<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/csaf_pepperlfuchsse/10</id>
  <title>Most recent entries from csaf_pepperlfuchsse</title>
  <updated>2026-10-02T07:59:38.554098+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2026-014</id>
    <title>VDE-2026-014 — Pepperl+Fuchs: ICE2-* and ICE3-* are affected by multiple security vulnerabilities</title>
    <updated>2026-09-16T08:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The affected devices have security vulnerabilities that can be used to bypass authentication. Code can be executed on the devices through command injection and local file inclusion. Path traversal and modified schemata can be used to read sensitive information such as password hashes or private keys from the devices.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2026-014"/>
    <published>2026-09-16T08:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-017</id>
    <title>VDE-2024-017 — Pepperl+Fuchs: ICE2- * and ICE3- * are affected by multiple vulnerabilities</title>
    <updated>2026-05-18T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Critical vulnerabilities have been discovered in the product due to outdated software components.The impact of the vulnerabilities on the affected device may result in</p>
<p>Denial of service
Bypassing of authentication
Information disclosure</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-017"/>
    <published>2024-04-10T06:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2025-011</id>
    <title>VDE-2025-011 — PEPPERL+FUCHS: Profinet Gateway LB8122A.1.EL – Device is affected by XSS vulnerability and information disclosure</title>
    <updated>2025-08-27T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A stored cross-site scripting vulnerability has been discovered in the profinet gateway LB8122A.1.EL. An attacker can write an HTML tag with up to 32 characters in the message field of a HART transmitter. The HTML tag is interpreted as HTML when the HART information is displayed in a webbrowser. If the HTML tag contains a link to a manipulated page, a user can be tricked into accessing this page.
Furthermore, an attacker can access information about running processes via the SNMP protocol. Sending such SNMP read commands can also trigger a reboot.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2025-011"/>
    <published>2025-05-26T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-038</id>
    <title>VDE-2024-038 — Pepperl+Fuchs: Anonymous FTP server and Telnet access allows information disclosure and manipulation</title>
    <updated>2025-08-27T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Critical vulnerabilities has been discovered in the product, mainly caused by ananonymous FTP server and Telnet access.The impact of the vulnerabilities on the affected device may result in</p>
<p>Information disclosure
Denial of service
Device manipulation</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-038"/>
    <published>2024-07-10T06:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2025-002</id>
    <title>VDE-2025-002 — PEPPERL+FUCHS: HMI – devices are affected by Windows RCE</title>
    <updated>2025-05-22T13:03:10+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An unauthenticated attacker could repeatedly send IPv6 packets, that include specially crafted packets, to a Windows machine which could enable remote code execution.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2025-002"/>
    <published>2025-02-25T11:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2022-021</id>
    <title>VDE-2022-021 — Pepperl+Fuchs: RSM-EX devices - Multiple Bluetooth vulnerabilities</title>
    <updated>2025-05-22T13:03:10+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (participating in the provisioning protocol) to identify the AuthValue used given the Provisioner's public key, and the confirmation number and nonce provided by the provisioning device. This could permit a device without the AuthValue to complete provisioning without brute-forcing the AuthValue. Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, reflecting the authentication evidence from a Provisioner, to complete authentication without possessing the AuthValue, and potentially acquire a NetKey and AppKey. Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (without possession of the AuthValue used in the provisioning protocol) to determine the AuthValue via a brute-force attack (unless the AuthValue is sufficiently random and changed each time). Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, able to conduct a successful brute-force attack on an insufficiently random AuthValue before the provisioning procedure times out, to complete authentication by leveraging Malleable Commitment. Bluetooth legacy BR/EDR PIN code pairing in Bluetooth Core Specification 1.0B through 5.2 may permit an unauthenticated nearby device to spoof the BD_ADDR of the peer device to complete pairing without knowledge of the PIN. Bluetooth LE and BR/EDR secure pairing in Bluet…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2022-021"/>
    <published>2022-05-16T14:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2021-041</id>
    <title>VDE-2021-041 — Pepperl+Fuchs: Multiple DTM and VisuNet Software affected by log4net vulnerability</title>
    <updated>2025-05-22T13:03:10+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Critical vulnerabilities have been discovered in the utilized component log4net by Apache Software Foundation.</p>
<p>UPDATE A: Remediation: added fixed VisuNet Products</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2021-041"/>
    <published>2021-10-26T13:35:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2020-053</id>
    <title>VDE-2020-053 — Pepperl+Fuchs: Comtrol RocketLinx ICRL-M - Multiple Vulnerabilities</title>
    <updated>2025-05-22T13:03:10+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Several critical vulnerabilities within firmware.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2020-053"/>
    <published>2021-03-08T13:44:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2020-017</id>
    <title>VDE-2020-017 — Pepperl+Fuchs, PACTware: Two password vulnerabilities found</title>
    <updated>2025-05-22T13:03:10+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>PACTware passwords are stored in a recoverable format (CVE-2020-9403)</p>
<p>PACTware passwords may be modified without knowing the current password (CVE-2020-9404)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2020-017"/>
    <published>2020-05-29T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-033</id>
    <title>VDE-2024-033 — PEPPERL+FUCHS: Device Master ICDM-RX/* – Vulnerability may allow unauthenticated remote attacker information disclosure…</title>
    <updated>2025-05-14T14:34:17+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Vulnerabilities have been discovered in the product, mainly caused by HTML injection and crosssite-scripting.  
The impact of the vulnerability on the affected device may result in an information disclosure and denial of service.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-033"/>
    <published>2024-08-13T12:00:00+00:00</published>
  </entry>
</feed>
