<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:58:15 +0000</lastBuildDate>
    <item>
      <title>9AKK108470A9491 — ABB ACS880 +N8010 Drives CODESYS RTS Vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/9akk108470a9491</link>
      <description>&lt;p&gt;Multiple vulnerabilities regarding the CODESYS Runtime System from CODESYS Group have been publicly reported. CODESYS Runtime System is utilized in the firmware of ABB ACS880 drives to provide IEC 61131-3 programming capabilities.&lt;/p&gt;
&lt;p&gt;These vulnerabilities could lead to out-of-bound memory access. Successful exploit may result in a denial-of-service condition or arbitrary code execution. Firmware updates are available that mitigate the publicly reported vulnerabilities of the product versions listed as affected in this advisory.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities regarding the CODESYS Runtime System from CODESYS Group have been publicly reported. CODESYS Runtime System is utilized in the firmware of ABB ACS880 drives to provide IEC 61131-3 programming capabilities.&lt;/p&gt;
&lt;p&gt;These vulnerabilities could lead to out-of-bound memory access. Successful exploit may result in a denial-of-service condition or arbitrary code execution. Firmware updates are available that mitigate the publicly reported vulnerabilities of the product versions listed as affected in this advisory.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/9akk108470a9491</guid>
    </item>
    <item>
      <title>bdu:2023-03155</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-03155</link>
      <description>bdu:2023-03155</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-03155</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0297 — De multiples vulnérabilités ont été découvertes dans les produits
Schneider Electric. Certaines d'entre elles permetten…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0297</link>
      <description>certfr-2023-avi-0297</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0297</guid>
    </item>
    <item>
      <title>EUVD-2026-322768</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-322768</link>
      <description>EUVD-2026-322768</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-322768</guid>
    </item>
    <item>
      <title>fkie_cve-2022-4046</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-4046</link>
      <description>&lt;p&gt;In CODESYS Control in multiple versions a improper restriction of operations within the bounds of a memory buffer allow an remote attacker with user privileges to gain full access of the device.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In CODESYS Control in multiple versions a improper restriction of operations within the bounds of a memory buffer allow an remote attacker with user privileges to gain full access of the device.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-4046</guid>
    </item>
    <item>
      <title>FSA-202601 — Several CODESYS vulnerabilities in Festo Automation Suite</title>
      <link>https://cve.radiocsirt.org/vuln/fsa-202601</link>
      <description>&lt;p&gt;Starting with Festo Automation Suite (FAS) version 2.8.0.138, the suite is delivered only with a connector to Codesys, rather than including Codesys directly. Prior to this version, Codesys was bundled within the FAS installation. From version 2.8.0.138 onwards, customers are required to download and install Codesys independently.&lt;/p&gt;
&lt;p&gt;This change impacts the handling of security vulnerabilities (CVEs) related to Codesys. Any Codesys-related security issues must now be addressed by the customer through their separate Codesys installation. The FAS itself includes only the connector component, which is maintained and updated within the suite.&lt;/p&gt;
&lt;p&gt;Please ensure that Codesys is kept up to date independently to mitigate any potential security risks associated with the Codesys software.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Starting with Festo Automation Suite (FAS) version 2.8.0.138, the suite is delivered only with a connector to Codesys, rather than including Codesys directly. Prior to this version, Codesys was bundled within the FAS installation. From version 2.8.0.138 onwards, customers are required to download and install Codesys independently.&lt;/p&gt;
&lt;p&gt;This change impacts the handling of security vulnerabilities (CVEs) related to Codesys. Any Codesys-related security issues must now be addressed by the customer through their separate Codesys installation. The FAS itself includes only the connector component, which is maintained and updated within the suite.&lt;/p&gt;
&lt;p&gt;Please ensure that Codesys is kept up to date independently to mitigate any potential security risks associated with the Codesys software.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fsa-202601</guid>
    </item>
    <item>
      <title>GHSA-w93c-fgm5-qf42</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-w93c-fgm5-qf42</link>
      <description>&lt;p&gt;In CODESYS Control in multiple versions a improper restriction of operations within the bounds of a memory buffer allow an remote attacker with user privileges to gain full access of the device.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In CODESYS Control in multiple versions a improper restriction of operations within the bounds of a memory buffer allow an remote attacker with user privileges to gain full access of the device.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-w93c-fgm5-qf42</guid>
    </item>
    <item>
      <title>gsd-2022-4046</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-4046</link>
      <description>gsd-2022-4046</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-4046</guid>
    </item>
    <item>
      <title>ICSA-25-093-03 — ABB ACS880 Drives Containing CODESYS RTS</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-25-093-03</link>
      <description>&lt;p&gt;Multiple vulnerabilities regarding the CODESYS Runtime System from CODESYS Group have been publicly reported. CODESYS Runtime System is utilized in the firmware of ABB ACS880 drives to provide IEC 61131-3 programming capabilities.&lt;/p&gt;
&lt;p&gt;These vulnerabilities could lead to out-of-bound memory access. Successful exploit may result in a denial-of-service condition or arbitrary code execution. Firmware updates are available that mitigate the publicly reported vulnerabilities of the product versions listed as affected in this advisory.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities regarding the CODESYS Runtime System from CODESYS Group have been publicly reported. CODESYS Runtime System is utilized in the firmware of ABB ACS880 drives to provide IEC 61131-3 programming capabilities.&lt;/p&gt;
&lt;p&gt;These vulnerabilities could lead to out-of-bound memory access. Successful exploit may result in a denial-of-service condition or arbitrary code execution. Firmware updates are available that mitigate the publicly reported vulnerabilities of the product versions listed as affected in this advisory.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-25-093-03</guid>
    </item>
    <item>
      <title>SEVD-2023-101-01 — CODESYS Runtime Vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/sevd-2023-101-01</link>
      <description>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities disclosed on CODESYS Runtime. Many
vendors, including Schneider Electric, embed CODESYS in their offers. If successfully
exploited, these vulnerabilities could result in a denial of service or, in some cases, in remote
code execution on PacDrive controllers, Modicon Controllers M241 / M251 / M262 / M258 /
LMC058 / M218 and HMISCU products.
Failure to apply the mitigations provided below may risk Logic Integrity and Permissions attacks,
which could result in loss of controllers’ integrity.
January 2024 Update: A remediation is available for CVE-2022-4224 for Harmony HMISCU
Controller, Modicon Controllers M241 / M251 / M262 and PacDrive Controllers LMC
Eco/Pro/Pro2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities disclosed on CODESYS Runtime. Many
vendors, including Schneider Electric, embed CODESYS in their offers. If successfully
exploited, these vulnerabilities could result in a denial of service or, in some cases, in remote
code execution on PacDrive controllers, Modicon Controllers M241 / M251 / M262 / M258 /
LMC058 / M218 and HMISCU products.
Failure to apply the mitigations provided below may risk Logic Integrity and Permissions attacks,
which could result in loss of controllers’ integrity.
January 2024 Update: A remediation is available for CVE-2022-4224 for Harmony HMISCU
Controller, Modicon Controllers M241 / M251 / M262 and PacDrive Controllers LMC
Eco/Pro/Pro2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sevd-2023-101-01</guid>
    </item>
    <item>
      <title>VDE-2023-025 — CODESYS: Control runtime system memory and integrity check vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2023-025</link>
      <description>&lt;p&gt;The CODESYS Control V3 runtime system does not restrict the memory accesses of the PLC application code to the PLC application data and does not sufficiently check the integrity of the application code by default. This could be exploited by authenticated PLC programmers.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The CODESYS Control V3 runtime system does not restrict the memory accesses of the PLC application code to the PLC application data and does not sufficiently check the integrity of the application code by default. This could be exploited by authenticated PLC programmers.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2023-025</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0943 — CODESYS: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0943</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in CODESYS ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen, vertrauliche Informationen offenzulegen, Dateien zu manipulieren oder einen Brute-Force-Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in CODESYS ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen, vertrauliche Informationen offenzulegen, Dateien zu manipulieren oder einen Brute-Force-Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0943</guid>
    </item>
  </channel>
</rss>
