<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from csaf_endresshauserag</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 08:00:48 +0000</lastBuildDate>
    <item>
      <title>VDE-2026-065 — Endress+Hauser: iDTM Debug Interface Vulnerability in the FDI Package Library</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2026-065</link>
      <description>&lt;p&gt;A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the debug interface by placing a crafted file in the application directory.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the debug interface by placing a crafted file in the application directory.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2026-065</guid>
      <pubDate>Mon, 03 Aug 2026 07:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2026-045 — Endress+Hauser: Multiple products affected by SopasET interface vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2026-045</link>
      <description>&lt;p&gt;A vulnerability was discovered in several Endress+Hauser products that can be accessed via ethernet.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was discovered in several Endress+Hauser products that can be accessed via ethernet.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2026-045</guid>
      <pubDate>Thu, 16 Jul 2026 10:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2026-032 — Endress+Hauser: sudo vulnerability affects Endress+Hauser MCS200HW</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2026-032</link>
      <description>&lt;p&gt;The display unit of the Endress+Hauser MCS200HW is affected by a sudo chroot vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The display unit of the Endress+Hauser MCS200HW is affected by a sudo chroot vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2026-032</guid>
      <pubDate>Tue, 21 Apr 2026 07:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2025-107 — Endress+Hauser: Multiple products affected by Qualcomm vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2025-107</link>
      <description>&lt;p&gt;Multiple vulnerabilities in a Qualcomm component have been reported in a closed-source report. This component is an integral part of the radio chip found in several Endress+Hauser products.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities in a Qualcomm component have been reported in a closed-source report. This component is an integral part of the radio chip found in several Endress+Hauser products.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2025-107</guid>
      <pubDate>Fri, 05 Dec 2025 11:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2026-003 — Endress+Hauser: Multiple products prone to multiple vulnerabilities in e!Runtime and CODESYS V3 Runtime</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2026-003</link>
      <description>&lt;p&gt;Multiple Endress+Hauser devices are prone to vulnerabilities found in e!Runtime and the CODESYS V3 framework.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple Endress+Hauser devices are prone to vulnerabilities found in e!Runtime and the CODESYS V3 framework.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2026-003</guid>
      <pubDate>Tue, 31 Mar 2026 08:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2026-002 — Endress+Hauser: buffer overflow in glibc ld.so leading to privilege escalation</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2026-002</link>
      <description>&lt;p&gt;A vulnerability has been identified in WAGO devices utilized in Endress+Hauser IoT solutions. WAGO has provided fixes for these vulnerabilities, which have been integrated into the solutions by Endress+Hauser.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability has been identified in WAGO devices utilized in Endress+Hauser IoT solutions. WAGO has provided fixes for these vulnerabilities, which have been integrated into the solutions by Endress+Hauser.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2026-002</guid>
      <pubDate>Mon, 02 Mar 2026 07:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2025-068 — Endress+Hauser: Proline 10 Maintenance credentials may be exposed under certain conditions</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2025-068</link>
      <description>&lt;p&gt;A privilege escalation vulnerability has been identified in Endress+Hauser&amp;#39;s Proline 10 devices. This flaw allows an authenticated user with Operator-level access to elevate their privileges and gain Maintenance-level access, potentially enabling unauthorized configuration changes.&lt;/p&gt;
&lt;p&gt;Endress+Hauser has released a security update addressing this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A privilege escalation vulnerability has been identified in Endress+Hauser&amp;#39;s Proline 10 devices. This flaw allows an authenticated user with Operator-level access to elevate their privileges and gain Maintenance-level access, potentially enabling unauthorized configuration changes.&lt;/p&gt;
&lt;p&gt;Endress+Hauser has released a security update addressing this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2025-068</guid>
      <pubDate>Tue, 02 Sep 2025 10:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2025-105 — Endress+Hauser: Multiple products affected by Wibu-Systems CodeMeter Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2025-105</link>
      <description>&lt;p&gt;A vulnerability in Wibu-Systems CodeMeter (up to version 7.60b) affects multiple Endress+Hauser products. This flaw can lead to a heap buffer overflow, which may allow remote code execution under certain conditions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in Wibu-Systems CodeMeter (up to version 7.60b) affects multiple Endress+Hauser products. This flaw can lead to a heap buffer overflow, which may allow remote code execution under certain conditions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2025-105</guid>
      <pubDate>Mon, 08 Dec 2025 09:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2024-054 — Endress+Hauser: Netilion Network Insights is affected by multiple vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2024-054</link>
      <description>&lt;p&gt;Several vulnerabilities have been identified in the web-based management of WAGO devices utilized in
Endress+Hauser IoT solutions. WAGO has provided fixes for these vulnerabilities, which have been
integrated into the solutions by Endress+Hauser. Additionally, a guideline on secure operation of these
solutions has been made available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Several vulnerabilities have been identified in the web-based management of WAGO devices utilized in
Endress+Hauser IoT solutions. WAGO has provided fixes for these vulnerabilities, which have been
integrated into the solutions by Endress+Hauser. Additionally, a guideline on secure operation of these
solutions has been made available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2024-054</guid>
      <pubDate>Mon, 21 Oct 2024 08:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2021-044 — Endress+Hauser: Multiple products affected by log4net vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2021-044</link>
      <description>&lt;p&gt;Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2021-044</guid>
      <pubDate>Thu, 20 Jan 2022 08:06:00 +0000</pubDate>
    </item>
  </channel>
</rss>
