<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from csaf_lenzese</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 11:27:58 +0000</lastBuildDate>
    <item>
      <title>VDE-2021-048 — Lenze: Multiple Vulnerabilities in CODESYS Control V2 communication</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2021-048</link>
      <description>&lt;p&gt;The affected products contain a CODESYS Control runtime system in version V2. They are therefore affected by the
vulnerability described in CODESYS Advisory 2021-06. It provides a communication server for the communication with clients like the CODESYS Development System.&lt;/p&gt;
&lt;p&gt;The 9400 servo inverters is only affected if the communication Path via the inserted EtherNet Module E94AYCEN on slot MXI1 or MXI2 is used. If the Module E94AYCEN is used, the following Versions are affected.&lt;/p&gt;
&lt;p&gt;Product Identification: E94xSHxxx (Single Drive, High Line)
Product Identification: E94xMHxxx (Multi Drive, High Line)&lt;/p&gt;
&lt;p&gt;Remark: If the product identification of your 9400 product does not fit to the above mentioned identification, please contact Lenze at Security.de@Lenze.com.&lt;/p&gt;
&lt;p&gt;The Versions P (power supply module) and R (regenerative power supply module) are not affected. Furthermore, the Variant P (PLC) and the Variant S (StateLine) are not affected. The communication paths via the diagnostic interface X6, the system bus (CAN) X1 or the field buses (other than the named Ethernet module) that can be plugged into the module slots MXI1 or MXI2 are not affected.&lt;/p&gt;
&lt;p&gt;The focus is therefore on 9400 servo inverters with the product-identification E94x{S/M}{H}... with a plugged in Ethernet module E94AYCEN... in module slot MXI1 or MXI2 and communication with the Engineer-Tools via exactly this channel.&lt;/p&gt;
&lt;p&gt;In addition to the standard tool Engineer, there is also a special Version of the PLC Designer (Version 0.x)…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The affected products contain a CODESYS Control runtime system in version V2. They are therefore affected by the
vulnerability described in CODESYS Advisory 2021-06. It provides a communication server for the communication with clients like the CODESYS Development System.&lt;/p&gt;
&lt;p&gt;The 9400 servo inverters is only affected if the communication Path via the inserted EtherNet Module E94AYCEN on slot MXI1 or MXI2 is used. If the Module E94AYCEN is used, the following Versions are affected.&lt;/p&gt;
&lt;p&gt;Product Identification: E94xSHxxx (Single Drive, High Line)
Product Identification: E94xMHxxx (Multi Drive, High Line)&lt;/p&gt;
&lt;p&gt;Remark: If the product identification of your 9400 product does not fit to the above mentioned identification, please contact Lenze at Security.de@Lenze.com.&lt;/p&gt;
&lt;p&gt;The Versions P (power supply module) and R (regenerative power supply module) are not affected. Furthermore, the Variant P (PLC) and the Variant S (StateLine) are not affected. The communication paths via the diagnostic interface X6, the system bus (CAN) X1 or the field buses (other than the named Ethernet module) that can be plugged into the module slots MXI1 or MXI2 are not affected.&lt;/p&gt;
&lt;p&gt;The focus is therefore on 9400 servo inverters with the product-identification E94x{S/M}{H}... with a plugged in Ethernet module E94AYCEN... in module slot MXI1 or MXI2 and communication with the Engineer-Tools via exactly this channel.&lt;/p&gt;
&lt;p&gt;In addition to the standard tool Engineer, there is also a special Version of the PLC Designer (Version 0.x)…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2021-048</guid>
      <pubDate>Mon, 04 Oct 2021 12:33:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2022-030 — Lenze: Vulnerability in the OPC-UA authentification connection in the firmware</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2022-030</link>
      <description>&lt;p&gt;The machine controller of the cabinet series include an OPC-UA server which uses an user management to authenticate clients via anonymous or user/password authentication. If the user/password authentication is selected, password verification is skipped upon second login. As a result, cases occur in which users can establish communication without correct authentication. This vulnerability is not located in the OPC-UA protocol or server, but in the interface to the products firmware.&lt;/p&gt;
&lt;p&gt;This Security Advisory is only relevant for the following use cases:&lt;/p&gt;
&lt;p&gt;• the user management has been activated on the machine controller (is deactivated by default)&lt;/p&gt;
&lt;p&gt;• the OPC-UA Server is used&lt;/p&gt;
&lt;p&gt;• Data are transferred via a symbol configuration (is not available by default)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The machine controller of the cabinet series include an OPC-UA server which uses an user management to authenticate clients via anonymous or user/password authentication. If the user/password authentication is selected, password verification is skipped upon second login. As a result, cases occur in which users can establish communication without correct authentication. This vulnerability is not located in the OPC-UA protocol or server, but in the interface to the products firmware.&lt;/p&gt;
&lt;p&gt;This Security Advisory is only relevant for the following use cases:&lt;/p&gt;
&lt;p&gt;• the user management has been activated on the machine controller (is deactivated by default)&lt;/p&gt;
&lt;p&gt;• the OPC-UA Server is used&lt;/p&gt;
&lt;p&gt;• Data are transferred via a symbol configuration (is not available by default)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2022-030</guid>
      <pubDate>Mon, 11 Jul 2022 10:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2024-053 — Lenze: Install Directory with insufficient permissions</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2024-053</link>
      <description>&lt;p&gt;The following tools:
* VisiWinNET Smart
* VisiWinNET Professional
* EASY UI Designer   
create a directory with insufficient permissions, allowing a low-level user the ability to add and modify certain files that hold SYSTEM privileges, which could lead to privilege escalation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The following tools:
* VisiWinNET Smart
* VisiWinNET Professional
* EASY UI Designer   
create a directory with insufficient permissions, allowing a low-level user the ability to add and modify certain files that hold SYSTEM privileges, which could lead to privilege escalation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2024-053</guid>
      <pubDate>Tue, 03 Sep 2024 08:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2025-042 — Lenze: VPN Client Privilege Escalation in combination with Lenze x500 IoT Gateway</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2025-042</link>
      <description>&lt;p&gt;IXON VPN Client before 1.4.4 on Linux and macOS allows Local Privilege Escalation to root because there is code execution from a configuration file that can be controlled by a low-privileged user. There is a race condition in which a temporary configuration file, in a world-writable directory, can be overwritten.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;IXON VPN Client before 1.4.4 on Linux and macOS allows Local Privilege Escalation to root because there is code execution from a configuration file that can be controlled by a low-privileged user. There is a race condition in which a temporary configuration file, in a world-writable directory, can be overwritten.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2025-042</guid>
      <pubDate>Tue, 27 May 2025 09:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2025-043 — Lenze: PLC Designer V4 with insecure storage of sensitive information</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2025-043</link>
      <description>&lt;p&gt;A security vulnerability was discovered in the PLC Designer V4 in the version 4.0.0 where the programmer of a Controller can set a password for the connected device. Here it is possible in an interface of the PLC Designer V4 for the programmer to enter a password for the Device. There is a special constellation where the password entered appears in plain text. Only the display in the tool is affected and not the management of the password on the device. This vulnerability of PLC Designer V4 only occurs in combination with the devices c430 controller, c520 controller and c550 controller and not in combination with other devices, as this functionality is only used here. It is generally recommended that all users update to 4.0.1, but especially all users who operate PLC Designer V4 in combination with the controllers mentioned.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A security vulnerability was discovered in the PLC Designer V4 in the version 4.0.0 where the programmer of a Controller can set a password for the connected device. Here it is possible in an interface of the PLC Designer V4 for the programmer to enter a password for the Device. There is a special constellation where the password entered appears in plain text. Only the display in the tool is affected and not the management of the password on the device. This vulnerability of PLC Designer V4 only occurs in combination with the devices c430 controller, c520 controller and c550 controller and not in combination with other devices, as this functionality is only used here. It is generally recommended that all users update to 4.0.1, but especially all users who operate PLC Designer V4 in combination with the controllers mentioned.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2025-043</guid>
      <pubDate>Wed, 25 Jun 2025 10:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2026-077 — Lenze: Incorrect signature validation in the enable SSH routine</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2026-077</link>
      <description>&lt;p&gt;The affected products belong to the Controller or Servo Drive product family and contain a vulnerability in a security-critical activation mechanism for service access. The signature verification of a file used for SSH activation can be compromised, which could allow unauthorized access to the device.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The affected products belong to the Controller or Servo Drive product family and contain a vulnerability in a security-critical activation mechanism for service access. The signature verification of a file used for SSH activation can be compromised, which could allow unauthorized access to the device.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2026-077</guid>
      <pubDate>Mon, 27 Jul 2026 10:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2026-089 — Lenze: VPN Client Remote Code Execution in combination with Lenze x500 IoT Gateway</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2026-089</link>
      <description>&lt;p&gt;The Lenze VPN client is vulnerable to a Remote Code Execution. The vulnerability would allow an attacker to perform a remote code execution on the computer running the client with elevated privileges.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Lenze VPN client is vulnerable to a Remote Code Execution. The vulnerability would allow an attacker to perform a remote code execution on the computer running the client with elevated privileges.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2026-089</guid>
      <pubDate>Mon, 21 Sep 2026 16:00:00 +0000</pubDate>
    </item>
  </channel>
</rss>
