<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from csaf_siemens</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:51:54 +0000</lastBuildDate>
    <item>
      <title>SSA-823812 — SSA-823812: Denial of Service Vulnerability in WTV676 and WTV776 devices</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-823812</link>
      <description>&lt;p&gt;The products listed below contain a denial of service vulnerability that could allow an attacker to force the devices into protection mode under certain conditions. This disables remote connectivity functions (Web Access) to the devices.&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for the affected products and recommends to update to the latest versions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The products listed below contain a denial of service vulnerability that could allow an attacker to force the devices into protection mode under certain conditions. This disables remote connectivity functions (Web Access) to the devices.&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for the affected products and recommends to update to the latest versions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-823812</guid>
      <pubDate>Wed, 16 Sep 2026 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SSA-517424 — SSA-517424: Path Traversal Vulnerability in SIMOVE Fleetmanager and SIPLANT</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-517424</link>
      <description>&lt;p&gt;SIMOVE Fleetmanager and SIPLANT contain a path traversal vulnerability that could allow an attacker to access files outside of intended scope.&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for the affected products and recommends to update to the latest versions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SIMOVE Fleetmanager and SIPLANT contain a path traversal vulnerability that could allow an attacker to access files outside of intended scope.&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for the affected products and recommends to update to the latest versions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-517424</guid>
      <pubDate>Tue, 08 Sep 2026 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SSA-503852 — SSA-503852: Authentication Bypass Vulnerability in Industrial Edge Management</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-503852</link>
      <description>&lt;p&gt;Industrial Edge Management contains an authentication bypass vulnerability that could allow an unauthenticated remote attacker to perform full account takeover by resetting user credentials without completing email verification.&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for the affected products and recommends to update to the latest versions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Industrial Edge Management contains an authentication bypass vulnerability that could allow an unauthenticated remote attacker to perform full account takeover by resetting user credentials without completing email verification.&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for the affected products and recommends to update to the latest versions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-503852</guid>
      <pubDate>Tue, 08 Sep 2026 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SSA-330084 — SSA-330084: Client Code Execution Vulnerability in Desigo CC Product Family</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-330084</link>
      <description>&lt;p&gt;A Client Code Execution (CCE) vulnerability has been identified in Desigo CC, potentially allowing malicious actors to execute arbitrary code on client devices through specially crafted graphics documents. This vulnerability leverages user-defined graphics containing embedded scripts that are executed on client application instances. Successful exploitation could lead to compromise of the client operating system and potential lateral movement within the organization.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A Client Code Execution (CCE) vulnerability has been identified in Desigo CC, potentially allowing malicious actors to execute arbitrary code on client devices through specially crafted graphics documents. This vulnerability leverages user-defined graphics containing embedded scripts that are executed on client application instances. Successful exploitation could lead to compromise of the client operating system and potential lateral movement within the organization.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-330084</guid>
      <pubDate>Tue, 08 Sep 2026 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SSA-328642 — SSA-328642: "Copy Fail" Vulnerability in Multiple Industrial Products</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-328642</link>
      <description>&lt;p&gt;Multiple Siemens products are vulnerable to the &amp;#34;Copy Fail&amp;#34; vulnerability.&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple Siemens products are vulnerable to the &amp;#34;Copy Fail&amp;#34; vulnerability.&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-328642</guid>
      <pubDate>Tue, 08 Sep 2026 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SSA-254516 — SSA-254516: Arbitrary File Upload in OIS Web Module</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-254516</link>
      <description>&lt;p&gt;A vulnerability has been identified in the Open Interface Services (OIS) web module affecting Siveillance Control and Siveillance Control Pro (versions OIS 3.x.y and OIS 4.x.y) . This vulnerability allows an attacker to upload arbitrary files, which can lead to unauthorized root-level access on the OIS server.&lt;/p&gt;
&lt;p&gt;Siemens has released patches and updates for Siveillance OIS to apply to the products that incorporate the OIS service, and recommends to update to the latest versions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability has been identified in the Open Interface Services (OIS) web module affecting Siveillance Control and Siveillance Control Pro (versions OIS 3.x.y and OIS 4.x.y) . This vulnerability allows an attacker to upload arbitrary files, which can lead to unauthorized root-level access on the OIS server.&lt;/p&gt;
&lt;p&gt;Siemens has released patches and updates for Siveillance OIS to apply to the products that incorporate the OIS service, and recommends to update to the latest versions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-254516</guid>
      <pubDate>Tue, 08 Sep 2026 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SSA-157465 — SSA-157465: Reflected Cross-site scripting Vulnerability in Teamcenter</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-157465</link>
      <description>&lt;p&gt;A reflected cross site scripting vulnerability in the authentication redirect flow (/auth/) of Teamcenter allows an unauthenticated remote attacker to inject JavaScript into an authenticated user&amp;#39;s session by crafting a malicious URL. Successful exploitation may enable the attacker to read data or perform actions within the victim&amp;#39;s Teamcenter session.&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for the affected products and recommends to update to the latest versions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A reflected cross site scripting vulnerability in the authentication redirect flow (/auth/) of Teamcenter allows an unauthenticated remote attacker to inject JavaScript into an authenticated user&amp;#39;s session by crafting a malicious URL. Successful exploitation may enable the attacker to read data or perform actions within the victim&amp;#39;s Teamcenter session.&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for the affected products and recommends to update to the latest versions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-157465</guid>
      <pubDate>Tue, 08 Sep 2026 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SSA-142885 — SSA-142885: Multiple Vulnerabilities in Reyrolle 7SR5 Before V2.70</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-142885</link>
      <description>&lt;p&gt;Siemens Reyrolle 7SR5 Before V2.70 is affected by multiple vulnerabilities.&lt;/p&gt;
&lt;p&gt;Siemens has released a new version for Reyrolle 7SR5 and recommends to update to the latest version.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Siemens Reyrolle 7SR5 Before V2.70 is affected by multiple vulnerabilities.&lt;/p&gt;
&lt;p&gt;Siemens has released a new version for Reyrolle 7SR5 and recommends to update to the latest version.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-142885</guid>
      <pubDate>Tue, 08 Sep 2026 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SSA-887643 — SSA-887643: Account Hijacking Vulnerability in Mendix SAML module</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-887643</link>
      <description>&lt;p&gt;Mendix SAML module contains a vulnerability that could allow unauthenticated remote attackers to hijack an account in specific SSO configurations.&lt;/p&gt;
&lt;p&gt;Mendix has provided fix releases for the Mendix SAML module and recommends to update to the latest version.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Mendix SAML module contains a vulnerability that could allow unauthenticated remote attackers to hijack an account in specific SSO configurations.&lt;/p&gt;
&lt;p&gt;Mendix has provided fix releases for the Mendix SAML module and recommends to update to the latest version.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-887643</guid>
      <pubDate>Thu, 03 Sep 2026 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SSA-682041 — SSA-682041: Cross Site Scripting Vulnerability in Element Maps</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-682041</link>
      <description>&lt;p&gt;The si-map component does not properly neutralize user-controllable input of the points property that is used to render the tooltip label of map pins.
This could allow an attacker to craft a malicious URL that, when loaded by a victim and the map pin is hovered over, executes arbitrary script code within the victim&amp;#39;s browser session. This vulnerability affects only the @siemens/maps-ng package.&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for the affected products and recommends to update to the latest versions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The si-map component does not properly neutralize user-controllable input of the points property that is used to render the tooltip label of map pins.
This could allow an attacker to craft a malicious URL that, when loaded by a victim and the map pin is hovered over, executes arbitrary script code within the victim&amp;#39;s browser session. This vulnerability affects only the @siemens/maps-ng package.&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for the affected products and recommends to update to the latest versions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-682041</guid>
      <pubDate>Thu, 27 Aug 2026 00:00:00 +0000</pubDate>
    </item>
  </channel>
</rss>
