<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/csaf_trumpfsecokg/10</id>
  <title>Most recent entries from csaf_trumpfsecokg</title>
  <updated>2026-10-10T19:12:10.044838+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2026-091</id>
    <title>VDE-2026-091 — TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities</title>
    <updated>2026-09-15T07:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowing privilege escalation.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2026-091"/>
    <published>2026-09-15T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2026-007</id>
    <title>VDE-2026-007 — TRUMPF: Multiple products affected by Wibu CodeMeter vulnerability</title>
    <updated>2026-02-23T08:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The TRUMPF product versions listed below include a Wibu CodeMeter component that is vulnerable to a privilege escalation vulnerability through the CodeMeter installer on Windows.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2026-007"/>
    <published>2026-02-23T08:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2025-078</id>
    <title>VDE-2025-078 — TRUMPF: Remote support uses an outdated encryption algorithm</title>
    <updated>2025-08-29T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The TRUMPF remote support infrastructure selects an outdated encryption algorithm when setting up communication channels for machines. This cannot be prevented for old machines. For most machines it is possible to change the encryption settings.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2025-078"/>
    <published>2025-08-25T06:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-004</id>
    <title>VDE-2024-004 — TRUMPF: Multiple products affected by log4net vulnerability</title>
    <updated>2025-05-22T13:03:10+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-004"/>
    <published>2025-04-22T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-040</id>
    <title>VDE-2024-040 — Multiple TRUMPF products prone to regreSSHion OpenSSH server vulnerabilities</title>
    <updated>2025-04-10T13:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>TruControl laser control software prior to version 1.60.0 uses an OpenSSH server version affected by CVE-2024-6387. The affected OpenSSH Server version could potentially lead to a remote code execution.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-040"/>
    <published>2024-06-25T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-034</id>
    <title>VDE-2024-034 — Multiple TRUMPF products prone to nftables server vulnerabilities</title>
    <updated>2025-04-10T13:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>TruControl laser control software from versions 3.50.0 to 4.00.0.B use Linux kernel versions affected by CVE-2024-1086. The affected kernel vulnerability could lead to local privilege escalation.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-034"/>
    <published>2024-06-25T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-001</id>
    <title>VDE-2024-001 — TRUMPF: Multiple products contain WIBU CodeMeter vulnerabilities</title>
    <updated>2024-01-29T07:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The TRUMPF CAD/CAM software tools mentioned above use the vulnerable CodeMeter Runtime (up to version 7.60d) application from WIBU-SYSTEMS AG to manage licenses within the component TRUMPF License Expert. This CodeMeter application contains new vulnerabilities, which may enable an attacker to gain full access to the server or workstation on which the TRUMPF License Expert has been installed on. A new version of the TRUMPF License Expert which fixes these vulnerabilities is available.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-001"/>
    <published>2024-01-29T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-006</id>
    <title>VDE-2024-006 — TRUMPF: Oseon contains vulnerable version of OpenSSL 1.1.x</title>
    <updated>2024-01-23T07:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multiple vulnerabilities in the included versions of OpenSSL can lead to different problems, including crashes of the OpenSSL modules (leading to a Denial of Service) or leakage of plaintext. These underlying vulnerabilities can be fixed by installing a software update provided by TRUMPF.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-006"/>
    <published>2024-01-23T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-005</id>
    <title>VDE-2024-005 — TRUMPF: Multiple products contain vulnerable version of 7-zip</title>
    <updated>2025-06-05T13:28:12+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Under certain circumstances, opening a specially crafted 7-zip package can exploit an integer
underflow vulnerability in 7-zip versions up to and including 22.x</p>
<p>This vulnerability allows for a remote code execution, resulting in unauthorized (remote) access to,
change of data or disruption of the whole service.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-005"/>
    <published>2024-01-23T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-003</id>
    <title>VDE-2024-003 — TRUMPF: Multiple products include a vulnerable version of Notepad++</title>
    <updated>2025-05-22T13:03:10+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The TRUMPF products that are listed above contain a vulnerable version of Notepad++. This version isbeing installed for support purposes only, so there is no danger of triggering this vulnerability inNotepad++ during normal operations. Nevertheless, TRUMPF recommends mitigation of thisvulnerability.When editing a specially crafted file containing UTF-8 characters in Notepad++ (Versions up to 8.5.6) and converting that file to UTF-16, a buffer overflow vulnerability can be exploited that allows an attacker to execute arbitrary code to take over the whole system.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-003"/>
    <published>2024-01-23T07:00:00+00:00</published>
  </entry>
</feed>
