<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/csaf_lenzese/10</id>
  <title>Most recent entries from csaf_lenzese</title>
  <updated>2026-10-02T14:48:40.601292+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2021-048</id>
    <title>VDE-2021-048 — Lenze: Multiple Vulnerabilities in CODESYS Control V2 communication</title>
    <updated>2021-10-04T12:33:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>The affected products contain a CODESYS Control runtime system in version V2. They are therefore affected by the
vulnerability described in CODESYS Advisory 2021-06. It provides a communication server for the communication with clients like the CODESYS Development System.</p>
<p>The 9400 servo inverters is only affected if the communication Path via the inserted EtherNet Module E94AYCEN on slot MXI1 or MXI2 is used. If the Module E94AYCEN is used, the following Versions are affected.</p>
<p>Product Identification: E94xSHxxx (Single Drive, High Line)
Product Identification: E94xMHxxx (Multi Drive, High Line)</p>
<p>Remark: If the product identification of your 9400 product does not fit to the above mentioned identification, please contact Lenze at Security.de@Lenze.com.</p>
<p>The Versions P (power supply module) and R (regenerative power supply module) are not affected. Furthermore, the Variant P (PLC) and the Variant S (StateLine) are not affected. The communication paths via the diagnostic interface X6, the system bus (CAN) X1 or the field buses (other than the named Ethernet module) that can be plugged into the module slots MXI1 or MXI2 are not affected.</p>
<p>The focus is therefore on 9400 servo inverters with the product-identification E94x{S/M}{H}... with a plugged in Ethernet module E94AYCEN... in module slot MXI1 or MXI2 and communication with the Engineer-Tools via exactly this channel.</p>
<p>In addition to the standard tool Engineer, there is also a special Version of the PLC Designer (Version 0.x)…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2021-048"/>
    <published>2021-10-04T12:33:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2022-030</id>
    <title>VDE-2022-030 — Lenze: Vulnerability in the OPC-UA authentification connection in the firmware</title>
    <updated>2022-07-11T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>The machine controller of the cabinet series include an OPC-UA server which uses an user management to authenticate clients via anonymous or user/password authentication. If the user/password authentication is selected, password verification is skipped upon second login. As a result, cases occur in which users can establish communication without correct authentication. This vulnerability is not located in the OPC-UA protocol or server, but in the interface to the products firmware.</p>
<p>This Security Advisory is only relevant for the following use cases:</p>
<p>• the user management has been activated on the machine controller (is deactivated by default)</p>
<p>• the OPC-UA Server is used</p>
<p>• Data are transferred via a symbol configuration (is not available by default)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2022-030"/>
    <published>2022-07-11T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-053</id>
    <title>VDE-2024-053 — Lenze: Install Directory with insufficient permissions</title>
    <updated>2025-03-13T11:30:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The following tools:
* VisiWinNET Smart
* VisiWinNET Professional
* EASY UI Designer   
create a directory with insufficient permissions, allowing a low-level user the ability to add and modify certain files that hold SYSTEM privileges, which could lead to privilege escalation.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-053"/>
    <published>2024-09-03T08:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2025-042</id>
    <title>VDE-2025-042 — Lenze: VPN Client Privilege Escalation in combination with Lenze x500 IoT Gateway</title>
    <updated>2025-05-27T09:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>IXON VPN Client before 1.4.4 on Linux and macOS allows Local Privilege Escalation to root because there is code execution from a configuration file that can be controlled by a low-privileged user. There is a race condition in which a temporary configuration file, in a world-writable directory, can be overwritten.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2025-042"/>
    <published>2025-05-27T09:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2025-043</id>
    <title>VDE-2025-043 — Lenze: PLC Designer V4 with insecure storage of sensitive information</title>
    <updated>2025-06-25T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A security vulnerability was discovered in the PLC Designer V4 in the version 4.0.0 where the programmer of a Controller can set a password for the connected device. Here it is possible in an interface of the PLC Designer V4 for the programmer to enter a password for the Device. There is a special constellation where the password entered appears in plain text. Only the display in the tool is affected and not the management of the password on the device. This vulnerability of PLC Designer V4 only occurs in combination with the devices c430 controller, c520 controller and c550 controller and not in combination with other devices, as this functionality is only used here. It is generally recommended that all users update to 4.0.1, but especially all users who operate PLC Designer V4 in combination with the controllers mentioned.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2025-043"/>
    <published>2025-06-25T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2026-077</id>
    <title>VDE-2026-077 — Lenze: Incorrect signature validation in the enable SSH routine</title>
    <updated>2026-07-27T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The affected products belong to the Controller or Servo Drive product family and contain a vulnerability in a security-critical activation mechanism for service access. The signature verification of a file used for SSH activation can be compromised, which could allow unauthorized access to the device.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2026-077"/>
    <published>2026-07-27T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2026-089</id>
    <title>VDE-2026-089 — Lenze: VPN Client Remote Code Execution in combination with Lenze x500 IoT Gateway</title>
    <updated>2026-09-21T16:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Lenze VPN client is vulnerable to a Remote Code Execution. The vulnerability would allow an attacker to perform a remote code execution on the computer running the client with elevated privileges.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2026-089"/>
    <published>2026-09-21T16:00:00+00:00</published>
  </entry>
</feed>
