<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/csaf_siemens/10</id>
  <title>Most recent entries from csaf_siemens</title>
  <updated>2026-10-02T08:00:27.621865+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-627195</id>
    <title>SSA-627195 — SSA-627195: Zip Path Traversal Vulnerability in Mendix Studio Pro's Module Installation Process</title>
    <updated>2026-09-28T00:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Mendix Studio Pro contains a vulnerability in the module installation process, that could allow an attacker to write or modify arbitrary files in directories outside a developer’s project directory.</p>
<p>Siemens has released new versions for the affected products and recommends to update to the latest versions.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-627195"/>
    <published>2025-06-12T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-814963</id>
    <title>SSA-814963 — SSA-814963: Insecure Inherited Permission in Mendix (Revoked)</title>
    <updated>2026-09-22T00:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>This advisory is revoked. Re-investigation confirmed the reported behavior is expected platform configuration and does not expose the protected attribute.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-814963"/>
    <published>2026-07-14T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-823812</id>
    <title>SSA-823812 — SSA-823812: Denial of Service Vulnerability in WTV676 and WTV776 devices</title>
    <updated>2026-09-16T00:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>The products listed below contain a denial of service vulnerability that could allow an attacker to force the devices into protection mode under certain conditions. This disables remote connectivity functions (Web Access) to the devices.</p>
<p>Siemens has released new versions for the affected products and recommends to update to the latest versions.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-823812"/>
    <published>2026-09-16T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-517424</id>
    <title>SSA-517424 — SSA-517424: Path Traversal Vulnerability in SIMOVE Fleetmanager and SIPLANT</title>
    <updated>2026-09-08T00:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>SIMOVE Fleetmanager and SIPLANT contain a path traversal vulnerability that could allow an attacker to access files outside of intended scope.</p>
<p>Siemens has released new versions for the affected products and recommends to update to the latest versions.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-517424"/>
    <published>2026-09-08T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-503852</id>
    <title>SSA-503852 — SSA-503852: Authentication Bypass Vulnerability in Industrial Edge Management</title>
    <updated>2026-09-08T00:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Industrial Edge Management contains an authentication bypass vulnerability that could allow an unauthenticated remote attacker to perform full account takeover by resetting user credentials without completing email verification.</p>
<p>Siemens has released new versions for the affected products and recommends to update to the latest versions.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-503852"/>
    <published>2026-09-08T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-434797</id>
    <title>SSA-434797 — SSA-434797: Buffer Overflow Vulnerability in OpenSSL affecting Siemens Products</title>
    <updated>2026-09-08T00:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution.</p>
<p>Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-434797"/>
    <published>2026-06-09T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-331739</id>
    <title>SSA-331739 — SSA-331739: Privilege Escalation Vulnerability in WIBU CodeMeter Runtime Affecting Siemens Products</title>
    <updated>2026-09-08T00:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>WIBU Systems published information about a privilege escalation vulnerability under a certain circumstances and associated fix releases of CodeMeter Runtime, a product provided by WIBU Systems and used in several Siemens industrial products.</p>
<p>Siemens has released new versions for the affected products and recommends to update to the latest versions.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-331739"/>
    <published>2025-08-12T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-330084</id>
    <title>SSA-330084 — SSA-330084: Client Code Execution Vulnerability in Desigo CC Product Family</title>
    <updated>2026-09-08T00:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A Client Code Execution (CCE) vulnerability has been identified in Desigo CC, potentially allowing malicious actors to execute arbitrary code on client devices through specially crafted graphics documents. This vulnerability leverages user-defined graphics containing embedded scripts that are executed on client application instances. Successful exploitation could lead to compromise of the client operating system and potential lateral movement within the organization.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-330084"/>
    <published>2026-09-08T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-328642</id>
    <title>SSA-328642 — SSA-328642: "Copy Fail" Vulnerability in Multiple Industrial Products</title>
    <updated>2026-09-08T00:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Multiple Siemens products are vulnerable to the "Copy Fail" vulnerability.</p>
<p>Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-328642"/>
    <published>2026-09-08T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-327438</id>
    <title>SSA-327438 — SSA-327438: Multiple Vulnerabilities in SCALANCE LPE9403</title>
    <updated>2026-09-08T00:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>SCALANCE LPE9403 is affected by multiple vulnerabilities which lead to a compromise in availability, integrity and confidentiality.</p>
<p>Siemens has released a new version for SCALANCE LPE9403 and recommends to update to the latest version. Siemens recommends specific countermeasures for products where fixes are not, or not yet available.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-327438"/>
    <published>2025-05-13T00:00:00+00:00</published>
  </entry>
</feed>
