<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 10:40:33 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-00036</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-00036</link>
      <description>bdu:2024-00036</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-00036</guid>
    </item>
    <item>
      <title>certfr-2023-avi-1015 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits Siemens&lt;/span&gt;. Certaines d'entr…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-1015</link>
      <description>certfr-2023-avi-1015</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-1015</guid>
    </item>
    <item>
      <title>cnvd-2023-97278</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2023-97278</link>
      <description>cnvd-2023-97278</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2023-97278</guid>
    </item>
    <item>
      <title>EUVD-2026-210312</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-210312</link>
      <description>EUVD-2026-210312</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-210312</guid>
    </item>
    <item>
      <title>fkie_cve-2023-46281</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-46281</link>
      <description>&lt;p&gt;A vulnerability has been identified in Opcenter Execution Foundation (All versions &amp;lt; V2407), Opcenter Quality (All versions &amp;lt; V2312), SIMATIC PCS neo (All versions &amp;lt; V4.1), SINEC NMS (All versions &amp;lt; V2.0 SP1), Totally Integrated Automation Portal (TIA Portal) V14 (All versions), Totally Integrated Automation Portal (TIA Portal) V15.1 (All versions), Totally Integrated Automation Portal (TIA Portal) V16 (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions &amp;lt; V17 Update 8), Totally Integrated Automation Portal (TIA Portal) V18 (All versions &amp;lt; V18 Update 3). When accessing the UMC Web-UI from affected products, UMC uses an overly permissive CORS policy. This could allow an attacker to trick a legitimate user to trigger unwanted behavior.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability has been identified in Opcenter Execution Foundation (All versions &amp;lt; V2407), Opcenter Quality (All versions &amp;lt; V2312), SIMATIC PCS neo (All versions &amp;lt; V4.1), SINEC NMS (All versions &amp;lt; V2.0 SP1), Totally Integrated Automation Portal (TIA Portal) V14 (All versions), Totally Integrated Automation Portal (TIA Portal) V15.1 (All versions), Totally Integrated Automation Portal (TIA Portal) V16 (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions &amp;lt; V17 Update 8), Totally Integrated Automation Portal (TIA Portal) V18 (All versions &amp;lt; V18 Update 3). When accessing the UMC Web-UI from affected products, UMC uses an overly permissive CORS policy. This could allow an attacker to trick a legitimate user to trigger unwanted behavior.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-46281</guid>
    </item>
    <item>
      <title>GHSA-9qvw-gvq6-g569</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9qvw-gvq6-g569</link>
      <description>&lt;p&gt;A vulnerability has been identified in Opcenter Quality (All versions), SIMATIC PCS neo (All versions &amp;lt; V4.1), SINUMERIK Integrate RunMyHMI /Automotive (All versions), Totally Integrated Automation Portal (TIA Portal) V14 (All versions), Totally Integrated Automation Portal (TIA Portal) V15.1 (All versions), Totally Integrated Automation Portal (TIA Portal) V16 (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All versions &amp;lt; V18 Update 3). When accessing the UMC Web-UI from affected products, UMC uses an overly permissive CORS policy. This could allow an attacker to trick a legitimate user to trigger unwanted behavior.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability has been identified in Opcenter Quality (All versions), SIMATIC PCS neo (All versions &amp;lt; V4.1), SINUMERIK Integrate RunMyHMI /Automotive (All versions), Totally Integrated Automation Portal (TIA Portal) V14 (All versions), Totally Integrated Automation Portal (TIA Portal) V15.1 (All versions), Totally Integrated Automation Portal (TIA Portal) V16 (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All versions &amp;lt; V18 Update 3). When accessing the UMC Web-UI from affected products, UMC uses an overly permissive CORS policy. This could allow an attacker to trick a legitimate user to trigger unwanted behavior.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9qvw-gvq6-g569</guid>
    </item>
    <item>
      <title>gsd-2023-46281</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-46281</link>
      <description>gsd-2023-46281</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-46281</guid>
    </item>
    <item>
      <title>ICSA-23-348-03 — Siemens User Management Component (UMC)</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-23-348-03</link>
      <description>&lt;p&gt;When accessing the UMC Web-UI from affected products, UMC uses an overly permissive CORS policy. This could allow an attacker to trick a legitimate user to trigger unwanted behavior. A reflected cross-site scripting (XSS) vulnerability exists in the web interface of the affected applications that could allow an attacker to inject arbitrary JavaScript code. The code could be potentially executed later by another (possibly privileged) user. The affected application contains an out of bounds write past the end of an allocated buffer when handling specific requests on port 4002/tcp. This could allow an attacker to crash the application. The corresponding service is auto-restarted after the crash. The affected application contains an out of bounds write past the end of an allocated buffer when handling specific requests on port 4002/tcp and 4004/tcp. This could allow an attacker to crash the application. The corresponding service is auto-restarted after the crash. The affected application contains an improper input validation vulnerability that could allow an attacker to bring the service into a Denial-of-Service state by sending a specifically crafted message to 4004/tcp. The corresponding service is auto-restarted after the crash is detected by a watchdog.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;When accessing the UMC Web-UI from affected products, UMC uses an overly permissive CORS policy. This could allow an attacker to trick a legitimate user to trigger unwanted behavior. A reflected cross-site scripting (XSS) vulnerability exists in the web interface of the affected applications that could allow an attacker to inject arbitrary JavaScript code. The code could be potentially executed later by another (possibly privileged) user. The affected application contains an out of bounds write past the end of an allocated buffer when handling specific requests on port 4002/tcp. This could allow an attacker to crash the application. The corresponding service is auto-restarted after the crash. The affected application contains an out of bounds write past the end of an allocated buffer when handling specific requests on port 4002/tcp and 4004/tcp. This could allow an attacker to crash the application. The corresponding service is auto-restarted after the crash. The affected application contains an improper input validation vulnerability that could allow an attacker to bring the service into a Denial-of-Service state by sending a specifically crafted message to 4004/tcp. The corresponding service is auto-restarted after the crash is detected by a watchdog.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-23-348-03</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-3100 — Siemens TIA Portal: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-3100</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Siemens TIA Portal ausnutzen, um ein unerwünschtes Verhalten auszulösen, einen Cross Site Scripting Angriff durchzuführen oder einen Denial of Service zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Siemens TIA Portal ausnutzen, um ein unerwünschtes Verhalten auszulösen, einen Cross Site Scripting Angriff durchzuführen oder einen Denial of Service zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-3100</guid>
    </item>
  </channel>
</rss>
