<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/csaf_endresshauserag/10</id>
  <title>Most recent entries from csaf_endresshauserag</title>
  <updated>2026-10-02T07:10:21.960152+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2026-065</id>
    <title>VDE-2026-065 — Endress+Hauser: iDTM Debug Interface Vulnerability in the FDI Package Library</title>
    <updated>2026-08-03T07:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the debug interface by placing a crafted file in the application directory.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2026-065"/>
    <published>2026-08-03T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2026-045</id>
    <title>VDE-2026-045 — Endress+Hauser: Multiple products affected by SopasET interface vulnerability</title>
    <updated>2026-07-16T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability was discovered in several Endress+Hauser products that can be accessed via ethernet.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2026-045"/>
    <published>2026-07-16T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2026-032</id>
    <title>VDE-2026-032 — Endress+Hauser: sudo vulnerability affects Endress+Hauser MCS200HW</title>
    <updated>2026-04-21T07:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The display unit of the Endress+Hauser MCS200HW is affected by a sudo chroot vulnerability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2026-032"/>
    <published>2026-04-21T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2025-107</id>
    <title>VDE-2025-107 — Endress+Hauser: Multiple products affected by Qualcomm vulnerabilities</title>
    <updated>2026-04-02T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multiple vulnerabilities in a Qualcomm component have been reported in a closed-source report. This component is an integral part of the radio chip found in several Endress+Hauser products.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2025-107"/>
    <published>2025-12-05T11:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2026-003</id>
    <title>VDE-2026-003 — Endress+Hauser: Multiple products prone to multiple vulnerabilities in e!Runtime and CODESYS V3 Runtime</title>
    <updated>2026-04-01T11:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multiple Endress+Hauser devices are prone to vulnerabilities found in e!Runtime and the CODESYS V3 framework.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2026-003"/>
    <published>2026-03-31T08:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2026-002</id>
    <title>VDE-2026-002 — Endress+Hauser: buffer overflow in glibc ld.so leading to privilege escalation</title>
    <updated>2026-03-02T07:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability has been identified in WAGO devices utilized in Endress+Hauser IoT solutions. WAGO has provided fixes for these vulnerabilities, which have been integrated into the solutions by Endress+Hauser.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2026-002"/>
    <published>2026-03-02T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2025-068</id>
    <title>VDE-2025-068 — Endress+Hauser: Proline 10 Maintenance credentials may be exposed under certain conditions</title>
    <updated>2026-02-20T09:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>A privilege escalation vulnerability has been identified in Endress+Hauser's Proline 10 devices. This flaw allows an authenticated user with Operator-level access to elevate their privileges and gain Maintenance-level access, potentially enabling unauthorized configuration changes.</p>
<p>Endress+Hauser has released a security update addressing this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2025-068"/>
    <published>2025-09-02T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2025-105</id>
    <title>VDE-2025-105 — Endress+Hauser: Multiple products affected by Wibu-Systems CodeMeter Vulnerability</title>
    <updated>2025-12-08T09:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability in Wibu-Systems CodeMeter (up to version 7.60b) affects multiple Endress+Hauser products. This flaw can lead to a heap buffer overflow, which may allow remote code execution under certain conditions.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2025-105"/>
    <published>2025-12-08T09:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-054</id>
    <title>VDE-2024-054 — Endress+Hauser: Netilion Network Insights is affected by multiple vulnerabilities</title>
    <updated>2025-05-22T13:03:10+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Several vulnerabilities have been identified in the web-based management of WAGO devices utilized in
Endress+Hauser IoT solutions. WAGO has provided fixes for these vulnerabilities, which have been
integrated into the solutions by Endress+Hauser. Additionally, a guideline on secure operation of these
solutions has been made available.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-054"/>
    <published>2024-10-21T08:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2021-044</id>
    <title>VDE-2021-044 — Endress+Hauser: Multiple products affected by log4net vulnerability</title>
    <updated>2025-05-14T13:00:14+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2021-044"/>
    <published>2022-01-20T08:06:00+00:00</published>
  </entry>
</feed>
