<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 16:07:17 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-52509</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-52509</link>
      <description>EUVD-2026-52509</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-52509</guid>
    </item>
    <item>
      <title>fkie_cve-2019-9012</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2019-9012</link>
      <description>&lt;p&gt;An issue was discovered in 3S-Smart CODESYS V3 products. A crafted communication request may cause uncontrolled memory allocations in the affected CODESYS products and may result in a denial-of-service condition. All variants of the following CODESYS V3 products in all versions prior to v3.5.14.20 that contain the CmpGateway component are affected, regardless of the CPU type or operating system: CODESYS Control for BeagleBone, CODESYS Control for emPC-A/iMX6, CODESYS Control for IOT2000, CODESYS Control for Linux, CODESYS Control for PFC100, CODESYS Control for PFC200, CODESYS Control for Raspberry Pi, CODESYS Control V3 Runtime System Toolkit, CODESYS Gateway V3, CODESYS V3 Development System.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered in 3S-Smart CODESYS V3 products. A crafted communication request may cause uncontrolled memory allocations in the affected CODESYS products and may result in a denial-of-service condition. All variants of the following CODESYS V3 products in all versions prior to v3.5.14.20 that contain the CmpGateway component are affected, regardless of the CPU type or operating system: CODESYS Control for BeagleBone, CODESYS Control for emPC-A/iMX6, CODESYS Control for IOT2000, CODESYS Control for Linux, CODESYS Control for PFC100, CODESYS Control for PFC200, CODESYS Control for Raspberry Pi, CODESYS Control V3 Runtime System Toolkit, CODESYS Gateway V3, CODESYS V3 Development System.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2019-9012</guid>
    </item>
    <item>
      <title>FSA-202202 — Festo: Controller CECC-S,LK,D family &lt;= 2.3.8.1 - multiple vulnerabilities in CODESYS V3 runtime system</title>
      <link>https://cve.radiocsirt.org/vuln/fsa-202202</link>
      <description>&lt;p&gt;The Festo controller CECC product family is affected by multiple vulnerabilities in the CODESYS V3 runtime.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Festo controller CECC product family is affected by multiple vulnerabilities in the CODESYS V3 runtime.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fsa-202202</guid>
    </item>
    <item>
      <title>GHSA-q2jg-8rwm-9rgx</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-q2jg-8rwm-9rgx</link>
      <description>&lt;p&gt;An issue was discovered in 3S-Smart CODESYS V3 products. A crafted communication request may cause uncontrolled memory allocations in the affected CODESYS products and may result in a denial-of-service condition. All variants of the following CODESYS V3 products in all versions prior to v3.5.14.20 that contain the CmpGateway component are affected, regardless of the CPU type or operating system: CODESYS Control for BeagleBone, CODESYS Control for emPC-A/iMX6, CODESYS Control for IOT2000, CODESYS Control for Linux, CODESYS Control for PFC100, CODESYS Control for PFC200, CODESYS Control for Raspberry Pi, CODESYS Control V3 Runtime System Toolkit, CODESYS Gateway V3, CODESYS V3 Development System.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered in 3S-Smart CODESYS V3 products. A crafted communication request may cause uncontrolled memory allocations in the affected CODESYS products and may result in a denial-of-service condition. All variants of the following CODESYS V3 products in all versions prior to v3.5.14.20 that contain the CmpGateway component are affected, regardless of the CPU type or operating system: CODESYS Control for BeagleBone, CODESYS Control for emPC-A/iMX6, CODESYS Control for IOT2000, CODESYS Control for Linux, CODESYS Control for PFC100, CODESYS Control for PFC200, CODESYS Control for Raspberry Pi, CODESYS Control V3 Runtime System Toolkit, CODESYS Gateway V3, CODESYS V3 Development System.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-q2jg-8rwm-9rgx</guid>
    </item>
    <item>
      <title>gsd-2019-9012</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2019-9012</link>
      <description>gsd-2019-9012</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2019-9012</guid>
    </item>
    <item>
      <title>ICSA-19-213-03 — 3S-Smart Software Solutions GmbH CODESYS V3</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-19-213-03</link>
      <description>&lt;p&gt;The CODESYS Gateway does not correctly verify the ownership of a communication channel. CVE-2019-9010 has been assigned to this vulnerability. A CVSS v3 base score of 9.0 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H). A crafted communication request may cause uncontrolled memory allocations in the affected CODESYS products and may result in a denial-of-service condition. CVE-2019-9012  has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The CODESYS Gateway does not correctly verify the ownership of a communication channel. CVE-2019-9010 has been assigned to this vulnerability. A CVSS v3 base score of 9.0 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H). A crafted communication request may cause uncontrolled memory allocations in the affected CODESYS products and may result in a denial-of-service condition. CVE-2019-9012  has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-19-213-03</guid>
    </item>
    <item>
      <title>VDE-2021-033 — TRUMPF Laser GmbH: multiple products prone to codesys runtime vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2021-033</link>
      <description>&lt;p&gt;The TruControl laser control software (versions 1.04 to 3.0.0) uses CODESYS runtime versions affected by multiple CVEs:&lt;/p&gt;
&lt;p&gt;**CVE list:**&lt;/p&gt;
&lt;p&gt;- CVE-2021-29242
- CVE-2021-29241
- CVE-2019-5105
- CVE-2020-7052
- CVE-2019-9012
- CVE-2019-9010
- CVE-2019-9009
- CVE-2018-10612&lt;/p&gt;
&lt;p&gt;In addition to the CVEs listed above, the affected products are also vulnerable to the following issues without a CVE ID:&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### **CODESYS Advisory 2018-07**&lt;/p&gt;
&lt;p&gt;A crafted communication request may cause an access violation in the affected CODESYS products and may result in a denial-of-service condition.&lt;/p&gt;
&lt;p&gt;- **CVSS v3.0 base score:** 6.5  
- **CVSS v3.0 vector:** `CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H`&lt;/p&gt;
&lt;p&gt;🔗 [Link to advisory](https://customers.codesys.com/index.php?eID=dumpFile&amp;amp;t=f&amp;amp;f=12928&amp;amp;token=6d1dcea05a15aeef7ad48eadc64c8eca5d4f07b2&amp;amp;download=)&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### **CODESYS Advisory 2018-04**&lt;/p&gt;
&lt;p&gt;The CODESYS runtime system allows access to files outside the restricted working directory of the controller by online services.&lt;/p&gt;
&lt;p&gt;- **CVSS v3.0 base score:** 9.9  
- **CVSS v3.0 vector:** `CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H`&lt;/p&gt;
&lt;p&gt;🔗 [Link to advisory](https://customers.codesys.com/index.php?eID=dumpFile&amp;amp;t=f&amp;amp;f=12925&amp;amp;token=50e7240fa947ea215311e3db441f82152f1109b6&amp;amp;download=)&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### **CODESYS Advisory 2017-03**&lt;/p&gt;
&lt;p&gt;A crafted request may cause an access violation in the affected CODESYS products and may result in a denial-of-service condition.&lt;/p&gt;
&lt;p&gt;- **CVSS v3.0 base score:** 7.5  
- **CVSS v3.0 vector:** `CVSS:3.0/AV:N/AC:L/PR:N/…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The TruControl laser control software (versions 1.04 to 3.0.0) uses CODESYS runtime versions affected by multiple CVEs:&lt;/p&gt;
&lt;p&gt;**CVE list:**&lt;/p&gt;
&lt;p&gt;- CVE-2021-29242
- CVE-2021-29241
- CVE-2019-5105
- CVE-2020-7052
- CVE-2019-9012
- CVE-2019-9010
- CVE-2019-9009
- CVE-2018-10612&lt;/p&gt;
&lt;p&gt;In addition to the CVEs listed above, the affected products are also vulnerable to the following issues without a CVE ID:&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### **CODESYS Advisory 2018-07**&lt;/p&gt;
&lt;p&gt;A crafted communication request may cause an access violation in the affected CODESYS products and may result in a denial-of-service condition.&lt;/p&gt;
&lt;p&gt;- **CVSS v3.0 base score:** 6.5  
- **CVSS v3.0 vector:** `CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H`&lt;/p&gt;
&lt;p&gt;🔗 [Link to advisory](https://customers.codesys.com/index.php?eID=dumpFile&amp;amp;t=f&amp;amp;f=12928&amp;amp;token=6d1dcea05a15aeef7ad48eadc64c8eca5d4f07b2&amp;amp;download=)&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### **CODESYS Advisory 2018-04**&lt;/p&gt;
&lt;p&gt;The CODESYS runtime system allows access to files outside the restricted working directory of the controller by online services.&lt;/p&gt;
&lt;p&gt;- **CVSS v3.0 base score:** 9.9  
- **CVSS v3.0 vector:** `CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H`&lt;/p&gt;
&lt;p&gt;🔗 [Link to advisory](https://customers.codesys.com/index.php?eID=dumpFile&amp;amp;t=f&amp;amp;f=12925&amp;amp;token=50e7240fa947ea215311e3db441f82152f1109b6&amp;amp;download=)&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### **CODESYS Advisory 2017-03**&lt;/p&gt;
&lt;p&gt;A crafted request may cause an access violation in the affected CODESYS products and may result in a denial-of-service condition.&lt;/p&gt;
&lt;p&gt;- **CVSS v3.0 base score:** 7.5  
- **CVSS v3.0 vector:** `CVSS:3.0/AV:N/AC:L/PR:N/…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2021-033</guid>
    </item>
  </channel>
</rss>
