<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from csaf_pilzgmbhcokg</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 00:52:22 +0000</lastBuildDate>
    <item>
      <title>VDE-2020-033 — Pilz: Multiple products prone to WIBU-SYSTEMS CodeMeter vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2020-033</link>
      <description>&lt;p&gt;A number of Pilz software tools use the Software CodeMeter Runtime application from WIBU-SYSTEMS AG to manage licences. This application contains a number of vulnerabilities, which enable an attacker to change and falsify a licence file, prevent normal operation of Code- Meter (Denial-of-Service) and potentially execute arbitrary code.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A number of Pilz software tools use the Software CodeMeter Runtime application from WIBU-SYSTEMS AG to manage licences. This application contains a number of vulnerabilities, which enable an attacker to change and falsify a licence file, prevent normal operation of Code- Meter (Denial-of-Service) and potentially execute arbitrary code.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2020-033</guid>
      <pubDate>Thu, 10 Sep 2020 13:18:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2021-009 — Pilz: Multiple products prone to Niche Ethernet Stack vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2021-009</link>
      <description>&lt;p&gt;Multiple products of PILZ utilise a third-party TCP/IP implementation - the &amp;#34;Niche Ethernet Stack&amp;#34;. This TCP/IP stack contains multiple vulnerabilities which are therefore affecting the products listed above.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple products of PILZ utilise a third-party TCP/IP implementation - the &amp;#34;Niche Ethernet Stack&amp;#34;. This TCP/IP stack contains multiple vulnerabilities which are therefore affecting the products listed above.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2021-009</guid>
      <pubDate>Mon, 20 Sep 2021 11:56:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2021-054 — Pilz: Multiple vulnerabilities in CODESYS V2 and V3 runtime system</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2021-054</link>
      <description>&lt;p&gt;Several Pilz products use Versions V2 and V3 of the CODESYS runtime system from CODESYS GmbH, which enables the execution of IEC 61131-3 PLC programs. These runtime environments contain several vulnerabilities, which an attacker can exploit via the network. Successful exploitation of the vulnerabilities results in reduced availability and, in a worst case, to the insertion of program code.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Several Pilz products use Versions V2 and V3 of the CODESYS runtime system from CODESYS GmbH, which enables the execution of IEC 61131-3 PLC programs. These runtime environments contain several vulnerabilities, which an attacker can exploit via the network. Successful exploitation of the vulnerabilities results in reduced availability and, in a worst case, to the insertion of program code.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2021-054</guid>
      <pubDate>Tue, 26 Apr 2022 10:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2021-055 — Pilz: PMC programming tool 2.x.x affected by multiple vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2021-055</link>
      <description>&lt;p&gt;The software product PMC programming tool from Pilz is based on the software CODESYS Development System from CODESYS GmbH. This software is affected by several vulnerabilities, which an attacker can exploit locally or via the network. This means that, in a worst case, attackers could execute arbitrary program code on the PC on which the PMC programming tool is used.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The software product PMC programming tool from Pilz is based on the software CODESYS Development System from CODESYS GmbH. This software is affected by several vulnerabilities, which an attacker can exploit locally or via the network. This means that, in a worst case, attackers could execute arbitrary program code on the PC on which the PMC programming tool is used.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2021-055</guid>
      <pubDate>Tue, 26 Apr 2022 10:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2021-061 — Pilz: PMC programming tool 3.x.x affected by multiple vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2021-061</link>
      <description>&lt;p&gt;The software product PMC programming tool from Pilz is based on the software CODESYS Development System from CODESYS GmbH. This software is affected by several vulnerabilities, which an attacker can exploit locally or via the network. This means that, in a worst case, attackers could execute arbitrary program code on the PC on which the PMC programming tool is used.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The software product PMC programming tool from Pilz is based on the software CODESYS Development System from CODESYS GmbH. This software is affected by several vulnerabilities, which an attacker can exploit locally or via the network. This means that, in a worst case, attackers could execute arbitrary program code on the PC on which the PMC programming tool is used.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2021-061</guid>
      <pubDate>Tue, 26 Apr 2022 10:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2022-033 — Pilz: PASvisu and PMI affected by multiple vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2022-033</link>
      <description>&lt;p&gt;PASvisu is an HMI solution for Machine Visualization. It is available as a standalone software product, but it is also included in various models of the PMI product family. The PASvisu Server component contains multiple vulnerabilities which can be utilised to write arbitrary files, potentially leading to code execution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;PASvisu is an HMI solution for Machine Visualization. It is available as a standalone software product, but it is also included in various models of the PMI product family. The PASvisu Server component contains multiple vulnerabilities which can be utilised to write arbitrary files, potentially leading to code execution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2022-033</guid>
      <pubDate>Thu, 24 Nov 2022 09:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2022-044 — Pilz: Multiple products affected by ZipSlip</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2022-044</link>
      <description>&lt;p&gt;Several Pilz software products do not properly check pathnames contained in archives. An attacker can utilise this vulnerability to write arbitrary files, potentially leading to code execution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Several Pilz software products do not properly check pathnames contained in archives. An attacker can utilise this vulnerability to write arbitrary files, potentially leading to code execution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2022-044</guid>
      <pubDate>Thu, 24 Nov 2022 09:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2022-045 — Pilz: PAS 4000 prone to ZipSlip</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2022-045</link>
      <description>&lt;p&gt;PAS4000 is the software platform for the Automation System PSS 4000. PAS 4000 does not properly check pathnames contained in archives. An attacker can utilise this vulnerability to write arbitrary files, potentially leading to code execution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;PAS4000 is the software platform for the Automation System PSS 4000. PAS 4000 does not properly check pathnames contained in archives. An attacker can utilise this vulnerability to write arbitrary files, potentially leading to code execution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2022-045</guid>
      <pubDate>Thu, 24 Nov 2022 09:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2023-033 — Pilz: WIBU Vulnerabilitiy in multiple Products</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2023-033</link>
      <description>&lt;p&gt;Several Pilz products use the 3rd party component &amp;#34;CodeMeter Runtime&amp;#34; from WIBU-SYSTEM AG to manage software licenses. This component is affected by a vulnerability, which may enable an attacker to gain full control over the system running the software product. The vulnerability can be exploited locally or over the network.&lt;/p&gt;
&lt;p&gt;Update A, 2023-12-05&lt;/p&gt;
&lt;p&gt;changed affected version of &amp;#34;Software PASvisu &amp;lt; 1.15.0&amp;#34; to &amp;#34;Software PASvisu &amp;lt; 1.14.1&amp;#34;
removed CVE-2023-4701 because it was revoked.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Several Pilz products use the 3rd party component &amp;#34;CodeMeter Runtime&amp;#34; from WIBU-SYSTEM AG to manage software licenses. This component is affected by a vulnerability, which may enable an attacker to gain full control over the system running the software product. The vulnerability can be exploited locally or over the network.&lt;/p&gt;
&lt;p&gt;Update A, 2023-12-05&lt;/p&gt;
&lt;p&gt;changed affected version of &amp;#34;Software PASvisu &amp;lt; 1.15.0&amp;#34; to &amp;#34;Software PASvisu &amp;lt; 1.14.1&amp;#34;
removed CVE-2023-4701 because it was revoked.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2023-033</guid>
      <pubDate>Thu, 12 Oct 2023 06:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2023-048 — Pilz: Multiple products prone to libwebp vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2023-048</link>
      <description>&lt;p&gt;Several Pilz products use the 3rd-party component &amp;#39;libwebp&amp;#39; for decoding of images in WebP format. This component is affected by a vulnerability, which may enable an attacker to gain full control over the system running the software product. Depending on the affected product, the vulnerabilities can be exploited locally or over the network.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Several Pilz products use the 3rd-party component &amp;#39;libwebp&amp;#39; for decoding of images in WebP format. This component is affected by a vulnerability, which may enable an attacker to gain full control over the system running the software product. Depending on the affected product, the vulnerabilities can be exploited locally or over the network.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2023-048</guid>
      <pubDate>Tue, 05 Dec 2023 07:00:00 +0000</pubDate>
    </item>
  </channel>
</rss>
