<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/csaf_pilzgmbhcokg/10</id>
  <title>Most recent entries from csaf_pilzgmbhcokg</title>
  <updated>2026-10-08T12:51:09.062788+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2020-033</id>
    <title>VDE-2020-033 — Pilz: Multiple products prone to WIBU-SYSTEMS CodeMeter vulnerabilities</title>
    <updated>2025-05-14T12:28:19+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A number of Pilz software tools use the Software CodeMeter Runtime application from WIBU-SYSTEMS AG to manage licences. This application contains a number of vulnerabilities, which enable an attacker to change and falsify a licence file, prevent normal operation of Code- Meter (Denial-of-Service) and potentially execute arbitrary code.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2020-033"/>
    <published>2020-09-10T13:18:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2021-009</id>
    <title>VDE-2021-009 — Pilz: Multiple products prone to Niche Ethernet Stack vulnerabilities</title>
    <updated>2025-05-14T13:00:14+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multiple products of PILZ utilise a third-party TCP/IP implementation - the "Niche Ethernet Stack". This TCP/IP stack contains multiple vulnerabilities which are therefore affecting the products listed above.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2021-009"/>
    <published>2021-09-20T11:56:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2021-054</id>
    <title>VDE-2021-054 — Pilz: Multiple vulnerabilities in CODESYS V2 and V3 runtime system</title>
    <updated>2022-04-26T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Several Pilz products use Versions V2 and V3 of the CODESYS runtime system from CODESYS GmbH, which enables the execution of IEC 61131-3 PLC programs. These runtime environments contain several vulnerabilities, which an attacker can exploit via the network. Successful exploitation of the vulnerabilities results in reduced availability and, in a worst case, to the insertion of program code.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2021-054"/>
    <published>2022-04-26T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2021-055</id>
    <title>VDE-2021-055 — Pilz: PMC programming tool 2.x.x affected by multiple vulnerabilities</title>
    <updated>2022-04-26T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The software product PMC programming tool from Pilz is based on the software CODESYS Development System from CODESYS GmbH. This software is affected by several vulnerabilities, which an attacker can exploit locally or via the network. This means that, in a worst case, attackers could execute arbitrary program code on the PC on which the PMC programming tool is used.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2021-055"/>
    <published>2022-04-26T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2021-061</id>
    <title>VDE-2021-061 — Pilz: PMC programming tool 3.x.x affected by multiple vulnerabilities</title>
    <updated>2022-04-26T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The software product PMC programming tool from Pilz is based on the software CODESYS Development System from CODESYS GmbH. This software is affected by several vulnerabilities, which an attacker can exploit locally or via the network. This means that, in a worst case, attackers could execute arbitrary program code on the PC on which the PMC programming tool is used.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2021-061"/>
    <published>2022-04-26T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2022-033</id>
    <title>VDE-2022-033 — Pilz: PASvisu and PMI affected by multiple vulnerabilities</title>
    <updated>2022-11-24T09:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>PASvisu is an HMI solution for Machine Visualization. It is available as a standalone software product, but it is also included in various models of the PMI product family. The PASvisu Server component contains multiple vulnerabilities which can be utilised to write arbitrary files, potentially leading to code execution.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2022-033"/>
    <published>2022-11-24T09:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2022-044</id>
    <title>VDE-2022-044 — Pilz: Multiple products affected by ZipSlip</title>
    <updated>2025-06-05T13:28:13+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Several Pilz software products do not properly check pathnames contained in archives. An attacker can utilise this vulnerability to write arbitrary files, potentially leading to code execution.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2022-044"/>
    <published>2022-11-24T09:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2022-045</id>
    <title>VDE-2022-045 — Pilz: PAS 4000 prone to ZipSlip</title>
    <updated>2025-05-22T13:03:10+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>PAS4000 is the software platform for the Automation System PSS 4000. PAS 4000 does not properly check pathnames contained in archives. An attacker can utilise this vulnerability to write arbitrary files, potentially leading to code execution.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2022-045"/>
    <published>2022-11-24T09:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2023-033</id>
    <title>VDE-2023-033 — Pilz: WIBU Vulnerabilitiy in multiple Products</title>
    <updated>2025-05-22T13:03:10+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Several Pilz products use the 3rd party component "CodeMeter Runtime" from WIBU-SYSTEM AG to manage software licenses. This component is affected by a vulnerability, which may enable an attacker to gain full control over the system running the software product. The vulnerability can be exploited locally or over the network.</p>
<p>Update A, 2023-12-05</p>
<p>changed affected version of "Software PASvisu &lt; 1.15.0" to "Software PASvisu &lt; 1.14.1"
removed CVE-2023-4701 because it was revoked.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2023-033"/>
    <published>2023-10-12T06:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2023-048</id>
    <title>VDE-2023-048 — Pilz: Multiple products prone to libwebp vulnerability</title>
    <updated>2025-05-22T13:03:10+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Several Pilz products use the 3rd-party component 'libwebp' for decoding of images in WebP format. This component is affected by a vulnerability, which may enable an attacker to gain full control over the system running the software product. Depending on the affected product, the vulnerabilities can be exploited locally or over the network.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2023-048"/>
    <published>2023-12-05T07:00:00+00:00</published>
  </entry>
</feed>
