<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from csaf_mieleciekg</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 07:10:28 +0000</lastBuildDate>
    <item>
      <title>VDE-2019-010 — Miele: Multiple Vulnerabilities in XGW 3000 ZigBee Gateway</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2019-010</link>
      <description>&lt;p&gt;Miele XGW 3000 is a ZigBee-TCP/IP gateway. The gateway connects Miele ZigBee-Appliances (called Miele@home) with local customer TCP/IP-Network and allows visualizing the appliance state on the web interface of the gateway, Miele SuperVision capable appliance, smartphone/tablet app or home automatization device.&lt;/p&gt;
&lt;p&gt;An external security researcher reported two vulnerabilities in XGW 3000 gateway and provided a Proof-of-Concept. The combined exploitation of both vulnerabilities allow the circumvention of the authentication mechanisms of the XGW3000.&lt;/p&gt;
&lt;p&gt;The Miele PSIRT managed to reproduce the findings and successfully exploited the gateway. Therefore, the existence of all vulnerabilities has been confirmed.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Miele XGW 3000 is a ZigBee-TCP/IP gateway. The gateway connects Miele ZigBee-Appliances (called Miele@home) with local customer TCP/IP-Network and allows visualizing the appliance state on the web interface of the gateway, Miele SuperVision capable appliance, smartphone/tablet app or home automatization device.&lt;/p&gt;
&lt;p&gt;An external security researcher reported two vulnerabilities in XGW 3000 gateway and provided a Proof-of-Concept. The combined exploitation of both vulnerabilities allow the circumvention of the authentication mechanisms of the XGW3000.&lt;/p&gt;
&lt;p&gt;The Miele PSIRT managed to reproduce the findings and successfully exploited the gateway. Therefore, the existence of all vulnerabilities has been confirmed.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2019-010</guid>
      <pubDate>Mon, 20 May 2019 06:58:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2020-024 — Miele: Treck TCP/IP Vulnerabilities (Ripple20) affecting Communication Module XKM3000 L MED</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2020-024</link>
      <description>&lt;p&gt;For process data documentation purposes the laboratory washers, thermal disinfectors and washer-disinfectors can be integrated in a TCP/IP network by utilizing the affected communication module.&lt;/p&gt;
&lt;p&gt;The communication module is separate from the actual device control and uses a chipset from Digi International.&lt;/p&gt;
&lt;p&gt;The TCP / IP stack required for networking is implemented in this chipset with the help of a 3rd party library from Treck. External security researchers have identified several security holes in this library called Ripple20. The most critical vulnerability allows an external attacker to execute arbitrary code on the chip and thus also on the communication module.&lt;/p&gt;
&lt;p&gt;The above named communication module can be integrated into the following laboratory washers, thermal disinfectors and washer- disinfectors:&lt;/p&gt;
&lt;p&gt;- PG 8581
- PG 8582
- PG 8583
- PG 8583 CD
- PG 8591
- PG 8582 CD
- PG 8592
- PG 8593
- PG 8562&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;For process data documentation purposes the laboratory washers, thermal disinfectors and washer-disinfectors can be integrated in a TCP/IP network by utilizing the affected communication module.&lt;/p&gt;
&lt;p&gt;The communication module is separate from the actual device control and uses a chipset from Digi International.&lt;/p&gt;
&lt;p&gt;The TCP / IP stack required for networking is implemented in this chipset with the help of a 3rd party library from Treck. External security researchers have identified several security holes in this library called Ripple20. The most critical vulnerability allows an external attacker to execute arbitrary code on the chip and thus also on the communication module.&lt;/p&gt;
&lt;p&gt;The above named communication module can be integrated into the following laboratory washers, thermal disinfectors and washer- disinfectors:&lt;/p&gt;
&lt;p&gt;- PG 8581
- PG 8582
- PG 8583
- PG 8583 CD
- PG 8591
- PG 8582 CD
- PG 8592
- PG 8593
- PG 8562&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2020-024</guid>
      <pubDate>Wed, 08 Jul 2020 07:29:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2022-052 — Miele: Vulnerability in ease2pay cloud service used by appWash</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2022-052</link>
      <description>&lt;p&gt;Up until October 5th, 2022 the ease2pay API used by Miele&amp;#39;s &amp;#34;AppWash&amp;#34; MobileApp was vulnerable to an authorization bypass. A low privileged, remote attacker would have been able to gain read and partial write access to other users data by modifying a small part of a HTTP request sent to the API. Reading or changing the password of another user was not possible, thus no impact to Availability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Up until October 5th, 2022 the ease2pay API used by Miele&amp;#39;s &amp;#34;AppWash&amp;#34; MobileApp was vulnerable to an authorization bypass. A low privileged, remote attacker would have been able to gain read and partial write access to other users data by modifying a small part of a HTTP request sent to the API. Reading or changing the password of another user was not possible, thus no impact to Availability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2022-052</guid>
      <pubDate>Mon, 21 Nov 2022 09:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2022-015 — Miele: Security vulnerability in Benchmark Programming Tool</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2022-015</link>
      <description>&lt;p&gt;The Miele Benchmark Programming Tool on a Microsoft Windows operating system, selects a folder by default upon installation that is writable for all users (C:\\MIELE_SERVICE). After the installation of the tool, users without administrative privileges are able to exchange or delete executable files in this path.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Miele Benchmark Programming Tool on a Microsoft Windows operating system, selects a folder by default upon installation that is writable for all users (C:\\MIELE_SERVICE). After the installation of the tool, users without administrative privileges are able to exchange or delete executable files in this path.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2022-015</guid>
      <pubDate>Wed, 27 Apr 2022 12:00:00 +0000</pubDate>
    </item>
  </channel>
</rss>
