<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 01:01:49 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-08946</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-08946</link>
      <description>bdu:2023-08946</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-08946</guid>
    </item>
    <item>
      <title>EUVD-2026-240947</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-240947</link>
      <description>EUVD-2026-240947</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-240947</guid>
    </item>
    <item>
      <title>fkie_cve-2023-46143</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-46143</link>
      <description>&lt;p&gt;Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT classic line PLCs allows an unauthenticated remote attacker to modify some or all applications on a PLC.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT classic line PLCs allows an unauthenticated remote attacker to modify some or all applications on a PLC.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-46143</guid>
    </item>
    <item>
      <title>GHSA-frfw-grgg-284c</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-frfw-grgg-284c</link>
      <description>&lt;p&gt;Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT classic line PLCs allows an unauthenticated remote attacker to modify some or all applications on a PLC.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT classic line PLCs allows an unauthenticated remote attacker to modify some or all applications on a PLC.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-frfw-grgg-284c</guid>
    </item>
    <item>
      <title>gsd-2023-46143</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-46143</link>
      <description>gsd-2023-46143</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-46143</guid>
    </item>
    <item>
      <title>ICSA-26-279-06 — Hitachi Energy RTU500</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-26-279-06</link>
      <description>&lt;p&gt;Hitachi Energy is publishing this cybersecurity advisory in response to the security findings reported by Dragos affecting end-of-life RTU500 CMU firmware version 9.x. The reported findings are associated with legacy RTU500 firmware versions that were developed according to the cybersecurity requirements, threat landscape, and industry practices that existed at the time of their release. As cybersecurity threats and security expectations have evolved, these end-of-life versions no longer incorporate many of the security controls and hardening measures that are standard in modern industrial control systems. Over successive RTU500 releases, Hitachi Energy has continuously enhanced the security of the product through the introduction of additional security features, protocol hardening, stronger authentication and access controls, encrypted communications, and other security-by-design improvements. While the findings reported by Dragos do not affect currently supported RTU500 CMU firmware versions, there is a likelihood that the end-of-life versions 11.x and prior are affected by these vulnerabilities. Since the end-of-life versions are no longer maintained with security updates, Hitachi Energy strongly recommends upgrading to a currently supported RTU500 firmware version. Customers should also implement appropriate defense-in-depth measures and cybersecurity best practices to reduce risk and strengthen the security posture of their operational environments. Please refer to the…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Hitachi Energy is publishing this cybersecurity advisory in response to the security findings reported by Dragos affecting end-of-life RTU500 CMU firmware version 9.x. The reported findings are associated with legacy RTU500 firmware versions that were developed according to the cybersecurity requirements, threat landscape, and industry practices that existed at the time of their release. As cybersecurity threats and security expectations have evolved, these end-of-life versions no longer incorporate many of the security controls and hardening measures that are standard in modern industrial control systems. Over successive RTU500 releases, Hitachi Energy has continuously enhanced the security of the product through the introduction of additional security features, protocol hardening, stronger authentication and access controls, encrypted communications, and other security-by-design improvements. While the findings reported by Dragos do not affect currently supported RTU500 CMU firmware versions, there is a likelihood that the end-of-life versions 11.x and prior are affected by these vulnerabilities. Since the end-of-life versions are no longer maintained with security updates, Hitachi Energy strongly recommends upgrading to a currently supported RTU500 firmware version. Customers should also implement appropriate defense-in-depth measures and cybersecurity best practices to reduce risk and strengthen the security posture of their operational environments. Please refer to the…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-26-279-06</guid>
    </item>
    <item>
      <title>VDE-2023-057 — Phoenix Contact: Classic line industrial controllers prone to inadequate integrity check of PLC</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2023-057</link>
      <description>&lt;p&gt;Phoenix Contact classic line industrial controllers are developed and designed for the use in closed industrial networks. The controllers don&amp;#39;t feature a function to check integrity and authenticity of the application (e.g.: logic files, executable logic, configurations).
A CRC Check warning the user if the application of the Engineering tool and the PLC differs can be manipulated.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Phoenix Contact classic line industrial controllers are developed and designed for the use in closed industrial networks. The controllers don&amp;#39;t feature a function to check integrity and authenticity of the application (e.g.: logic files, executable logic, configurations).
A CRC Check warning the user if the application of the Engineering tool and the PLC differs can be manipulated.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2023-057</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3658 — Hitachi Energy RTU500: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3658</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Hitachi Energy RTU500 ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, die Gerätefunktionalität zu verändern oder Denial-of-Service-Zustände zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Hitachi Energy RTU500 ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, die Gerätefunktionalität zu verändern oder Denial-of-Service-Zustände zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3658</guid>
    </item>
  </channel>
</rss>
