<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from csaf_pilzgmbhcokg</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 07:11:49 +0000</lastBuildDate>
    <item>
      <title>PPSA-2026-003 — Pilz: Multiple Vulnerabilities affecting industrial PC IndustrialPI</title>
      <link>https://cve.radiocsirt.org/vuln/ppsa-2026-003</link>
      <description>&lt;p&gt;The Linux kernel used in the IndustrialPI, &amp;#39;linux-image-revpi-v8&amp;#39;, prior to version 6.12.91-revpi0-rpi-v8 contains multiple vulnerabilities. Successful exploitation of these vulnerabilities can give an attacker full control over the device.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Linux kernel used in the IndustrialPI, &amp;#39;linux-image-revpi-v8&amp;#39;, prior to version 6.12.91-revpi0-rpi-v8 contains multiple vulnerabilities. Successful exploitation of these vulnerabilities can give an attacker full control over the device.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ppsa-2026-003</guid>
      <pubDate>Tue, 04 Aug 2026 10:00:00 +0000</pubDate>
    </item>
    <item>
      <title>PPSA-2026-002 — Pilz: Vulnerability affecting PASvisu Runtime</title>
      <link>https://cve.radiocsirt.org/vuln/ppsa-2026-002</link>
      <description>&lt;p&gt;The PASvisu Runtime is affected by a vulnerability in a third-party component which can be exploited by malicious web requests.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The PASvisu Runtime is affected by a vulnerability in a third-party component which can be exploited by malicious web requests.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ppsa-2026-002</guid>
      <pubDate>Thu, 23 Apr 2026 12:00:00 +0000</pubDate>
    </item>
    <item>
      <title>PPSA-2026-001 — Pilz: Multiple Vulnerabilities affecting the PIT User Authentication Service</title>
      <link>https://cve.radiocsirt.org/vuln/ppsa-2026-001</link>
      <description>&lt;p&gt;**PIT User Authentication Service is part of the operating mode selection and access permission system PITmode.** The PIT User Authentication Service is affected by multiple vulnerabilities in included third-party components.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;**PIT User Authentication Service is part of the operating mode selection and access permission system PITmode.** The PIT User Authentication Service is affected by multiple vulnerabilities in included third-party components.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ppsa-2026-001</guid>
      <pubDate>Mon, 02 Feb 2026 08:00:00 +0000</pubDate>
    </item>
    <item>
      <title>PPSA-2025-004 — Pilz: Vulnerability affecting PASvisu Runtime</title>
      <link>https://cve.radiocsirt.org/vuln/ppsa-2025-004</link>
      <description>&lt;p&gt;The PASvisu Runtime is affected by a vulnerability in a third-party component which can be exploited by a malicious web request.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The PASvisu Runtime is affected by a vulnerability in a third-party component which can be exploited by a malicious web request.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ppsa-2025-004</guid>
      <pubDate>Mon, 20 Oct 2025 10:00:00 +0000</pubDate>
    </item>
    <item>
      <title>PPSA-2025-003 — Pilz: Authentication Bypass in IndustrialPI Webstatus</title>
      <link>https://cve.radiocsirt.org/vuln/ppsa-2025-003</link>
      <description>&lt;p&gt;The Pilz industrial PC IndustrialPI webstatus application is vulnerable to an authentication bypass.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Pilz industrial PC IndustrialPI webstatus application is vulnerable to an authentication bypass.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ppsa-2025-003</guid>
      <pubDate>Tue, 01 Jul 2025 10:00:00 +0000</pubDate>
    </item>
    <item>
      <title>PPSA-2025-002 — Pilz: Missing Authentication in Node-RED integration</title>
      <link>https://cve.radiocsirt.org/vuln/ppsa-2025-002</link>
      <description>&lt;p&gt;Authentication is not configured by default for the Node-RED server on the Pilz industrial PC IndustrialPI. An unauthenticated remote attacker has full access to the Node-RED server and can run arbitrary operating system commands on the underlying operating system with privileged rights.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Authentication is not configured by default for the Node-RED server on the Pilz industrial PC IndustrialPI. An unauthenticated remote attacker has full access to the Node-RED server and can run arbitrary operating system commands on the underlying operating system with privileged rights.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ppsa-2025-002</guid>
      <pubDate>Tue, 01 Jul 2025 10:00:00 +0000</pubDate>
    </item>
    <item>
      <title>PPSA-2025-001 — Pilz: Authentication Bypass and Cross-Site-Scripting in PiCtory</title>
      <link>https://cve.radiocsirt.org/vuln/ppsa-2025-001</link>
      <description>&lt;p&gt;PiCtory, a web application to configure the Pilz industrial PC IndustrialPI, has three vulnerabilities with varying degrees of severity. The first two are of critical severity and can lead to a bypass of authentication and a cross-site-scripting attack. The third vulnerability with medium severity puts PiCtory at a risk of a reflected cross-site-scripting attack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;PiCtory, a web application to configure the Pilz industrial PC IndustrialPI, has three vulnerabilities with varying degrees of severity. The first two are of critical severity and can lead to a bypass of authentication and a cross-site-scripting attack. The third vulnerability with medium severity puts PiCtory at a risk of a reflected cross-site-scripting attack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ppsa-2025-001</guid>
      <pubDate>Mon, 30 Jun 2025 10:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2022-044 — Pilz: Multiple products affected by ZipSlip</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2022-044</link>
      <description>&lt;p&gt;Several Pilz software products do not properly check pathnames contained in archives. An attacker can utilise this vulnerability to write arbitrary files, potentially leading to code execution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Several Pilz software products do not properly check pathnames contained in archives. An attacker can utilise this vulnerability to write arbitrary files, potentially leading to code execution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2022-044</guid>
      <pubDate>Thu, 24 Nov 2022 09:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2023-048 — Pilz: Multiple products prone to libwebp vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2023-048</link>
      <description>&lt;p&gt;Several Pilz products use the 3rd-party component &amp;#39;libwebp&amp;#39; for decoding of images in WebP format. This component is affected by a vulnerability, which may enable an attacker to gain full control over the system running the software product. Depending on the affected product, the vulnerabilities can be exploited locally or over the network.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Several Pilz products use the 3rd-party component &amp;#39;libwebp&amp;#39; for decoding of images in WebP format. This component is affected by a vulnerability, which may enable an attacker to gain full control over the system running the software product. Depending on the affected product, the vulnerabilities can be exploited locally or over the network.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2023-048</guid>
      <pubDate>Tue, 05 Dec 2023 07:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2023-033 — Pilz: WIBU Vulnerabilitiy in multiple Products</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2023-033</link>
      <description>&lt;p&gt;Several Pilz products use the 3rd party component &amp;#34;CodeMeter Runtime&amp;#34; from WIBU-SYSTEM AG to manage software licenses. This component is affected by a vulnerability, which may enable an attacker to gain full control over the system running the software product. The vulnerability can be exploited locally or over the network.&lt;/p&gt;
&lt;p&gt;Update A, 2023-12-05&lt;/p&gt;
&lt;p&gt;changed affected version of &amp;#34;Software PASvisu &amp;lt; 1.15.0&amp;#34; to &amp;#34;Software PASvisu &amp;lt; 1.14.1&amp;#34;
removed CVE-2023-4701 because it was revoked.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Several Pilz products use the 3rd party component &amp;#34;CodeMeter Runtime&amp;#34; from WIBU-SYSTEM AG to manage software licenses. This component is affected by a vulnerability, which may enable an attacker to gain full control over the system running the software product. The vulnerability can be exploited locally or over the network.&lt;/p&gt;
&lt;p&gt;Update A, 2023-12-05&lt;/p&gt;
&lt;p&gt;changed affected version of &amp;#34;Software PASvisu &amp;lt; 1.15.0&amp;#34; to &amp;#34;Software PASvisu &amp;lt; 1.14.1&amp;#34;
removed CVE-2023-4701 because it was revoked.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2023-033</guid>
      <pubDate>Thu, 12 Oct 2023 06:00:00 +0000</pubDate>
    </item>
  </channel>
</rss>
