<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from csaf_pepperlfuchsse</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 16:16:37 +0000</lastBuildDate>
    <item>
      <title>VDE-2017-005 — Pepperl+Fuchs / ecom instruments: WLAN enabled products utilizing WPA2 encryption</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2017-005</link>
      <description>&lt;p&gt;Multiple security issues and vulnerabilities within the WPA2 standard have been identified and publicized by Mr. Mathy Vanhoef of KU Leuven. These vulnerabilities may allow the reinstallation of a pairwise transient key, a group key, or an integrity key on either a wireless client or a wireless access point (AP). In consequence, an attacker could establish a man-in-the-middle position between AP and client facilitating packet decryption and injection.  
  
ecom instruments is a subsidiary company of PEPPERL+FUCHS.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple security issues and vulnerabilities within the WPA2 standard have been identified and publicized by Mr. Mathy Vanhoef of KU Leuven. These vulnerabilities may allow the reinstallation of a pairwise transient key, a group key, or an integrity key on either a wireless client or a wireless access point (AP). In consequence, an attacker could establish a man-in-the-middle position between AP and client facilitating packet decryption and injection.  
  
ecom instruments is a subsidiary company of PEPPERL+FUCHS.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2017-005</guid>
      <pubDate>Mon, 11 Dec 2017 13:26:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2018-002 — Pepperl+Fuchs: HMI devices vulnerable to Meltdown and Spectre Attacks</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2018-002</link>
      <description>&lt;p&gt;Critical vulnerabilities within several CPUs have been identified by security researchers. These hardware vulnerabilities allow programs to learn about the contents of a system&amp;#39;s memory, using side-channel attacks. Potential attack vectors against these vulnerabilities have been published and dubbed Meltdown and Spectre. While programs are typically not permitted to read data from the OS kernel or from other programs, a malicious program can exploit Meltdown and Spectre to get hold of secrets stored in kernel memory or the memory of other programs executed on the same CPU. As a consequence, an exploit could allow attackers to get access to any sensitive data, including passwords or cryptographic keys.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Critical vulnerabilities within several CPUs have been identified by security researchers. These hardware vulnerabilities allow programs to learn about the contents of a system&amp;#39;s memory, using side-channel attacks. Potential attack vectors against these vulnerabilities have been published and dubbed Meltdown and Spectre. While programs are typically not permitted to read data from the OS kernel or from other programs, a malicious program can exploit Meltdown and Spectre to get hold of secrets stored in kernel memory or the memory of other programs executed on the same CPU. As a consequence, an exploit could allow attackers to get access to any sensitive data, including passwords or cryptographic keys.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2018-002</guid>
      <pubDate>Wed, 14 Feb 2018 08:50:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2018-008 — Pepperl+Fuchs: Remote Code Execution Vulnerability in HMI Devices</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2018-008</link>
      <description>&lt;p&gt;A remote code execution vulnerability in the Microsoft&amp;#39;s Credential Security Support Provider protocol (CredSSP) was identified by security researchers. If exploited successfully, it is possible to relay user credentials for arbitrary code execution on the target system.
See details on Microsoft Advisory CVE-2018-0866 (https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2018-0886)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A remote code execution vulnerability in the Microsoft&amp;#39;s Credential Security Support Provider protocol (CredSSP) was identified by security researchers. If exploited successfully, it is possible to relay user credentials for arbitrary code execution on the target system.
See details on Microsoft Advisory CVE-2018-0866 (https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2018-0886)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2018-008</guid>
      <pubDate>Fri, 06 Jul 2018 13:37:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2018-009 — Pepperl+Fuchs: Security advisory for MELTDOWN and SPECTRE attacks in ecom mobile Devices</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2018-009</link>
      <description>&lt;p&gt;Critical vulnerabilities within several CPUs have been identified by security researchers. These hardware vulnerabilities allow programs to learn about the contents of a system&amp;#39;s memory, using side-channel attacks. Potential attack vectors against these vulnerabilities have been published and dubbed Meltdown and Spectre.&lt;/p&gt;
&lt;p&gt;While programs are typically not permitted to read data from the OS kernel or from other programs, a malicious program can exploit Meltdown and Spectre to get hold of secrets stored in kernel memory or the memory of other programs executed on the same CPU.&lt;/p&gt;
&lt;p&gt;As a consequence, an exploit could allow attackers to get access to any sensitive data, including passwords or cryptographic keys.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Critical vulnerabilities within several CPUs have been identified by security researchers. These hardware vulnerabilities allow programs to learn about the contents of a system&amp;#39;s memory, using side-channel attacks. Potential attack vectors against these vulnerabilities have been published and dubbed Meltdown and Spectre.&lt;/p&gt;
&lt;p&gt;While programs are typically not permitted to read data from the OS kernel or from other programs, a malicious program can exploit Meltdown and Spectre to get hold of secrets stored in kernel memory or the memory of other programs executed on the same CPU.&lt;/p&gt;
&lt;p&gt;As a consequence, an exploit could allow attackers to get access to any sensitive data, including passwords or cryptographic keys.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2018-009</guid>
      <pubDate>Fri, 06 Jul 2018 14:47:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2018-016 — Pepperl+Fuchs: ecom Mobile devices prone to Android privilege elevation vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2018-016</link>
      <description>&lt;p&gt;An attacker may gain access (by elevated privileges) to CT50-Ex mobile computers through a vulnerability in a system service running the Android Operating System (OS). The system service improperly validates incoming connection requests. Although the vulnerability is significant, currently no known exploits publicly available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An attacker may gain access (by elevated privileges) to CT50-Ex mobile computers through a vulnerability in a system service running the Android Operating System (OS). The system service improperly validates incoming connection requests. Although the vulnerability is significant, currently no known exploits publicly available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2018-016</guid>
      <pubDate>Fri, 19 Oct 2018 10:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2019-002 — Pepperl+Fuchs: Path traversal in WirelessHART Gateway</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2019-002</link>
      <description>&lt;p&gt;Pepperl+Fuchs analyzed WirelessHART-Gateways in respect of a critical vulnerability within the Firmware. An attacker may exploit this vulnerability to get access to files and access restricted directories that are stored on the device by manipulating file parameters that reference these. Incoming HTTP requests using fcgi-bin/wgsetcgi and a filename parameter allow a directory / path traversal. A publicly available exploit already exists for this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Pepperl+Fuchs analyzed WirelessHART-Gateways in respect of a critical vulnerability within the Firmware. An attacker may exploit this vulnerability to get access to files and access restricted directories that are stored on the device by manipulating file parameters that reference these. Incoming HTTP requests using fcgi-bin/wgsetcgi and a filename parameter allow a directory / path traversal. A publicly available exploit already exists for this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2019-002</guid>
      <pubDate>Wed, 06 Mar 2019 10:35:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2019-004 — Pepperl+Fuchs: ecom Mobile Devices prone to BlueBorne Attack</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2019-004</link>
      <description>&lt;p&gt;A collection of Bluetooth attack vectors were discovered and related vulnerabilities known as &amp;#34;BlueBorne&amp;#34; were disclosed. These vulnerabilities collectively endanger amongst others Windows, Linux and mobile operating systems like Android or IOS. An unauthenticated attacker may take control of devices and perform commands or access sensitive data.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A collection of Bluetooth attack vectors were discovered and related vulnerabilities known as &amp;#34;BlueBorne&amp;#34; were disclosed. These vulnerabilities collectively endanger amongst others Windows, Linux and mobile operating systems like Android or IOS. An unauthenticated attacker may take control of devices and perform commands or access sensitive data.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2019-004</guid>
      <pubDate>Thu, 14 Mar 2019 07:52:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2019-011 — Pepperl+Fuchs: Remote code execution vulnerability in HMI devices</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2019-011</link>
      <description>&lt;p&gt;A remote code execution vulnerability exists in **Remote Desktop Services** – formerly known as **Terminal Services** – when an unauthenticated attacker connects to the target system using **RDP** and sends specially crafted requests.  
This vulnerability is **pre-authentication** and requires **no user interaction**.  
An attacker who successfully exploits this vulnerability could execute arbitrary code on the target system.&lt;/p&gt;
&lt;p&gt;To exploit this vulnerability, an attacker would need to send a specially crafted request to the target system&amp;#39;s Remote Desktop Service via **RDP**.&lt;/p&gt;
&lt;p&gt;### Microsoft Advisories&lt;/p&gt;
&lt;p&gt;- [CVE-2019-0708](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708)
- [CVE-2019-1181](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1181)
- [CVE-2019-1182](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1182)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A remote code execution vulnerability exists in **Remote Desktop Services** – formerly known as **Terminal Services** – when an unauthenticated attacker connects to the target system using **RDP** and sends specially crafted requests.  
This vulnerability is **pre-authentication** and requires **no user interaction**.  
An attacker who successfully exploits this vulnerability could execute arbitrary code on the target system.&lt;/p&gt;
&lt;p&gt;To exploit this vulnerability, an attacker would need to send a specially crafted request to the target system&amp;#39;s Remote Desktop Service via **RDP**.&lt;/p&gt;
&lt;p&gt;### Microsoft Advisories&lt;/p&gt;
&lt;p&gt;- [CVE-2019-0708](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708)
- [CVE-2019-1181](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1181)
- [CVE-2019-1182](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1182)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2019-011</guid>
      <pubDate>Wed, 29 May 2019 07:35:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2020-014 — Pepperl+Fuchs: Kr00k vulnerabilities in Broadcom Wi-Fi chipsets</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2020-014</link>
      <description>&lt;p&gt;Security researchers at ESET have reported a vulnerability called Kr00k (CVE-2019- 15126) which affects encrypted WiFi traffic for devices using Broadcom or Cypress chipsets. The vulnerability may allow an attacker to decrypt some WPA2- Personal/Enterprise traffic by forcing an AP/client to start utilizing an all-zero encryption key (similar to KRACK vulnerability).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security researchers at ESET have reported a vulnerability called Kr00k (CVE-2019- 15126) which affects encrypted WiFi traffic for devices using Broadcom or Cypress chipsets. The vulnerability may allow an attacker to decrypt some WPA2- Personal/Enterprise traffic by forcing an AP/client to start utilizing an all-zero encryption key (similar to KRACK vulnerability).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2020-014</guid>
      <pubDate>Tue, 31 Mar 2020 13:30:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2020-017 — Pepperl+Fuchs, PACTware: Two password vulnerabilities found</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2020-017</link>
      <description>&lt;p&gt;PACTware passwords are stored in a recoverable format (CVE-2020-9403)&lt;/p&gt;
&lt;p&gt;PACTware passwords may be modified without knowing the current password (CVE-2020-9404)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;PACTware passwords are stored in a recoverable format (CVE-2020-9403)&lt;/p&gt;
&lt;p&gt;PACTware passwords may be modified without knowing the current password (CVE-2020-9404)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2020-017</guid>
      <pubDate>Fri, 29 May 2020 10:00:00 +0000</pubDate>
    </item>
  </channel>
</rss>
