<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from csaf_pepperlfuchsse</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:32:12 +0000</lastBuildDate>
    <item>
      <title>VDE-2018-008 — Pepperl+Fuchs: Remote Code Execution Vulnerability in HMI Devices</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2018-008</link>
      <description>&lt;p&gt;A remote code execution vulnerability in the Microsoft&amp;#39;s Credential Security Support Provider protocol (CredSSP) was identified by security researchers. If exploited successfully, it is possible to relay user credentials for arbitrary code execution on the target system.
See details on Microsoft Advisory CVE-2018-0866 (https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2018-0886)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A remote code execution vulnerability in the Microsoft&amp;#39;s Credential Security Support Provider protocol (CredSSP) was identified by security researchers. If exploited successfully, it is possible to relay user credentials for arbitrary code execution on the target system.
See details on Microsoft Advisory CVE-2018-0866 (https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2018-0886)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2018-008</guid>
      <pubDate>Fri, 06 Jul 2018 13:37:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2017-005 — Pepperl+Fuchs / ecom instruments: WLAN enabled products utilizing WPA2 encryption</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2017-005</link>
      <description>&lt;p&gt;Multiple security issues and vulnerabilities within the WPA2 standard have been identified and publicized by Mr. Mathy Vanhoef of KU Leuven. These vulnerabilities may allow the reinstallation of a pairwise transient key, a group key, or an integrity key on either a wireless client or a wireless access point (AP). In consequence, an attacker could establish a man-in-the-middle position between AP and client facilitating packet decryption and injection.  
  
ecom instruments is a subsidiary company of PEPPERL+FUCHS.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple security issues and vulnerabilities within the WPA2 standard have been identified and publicized by Mr. Mathy Vanhoef of KU Leuven. These vulnerabilities may allow the reinstallation of a pairwise transient key, a group key, or an integrity key on either a wireless client or a wireless access point (AP). In consequence, an attacker could establish a man-in-the-middle position between AP and client facilitating packet decryption and injection.  
  
ecom instruments is a subsidiary company of PEPPERL+FUCHS.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2017-005</guid>
      <pubDate>Mon, 11 Dec 2017 13:26:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2018-009 — Pepperl+Fuchs: Security advisory for MELTDOWN and SPECTRE attacks in ecom mobile Devices</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2018-009</link>
      <description>&lt;p&gt;Critical vulnerabilities within several CPUs have been identified by security researchers. These hardware vulnerabilities allow programs to learn about the contents of a system&amp;#39;s memory, using side-channel attacks. Potential attack vectors against these vulnerabilities have been published and dubbed Meltdown and Spectre.&lt;/p&gt;
&lt;p&gt;While programs are typically not permitted to read data from the OS kernel or from other programs, a malicious program can exploit Meltdown and Spectre to get hold of secrets stored in kernel memory or the memory of other programs executed on the same CPU.&lt;/p&gt;
&lt;p&gt;As a consequence, an exploit could allow attackers to get access to any sensitive data, including passwords or cryptographic keys.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Critical vulnerabilities within several CPUs have been identified by security researchers. These hardware vulnerabilities allow programs to learn about the contents of a system&amp;#39;s memory, using side-channel attacks. Potential attack vectors against these vulnerabilities have been published and dubbed Meltdown and Spectre.&lt;/p&gt;
&lt;p&gt;While programs are typically not permitted to read data from the OS kernel or from other programs, a malicious program can exploit Meltdown and Spectre to get hold of secrets stored in kernel memory or the memory of other programs executed on the same CPU.&lt;/p&gt;
&lt;p&gt;As a consequence, an exploit could allow attackers to get access to any sensitive data, including passwords or cryptographic keys.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2018-009</guid>
      <pubDate>Fri, 06 Jul 2018 14:47:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2019-004 — Pepperl+Fuchs: ecom Mobile Devices prone to BlueBorne Attack</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2019-004</link>
      <description>&lt;p&gt;A collection of Bluetooth attack vectors were discovered and related vulnerabilities known as &amp;#34;BlueBorne&amp;#34; were disclosed. These vulnerabilities collectively endanger amongst others Windows, Linux and mobile operating systems like Android or IOS. An unauthenticated attacker may take control of devices and perform commands or access sensitive data.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A collection of Bluetooth attack vectors were discovered and related vulnerabilities known as &amp;#34;BlueBorne&amp;#34; were disclosed. These vulnerabilities collectively endanger amongst others Windows, Linux and mobile operating systems like Android or IOS. An unauthenticated attacker may take control of devices and perform commands or access sensitive data.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2019-004</guid>
      <pubDate>Thu, 14 Mar 2019 07:52:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2019-011 — Pepperl+Fuchs: Remote code execution vulnerability in HMI devices</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2019-011</link>
      <description>&lt;p&gt;A remote code execution vulnerability exists in **Remote Desktop Services** – formerly known as **Terminal Services** – when an unauthenticated attacker connects to the target system using **RDP** and sends specially crafted requests.  
This vulnerability is **pre-authentication** and requires **no user interaction**.  
An attacker who successfully exploits this vulnerability could execute arbitrary code on the target system.&lt;/p&gt;
&lt;p&gt;To exploit this vulnerability, an attacker would need to send a specially crafted request to the target system&amp;#39;s Remote Desktop Service via **RDP**.&lt;/p&gt;
&lt;p&gt;### Microsoft Advisories&lt;/p&gt;
&lt;p&gt;- [CVE-2019-0708](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708)
- [CVE-2019-1181](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1181)
- [CVE-2019-1182](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1182)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A remote code execution vulnerability exists in **Remote Desktop Services** – formerly known as **Terminal Services** – when an unauthenticated attacker connects to the target system using **RDP** and sends specially crafted requests.  
This vulnerability is **pre-authentication** and requires **no user interaction**.  
An attacker who successfully exploits this vulnerability could execute arbitrary code on the target system.&lt;/p&gt;
&lt;p&gt;To exploit this vulnerability, an attacker would need to send a specially crafted request to the target system&amp;#39;s Remote Desktop Service via **RDP**.&lt;/p&gt;
&lt;p&gt;### Microsoft Advisories&lt;/p&gt;
&lt;p&gt;- [CVE-2019-0708](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708)
- [CVE-2019-1181](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1181)
- [CVE-2019-1182](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1182)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2019-011</guid>
      <pubDate>Wed, 29 May 2019 07:35:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2020-034 — Pepperl+Fuchs: VMT MSS and VMT IS - Several vulnerabilities in products utilizing WIBU-SYSTEMS CodeMeter components</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2020-034</link>
      <description>&lt;p&gt;Several vulnerabilities have been discovered in the utilized component WIBU-SYSTEMS CodeMeter Runtime.
For detailed information please refer to WIBU-SYSTEMS original Advisories at https://wibu.com/support/security-advisories.html&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Several vulnerabilities have been discovered in the utilized component WIBU-SYSTEMS CodeMeter Runtime.
For detailed information please refer to WIBU-SYSTEMS original Advisories at https://wibu.com/support/security-advisories.html&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2020-034</guid>
      <pubDate>Thu, 10 Sep 2020 13:22:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2020-040 — Pepperl+Fuchs: Multiple Products prone to multiple vulnerabilities in Comtrol RocketLinux</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2020-040</link>
      <description>&lt;p&gt;Active TFTP-Service Unauthenticated Device Administration Undocumented Accounts Unauthenticated Device Administration Multiple Authenticated Command Injections&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Active TFTP-Service Unauthenticated Device Administration Undocumented Accounts Unauthenticated Device Administration Multiple Authenticated Command Injections&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2020-040</guid>
      <pubDate>Mon, 05 Oct 2020 12:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2021-018 — Pepperl+Fuchs: Multiple vulnerabilites in ICE1 Ethernet IO Modules</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2021-018</link>
      <description>&lt;p&gt;Critical vulnerability has been discovered in the utilized components rcX, mbedTLS, PROFINET IO Device and EtherNet/IP Core by Hilscher Gesellschaft für Systemautomation mbH.
The impact of the vulnerabilities on the affected device is that it can result in:
* Denial of Service (DoS)
* Remote Code Execution (RCE)
* Code Exposure&lt;/p&gt;
&lt;p&gt;**Note:**
ICE1-8IOL-S2-G60L-V1D (70103603) is not affected by CVE-2021-20986&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Critical vulnerability has been discovered in the utilized components rcX, mbedTLS, PROFINET IO Device and EtherNet/IP Core by Hilscher Gesellschaft für Systemautomation mbH.
The impact of the vulnerabilities on the affected device is that it can result in:
* Denial of Service (DoS)
* Remote Code Execution (RCE)
* Code Exposure&lt;/p&gt;
&lt;p&gt;**Note:**
ICE1-8IOL-S2-G60L-V1D (70103603) is not affected by CVE-2021-20986&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2021-018</guid>
      <pubDate>Wed, 12 May 2021 08:57:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2021-034 — Pepperl+Fuchs: Security Advisory for PrintNightmare Vulnerability in multiple HMI Devices</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2021-034</link>
      <description>&lt;p&gt;A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
See details on Microsoft Advisory CVE-2021-34527 (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
See details on Microsoft Advisory CVE-2021-34527 (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2021-034</guid>
      <pubDate>Fri, 30 Jul 2021 07:55:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2022-012 — Pepperl+Fuchs: Vulnerability in multiple VisuNet devices</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2022-012</link>
      <description>&lt;p&gt;Critical vulnerabilities have been discovered in the utilized component Remote Desktop Client by Microsoft.For more information see: https://msrc.microsoft.com/update-guide/vulnerability/CVE- 2022-21990&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Critical vulnerabilities have been discovered in the utilized component Remote Desktop Client by Microsoft.For more information see: https://msrc.microsoft.com/update-guide/vulnerability/CVE- 2022-21990&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2022-012</guid>
      <pubDate>Tue, 26 Apr 2022 12:00:00 +0000</pubDate>
    </item>
  </channel>
</rss>
