileged local attacker to execute privileged commands in the underlying OS.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hq54-fc5j-p5hh</guid>
    </item>
    <item>
      <title>ICSA-24-284-06 — Siemens SINEC Security Monitor</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-24-284-06</link>
      <description>&lt;p&gt;The affected application does not properly validate user input to the ```ssmctl-client``` command.&#13;
This could allow an authenticated, lowly privileged remote attacker to execute arbitrary code with root privileges on the underlying OS. The affected application does not properly neutralize special elements in user input to the ```ssmctl-client``` command.&#13;
This could allow an authenticated, lowly privileged local attacker to execute privileged commands in the underlying OS. The affected application does not properly validate a file path that is supplied to an endpoint intended to create CSR files.&#13;
This could allow an unauthenticated remote attacker to create files in writable directories outside the intended location and thus compromise integrity of files in those writable directories. The affected application does not properly validate that user input complies with a list of allowed values.&#13;
This could allow an authenticated remote attacker to compromise the integrity of the configuration of the affected application. The affected application leaks confidential information in metadata, and files such as information on contributors and email address, on `SSM Server`.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The affected application does not properly validate user input to the ```ssmctl-client``` command.&#13;
This could allow an authenticated, lowly privileged remote attacker to execute arbitrary code with root privileges on the underlying OS. The affected application does not properly neutralize special elements in user input to the ```ssmctl-client``` command.&#13;
This could allow an authenticated, lowly privileged local attacker to execute privileged commands in the underlying OS. The affected application does not properly validate a file path that is supplied to an endpoint intended to create CSR files.&#13;
This could allow an unauthenticated remote attacker to create files in writable directories outside the intended location and thus compromise integrity of files in those writable directories. The affected application does not properly validate that user input complies with a list of allowed values.&#13;
This could allow an authenticated remote attacker to compromise the integrity of the configuration of the affected application. The affected application leaks confidential information in metadata, and files such as information on contributors and email address, on `SSM Server`.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-24-284-06</guid>
    </item>
    <item>
      <title>SSA-430425 — SSA-430425: Multiple Vulnerabilities in SINEC Security Monitor before V4.9.0</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-430425</link>
      <description>&lt;p&gt;The affected application does not properly validate user input to the ```ssmctl-client``` command.&#13;
This could allow an authenticated, lowly privileged remote attacker to execute arbitrary code with root privileges on the underlying OS. The affected application does not properly neutralize special elements in user input to the ```ssmctl-client``` command.&#13;
This could allow an authenticated, lowly privileged local attacker to execute privileged commands in the underlying OS. The affected application does not properly validate a file path that is supplied to an endpoint intended to create CSR files.&#13;
This could allow an unauthenticated remote attacker to create files in writable directories outside the intended location and thus compromise integrity of files in those writable directories. The affected application does not properly validate that user input complies with a list of allowed values.&#13;
This could allow an authenticated remote attacker to compromise the integrity of the configuration of the affected application. The affected application leaks confidential information in metadata, and files such as information on contributors and email address, on `SSM Server`.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The affected application does not properly validate user input to the ```ssmctl-client``` command.&#13;
This could allow an authenticated, lowly privileged remote attacker to execute arbitrary code with root privileges on the underlying OS. The affected application does not properly neutralize special elements in user input to the ```ssmctl-client``` command.&#13;
This could allow an authenticated, lowly privileged local attacker to execute privileged commands in the underlying OS. The affected application does not properly validate a file path that is supplied to an endpoint intended to create CSR files.&#13;
This could allow an unauthenticated remote attacker to create files in writable directories outside the intended location and thus compromise integrity of files in those writable directories. The affected application does not properly validate that user input complies with a list of allowed values.&#13;
This could allow an authenticated remote attacker to compromise the integrity of the configuration of the affected application. The affected application leaks confidential information in metadata, and files such as information on contributors and email address, on `SSM Server`.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-430425</guid>
    </item>
  </channel>
</rss>
