<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/csaf_endresshauserag/10</id>
  <title>Most recent entries from csaf_endresshauserag</title>
  <updated>2026-10-04T18:57:37.190517+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2019-005</id>
    <title>VDE-2019-005 — Endress+Hauser: WIFI enabled products utilising WPA2</title>
    <updated>2019-03-19T15:34:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multiple security issues and vulnerabilities within the WPA2 standard have been identified and publicized by Mr. Mathy Vanhoef of KU Leuven. These vulnerabilities may allow the reinstallation of a pairwise transient key, a group key, or an integrity key on either a wireless client or a wireless access point (AP). In consequence, an attacker could establish a man-in-the-middle position between AP and client facilitating packet decryption and injection.
The Field Xpert SFX370 and SFX350 handhelds are manufactured by Pepperl+Fuchs/ecom instruments for Endress+Hauser.
The Advisory for Pepperl+Fuchs/ecom instruments can be found here: VDE-2017-005</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2019-005"/>
    <published>2019-03-19T15:34:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2022-006</id>
    <title>VDE-2022-006 — Endress+Hauser: FieldPort SFP50 Memory Corruption in Bluetooth Controller Firmware</title>
    <updated>2022-03-24T10:48:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Possible memory corruption in BT controller when it receives an oversized LMP packet over 2-DH1 link and leads to denial of service.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2022-006"/>
    <published>2022-03-24T10:48:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2022-019</id>
    <title>VDE-2022-019 — Endress+Hauser: Multiple products utilizing vulnerable WIBU-SYSTEMS CodeMeter components</title>
    <updated>2022-06-02T15:11:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>For detailed information please refer to WIBU SYSTEMS original Advisories at https://wibu.com/support/security-advisories.html.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2022-019"/>
    <published>2022-06-02T15:11:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-041</id>
    <title>VDE-2024-041 — Endress+Hauser: Multiple products are vulnerable to code injection</title>
    <updated>2024-09-10T08:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Echo Curve Viewer is an utility used for offline visualization of previously recorded envelope curve data. Envelope curve records are exported from other Endress+Hauser software products like FieldCare as .curves files.</p>
<p>Echo Curve Viewer opens .curves files and displays their contents. The .curves files contain device- specific C# calculation scripts as .cs files, that are needed for the interpretation of certain curve record types.</p>
<p>Echo Curve Viewer loads .curves files and executes the contained C# code.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-041"/>
    <published>2024-09-10T08:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2025-036</id>
    <title>VDE-2025-036 — Multiple vulnerabilities in Endress+Hauser MEAC300-FNADE4</title>
    <updated>2025-03-06T14:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Several vulnerabilities in the Endress+Hauser MEAC300-FNADE4 were discovered, that can be accessed via Ethernet.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2025-036"/>
    <published>2025-03-06T14:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2020-021</id>
    <title>VDE-2020-021 — Endress+Hauser: Ecograph T utilizing Webserver firmware version 1.x suffers from improper privilege management</title>
    <updated>2025-04-11T07:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The affected device has a web-based user interface with a role-based access system. Users with different roles have different write and read privileges. The access system is based on dynamic "tokens".</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2020-021"/>
    <published>2020-11-19T14:48:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2021-010</id>
    <title>VDE-2021-010 — Endress+Hauser: products utilizing WPA2 vulnerable to KRACK attacks</title>
    <updated>2025-05-14T12:28:19+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Endress+Hauser products utilizing WPA2 are vulnerable to KRACK attacks.
Proline portfolio is a flow meter with an optional WLAN interface in the display. The flowmeters are only affected if the optional WLAN display is present.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2021-010"/>
    <published>2021-05-18T09:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2021-040</id>
    <title>VDE-2021-040 — Endress+Hauser: Promass 83 with EtherNet/IP affected by a stack-based buffer overflow</title>
    <updated>2025-05-14T12:28:19+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Promass 83 devices utilizing 499ES EtherNet/IP (ENIP) Stack by Real Time Automation (RTA) are vulnerable to a stack-based buffer overflow.</p>
<p>Update A, 2021-10-07:</p>
<p>added credits
changed title from "ENDRESS+HAUSER: Promass 83 with Ether/IP affected by DoS vulnerability" to "ENDRESS+HAUSER: Promass 83 with EtherNet/IP affected by a stack-based buffer overflow"</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2021-040"/>
    <published>2021-10-04T12:30:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2020-022</id>
    <title>VDE-2020-022 — Endress+Hauser: Ecograph T utilizing Webserver firmware version 2.x exposes sensitive information</title>
    <updated>2025-05-14T13:00:14+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The firmware release has a dynamic token for each request submitted to the server, which makes repeating requests and analysis complex enough. Nevertheless, it's possible and during the analysis it was discovered that it also has an issue with the access-control matrix on the server-side.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2020-022"/>
    <published>2020-11-19T14:48:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2020-031</id>
    <title>VDE-2020-031 — Endress+Hauser: Multiple products prone to WIBU CodeMeter vulnerabilities</title>
    <updated>2025-05-14T13:00:14+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>For further Information please refer to WIBU Advisories directly at https://wibu.com/support/security-advisories.html and the aforementioned CVE-IDs.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2020-031"/>
    <published>2020-10-27T13:10:00+00:00</published>
  </entry>
</feed>
