<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 07:42:07 +0000</lastBuildDate>
    <item>
      <title>CVE-2020-28388</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2020-28388</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Siemens APOGEE PXC Compact (BACnet), Siemens APOGEE PXC Compact (P2 Ethernet), Siemens APOGEE PXC Modular (BACnet), Siemens APOGEE PXC Modular (P2 Ethernet), Siemens Nucleus NET, Siemens Nucleus ReadyStart V3, Siemens Nucleus Source Code, Siemens PLUSCONTROL 1st Gen, Siemens TALON TC Compact (BACnet), Siemens TALON TC Modular (BACnet)&lt;/p&gt;
&lt;p&gt;A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions &amp;lt; V3.5.5), APOGEE PXC Compact (P2 Ethernet) (All versions &amp;lt; V2.8.20), APOGEE PXC Modular (BACnet) (All versions &amp;lt; V3.5.5), APOGEE PXC Modular (P2 Ethernet) (All versions &amp;lt; V2.8.20), Nucleus NET (All versions &amp;lt; V5.2), Nucleus ReadyStart V3 (All versions &amp;lt; V2012.12), Nucleus Source Code (All versions), PLUSCONTROL 1st Gen (All versions), TALON TC Compact (BACnet) (All versions &amp;lt; V3.5.5), TALON TC Modular (BACnet) (All versions &amp;lt; V3.5.5). Initial Sequence Numbers (ISNs) for TCP connections are derived from an insufficiently random source. As a result, the ISN of current and future TCP connections could be predictable. An attacker could hijack existing sessions or spoof future ones.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Siemens APOGEE PXC Compact (BACnet), Siemens APOGEE PXC Compact (P2 Ethernet), Siemens APOGEE PXC Modular (BACnet), Siemens APOGEE PXC Modular (P2 Ethernet), Siemens Nucleus NET, Siemens Nucleus ReadyStart V3, Siemens Nucleus Source Code, Siemens PLUSCONTROL 1st Gen, Siemens TALON TC Compact (BACnet), Siemens TALON TC Modular (BACnet)&lt;/p&gt;
&lt;p&gt;A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions &amp;lt; V3.5.5), APOGEE PXC Compact (P2 Ethernet) (All versions &amp;lt; V2.8.20), APOGEE PXC Modular (BACnet) (All versions &amp;lt; V3.5.5), APOGEE PXC Modular (P2 Ethernet) (All versions &amp;lt; V2.8.20), Nucleus NET (All versions &amp;lt; V5.2), Nucleus ReadyStart V3 (All versions &amp;lt; V2012.12), Nucleus Source Code (All versions), PLUSCONTROL 1st Gen (All versions), TALON TC Compact (BACnet) (All versions &amp;lt; V3.5.5), TALON TC Modular (BACnet) (All versions &amp;lt; V3.5.5). Initial Sequence Numbers (ISNs) for TCP connections are derived from an insufficiently random source. As a result, the ISN of current and future TCP connections could be predictable. An attacker could hijack existing sessions or spoof future ones.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2020-28388</guid>
    </item>
    <item>
      <title>ICSA-21-042-01 — Multiple Embedded TCP/IP Stacks (Update B)</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-21-042-01</link>
      <description>&lt;p&gt;Nut/Net software relies on highly predictable source values and has consistent increments when generating initial sequence numbers (ISN), which may allow an attacker to spoof or disrupt TCP connections.CVE-2020-27213 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N). uC/TCP-IP ISN generation relies on a linear congruential generator (LCG), which is reversable from observed output streams as the algorithm is seeded with publicly recoverable information. This defect may allow an attacker to spoof or disrupt TCP connections.CVE-2020-27630 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N). CycloneTCP ISN generation relies on a linear congruential generator (LCG), which is reversable from observed output streams as the algorithm is seeded with publicly recoverable information. This defect may allow an attacker to spoof or disrupt TCP connections.CVE-2020-27631 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N). NDKTCPIP software is initialized with a consistent value and has consistent increments when generating initial sequence numbers (ISN), which may allow an attacker to spoof or disrupt TCP connections.CVE-2020-27632 has been assigned to this vulnerability. A CVSS v3 bas…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Nut/Net software relies on highly predictable source values and has consistent increments when generating initial sequence numbers (ISN), which may allow an attacker to spoof or disrupt TCP connections.CVE-2020-27213 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N). uC/TCP-IP ISN generation relies on a linear congruential generator (LCG), which is reversable from observed output streams as the algorithm is seeded with publicly recoverable information. This defect may allow an attacker to spoof or disrupt TCP connections.CVE-2020-27630 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N). CycloneTCP ISN generation relies on a linear congruential generator (LCG), which is reversable from observed output streams as the algorithm is seeded with publicly recoverable information. This defect may allow an attacker to spoof or disrupt TCP connections.CVE-2020-27631 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N). NDKTCPIP software is initialized with a consistent value and has consistent increments when generating initial sequence numbers (ISN), which may allow an attacker to spoof or disrupt TCP connections.CVE-2020-27632 has been assigned to this vulnerability. A CVSS v3 bas…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-21-042-01</guid>
    </item>
  </channel>
</rss>
