<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from csaf_aumariestergmbhcokg</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 07:12:01 +0000</lastBuildDate>
    <item>
      <title>VDE-2025-047 — AUMA: Incorrect delivery status of the Bluetooth configuration</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2025-047</link>
      <description>&lt;p&gt;For actuators with AC.2 controls and PROFOX actuators, a wrong configuration occurred for deliveries within the period from 01.01.2024 to 09.05.2025. Despite the ordered option &amp;#34;L90.00 = Bluetooth always deactivated&amp;#34;, these actuators were delivered with an activated Bluetooth module which would allow an attacker to utilize the Bluetooth interface. It is possible to deactivate the Bluetooth interface of the affected actuators after the delivery using the standard procedures listed in the manuals.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;For actuators with AC.2 controls and PROFOX actuators, a wrong configuration occurred for deliveries within the period from 01.01.2024 to 09.05.2025. Despite the ordered option &amp;#34;L90.00 = Bluetooth always deactivated&amp;#34;, these actuators were delivered with an activated Bluetooth module which would allow an attacker to utilize the Bluetooth interface. It is possible to deactivate the Bluetooth interface of the affected actuators after the delivery using the standard procedures listed in the manuals.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2025-047</guid>
      <pubDate>Tue, 10 Jun 2025 10:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2023-028 — AUMA: SIMA Master Station affected by WRECK vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2023-028</link>
      <description>&lt;p&gt;** UNSUPPORTED WHEN ASSIGNED ** A DNS client stack-based buffer overflow in ipdnsc_decode_name() affects Wind River VxWorks 6.5 through 7. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;** UNSUPPORTED WHEN ASSIGNED ** A DNS client stack-based buffer overflow in ipdnsc_decode_name() affects Wind River VxWorks 6.5 through 7. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2023-028</guid>
      <pubDate>Mon, 07 Aug 2023 11:35:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2022-024 — Auma: SIMA² Master Station Denial of Service Vulnerability on Automation Runtime Webserver</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2022-024</link>
      <description>&lt;p&gt;Buffer Overflow vulnerability in B&amp;amp;R Automation Runtime webserver allows an unauthenticated network-based attacker to stop the cyclic program on the device and cause a denial of service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Buffer Overflow vulnerability in B&amp;amp;R Automation Runtime webserver allows an unauthenticated network-based attacker to stop the cyclic program on the device and cause a denial of service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2022-024</guid>
      <pubDate>Wed, 15 Jun 2022 10:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2025-026 — AUMA Riester: Buffer overflow in service telegram</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2025-026</link>
      <description>&lt;p&gt;Sending too much data in the service telegram of AUMA actuators leads to a buffer overflow in the actuator controls. Depending on the actuator, the service telegram is transmitted either via Bluetooth or RS232&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Sending too much data in the service telegram of AUMA actuators leads to a buffer overflow in the actuator controls. Depending on the actuator, the service telegram is transmitted either via Bluetooth or RS232&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2025-026</guid>
      <pubDate>Mon, 12 May 2025 10:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2023-027 — AUMA: Reflected Cross-Site Scripting Vulnerability in SIMA Master Stations</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2023-027</link>
      <description>&lt;p&gt;A reflected cross-site scripting vulnerability exists in the System Diagnostics Manager (SDM) component of SIMA² Master Stations.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A reflected cross-site scripting vulnerability exists in the System Diagnostics Manager (SDM) component of SIMA² Master Stations.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2023-027</guid>
      <pubDate>Mon, 07 Aug 2023 09:35:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2022-032 — AUMA: Multiple Vulnerabilities in Automation Runtime NTP Service</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2022-032</link>
      <description>&lt;p&gt;The SIMA2 Master Station features an NTP service based on ntpd, a reference implementation of the Network Time Protocol (NTP). Affected SIMA2 Master Stations with software version &amp;lt; V2.6 include an outdated version of ntpd which is affected by a large number of vulnerabilities&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The SIMA2 Master Station features an NTP service based on ntpd, a reference implementation of the Network Time Protocol (NTP). Affected SIMA2 Master Stations with software version &amp;lt; V2.6 include an outdated version of ntpd which is affected by a large number of vulnerabilities&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2022-032</guid>
      <pubDate>Tue, 09 Aug 2022 08:00:00 +0000</pubDate>
    </item>
  </channel>
</rss>
