<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 20:36:52 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-383142</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-383142</link>
      <description>EUVD-2026-383142</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-383142</guid>
    </item>
    <item>
      <title>fkie_cve-2026-94293</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-94293</link>
      <description>&lt;p&gt;An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests and can read all data exposed by the GET endpoints.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests and can read all data exposed by the GET endpoints.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-94293</guid>
    </item>
    <item>
      <title>GHSA-38w2-7jv3-258f</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-38w2-7jv3-258f</link>
      <description>&lt;p&gt;An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests and can read all data exposed by the GET endpoints.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests and can read all data exposed by the GET endpoints.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-38w2-7jv3-258f</guid>
    </item>
    <item>
      <title>VDE-2026-108 — Murrelektronik: Missing Authentication in aas-edge-client Reference Implementation allows Manipulation of AAS Data</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2026-108</link>
      <description>&lt;p&gt;The aas-edge-client is a reference implementation of an Asset Administration Shell (AAS) edge application, published by Murrelektronik GmbH on GitHub for the LNI 4.0 testbed demonstrator. Its REST API is bound to all network interfaces on TCP port 18000, requires no authentication and accepts cross-origin requests from any origin. The reference implementation was never intended for productive use and is no longer maintained. Affected are all aas-edge-client versions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The aas-edge-client is a reference implementation of an Asset Administration Shell (AAS) edge application, published by Murrelektronik GmbH on GitHub for the LNI 4.0 testbed demonstrator. Its REST API is bound to all network interfaces on TCP port 18000, requires no authentication and accepts cross-origin requests from any origin. The reference implementation was never intended for productive use and is no longer maintained. Affected are all aas-edge-client versions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2026-108</guid>
    </item>
  </channel>
</rss>
