<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from csaf_endresshauserag</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 15:29:41 +0000</lastBuildDate>
    <item>
      <title>VDE-2019-005 — Endress+Hauser: WIFI enabled products utilising WPA2</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2019-005</link>
      <description>&lt;p&gt;Multiple security issues and vulnerabilities within the WPA2 standard have been identified and publicized by Mr. Mathy Vanhoef of KU Leuven. These vulnerabilities may allow the reinstallation of a pairwise transient key, a group key, or an integrity key on either a wireless client or a wireless access point (AP). In consequence, an attacker could establish a man-in-the-middle position between AP and client facilitating packet decryption and injection.
The Field Xpert SFX370 and SFX350 handhelds are manufactured by Pepperl+Fuchs/ecom instruments for Endress+Hauser.
The Advisory for Pepperl+Fuchs/ecom instruments can be found here: VDE-2017-005&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple security issues and vulnerabilities within the WPA2 standard have been identified and publicized by Mr. Mathy Vanhoef of KU Leuven. These vulnerabilities may allow the reinstallation of a pairwise transient key, a group key, or an integrity key on either a wireless client or a wireless access point (AP). In consequence, an attacker could establish a man-in-the-middle position between AP and client facilitating packet decryption and injection.
The Field Xpert SFX370 and SFX350 handhelds are manufactured by Pepperl+Fuchs/ecom instruments for Endress+Hauser.
The Advisory for Pepperl+Fuchs/ecom instruments can be found here: VDE-2017-005&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2019-005</guid>
      <pubDate>Tue, 19 Mar 2019 15:34:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2022-006 — Endress+Hauser: FieldPort SFP50 Memory Corruption in Bluetooth Controller Firmware</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2022-006</link>
      <description>&lt;p&gt;Possible memory corruption in BT controller when it receives an oversized LMP packet over 2-DH1 link and leads to denial of service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Possible memory corruption in BT controller when it receives an oversized LMP packet over 2-DH1 link and leads to denial of service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2022-006</guid>
      <pubDate>Thu, 24 Mar 2022 10:48:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2022-019 — Endress+Hauser: Multiple products utilizing vulnerable WIBU-SYSTEMS CodeMeter components</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2022-019</link>
      <description>&lt;p&gt;For detailed information please refer to WIBU SYSTEMS original Advisories at https://wibu.com/support/security-advisories.html.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;For detailed information please refer to WIBU SYSTEMS original Advisories at https://wibu.com/support/security-advisories.html.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2022-019</guid>
      <pubDate>Thu, 02 Jun 2022 15:11:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2024-041 — Endress+Hauser: Multiple products are vulnerable to code injection</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2024-041</link>
      <description>&lt;p&gt;Echo Curve Viewer is an utility used for offline visualization of previously recorded envelope curve data. Envelope curve records are exported from other Endress+Hauser software products like FieldCare as .curves files.&lt;/p&gt;
&lt;p&gt;Echo Curve Viewer opens .curves files and displays their contents. The .curves files contain device- specific C# calculation scripts as .cs files, that are needed for the interpretation of certain curve record types.&lt;/p&gt;
&lt;p&gt;Echo Curve Viewer loads .curves files and executes the contained C# code.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Echo Curve Viewer is an utility used for offline visualization of previously recorded envelope curve data. Envelope curve records are exported from other Endress+Hauser software products like FieldCare as .curves files.&lt;/p&gt;
&lt;p&gt;Echo Curve Viewer opens .curves files and displays their contents. The .curves files contain device- specific C# calculation scripts as .cs files, that are needed for the interpretation of certain curve record types.&lt;/p&gt;
&lt;p&gt;Echo Curve Viewer loads .curves files and executes the contained C# code.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2024-041</guid>
      <pubDate>Tue, 10 Sep 2024 08:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2025-036 — Multiple vulnerabilities in Endress+Hauser MEAC300-FNADE4</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2025-036</link>
      <description>&lt;p&gt;Several vulnerabilities in the Endress+Hauser MEAC300-FNADE4 were discovered, that can be accessed via Ethernet.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Several vulnerabilities in the Endress+Hauser MEAC300-FNADE4 were discovered, that can be accessed via Ethernet.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2025-036</guid>
      <pubDate>Thu, 06 Mar 2025 14:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2020-021 — Endress+Hauser: Ecograph T utilizing Webserver firmware version 1.x suffers from improper privilege management</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2020-021</link>
      <description>&lt;p&gt;The affected device has a web-based user interface with a role-based access system. Users with different roles have different write and read privileges. The access system is based on dynamic &amp;#34;tokens&amp;#34;.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The affected device has a web-based user interface with a role-based access system. Users with different roles have different write and read privileges. The access system is based on dynamic &amp;#34;tokens&amp;#34;.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2020-021</guid>
      <pubDate>Thu, 19 Nov 2020 14:48:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2021-010 — Endress+Hauser: products utilizing WPA2 vulnerable to KRACK attacks</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2021-010</link>
      <description>&lt;p&gt;Endress+Hauser products utilizing WPA2 are vulnerable to KRACK attacks.
Proline portfolio is a flow meter with an optional WLAN interface in the display. The flowmeters are only affected if the optional WLAN display is present.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Endress+Hauser products utilizing WPA2 are vulnerable to KRACK attacks.
Proline portfolio is a flow meter with an optional WLAN interface in the display. The flowmeters are only affected if the optional WLAN display is present.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2021-010</guid>
      <pubDate>Tue, 18 May 2021 09:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2021-040 — Endress+Hauser: Promass 83 with EtherNet/IP affected by a stack-based buffer overflow</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2021-040</link>
      <description>&lt;p&gt;Promass 83 devices utilizing 499ES EtherNet/IP (ENIP) Stack by Real Time Automation (RTA) are vulnerable to a stack-based buffer overflow.&lt;/p&gt;
&lt;p&gt;Update A, 2021-10-07:&lt;/p&gt;
&lt;p&gt;added credits
changed title from &amp;#34;ENDRESS+HAUSER: Promass 83 with Ether/IP affected by DoS vulnerability&amp;#34; to &amp;#34;ENDRESS+HAUSER: Promass 83 with EtherNet/IP affected by a stack-based buffer overflow&amp;#34;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Promass 83 devices utilizing 499ES EtherNet/IP (ENIP) Stack by Real Time Automation (RTA) are vulnerable to a stack-based buffer overflow.&lt;/p&gt;
&lt;p&gt;Update A, 2021-10-07:&lt;/p&gt;
&lt;p&gt;added credits
changed title from &amp;#34;ENDRESS+HAUSER: Promass 83 with Ether/IP affected by DoS vulnerability&amp;#34; to &amp;#34;ENDRESS+HAUSER: Promass 83 with EtherNet/IP affected by a stack-based buffer overflow&amp;#34;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2021-040</guid>
      <pubDate>Mon, 04 Oct 2021 12:30:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2020-022 — Endress+Hauser: Ecograph T utilizing Webserver firmware version 2.x exposes sensitive information</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2020-022</link>
      <description>&lt;p&gt;The firmware release has a dynamic token for each request submitted to the server, which makes repeating requests and analysis complex enough. Nevertheless, it&amp;#39;s possible and during the analysis it was discovered that it also has an issue with the access-control matrix on the server-side.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The firmware release has a dynamic token for each request submitted to the server, which makes repeating requests and analysis complex enough. Nevertheless, it&amp;#39;s possible and during the analysis it was discovered that it also has an issue with the access-control matrix on the server-side.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2020-022</guid>
      <pubDate>Thu, 19 Nov 2020 14:48:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2020-031 — Endress+Hauser: Multiple products prone to WIBU CodeMeter vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2020-031</link>
      <description>&lt;p&gt;For further Information please refer to WIBU Advisories directly at https://wibu.com/support/security-advisories.html and the aforementioned CVE-IDs.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;For further Information please refer to WIBU Advisories directly at https://wibu.com/support/security-advisories.html and the aforementioned CVE-IDs.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2020-031</guid>
      <pubDate>Tue, 27 Oct 2020 13:10:00 +0000</pubDate>
    </item>
  </channel>
</rss>
