<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/csaf_pepperlfuchsse/10</id>
  <title>Most recent entries from csaf_pepperlfuchsse</title>
  <updated>2026-10-02T09:43:16.774563+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2018-008</id>
    <title>VDE-2018-008 — Pepperl+Fuchs: Remote Code Execution Vulnerability in HMI Devices</title>
    <updated>2018-07-06T13:37:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A remote code execution vulnerability in the Microsoft's Credential Security Support Provider protocol (CredSSP) was identified by security researchers. If exploited successfully, it is possible to relay user credentials for arbitrary code execution on the target system.
See details on Microsoft Advisory CVE-2018-0866 (https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2018-0886)</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2018-008"/>
    <published>2018-07-06T13:37:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2017-005</id>
    <title>VDE-2017-005 — Pepperl+Fuchs / ecom instruments: WLAN enabled products utilizing WPA2 encryption</title>
    <updated>2018-10-23T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multiple security issues and vulnerabilities within the WPA2 standard have been identified and publicized by Mr. Mathy Vanhoef of KU Leuven. These vulnerabilities may allow the reinstallation of a pairwise transient key, a group key, or an integrity key on either a wireless client or a wireless access point (AP). In consequence, an attacker could establish a man-in-the-middle position between AP and client facilitating packet decryption and injection.  
  
ecom instruments is a subsidiary company of PEPPERL+FUCHS.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2017-005"/>
    <published>2017-12-11T13:26:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2018-009</id>
    <title>VDE-2018-009 — Pepperl+Fuchs: Security advisory for MELTDOWN and SPECTRE attacks in ecom mobile Devices</title>
    <updated>2018-10-23T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Critical vulnerabilities within several CPUs have been identified by security researchers. These hardware vulnerabilities allow programs to learn about the contents of a system's memory, using side-channel attacks. Potential attack vectors against these vulnerabilities have been published and dubbed Meltdown and Spectre.</p>
<p>While programs are typically not permitted to read data from the OS kernel or from other programs, a malicious program can exploit Meltdown and Spectre to get hold of secrets stored in kernel memory or the memory of other programs executed on the same CPU.</p>
<p>As a consequence, an exploit could allow attackers to get access to any sensitive data, including passwords or cryptographic keys.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2018-009"/>
    <published>2018-07-06T14:47:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2019-004</id>
    <title>VDE-2019-004 — Pepperl+Fuchs: ecom Mobile Devices prone to BlueBorne Attack</title>
    <updated>2019-03-14T07:52:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A collection of Bluetooth attack vectors were discovered and related vulnerabilities known as "BlueBorne" were disclosed. These vulnerabilities collectively endanger amongst others Windows, Linux and mobile operating systems like Android or IOS. An unauthenticated attacker may take control of devices and perform commands or access sensitive data.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2019-004"/>
    <published>2019-03-14T07:52:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2019-011</id>
    <title>VDE-2019-011 — Pepperl+Fuchs: Remote code execution vulnerability in HMI devices</title>
    <updated>2019-10-07T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>A remote code execution vulnerability exists in **Remote Desktop Services** – formerly known as **Terminal Services** – when an unauthenticated attacker connects to the target system using **RDP** and sends specially crafted requests.  
This vulnerability is **pre-authentication** and requires **no user interaction**.  
An attacker who successfully exploits this vulnerability could execute arbitrary code on the target system.</p>
<p>To exploit this vulnerability, an attacker would need to send a specially crafted request to the target system's Remote Desktop Service via **RDP**.</p>
<p>### Microsoft Advisories</p>
<p>- [CVE-2019-0708](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708)
- [CVE-2019-1181](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1181)
- [CVE-2019-1182](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1182)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2019-011"/>
    <published>2019-05-29T07:35:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2020-034</id>
    <title>VDE-2020-034 — Pepperl+Fuchs: VMT MSS and VMT IS - Several vulnerabilities in products utilizing WIBU-SYSTEMS CodeMeter components</title>
    <updated>2020-09-10T13:22:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Several vulnerabilities have been discovered in the utilized component WIBU-SYSTEMS CodeMeter Runtime.
For detailed information please refer to WIBU-SYSTEMS original Advisories at https://wibu.com/support/security-advisories.html</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2020-034"/>
    <published>2020-09-10T13:22:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2020-040</id>
    <title>VDE-2020-040 — Pepperl+Fuchs: Multiple Products prone to multiple vulnerabilities in Comtrol RocketLinux</title>
    <updated>2020-10-05T12:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Active TFTP-Service Unauthenticated Device Administration Undocumented Accounts Unauthenticated Device Administration Multiple Authenticated Command Injections</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2020-040"/>
    <published>2020-10-05T12:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2021-018</id>
    <title>VDE-2021-018 — Pepperl+Fuchs: Multiple vulnerabilites in ICE1 Ethernet IO Modules</title>
    <updated>2021-05-12T08:57:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Critical vulnerability has been discovered in the utilized components rcX, mbedTLS, PROFINET IO Device and EtherNet/IP Core by Hilscher Gesellschaft für Systemautomation mbH.
The impact of the vulnerabilities on the affected device is that it can result in:
* Denial of Service (DoS)
* Remote Code Execution (RCE)
* Code Exposure</p>
<p>**Note:**
ICE1-8IOL-S2-G60L-V1D (70103603) is not affected by CVE-2021-20986</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2021-018"/>
    <published>2021-05-12T08:57:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2021-034</id>
    <title>VDE-2021-034 — Pepperl+Fuchs: Security Advisory for PrintNightmare Vulnerability in multiple HMI Devices</title>
    <updated>2021-07-30T07:55:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
See details on Microsoft Advisory CVE-2021-34527 (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527)</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2021-034"/>
    <published>2021-07-30T07:55:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2022-012</id>
    <title>VDE-2022-012 — Pepperl+Fuchs: Vulnerability in multiple VisuNet devices</title>
    <updated>2022-05-16T14:15:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Critical vulnerabilities have been discovered in the utilized component Remote Desktop Client by Microsoft.For more information see: https://msrc.microsoft.com/update-guide/vulnerability/CVE- 2022-21990</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2022-012"/>
    <published>2022-04-26T12:00:00+00:00</published>
  </entry>
</feed>
