<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 22:22:16 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-03446</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-03446</link>
      <description>bdu:2023-03446</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-03446</guid>
    </item>
    <item>
      <title>certfr-2021-avi-622 — De multiples vulnérabilités ont été découvertes dans les produits
Schneider Electric. Certaines d'entre elles permetten…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-622</link>
      <description>certfr-2021-avi-622</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-622</guid>
    </item>
    <item>
      <title>EUVD-2026-322751</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-322751</link>
      <description>EUVD-2026-322751</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-322751</guid>
    </item>
    <item>
      <title>fkie_cve-2021-22792</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-22792</link>
      <description>&lt;p&gt;A CWE-476: NULL Pointer Dereference vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP* and BMEH*, all versions), Modicon M340 CPU (part numbers BMXP34*, all versions), Modicon MC80 (part numbers BMKC80*, all versions), Modicon Momentum Ethernet CPU (part numbers 171CBU*, all versions), PLC Simulator for EcoStruxureª Control Expert, including all Unity Pro versions (former name of EcoStruxureª Control Expert, all versions), PLC Simulator for EcoStruxureª Process Expert including all HDCS versions (former name of EcoStruxureª Process Expert, all versions), Modicon Quantum CPU (part numbers 140CPU*, all versions), Modicon Premium CPU (part numbers TSXP5*, all versions).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A CWE-476: NULL Pointer Dereference vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP* and BMEH*, all versions), Modicon M340 CPU (part numbers BMXP34*, all versions), Modicon MC80 (part numbers BMKC80*, all versions), Modicon Momentum Ethernet CPU (part numbers 171CBU*, all versions), PLC Simulator for EcoStruxureª Control Expert, including all Unity Pro versions (former name of EcoStruxureª Control Expert, all versions), PLC Simulator for EcoStruxureª Process Expert including all HDCS versions (former name of EcoStruxureª Process Expert, all versions), Modicon Quantum CPU (part numbers 140CPU*, all versions), Modicon Premium CPU (part numbers TSXP5*, all versions).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-22792</guid>
    </item>
    <item>
      <title>GHSA-f4gm-v37p-h557</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-f4gm-v37p-h557</link>
      <description>&lt;p&gt;A CWE-476: NULL Pointer Dereference vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP* and BMEH*, all versions), Modicon M340 CPU (part numbers BMXP34*, all versions), Modicon MC80 (part numbers BMKC80*, all versions), Modicon Momentum Ethernet CPU (part numbers 171CBU*, all versions), PLC Simulator for EcoStruxureª Control Expert, including all Unity Pro versions (former name of EcoStruxureª Control Expert, all versions), PLC Simulator for EcoStruxureª Process Expert including all HDCS versions (former name of EcoStruxureª Process Expert, all versions), Modicon Quantum CPU (part numbers 140CPU*, all versions), Modicon Premium CPU (part numbers TSXP5*, all versions).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A CWE-476: NULL Pointer Dereference vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP* and BMEH*, all versions), Modicon M340 CPU (part numbers BMXP34*, all versions), Modicon MC80 (part numbers BMKC80*, all versions), Modicon Momentum Ethernet CPU (part numbers 171CBU*, all versions), PLC Simulator for EcoStruxureª Control Expert, including all Unity Pro versions (former name of EcoStruxureª Control Expert, all versions), PLC Simulator for EcoStruxureª Process Expert including all HDCS versions (former name of EcoStruxureª Process Expert, all versions), Modicon Quantum CPU (part numbers 140CPU*, all versions), Modicon Premium CPU (part numbers TSXP5*, all versions).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-f4gm-v37p-h557</guid>
    </item>
    <item>
      <title>gsd-2021-22792</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-22792</link>
      <description>gsd-2021-22792</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-22792</guid>
    </item>
    <item>
      <title>SEVD-2021-222-04 — Modicon PAC Controllers and PLC Simulator for EcoStruxure™ Control Expert and EcoStruxure™ Process Expert</title>
      <link>https://cve.radiocsirt.org/vuln/sevd-2021-222-04</link>
      <description>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities in the Modicon PAC Controllers and PLC simulator included in EcoStruxure™ Control Expert and EcoStruxure™ Process Expert.
Modicon PLCs (Programmable Logic Controllers) and PACs (Programmable Automation Controllers) control and monitor industrial operations in a sustainable, flexible, efficient and protected way.
The PLC Simulator feature is part of the EcoStruxure™ Control Expert and EcoStruxure™ Process Expert software and it helps users to review and test their configurations files in a simulation environment and is not intended to be used as a controller CPU in a production environment.
Failure to apply the mitigations provided below may lead to the execution of a malicious project file, which could result in loss of availability of the controller or of the PLC simulator. For an attack to be successful, a malicious project file must be downloaded in the controller or in the simulator.
March 2023 Update: A remediation is available for Modicon M580 CPU and Modicon Momentum Unity M1E Processor for CVE-2021-22789 , and update to the PLC Simulator user manual to reflect the mitigation&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities in the Modicon PAC Controllers and PLC simulator included in EcoStruxure™ Control Expert and EcoStruxure™ Process Expert.
Modicon PLCs (Programmable Logic Controllers) and PACs (Programmable Automation Controllers) control and monitor industrial operations in a sustainable, flexible, efficient and protected way.
The PLC Simulator feature is part of the EcoStruxure™ Control Expert and EcoStruxure™ Process Expert software and it helps users to review and test their configurations files in a simulation environment and is not intended to be used as a controller CPU in a production environment.
Failure to apply the mitigations provided below may lead to the execution of a malicious project file, which could result in loss of availability of the controller or of the PLC simulator. For an attack to be successful, a malicious project file must be downloaded in the controller or in the simulator.
March 2023 Update: A remediation is available for Modicon M580 CPU and Modicon Momentum Unity M1E Processor for CVE-2021-22789 , and update to the PLC Simulator user manual to reflect the mitigation&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sevd-2021-222-04</guid>
    </item>
  </channel>
</rss>
