<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/csaf_aumariestergmbhcokg/10</id>
  <title>Most recent entries from csaf_aumariestergmbhcokg</title>
  <updated>2026-10-02T07:11:59.628499+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2025-047</id>
    <title>VDE-2025-047 — AUMA: Incorrect delivery status of the Bluetooth configuration</title>
    <updated>2025-06-10T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>For actuators with AC.2 controls and PROFOX actuators, a wrong configuration occurred for deliveries within the period from 01.01.2024 to 09.05.2025. Despite the ordered option "L90.00 = Bluetooth always deactivated", these actuators were delivered with an activated Bluetooth module which would allow an attacker to utilize the Bluetooth interface. It is possible to deactivate the Bluetooth interface of the affected actuators after the delivery using the standard procedures listed in the manuals.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2025-047"/>
    <published>2025-06-10T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2023-028</id>
    <title>VDE-2023-028 — AUMA: SIMA Master Station affected by WRECK vulnerability</title>
    <updated>2025-05-14T13:00:15+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>** UNSUPPORTED WHEN ASSIGNED ** A DNS client stack-based buffer overflow in ipdnsc_decode_name() affects Wind River VxWorks 6.5 through 7. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2023-028"/>
    <published>2023-08-07T11:35:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2022-024</id>
    <title>VDE-2022-024 — Auma: SIMA² Master Station Denial of Service Vulnerability on Automation Runtime Webserver</title>
    <updated>2025-05-14T13:00:15+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Buffer Overflow vulnerability in B&amp;R Automation Runtime webserver allows an unauthenticated network-based attacker to stop the cyclic program on the device and cause a denial of service.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2022-024"/>
    <published>2022-06-15T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2025-026</id>
    <title>VDE-2025-026 — AUMA Riester: Buffer overflow in service telegram</title>
    <updated>2025-05-14T13:00:14+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Sending too much data in the service telegram of AUMA actuators leads to a buffer overflow in the actuator controls. Depending on the actuator, the service telegram is transmitted either via Bluetooth or RS232</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2025-026"/>
    <published>2025-05-12T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2023-027</id>
    <title>VDE-2023-027 — AUMA: Reflected Cross-Site Scripting Vulnerability in SIMA Master Stations</title>
    <updated>2023-08-07T09:35:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A reflected cross-site scripting vulnerability exists in the System Diagnostics Manager (SDM) component of SIMA² Master Stations.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2023-027"/>
    <published>2023-08-07T09:35:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2022-032</id>
    <title>VDE-2022-032 — AUMA: Multiple Vulnerabilities in Automation Runtime NTP Service</title>
    <updated>2022-08-09T08:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The SIMA2 Master Station features an NTP service based on ntpd, a reference implementation of the Network Time Protocol (NTP). Affected SIMA2 Master Stations with software version &lt; V2.6 include an outdated version of ntpd which is affected by a large number of vulnerabilities</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2022-032"/>
    <published>2022-08-09T08:00:00+00:00</published>
  </entry>
</feed>
