<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/csaf_pilzgmbhcokg/10</id>
  <title>Most recent entries from csaf_pilzgmbhcokg</title>
  <updated>2026-10-02T09:11:19.806599+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2021-054</id>
    <title>VDE-2021-054 — Pilz: Multiple vulnerabilities in CODESYS V2 and V3 runtime system</title>
    <updated>2022-04-26T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Several Pilz products use Versions V2 and V3 of the CODESYS runtime system from CODESYS GmbH, which enables the execution of IEC 61131-3 PLC programs. These runtime environments contain several vulnerabilities, which an attacker can exploit via the network. Successful exploitation of the vulnerabilities results in reduced availability and, in a worst case, to the insertion of program code.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2021-054"/>
    <published>2022-04-26T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2021-055</id>
    <title>VDE-2021-055 — Pilz: PMC programming tool 2.x.x affected by multiple vulnerabilities</title>
    <updated>2022-04-26T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The software product PMC programming tool from Pilz is based on the software CODESYS Development System from CODESYS GmbH. This software is affected by several vulnerabilities, which an attacker can exploit locally or via the network. This means that, in a worst case, attackers could execute arbitrary program code on the PC on which the PMC programming tool is used.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2021-055"/>
    <published>2022-04-26T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2021-061</id>
    <title>VDE-2021-061 — Pilz: PMC programming tool 3.x.x affected by multiple vulnerabilities</title>
    <updated>2022-04-26T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The software product PMC programming tool from Pilz is based on the software CODESYS Development System from CODESYS GmbH. This software is affected by several vulnerabilities, which an attacker can exploit locally or via the network. This means that, in a worst case, attackers could execute arbitrary program code on the PC on which the PMC programming tool is used.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2021-061"/>
    <published>2022-04-26T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2022-033</id>
    <title>VDE-2022-033 — Pilz: PASvisu and PMI affected by multiple vulnerabilities</title>
    <updated>2022-11-24T09:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>PASvisu is an HMI solution for Machine Visualization. It is available as a standalone software product, but it is also included in various models of the PMI product family. The PASvisu Server component contains multiple vulnerabilities which can be utilised to write arbitrary files, potentially leading to code execution.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2022-033"/>
    <published>2022-11-24T09:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2023-059</id>
    <title>VDE-2023-059 — Pilz: Electron Vulnerabilities in PASvisu and PMI v8xx</title>
    <updated>2023-12-05T07:06:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Builder and Viewer components of the product PASvisu are based on the 3rd-party-component Electron. Electron contains several other open-source components which are affected by vulnerabilities. The vulnerabilities may enable an attacker to gain full control over the system. The vulnerabilities can be exploited locally or over the network.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2023-059"/>
    <published>2023-12-05T07:06:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-002</id>
    <title>VDE-2024-002 — Pilz: Multiple products affected by uC/HTTP vulnerability</title>
    <updated>2024-02-06T07:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The PITreader product family is using the 3rd -party-component uC/HTTP to implement the web server functionality. uC/HTTP is affected by multiple vulnerabilities. These vulnerabilities may enable an attacker to gain full control over the system.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-002"/>
    <published>2024-02-06T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2023-050</id>
    <title>VDE-2023-050 — Pilz: Vulnerability in PASvisu and PMI v8xx</title>
    <updated>2025-04-10T13:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Multiple Pilz products are affected by stored cross-site-scripting (XSS) vulnerabilities. The vulnerabilities may enable an attacker to gain full control over the system.</p>
<p>Update: 27.02.2024 Fix typo in advisory title</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2023-050"/>
    <published>2024-01-30T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2020-033</id>
    <title>VDE-2020-033 — Pilz: Multiple products prone to WIBU-SYSTEMS CodeMeter vulnerabilities</title>
    <updated>2025-05-14T12:28:19+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A number of Pilz software tools use the Software CodeMeter Runtime application from WIBU-SYSTEMS AG to manage licences. This application contains a number of vulnerabilities, which enable an attacker to change and falsify a licence file, prevent normal operation of Code- Meter (Denial-of-Service) and potentially execute arbitrary code.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2020-033"/>
    <published>2020-09-10T13:18:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2021-009</id>
    <title>VDE-2021-009 — Pilz: Multiple products prone to Niche Ethernet Stack vulnerabilities</title>
    <updated>2025-05-14T13:00:14+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multiple products of PILZ utilise a third-party TCP/IP implementation - the "Niche Ethernet Stack". This TCP/IP stack contains multiple vulnerabilities which are therefore affecting the products listed above.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2021-009"/>
    <published>2021-09-20T11:56:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2022-045</id>
    <title>VDE-2022-045 — Pilz: PAS 4000 prone to ZipSlip</title>
    <updated>2025-05-22T13:03:10+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>PAS4000 is the software platform for the Automation System PSS 4000. PAS 4000 does not properly check pathnames contained in archives. An attacker can utilise this vulnerability to write arbitrary files, potentially leading to code execution.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2022-045"/>
    <published>2022-11-24T09:00:00+00:00</published>
  </entry>
</feed>
