<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/csaf_siemens/10</id>
  <title>Most recent entries from csaf_siemens</title>
  <updated>2026-10-03T13:04:36.509818+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-823812</id>
    <title>SSA-823812 — SSA-823812: Denial of Service Vulnerability in WTV676 and WTV776 devices</title>
    <updated>2026-09-16T00:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>The products listed below contain a denial of service vulnerability that could allow an attacker to force the devices into protection mode under certain conditions. This disables remote connectivity functions (Web Access) to the devices.</p>
<p>Siemens has released new versions for the affected products and recommends to update to the latest versions.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-823812"/>
    <published>2026-09-16T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-517424</id>
    <title>SSA-517424 — SSA-517424: Path Traversal Vulnerability in SIMOVE Fleetmanager and SIPLANT</title>
    <updated>2026-09-08T00:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>SIMOVE Fleetmanager and SIPLANT contain a path traversal vulnerability that could allow an attacker to access files outside of intended scope.</p>
<p>Siemens has released new versions for the affected products and recommends to update to the latest versions.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-517424"/>
    <published>2026-09-08T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-503852</id>
    <title>SSA-503852 — SSA-503852: Authentication Bypass Vulnerability in Industrial Edge Management</title>
    <updated>2026-09-08T00:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Industrial Edge Management contains an authentication bypass vulnerability that could allow an unauthenticated remote attacker to perform full account takeover by resetting user credentials without completing email verification.</p>
<p>Siemens has released new versions for the affected products and recommends to update to the latest versions.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-503852"/>
    <published>2026-09-08T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-330084</id>
    <title>SSA-330084 — SSA-330084: Client Code Execution Vulnerability in Desigo CC Product Family</title>
    <updated>2026-09-08T00:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A Client Code Execution (CCE) vulnerability has been identified in Desigo CC, potentially allowing malicious actors to execute arbitrary code on client devices through specially crafted graphics documents. This vulnerability leverages user-defined graphics containing embedded scripts that are executed on client application instances. Successful exploitation could lead to compromise of the client operating system and potential lateral movement within the organization.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-330084"/>
    <published>2026-09-08T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-328642</id>
    <title>SSA-328642 — SSA-328642: "Copy Fail" Vulnerability in Multiple Industrial Products</title>
    <updated>2026-09-08T00:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Multiple Siemens products are vulnerable to the "Copy Fail" vulnerability.</p>
<p>Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-328642"/>
    <published>2026-09-08T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-254516</id>
    <title>SSA-254516 — SSA-254516: Arbitrary File Upload in OIS Web Module</title>
    <updated>2026-09-08T00:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>A vulnerability has been identified in the Open Interface Services (OIS) web module affecting Siveillance Control and Siveillance Control Pro (versions OIS 3.x.y and OIS 4.x.y) . This vulnerability allows an attacker to upload arbitrary files, which can lead to unauthorized root-level access on the OIS server.</p>
<p>Siemens has released patches and updates for Siveillance OIS to apply to the products that incorporate the OIS service, and recommends to update to the latest versions.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-254516"/>
    <published>2026-09-08T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-157465</id>
    <title>SSA-157465 — SSA-157465: Reflected Cross-site scripting Vulnerability in Teamcenter</title>
    <updated>2026-09-08T00:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>A reflected cross site scripting vulnerability in the authentication redirect flow (/auth/) of Teamcenter allows an unauthenticated remote attacker to inject JavaScript into an authenticated user's session by crafting a malicious URL. Successful exploitation may enable the attacker to read data or perform actions within the victim's Teamcenter session.</p>
<p>Siemens has released new versions for the affected products and recommends to update to the latest versions.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-157465"/>
    <published>2026-09-08T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-142885</id>
    <title>SSA-142885 — SSA-142885: Multiple Vulnerabilities in Reyrolle 7SR5 Before V2.70</title>
    <updated>2026-09-08T00:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Siemens Reyrolle 7SR5 Before V2.70 is affected by multiple vulnerabilities.</p>
<p>Siemens has released a new version for Reyrolle 7SR5 and recommends to update to the latest version.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-142885"/>
    <published>2026-09-08T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-887643</id>
    <title>SSA-887643 — SSA-887643: Account Hijacking Vulnerability in Mendix SAML module</title>
    <updated>2026-09-03T00:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Mendix SAML module contains a vulnerability that could allow unauthenticated remote attackers to hijack an account in specific SSO configurations.</p>
<p>Mendix has provided fix releases for the Mendix SAML module and recommends to update to the latest version.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-887643"/>
    <published>2026-09-03T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-682041</id>
    <title>SSA-682041 — SSA-682041: Cross Site Scripting Vulnerability in Element Maps</title>
    <updated>2026-08-27T00:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>The si-map component does not properly neutralize user-controllable input of the points property that is used to render the tooltip label of map pins.
This could allow an attacker to craft a malicious URL that, when loaded by a victim and the map pin is hovered over, executes arbitrary script code within the victim's browser session. This vulnerability affects only the @siemens/maps-ng package.</p>
<p>Siemens has released new versions for the affected products and recommends to update to the latest versions.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-682041"/>
    <published>2026-08-27T00:00:00+00:00</published>
  </entry>
</feed>
