<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 11:41:28 +0000</lastBuildDate>
    <item>
      <title>Advisory2026-02_VDE-2026-011 — CODESYS Control V3 - Untrusted boot application</title>
      <link>https://cve.radiocsirt.org/vuln/advisory2026-02_vde-2026-011</link>
      <description>&lt;p&gt;The CODESYS Control runtime system provides a user management mechanism with multiple privilege groups. While only the privileged Administrators and Developer groups are intended to load or debug applications on the controller, users in the restricted Service group are allowed to perform maintenance operations, including explicitly replacing the boot application.&lt;/p&gt;
&lt;p&gt;In addition to access control, the CODESYS Control runtime system includes an optional application signing feature. When enabled, the controller executes only applications that have been validly signed by authorized developers. However, the CmpApp component of the CODESYS Control runtime systems allows Service‑group users to install a new boot application without requiring any cryptographic validation, if the application signing is not enforced.&lt;/p&gt;
&lt;p&gt;As a result, users with Service‑level privileges can install arbitrary boot applications and gain control over the code executed on the controller.&lt;/p&gt;
&lt;p&gt;Note: The user group &amp;#34;Service&amp;#34; is a predefined group within the CODESYS Control runtime system. If additional user groups have been created or if the permissions of predefined groups have been modified, then the term &amp;#34;Service&amp;#34; should be understood as a synonym for all groups and their users with no or only limited access rights to the &amp;#34;PlcLogic&amp;#34; object, in conjunction with &amp;#34;Add/Remove&amp;#34; or &amp;#34;Modify&amp;#34; permissions for the boot application files.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The CODESYS Control runtime system provides a user management mechanism with multiple privilege groups. While only the privileged Administrators and Developer groups are intended to load or debug applications on the controller, users in the restricted Service group are allowed to perform maintenance operations, including explicitly replacing the boot application.&lt;/p&gt;
&lt;p&gt;In addition to access control, the CODESYS Control runtime system includes an optional application signing feature. When enabled, the controller executes only applications that have been validly signed by authorized developers. However, the CmpApp component of the CODESYS Control runtime systems allows Service‑group users to install a new boot application without requiring any cryptographic validation, if the application signing is not enforced.&lt;/p&gt;
&lt;p&gt;As a result, users with Service‑level privileges can install arbitrary boot applications and gain control over the code executed on the controller.&lt;/p&gt;
&lt;p&gt;Note: The user group &amp;#34;Service&amp;#34; is a predefined group within the CODESYS Control runtime system. If additional user groups have been created or if the permissions of predefined groups have been modified, then the term &amp;#34;Service&amp;#34; should be understood as a synonym for all groups and their users with no or only limited access rights to the &amp;#34;PlcLogic&amp;#34; object, in conjunction with &amp;#34;Add/Remove&amp;#34; or &amp;#34;Modify&amp;#34; permissions for the boot application files.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/advisory2026-02_vde-2026-011</guid>
    </item>
    <item>
      <title>bdu:2026-04079</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-04079</link>
      <description>bdu:2026-04079</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-04079</guid>
    </item>
    <item>
      <title>EUVD-2026-277089</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-277089</link>
      <description>EUVD-2026-277089</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-277089</guid>
    </item>
    <item>
      <title>fkie_cve-2025-41660</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-41660</link>
      <description>&lt;p&gt;A low-privileged remote attacker may be able to replace the boot application of the CODESYS Control runtime system, enabling unauthorized code execution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A low-privileged remote attacker may be able to replace the boot application of the CODESYS Control runtime system, enabling unauthorized code execution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-41660</guid>
    </item>
    <item>
      <title>GHSA-25xg-52c8-p9q8</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-25xg-52c8-p9q8</link>
      <description>&lt;p&gt;A low-privileged remote attacker may be able to replace the boot application of the CODESYS Control runtime system, enabling unauthorized code execution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A low-privileged remote attacker may be able to replace the boot application of the CODESYS Control runtime system, enabling unauthorized code execution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-25xg-52c8-p9q8</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0832 — CODESYS: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0832</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in CODESYS ausnutzen, um beliebigen Programmcode auszuführen, und um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in CODESYS ausnutzen, um beliebigen Programmcode auszuführen, und um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0832</guid>
    </item>
  </channel>
</rss>
