<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 14:55:35 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-01879</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-01879</link>
      <description>bdu:2025-01879</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-01879</guid>
    </item>
    <item>
      <title>EUVD-2026-218536</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-218536</link>
      <description>EUVD-2026-218536</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-218536</guid>
    </item>
    <item>
      <title>fkie_cve-2025-0867</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-0867</link>
      <description>&lt;p&gt;The standard user uses the run as function to start the MEAC applications with administrative privileges. To ensure that the system can startup on its own, the credentials of the administrator were stored. Consequently, the EPC2 user can execute any command with administrative privileges. This allows a privilege escalation to the administrative level.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The standard user uses the run as function to start the MEAC applications with administrative privileges. To ensure that the system can startup on its own, the credentials of the administrator were stored. Consequently, the EPC2 user can execute any command with administrative privileges. This allows a privilege escalation to the administrative level.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-0867</guid>
    </item>
    <item>
      <title>GHSA-5gcv-59gg-xc7c</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5gcv-59gg-xc7c</link>
      <description>&lt;p&gt;The standard user uses the run as function to start the MEAC applications with administrative privileges. To ensure that the system can startup on its own, the credentials of the administrator were stored. Consequently, the EPC2 user can execute any command with administrative privileges. This allows a privilege escalation to the administrative level.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The standard user uses the run as function to start the MEAC applications with administrative privileges. To ensure that the system can startup on its own, the credentials of the administrator were stored. Consequently, the EPC2 user can execute any command with administrative privileges. This allows a privilege escalation to the administrative level.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5gcv-59gg-xc7c</guid>
    </item>
    <item>
      <title>SCA-2025-0001 — Multiple vulnerabilities in SICK MEAC300</title>
      <link>https://cve.radiocsirt.org/vuln/sca-2025-0001</link>
      <description>&lt;p&gt;The standard user uses the runas function to start the MEAC applications with administrative privileges.
To ensure that the system can startup on its own, the credentials of the administrator were stored.
Consequently, the EPC2 user can execute any command with administrative privileges.
This allows a privilege escalation to the administrative level. Description of the original advisory from OpenSSL: “The OpenSSL BN mod sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. It is possible to trigger the infinite loop by crafting a certificate that has invalid explicit curve parameters. Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate may thus be subject to a denial-of-service attack. The infinite loop can also be reached when parsing crafted private keys as they can contain explicit elliptic curve parameters.”&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The standard user uses the runas function to start the MEAC applications with administrative privileges.
To ensure that the system can startup on its own, the credentials of the administrator were stored.
Consequently, the EPC2 user can execute any command with administrative privileges.
This allows a privilege escalation to the administrative level. Description of the original advisory from OpenSSL: “The OpenSSL BN mod sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. It is possible to trigger the infinite loop by crafting a certificate that has invalid explicit curve parameters. Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate may thus be subject to a denial-of-service attack. The infinite loop can also be reached when parsing crafted private keys as they can contain explicit elliptic curve parameters.”&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sca-2025-0001</guid>
    </item>
  </channel>
</rss>
