<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from csaf_siemens</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 14:24:05 +0000</lastBuildDate>
    <item>
      <title>SSA-039007 — SSA-039007: Heap-based Buffer Overflow Vulnerability in User Management Component (UMC)</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-039007</link>
      <description>&lt;p&gt;Affected products contain a heap-based buffer overflow vulnerability in the integrated UMC component. This could allow an unauthenticated remote attacker to execute arbitrary code.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Affected products contain a heap-based buffer overflow vulnerability in the integrated UMC component. This could allow an unauthenticated remote attacker to execute arbitrary code.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-039007</guid>
      <pubDate>Tue, 10 Sep 2024 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SSA-054046 — SSA-054046: Unauthenticated Information Disclosure in Web Server of SIMATIC S7-1500 CPUs</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-054046</link>
      <description>&lt;p&gt;The web server of affected devices do not properly authenticate user request to the &amp;#39;/ClientArea/RuntimeInfoData.mwsl&amp;#39; endpoint. This could allow an unauthenticated remote attacker to gain knowledge about current actual and configured maximum cycle times as well as about configured maximum communication load.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The web server of affected devices do not properly authenticate user request to the &amp;#39;/ClientArea/RuntimeInfoData.mwsl&amp;#39; endpoint. This could allow an unauthenticated remote attacker to gain knowledge about current actual and configured maximum cycle times as well as about configured maximum communication load.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-054046</guid>
      <pubDate>Tue, 08 Oct 2024 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SSA-062309 — SSA-062309: Information Disclosure Vulnerability in TeleControl Server Basic V3.1</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-062309</link>
      <description>&lt;p&gt;The affected application contains an information disclosure vulnerability. This could allow an unauthenticated remote attacker to obtain password hashes of users and to login to and perform authenticated operations of the database service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The affected application contains an information disclosure vulnerability. This could allow an unauthenticated remote attacker to obtain password hashes of users and to login to and perform authenticated operations of the database service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-062309</guid>
      <pubDate>Tue, 14 Oct 2025 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SSA-083019 — SSA-083019: Multiple Vulnerabilities in RUGGEDCOM ROS Devices</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-083019</link>
      <description>&lt;p&gt;The affected products support insecure cryptographic algorithms. An attacker could leverage these legacy algorithms to achieve a man-in-the-middle attack or impersonate communicating parties. Affected devices do not properly handle malformed TLS handshake messages. This could allow an attacker with network access to the webserver to cause a denial of service resulting in the web server and the device to crash. The affected devices support the TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256 cipher suite, which uses CBC (Cipher Block Chaining) mode that is known to be vulnerable to timing attacks. This could allow an attacker to compromise the integrity and confidentiality of encrypted communications. The affected products do not properly enforce interface access restrictions when changing from management to non-management interface configurations until a system reboot occurs, despite configuration being saved. This could allow an attacker with network access and credentials to gain access to device through non-management and maintain SSH access to the device until reboot.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The affected products support insecure cryptographic algorithms. An attacker could leverage these legacy algorithms to achieve a man-in-the-middle attack or impersonate communicating parties. Affected devices do not properly handle malformed TLS handshake messages. This could allow an attacker with network access to the webserver to cause a denial of service resulting in the web server and the device to crash. The affected devices support the TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256 cipher suite, which uses CBC (Cipher Block Chaining) mode that is known to be vulnerable to timing attacks. This could allow an attacker to compromise the integrity and confidentiality of encrypted communications. The affected products do not properly enforce interface access restrictions when changing from management to non-management interface configurations until a system reboot occurs, despite configuration being saved. This could allow an attacker with network access and credentials to gain access to device through non-management and maintain SSH access to the device until reboot.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-083019</guid>
      <pubDate>Tue, 08 Jul 2025 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SSA-240718 — SSA-240718: Insecure Storage of HTTPS CA Certificate in SIMATIC S7-1200 CPU V2</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-240718</link>
      <description>&lt;p&gt;Affected devices do not properly protect the private key of the integrated Certification Authority (CA) certificate. Possession of this key could allow remote attackers to spoof the device&amp;#39;s web server by creating a forged web server certificate.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Affected devices do not properly protect the private key of the integrated Certification Authority (CA) certificate. Possession of this key could allow remote attackers to spoof the device&amp;#39;s web server by creating a forged web server certificate.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-240718</guid>
      <pubDate>Thu, 13 Sep 2012 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SSA-279823 — SSA-279823: Cross-Site Scripting Vulnerability in SIMATIC S7-1200 CPU V2/V3 Before V3.0.2</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-279823</link>
      <description>&lt;p&gt;The web server on affected devices contains a cross-site scripting (XSS) vulnerability that could allow remote attackers to inject arbitrary web script or HTML via a crafted URI.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The web server on affected devices contains a cross-site scripting (XSS) vulnerability that could allow remote attackers to inject arbitrary web script or HTML via a crafted URI.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-279823</guid>
      <pubDate>Mon, 08 Oct 2012 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SSA-318832 — SSA-318832: SQL Injection Vulnerability in SINEC NMS</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-318832</link>
      <description>&lt;p&gt;Affected applications are vulnerable to SQL injection through getTotalAndFilterCounts endpoint. An authenticated low privileged attacker could exploit to insert data and achieve privilege escalation. (ZDI-CAN-26570)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Affected applications are vulnerable to SQL injection through getTotalAndFilterCounts endpoint. An authenticated low privileged attacker could exploit to insert data and achieve privilege escalation. (ZDI-CAN-26570)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-318832</guid>
      <pubDate>Tue, 14 Oct 2025 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SSA-367714 — SSA-367714: Improper Integrity Check of Firmware Updates in SiPass integrated AC5102 / ACC-G2 and ACC-AP</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-367714</link>
      <description>&lt;p&gt;Affected devices do not properly check the integrity of firmware updates. This could allow a local attacker to upload a maliciously modified firmware onto the device. In a second scenario, a remote attacker who is able to intercept the transfer of a valid firmware from the server to the device could modify the firmware &amp;#34;on the fly&amp;#34;.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Affected devices do not properly check the integrity of firmware updates. This could allow a local attacker to upload a maliciously modified firmware onto the device. In a second scenario, a remote attacker who is able to intercept the transfer of a valid firmware from the server to the device could modify the firmware &amp;#34;on the fly&amp;#34;.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-367714</guid>
      <pubDate>Fri, 23 May 2025 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SSA-373591 — SSA-373591: Buffer Overflow Vulnerability in RUGGEDCOM ROS Devices</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-373591</link>
      <description>&lt;p&gt;The DHCP client in affected devices fails to properly sanitize incoming DHCP packets. This could allow an unauthenticated remote attacker to cause memory to be overwritten, potentially allowing remote code execution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The DHCP client in affected devices fails to properly sanitize incoming DHCP packets. This could allow an unauthenticated remote attacker to cause memory to be overwritten, potentially allowing remote code execution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-373591</guid>
      <pubDate>Tue, 13 Jul 2021 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SSA-486936 — SSA-486936: Authentication Vulnerability in SIMATIC ET 200SP Communication Processors</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-486936</link>
      <description>&lt;p&gt;Affected devices do not properly authenticate configuration connections. This could allow an unauthenticated remote attacker to access the configuration data.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Affected devices do not properly authenticate configuration connections. This could allow an unauthenticated remote attacker to access the configuration data.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-486936</guid>
      <pubDate>Tue, 14 Oct 2025 00:00:00 +0000</pubDate>
    </item>
  </channel>
</rss>
