<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 15:01:41 +0000</lastBuildDate>
    <item>
      <title>9AKK108471A7121 — FLXeon Controllers Multiple vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/9akk108471a7121</link>
      <description>&lt;p&gt;ABB is aware of vulnerabilities in the product versions listed as affected in the advisory.
 
FLXEON devices are not intended to be internet-facing. A product advisory issued in June 2023 informed 
customers of this parameter.&lt;/p&gt;
&lt;p&gt;An attacker can successfully exploit these vulnerabilities and could take remote control of the product 
and potentially insert and run arbitrary code.
ABB requires, as noted in previous security advisories and user documentation, that FLXEON should not be exposed to the internet or any other insecure network.&lt;/p&gt;
&lt;p&gt;Note: In order to exploit an FLXEON, an attacker would need a misconfigured system.&lt;/p&gt;
&lt;p&gt;ABB strongly advises customers and system integrators to follow the instructions documented in: FBXi, 
CBXi and ASPECT® SOLUTIONS, which can be downloaded from the ABB library.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ABB is aware of vulnerabilities in the product versions listed as affected in the advisory.
 
FLXEON devices are not intended to be internet-facing. A product advisory issued in June 2023 informed 
customers of this parameter.&lt;/p&gt;
&lt;p&gt;An attacker can successfully exploit these vulnerabilities and could take remote control of the product 
and potentially insert and run arbitrary code.
ABB requires, as noted in previous security advisories and user documentation, that FLXEON should not be exposed to the internet or any other insecure network.&lt;/p&gt;
&lt;p&gt;Note: In order to exploit an FLXEON, an attacker would need a misconfigured system.&lt;/p&gt;
&lt;p&gt;ABB strongly advises customers and system integrators to follow the instructions documented in: FBXi, 
CBXi and ASPECT® SOLUTIONS, which can be downloaded from the ABB library.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/9akk108471a7121</guid>
    </item>
    <item>
      <title>EUVD-2026-252961</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-252961</link>
      <description>EUVD-2026-252961</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-252961</guid>
    </item>
    <item>
      <title>fkie_cve-2025-10205</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-10205</link>
      <description>&lt;p&gt;Use of a One-Way Hash with a Predictable Salt vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5. and newer versions&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Use of a One-Way Hash with a Predictable Salt vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5. and newer versions&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-10205</guid>
    </item>
    <item>
      <title>GHSA-pj22-7pjr-wrh3</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pj22-7pjr-wrh3</link>
      <description>&lt;p&gt;Use of a One-Way Hash with a Predictable Salt vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5. and newer versions&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Use of a One-Way Hash with a Predictable Salt vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5. and newer versions&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pj22-7pjr-wrh3</guid>
    </item>
    <item>
      <title>ICSA-25-310-03 — ABB FLXeon Controllers</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-25-310-03</link>
      <description>&lt;p&gt;Credentials that are required for the functioning of the product cannot be stored in a HW supported secure storage as the product does not implement such a component.  A remote code execution is possible due to an improper input validation. Password hashes are stored using a vulnerable MD5 algorithm with low entropy on salt, stored in plain text on unencrypted partitions. Users can push files with full pathnames allowing file operations in off limits directories.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Credentials that are required for the functioning of the product cannot be stored in a HW supported secure storage as the product does not implement such a component.  A remote code execution is possible due to an improper input validation. Password hashes are stored using a vulnerable MD5 algorithm with low entropy on salt, stored in plain text on unencrypted partitions. Users can push files with full pathnames allowing file operations in off limits directories.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-25-310-03</guid>
    </item>
  </channel>
</rss>
