<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from csaf_siemens</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 07:10:19 +0000</lastBuildDate>
    <item>
      <title>SSA-627195 — SSA-627195: Zip Path Traversal Vulnerability in Mendix Studio Pro's Module Installation Process</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-627195</link>
      <description>&lt;p&gt;Mendix Studio Pro contains a vulnerability in the module installation process, that could allow an attacker to write or modify arbitrary files in directories outside a developer’s project directory.&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for the affected products and recommends to update to the latest versions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Mendix Studio Pro contains a vulnerability in the module installation process, that could allow an attacker to write or modify arbitrary files in directories outside a developer’s project directory.&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for the affected products and recommends to update to the latest versions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-627195</guid>
      <pubDate>Thu, 12 Jun 2025 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SSA-814963 — SSA-814963: Insecure Inherited Permission in Mendix (Revoked)</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-814963</link>
      <description>&lt;p&gt;This advisory is revoked. Re-investigation confirmed the reported behavior is expected platform configuration and does not expose the protected attribute.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;This advisory is revoked. Re-investigation confirmed the reported behavior is expected platform configuration and does not expose the protected attribute.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-814963</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SSA-823812 — SSA-823812: Denial of Service Vulnerability in WTV676 and WTV776 devices</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-823812</link>
      <description>&lt;p&gt;The products listed below contain a denial of service vulnerability that could allow an attacker to force the devices into protection mode under certain conditions. This disables remote connectivity functions (Web Access) to the devices.&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for the affected products and recommends to update to the latest versions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The products listed below contain a denial of service vulnerability that could allow an attacker to force the devices into protection mode under certain conditions. This disables remote connectivity functions (Web Access) to the devices.&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for the affected products and recommends to update to the latest versions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-823812</guid>
      <pubDate>Wed, 16 Sep 2026 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SSA-517424 — SSA-517424: Path Traversal Vulnerability in SIMOVE Fleetmanager and SIPLANT</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-517424</link>
      <description>&lt;p&gt;SIMOVE Fleetmanager and SIPLANT contain a path traversal vulnerability that could allow an attacker to access files outside of intended scope.&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for the affected products and recommends to update to the latest versions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SIMOVE Fleetmanager and SIPLANT contain a path traversal vulnerability that could allow an attacker to access files outside of intended scope.&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for the affected products and recommends to update to the latest versions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-517424</guid>
      <pubDate>Tue, 08 Sep 2026 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SSA-503852 — SSA-503852: Authentication Bypass Vulnerability in Industrial Edge Management</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-503852</link>
      <description>&lt;p&gt;Industrial Edge Management contains an authentication bypass vulnerability that could allow an unauthenticated remote attacker to perform full account takeover by resetting user credentials without completing email verification.&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for the affected products and recommends to update to the latest versions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Industrial Edge Management contains an authentication bypass vulnerability that could allow an unauthenticated remote attacker to perform full account takeover by resetting user credentials without completing email verification.&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for the affected products and recommends to update to the latest versions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-503852</guid>
      <pubDate>Tue, 08 Sep 2026 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SSA-434797 — SSA-434797: Buffer Overflow Vulnerability in OpenSSL affecting Siemens Products</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-434797</link>
      <description>&lt;p&gt;OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution.&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution.&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-434797</guid>
      <pubDate>Tue, 09 Jun 2026 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SSA-331739 — SSA-331739: Privilege Escalation Vulnerability in WIBU CodeMeter Runtime Affecting Siemens Products</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-331739</link>
      <description>&lt;p&gt;WIBU Systems published information about a privilege escalation vulnerability under a certain circumstances and associated fix releases of CodeMeter Runtime, a product provided by WIBU Systems and used in several Siemens industrial products.&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for the affected products and recommends to update to the latest versions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;WIBU Systems published information about a privilege escalation vulnerability under a certain circumstances and associated fix releases of CodeMeter Runtime, a product provided by WIBU Systems and used in several Siemens industrial products.&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for the affected products and recommends to update to the latest versions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-331739</guid>
      <pubDate>Tue, 12 Aug 2025 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SSA-330084 — SSA-330084: Client Code Execution Vulnerability in Desigo CC Product Family</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-330084</link>
      <description>&lt;p&gt;A Client Code Execution (CCE) vulnerability has been identified in Desigo CC, potentially allowing malicious actors to execute arbitrary code on client devices through specially crafted graphics documents. This vulnerability leverages user-defined graphics containing embedded scripts that are executed on client application instances. Successful exploitation could lead to compromise of the client operating system and potential lateral movement within the organization.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A Client Code Execution (CCE) vulnerability has been identified in Desigo CC, potentially allowing malicious actors to execute arbitrary code on client devices through specially crafted graphics documents. This vulnerability leverages user-defined graphics containing embedded scripts that are executed on client application instances. Successful exploitation could lead to compromise of the client operating system and potential lateral movement within the organization.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-330084</guid>
      <pubDate>Tue, 08 Sep 2026 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SSA-328642 — SSA-328642: "Copy Fail" Vulnerability in Multiple Industrial Products</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-328642</link>
      <description>&lt;p&gt;Multiple Siemens products are vulnerable to the &amp;#34;Copy Fail&amp;#34; vulnerability.&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple Siemens products are vulnerable to the &amp;#34;Copy Fail&amp;#34; vulnerability.&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-328642</guid>
      <pubDate>Tue, 08 Sep 2026 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SSA-327438 — SSA-327438: Multiple Vulnerabilities in SCALANCE LPE9403</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-327438</link>
      <description>&lt;p&gt;SCALANCE LPE9403 is affected by multiple vulnerabilities which lead to a compromise in availability, integrity and confidentiality.&lt;/p&gt;
&lt;p&gt;Siemens has released a new version for SCALANCE LPE9403 and recommends to update to the latest version. Siemens recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SCALANCE LPE9403 is affected by multiple vulnerabilities which lead to a compromise in availability, integrity and confidentiality.&lt;/p&gt;
&lt;p&gt;Siemens has released a new version for SCALANCE LPE9403 and recommends to update to the latest version. Siemens recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-327438</guid>
      <pubDate>Tue, 13 May 2025 00:00:00 +0000</pubDate>
    </item>
  </channel>
</rss>
