<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 14:29:17 +0000</lastBuildDate>
    <item>
      <title>Advisory2025-06_VDE-2025-049 — CODESYS Control V3 - Insecure default permissions</title>
      <link>https://cve.radiocsirt.org/vuln/advisory2025-06_vde-2025-049</link>
      <description>&lt;p&gt;On certain operating systems (e.g., Linux), default file system permissions may allow read access to the files of the CODESYS Control runtime system for non-administrator users. The documentation provided with the CODESYS Runtime Toolkit does not explicitly address this risk. As a result, products based on the toolkit may unintentionally expose sensitive runtime files to local operating system users with limited privileges.&lt;/p&gt;
&lt;p&gt;CODESYS Control runtime system based devices are affected if they provide access to the operating system (e.g., via a local user interface or SSH) and user accounts without administrator rights for this access exist or can be created.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;On certain operating systems (e.g., Linux), default file system permissions may allow read access to the files of the CODESYS Control runtime system for non-administrator users. The documentation provided with the CODESYS Runtime Toolkit does not explicitly address this risk. As a result, products based on the toolkit may unintentionally expose sensitive runtime files to local operating system users with limited privileges.&lt;/p&gt;
&lt;p&gt;CODESYS Control runtime system based devices are affected if they provide access to the operating system (e.g., via a local user interface or SSH) and user accounts without administrator rights for this access exist or can be created.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/advisory2025-06_vde-2025-049</guid>
    </item>
    <item>
      <title>bdu:2026-00083</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-00083</link>
      <description>bdu:2026-00083</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-00083</guid>
    </item>
    <item>
      <title>EUVD-2026-248925</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-248925</link>
      <description>EUVD-2026-248925</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-248925</guid>
    </item>
    <item>
      <title>fkie_cve-2025-41658</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-41658</link>
      <description>&lt;p&gt;CODESYS Runtime Toolkit-based products may expose sensitive files to local low-privileged operating system users due to default file permissions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;CODESYS Runtime Toolkit-based products may expose sensitive files to local low-privileged operating system users due to default file permissions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-41658</guid>
    </item>
    <item>
      <title>FSA-202601 — Several CODESYS vulnerabilities in Festo Automation Suite</title>
      <link>https://cve.radiocsirt.org/vuln/fsa-202601</link>
      <description>&lt;p&gt;Starting with Festo Automation Suite (FAS) version 2.8.0.138, the suite is delivered only with a connector to Codesys, rather than including Codesys directly. Prior to this version, Codesys was bundled within the FAS installation. From version 2.8.0.138 onwards, customers are required to download and install Codesys independently.&lt;/p&gt;
&lt;p&gt;This change impacts the handling of security vulnerabilities (CVEs) related to Codesys. Any Codesys-related security issues must now be addressed by the customer through their separate Codesys installation. The FAS itself includes only the connector component, which is maintained and updated within the suite.&lt;/p&gt;
&lt;p&gt;Please ensure that Codesys is kept up to date independently to mitigate any potential security risks associated with the Codesys software.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Starting with Festo Automation Suite (FAS) version 2.8.0.138, the suite is delivered only with a connector to Codesys, rather than including Codesys directly. Prior to this version, Codesys was bundled within the FAS installation. From version 2.8.0.138 onwards, customers are required to download and install Codesys independently.&lt;/p&gt;
&lt;p&gt;This change impacts the handling of security vulnerabilities (CVEs) related to Codesys. Any Codesys-related security issues must now be addressed by the customer through their separate Codesys installation. The FAS itself includes only the connector component, which is maintained and updated within the suite.&lt;/p&gt;
&lt;p&gt;Please ensure that Codesys is kept up to date independently to mitigate any potential security risks associated with the Codesys software.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fsa-202601</guid>
    </item>
    <item>
      <title>GHSA-ff63-c723-v97g</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-ff63-c723-v97g</link>
      <description>&lt;p&gt;CODESYS Runtime Toolkit-based products may expose sensitive files to local low-privileged operating system users due to default file permissions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;CODESYS Runtime Toolkit-based products may expose sensitive files to local low-privileged operating system users due to default file permissions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-ff63-c723-v97g</guid>
    </item>
    <item>
      <title>ICSA-26-076-01 — CODESYS in Festo Automation Suite</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-26-076-01</link>
      <description>&lt;p&gt;Starting with Festo Automation Suite (FAS) version 2.8.0.138, the suite is delivered only with a connector to Codesys, rather than including Codesys directly. Prior to this version, Codesys was bundled within the FAS installation. From version 2.8.0.138 onwards, customers are required to download and install Codesys independently.&lt;/p&gt;
&lt;p&gt;This change impacts the handling of security vulnerabilities (CVEs) related to Codesys. Any Codesys-related security issues must now be addressed by the customer through their separate Codesys installation. The FAS itself includes only the connector component, which is maintained and updated within the suite.&lt;/p&gt;
&lt;p&gt;Please ensure that Codesys is kept up to date independently to mitigate any potential security risks associated with the Codesys software.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Starting with Festo Automation Suite (FAS) version 2.8.0.138, the suite is delivered only with a connector to Codesys, rather than including Codesys directly. Prior to this version, Codesys was bundled within the FAS installation. From version 2.8.0.138 onwards, customers are required to download and install Codesys independently.&lt;/p&gt;
&lt;p&gt;This change impacts the handling of security vulnerabilities (CVEs) related to Codesys. Any Codesys-related security issues must now be addressed by the customer through their separate Codesys installation. The FAS itself includes only the connector component, which is maintained and updated within the suite.&lt;/p&gt;
&lt;p&gt;Please ensure that Codesys is kept up to date independently to mitigate any potential security risks associated with the Codesys software.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-26-076-01</guid>
    </item>
    <item>
      <title>VDE-2026-005 — ifm: Multiple Vulnerabilities in CR3171</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2026-005</link>
      <description>&lt;p&gt;The Firmware installed on the CR3171 is impacted by various CODESYS vulnerabilities.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Firmware installed on the CR3171 is impacted by various CODESYS vulnerabilities.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2026-005</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1705 — CODESYS: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1705</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in CODESYS ausnutzen, um einen Denial-of-Service-Zustand auszulösen, Daten zu manipulieren und vertrauliche Informationen preiszugeben.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in CODESYS ausnutzen, um einen Denial-of-Service-Zustand auszulösen, Daten zu manipulieren und vertrauliche Informationen preiszugeben.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1705</guid>
    </item>
  </channel>
</rss>
