<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from csaf_adstecindustrialitgmbh</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 11:08:44 +0000</lastBuildDate>
    <item>
      <title>VDE-2026-076 — ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2026-076</link>
      <description>&lt;p&gt;The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2026-076</guid>
      <pubDate>Tue, 28 Jul 2026 10:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2025-033 — ads-tec Industrial IT: Mosquitto MQTT Client Vulnerability in ADS-TEC IRF Products</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2025-033</link>
      <description>&lt;p&gt;The ADS-TEC firewall products IRF1000, IRF2000, and IRF3000 include Eclipse Mosquitto, affected by multiple vulnerabilities. Exploitation requires a compromised upstream MQTT broker, limiting direct device exposure.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The ADS-TEC firewall products IRF1000, IRF2000, and IRF3000 include Eclipse Mosquitto, affected by multiple vulnerabilities. Exploitation requires a compromised upstream MQTT broker, limiting direct device exposure.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2025-033</guid>
      <pubDate>Mon, 14 Apr 2025 10:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2024-016 — ADS-TEC Industrial IT: Docker vulnerability affects multiple products</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2024-016</link>
      <description>&lt;p&gt;The affected products and versions present a vulnerability due to a vulnerable integrated software component the docker runc &amp;lt;= 1.1.11. In the worst-case scenario, the integrated Docker container environment could be compromised, potentially enabling the execution of arbitrary code within the Docker environment or neighboring Docker containers if dockerfiles or Docker images from untrusted sources are utilized.&lt;/p&gt;
&lt;p&gt;It&amp;#39;s crucial to emphasize that while the Docker environment is vulnerable, the host operating system remains
unharmed due to its isolation from the Docker environment within the ads-tec products.&lt;/p&gt;
&lt;p&gt;Using Docker images or Dockerfiles from untrusted sources poses a risk. This advice is especially pertinent for Docker use in productive operational technology (OT) environments, and it&amp;#39;s our expectation that our customers adhere strictly to this guidance anyway.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The affected products and versions present a vulnerability due to a vulnerable integrated software component the docker runc &amp;lt;= 1.1.11. In the worst-case scenario, the integrated Docker container environment could be compromised, potentially enabling the execution of arbitrary code within the Docker environment or neighboring Docker containers if dockerfiles or Docker images from untrusted sources are utilized.&lt;/p&gt;
&lt;p&gt;It&amp;#39;s crucial to emphasize that while the Docker environment is vulnerable, the host operating system remains
unharmed due to its isolation from the Docker environment within the ads-tec products.&lt;/p&gt;
&lt;p&gt;Using Docker images or Dockerfiles from untrusted sources poses a risk. This advice is especially pertinent for Docker use in productive operational technology (OT) environments, and it&amp;#39;s our expectation that our customers adhere strictly to this guidance anyway.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2024-016</guid>
      <pubDate>Mon, 19 Feb 2024 07:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2023-009 — ads-tec: Multiple Vulnerabilities in IRF1000, IRF2000 and IRF3000</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2023-009</link>
      <description>VDE-2023-009</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2023-009</guid>
      <pubDate>Mon, 08 May 2023 13:37:00 +0000</pubDate>
    </item>
  </channel>
</rss>
