<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/csaf_pilzgmbhcokg/10</id>
  <title>Most recent entries from csaf_pilzgmbhcokg</title>
  <updated>2026-10-02T07:11:48.392607+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ppsa-2026-003</id>
    <title>PPSA-2026-003 — Pilz: Multiple Vulnerabilities affecting industrial PC IndustrialPI</title>
    <updated>2026-08-04T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Linux kernel used in the IndustrialPI, 'linux-image-revpi-v8', prior to version 6.12.91-revpi0-rpi-v8 contains multiple vulnerabilities. Successful exploitation of these vulnerabilities can give an attacker full control over the device.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ppsa-2026-003"/>
    <published>2026-08-04T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ppsa-2026-002</id>
    <title>PPSA-2026-002 — Pilz: Vulnerability affecting PASvisu Runtime</title>
    <updated>2026-04-23T12:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The PASvisu Runtime is affected by a vulnerability in a third-party component which can be exploited by malicious web requests.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ppsa-2026-002"/>
    <published>2026-04-23T12:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ppsa-2026-001</id>
    <title>PPSA-2026-001 — Pilz: Multiple Vulnerabilities affecting the PIT User Authentication Service</title>
    <updated>2026-02-02T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>**PIT User Authentication Service is part of the operating mode selection and access permission system PITmode.** The PIT User Authentication Service is affected by multiple vulnerabilities in included third-party components.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ppsa-2026-001"/>
    <published>2026-02-02T08:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ppsa-2025-004</id>
    <title>PPSA-2025-004 — Pilz: Vulnerability affecting PASvisu Runtime</title>
    <updated>2025-10-20T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The PASvisu Runtime is affected by a vulnerability in a third-party component which can be exploited by a malicious web request.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ppsa-2025-004"/>
    <published>2025-10-20T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ppsa-2025-003</id>
    <title>PPSA-2025-003 — Pilz: Authentication Bypass in IndustrialPI Webstatus</title>
    <updated>2025-07-01T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Pilz industrial PC IndustrialPI webstatus application is vulnerable to an authentication bypass.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ppsa-2025-003"/>
    <published>2025-07-01T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ppsa-2025-002</id>
    <title>PPSA-2025-002 — Pilz: Missing Authentication in Node-RED integration</title>
    <updated>2025-07-01T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Authentication is not configured by default for the Node-RED server on the Pilz industrial PC IndustrialPI. An unauthenticated remote attacker has full access to the Node-RED server and can run arbitrary operating system commands on the underlying operating system with privileged rights.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ppsa-2025-002"/>
    <published>2025-07-01T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ppsa-2025-001</id>
    <title>PPSA-2025-001 — Pilz: Authentication Bypass and Cross-Site-Scripting in PiCtory</title>
    <updated>2025-06-30T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>PiCtory, a web application to configure the Pilz industrial PC IndustrialPI, has three vulnerabilities with varying degrees of severity. The first two are of critical severity and can lead to a bypass of authentication and a cross-site-scripting attack. The third vulnerability with medium severity puts PiCtory at a risk of a reflected cross-site-scripting attack.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ppsa-2025-001"/>
    <published>2025-06-30T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2022-044</id>
    <title>VDE-2022-044 — Pilz: Multiple products affected by ZipSlip</title>
    <updated>2025-06-05T13:28:13+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Several Pilz software products do not properly check pathnames contained in archives. An attacker can utilise this vulnerability to write arbitrary files, potentially leading to code execution.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2022-044"/>
    <published>2022-11-24T09:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2023-048</id>
    <title>VDE-2023-048 — Pilz: Multiple products prone to libwebp vulnerability</title>
    <updated>2025-05-22T13:03:10+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Several Pilz products use the 3rd-party component 'libwebp' for decoding of images in WebP format. This component is affected by a vulnerability, which may enable an attacker to gain full control over the system running the software product. Depending on the affected product, the vulnerabilities can be exploited locally or over the network.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2023-048"/>
    <published>2023-12-05T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2023-033</id>
    <title>VDE-2023-033 — Pilz: WIBU Vulnerabilitiy in multiple Products</title>
    <updated>2025-05-22T13:03:10+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Several Pilz products use the 3rd party component "CodeMeter Runtime" from WIBU-SYSTEM AG to manage software licenses. This component is affected by a vulnerability, which may enable an attacker to gain full control over the system running the software product. The vulnerability can be exploited locally or over the network.</p>
<p>Update A, 2023-12-05</p>
<p>changed affected version of "Software PASvisu &lt; 1.15.0" to "Software PASvisu &lt; 1.14.1"
removed CVE-2023-4701 because it was revoked.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2023-033"/>
    <published>2023-10-12T06:00:00+00:00</published>
  </entry>
</feed>
