<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from csaf_sick</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 14:44:47 +0000</lastBuildDate>
    <item>
      <title>sca-2026-0013 — Vulnerabilities Affecting SICK CorivaEngine</title>
      <link>https://cve.radiocsirt.org/vuln/sca-2026-0013</link>
      <description>&lt;p&gt;Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ab attacker can force WebSocket upgrade via the lax V07 (or V08) handshaker by sending `Sec-WebSocket-Version: 7` and omitting `Connection: Upgrade` / `Upgrade: websocket` headers, completing a protocol switch that a proxy would not recognize as an Upgrade request and enabling HTTP request smuggling / protocol-confusion attacks. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final. Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, `HttpContentEncoder` (the superclass of the production handler `HttpContentCompressor`) maintains a per-channel `ArrayDeque&amp;lt;CharSequence&amp;gt;` named `acceptEncodingQueue` that accumulates attacker-controlled data without any size limit. The queue is filled on the I/O thread for every inbound HTTP request and drained only when the application later writes a non-1xx response. This creates a resource exhaustion vulnerability when an attacker exploits HTTP/1.1 pipelining to flood the connection with requests faster than the application produces responses. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final. Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies in certain configuration scenarios. This affects both the WebMVC and WebFlux Gateway Servers. Affected versions: Spring Cloud Gatewa…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ab attacker can force WebSocket upgrade via the lax V07 (or V08) handshaker by sending `Sec-WebSocket-Version: 7` and omitting `Connection: Upgrade` / `Upgrade: websocket` headers, completing a protocol switch that a proxy would not recognize as an Upgrade request and enabling HTTP request smuggling / protocol-confusion attacks. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final. Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, `HttpContentEncoder` (the superclass of the production handler `HttpContentCompressor`) maintains a per-channel `ArrayDeque&amp;lt;CharSequence&amp;gt;` named `acceptEncodingQueue` that accumulates attacker-controlled data without any size limit. The queue is filled on the I/O thread for every inbound HTTP request and drained only when the application later writes a non-1xx response. This creates a resource exhaustion vulnerability when an attacker exploits HTTP/1.1 pipelining to flood the connection with requests faster than the application produces responses. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final. Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies in certain configuration scenarios. This affects both the WebMVC and WebFlux Gateway Servers. Affected versions: Spring Cloud Gatewa…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sca-2026-0013</guid>
      <pubDate>Fri, 11 Sep 2026 16:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SCA-2026-0012 — Vulnerability Affecting Sentio Creator Extension 'Device Manager'</title>
      <link>https://cve.radiocsirt.org/vuln/sca-2026-0012</link>
      <description>&lt;p&gt;An attacker may achieve arbitrary code execution on a target system by uploading a malicious device driver package, bypassing driver verification mechanisms, and triggering the execution of attacker-controlled code. User interaction is required.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An attacker may achieve arbitrary code execution on a target system by uploading a malicious device driver package, bypassing driver verification mechanisms, and triggering the execution of attacker-controlled code. User interaction is required.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sca-2026-0012</guid>
      <pubDate>Fri, 11 Sep 2026 15:53:00 +0000</pubDate>
    </item>
    <item>
      <title>sca-2026-0011 — Vulnerabilities in Wibu Systems CodeMeter Runtime Affect Multiple SICK Products</title>
      <link>https://cve.radiocsirt.org/vuln/sca-2026-0011</link>
      <description>&lt;p&gt;cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-Stick. The directory and file paths are not properly checked for NTFS reparse points, such as junctions or symbolic links, before file operations are performed. A local attacker can create a junction at the temporary file that points to an arbitrary system path. Because CodeMeter Runtime runs with System privileges, this could allow arbitrary files to be deleted with System privileges and potentially enable local privilege escalation. If CodeMeter Runtime is configured as a server, the configuration command handler does not enforce network-origin restrictions. Commands intended only for local or same-network clients can therefore be executed by arbitrary remote peers. An attacker can read potentially sensitive configuration data and overwrite selected values in Server.ini. This does include the hash of the credentials for the CodeMeter WebAdmin, enabling WebAdmin takeover. The logger does not sanitize input strings in certain cases, allowing an attacker to inject printf-style format specifiers. This can be used to reliably crash CodeMeter and disclose sensitive information such as process memory and stack canaries. The attack works locally, for example by using cmu --set-proxy to set the proxy value, and remotely when combined with CVE‑2026‑81573 by setting General.ProxyServer and then triggering this vulnerability. If configured as a server, CodeMeter Runtime accepts requests with opcode 0x5e, wh…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-Stick. The directory and file paths are not properly checked for NTFS reparse points, such as junctions or symbolic links, before file operations are performed. A local attacker can create a junction at the temporary file that points to an arbitrary system path. Because CodeMeter Runtime runs with System privileges, this could allow arbitrary files to be deleted with System privileges and potentially enable local privilege escalation. If CodeMeter Runtime is configured as a server, the configuration command handler does not enforce network-origin restrictions. Commands intended only for local or same-network clients can therefore be executed by arbitrary remote peers. An attacker can read potentially sensitive configuration data and overwrite selected values in Server.ini. This does include the hash of the credentials for the CodeMeter WebAdmin, enabling WebAdmin takeover. The logger does not sanitize input strings in certain cases, allowing an attacker to inject printf-style format specifiers. This can be used to reliably crash CodeMeter and disclose sensitive information such as process memory and stack canaries. The attack works locally, for example by using cmu --set-proxy to set the proxy value, and remotely when combined with CVE‑2026‑81573 by setting General.ProxyServer and then triggering this vulnerability. If configured as a server, CodeMeter Runtime accepts requests with opcode 0x5e, wh…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sca-2026-0011</guid>
      <pubDate>Fri, 04 Sep 2026 13:00:00 +0000</pubDate>
    </item>
    <item>
      <title>sca-2026-0010 — AppEngine vulnerability affects SICK ICR890-4 and SICK InspectorP6xx devices</title>
      <link>https://cve.radiocsirt.org/vuln/sca-2026-0010</link>
      <description>&lt;p&gt;A vulnerability has been identified in the SOPAS FileSystemAccess method that allows unintended remote access to internal virtual filesystem paths. Due to insufficient access restrictions, an attacker with network access can query and modify internal storage locations, configuration files, and system-related application directories. This exposure may lead to the Denial of Service, unauthorized change of device configuration or disclosure of sensitive system information that could facilitate further attacks or compromise of the device.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability has been identified in the SOPAS FileSystemAccess method that allows unintended remote access to internal virtual filesystem paths. Due to insufficient access restrictions, an attacker with network access can query and modify internal storage locations, configuration files, and system-related application directories. This exposure may lead to the Denial of Service, unauthorized change of device configuration or disclosure of sensitive system information that could facilitate further attacks or compromise of the device.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sca-2026-0010</guid>
      <pubDate>Mon, 24 Aug 2026 13:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SCA-2026-0009 — Vulnerability in several Endress+Hauser products</title>
      <link>https://cve.radiocsirt.org/vuln/sca-2026-0009</link>
      <description>&lt;p&gt;A vulnerability was discovered in several Endress+Hauser products that can be accessed via ethernet.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was discovered in several Endress+Hauser products that can be accessed via ethernet.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sca-2026-0009</guid>
      <pubDate>Thu, 16 Jul 2026 13:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SCA-2026-0008 — Vulnerability Affecting SICK Sentio Creator Extension “Software Deployment Manager”</title>
      <link>https://cve.radiocsirt.org/vuln/sca-2026-0008</link>
      <description>&lt;p&gt;Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions 3.3.5, 3.4.4, and 4.2.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This issue has been patched in versions 3.3.5, 3.4.4, and 4.2.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions 3.3.5, 3.4.4, and 4.2.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This issue has been patched in versions 3.3.5, 3.4.4, and 4.2.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sca-2026-0008</guid>
      <pubDate>Fri, 10 Jul 2026 13:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SCA-2026-0007 — Sudo vulnerability affects Endress+Hauser MCS200HW</title>
      <link>https://cve.radiocsirt.org/vuln/sca-2026-0007</link>
      <description>&lt;p&gt;The display unit of the Endress+Hauser MCS200HW is affected by a sudo chroot vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The display unit of the Endress+Hauser MCS200HW is affected by a sudo chroot vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sca-2026-0007</guid>
      <pubDate>Tue, 21 Apr 2026 13:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SCA-2026-0006 — Vulnerabilities affecting SICK Lector85x and SICK Lector83x</title>
      <link>https://cve.radiocsirt.org/vuln/sca-2026-0006</link>
      <description>&lt;p&gt;An attacker may access restricted filesystem areas on the device via the CROWN REST interface due to incomplete whitelist enforcement. Certain directories intended for internal testing were not covered by the whitelist and are accessible without authentication. An unauthenticated attacker could place a manipulated parameter file that becomes active after a reboot, allowing modification of critical device settings, including network configuration and application parameters. An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed through the HTTP-based file access feature, allowing access without authentication. This includes device parameter files, enabling an attacker to read and modify application settings, including customer-defined passwords. Additionally, exposure of the custom application directory may allow execution of arbitrary Lua code within the sandboxed AppEngine environment.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An attacker may access restricted filesystem areas on the device via the CROWN REST interface due to incomplete whitelist enforcement. Certain directories intended for internal testing were not covered by the whitelist and are accessible without authentication. An unauthenticated attacker could place a manipulated parameter file that becomes active after a reboot, allowing modification of critical device settings, including network configuration and application parameters. An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed through the HTTP-based file access feature, allowing access without authentication. This includes device parameter files, enabling an attacker to read and modify application settings, including customer-defined passwords. Additionally, exposure of the custom application directory may allow execution of arbitrary Lua code within the sandboxed AppEngine environment.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sca-2026-0006</guid>
      <pubDate>Fri, 06 Mar 2026 14:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SCA-2026-0005 — Vulnerabilities affecting SICK LMS1000 and SICK MRS1000</title>
      <link>https://cve.radiocsirt.org/vuln/sca-2026-0005</link>
      <description>&lt;p&gt;An attacker may exploit the use of weak CBC-based cipher suites in the device’s SSH service to potentially observe or manipulate parts of the encrypted SSH communication, if they are able to intercept or interact with the network traffic. An attacker may exploit the use of outdated and weak MAC algorithms in the device’s SSH service to potentially compromise the integrity of the SSH session, allowing manipulation of transmitted data if the attacker can interact with the network traffic.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An attacker may exploit the use of weak CBC-based cipher suites in the device’s SSH service to potentially observe or manipulate parts of the encrypted SSH communication, if they are able to intercept or interact with the network traffic. An attacker may exploit the use of outdated and weak MAC algorithms in the device’s SSH service to potentially compromise the integrity of the SSH session, allowing manipulation of transmitted data if the attacker can interact with the network traffic.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sca-2026-0005</guid>
      <pubDate>Fri, 27 Feb 2026 14:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SCA-2026-0004 — Eclipse Cyclone DDS Vulnerabilities have no impact on SICK picoScan150 &amp; SICK picoScan120 products</title>
      <link>https://cve.radiocsirt.org/vuln/sca-2026-0004</link>
      <description>&lt;p&gt;An attacker can arbitrarily craft malicious DDS Participants (or ROS 2 Nodes) with valid certificates to compromise and get full control of the attacked secure DDS databus system by exploiting vulnerable attributes in the configuration of PKCS#7 certificate’s validation. This is caused by a non-compliant implementation of permission document verification used by some DDS vendors. Specifically, an improper use of the OpenSSL PKCS7_verify function used to validate S/MIME signatures. Improper verification of the time certificate in Eclipse Cyclone DDS before v0.10.5 allows attackers to bypass certificate checks and execute commands with System privileges.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An attacker can arbitrarily craft malicious DDS Participants (or ROS 2 Nodes) with valid certificates to compromise and get full control of the attacked secure DDS databus system by exploiting vulnerable attributes in the configuration of PKCS#7 certificate’s validation. This is caused by a non-compliant implementation of permission document verification used by some DDS vendors. Specifically, an improper use of the OpenSSL PKCS7_verify function used to validate S/MIME signatures. Improper verification of the time certificate in Eclipse Cyclone DDS before v0.10.5 allows attackers to bypass certificate checks and execute commands with System privileges.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sca-2026-0004</guid>
      <pubDate>Fri, 13 Feb 2026 14:00:00 +0000</pubDate>
    </item>
  </channel>
</rss>
