<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from csaf_trumpfsecokg</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 07:11:01 +0000</lastBuildDate>
    <item>
      <title>VDE-2026-091 — TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2026-091</link>
      <description>&lt;p&gt;The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowing privilege escalation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowing privilege escalation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2026-091</guid>
      <pubDate>Tue, 15 Sep 2026 07:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2026-007 — TRUMPF: Multiple products affected by Wibu CodeMeter vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2026-007</link>
      <description>&lt;p&gt;The TRUMPF product versions listed below include a Wibu CodeMeter component that is vulnerable to a privilege escalation vulnerability through the CodeMeter installer on Windows.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The TRUMPF product versions listed below include a Wibu CodeMeter component that is vulnerable to a privilege escalation vulnerability through the CodeMeter installer on Windows.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2026-007</guid>
      <pubDate>Mon, 23 Feb 2026 08:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2021-011 — TRUMPF Laser GmbH: TruControl 2.14.0 to 3.14.0 affected by recent sudo vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2021-011</link>
      <description>&lt;p&gt;TruControl laser control software from versions 2.14.0 to 3.14.0 use sudo versions affected by CVE-2021-3156. The affected sudo has a heap-based buffer overflow, allowing privilege escalation to root via &amp;#34;sudoedit -s&amp;#34; and a command-line argument that ends with a single backslash character.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;TruControl laser control software from versions 2.14.0 to 3.14.0 use sudo versions affected by CVE-2021-3156. The affected sudo has a heap-based buffer overflow, allowing privilege escalation to root via &amp;#34;sudoedit -s&amp;#34; and a command-line argument that ends with a single backslash character.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2021-011</guid>
      <pubDate>Mon, 22 Mar 2021 08:59:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2025-078 — TRUMPF: Remote support uses an outdated encryption algorithm</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2025-078</link>
      <description>&lt;p&gt;The TRUMPF remote support infrastructure selects an outdated encryption algorithm when setting up communication channels for machines. This cannot be prevented for old machines. For most machines it is possible to change the encryption settings.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The TRUMPF remote support infrastructure selects an outdated encryption algorithm when setting up communication channels for machines. This cannot be prevented for old machines. For most machines it is possible to change the encryption settings.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2025-078</guid>
      <pubDate>Mon, 25 Aug 2025 06:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2024-005 — TRUMPF: Multiple products contain vulnerable version of 7-zip</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2024-005</link>
      <description>&lt;p&gt;Under certain circumstances, opening a specially crafted 7-zip package can exploit an integer
underflow vulnerability in 7-zip versions up to and including 22.x&lt;/p&gt;
&lt;p&gt;This vulnerability allows for a remote code execution, resulting in unauthorized (remote) access to,
change of data or disruption of the whole service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Under certain circumstances, opening a specially crafted 7-zip package can exploit an integer
underflow vulnerability in 7-zip versions up to and including 22.x&lt;/p&gt;
&lt;p&gt;This vulnerability allows for a remote code execution, resulting in unauthorized (remote) access to,
change of data or disruption of the whole service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2024-005</guid>
      <pubDate>Tue, 23 Jan 2024 07:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2024-004 — TRUMPF: Multiple products affected by log4net vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2024-004</link>
      <description>&lt;p&gt;Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2024-004</guid>
      <pubDate>Tue, 22 Apr 2025 10:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2024-003 — TRUMPF: Multiple products include a vulnerable version of Notepad++</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2024-003</link>
      <description>&lt;p&gt;The TRUMPF products that are listed above contain a vulnerable version of Notepad++. This version isbeing installed for support purposes only, so there is no danger of triggering this vulnerability inNotepad++ during normal operations. Nevertheless, TRUMPF recommends mitigation of thisvulnerability.When editing a specially crafted file containing UTF-8 characters in Notepad++ (Versions up to 8.5.6) and converting that file to UTF-16, a buffer overflow vulnerability can be exploited that allows an attacker to execute arbitrary code to take over the whole system.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The TRUMPF products that are listed above contain a vulnerable version of Notepad++. This version isbeing installed for support purposes only, so there is no danger of triggering this vulnerability inNotepad++ during normal operations. Nevertheless, TRUMPF recommends mitigation of thisvulnerability.When editing a specially crafted file containing UTF-8 characters in Notepad++ (Versions up to 8.5.6) and converting that file to UTF-16, a buffer overflow vulnerability can be exploited that allows an attacker to execute arbitrary code to take over the whole system.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2024-003</guid>
      <pubDate>Tue, 23 Jan 2024 07:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2022-049 — TRUMPF: Multiple products prone to X.Org server vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2022-049</link>
      <description>&lt;p&gt;TruControl laser control software from versions 1.60.0 to 3.40.0 use a vulnerable  X.Org server versions. The affected X.Org vulnerability is not validating the request length properly for the handler &amp;#39;ProcXkbSetGeometry&amp;#39;. An authenticated Attacker could craft a request which could lead to memory out-of bounds write.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;TruControl laser control software from versions 1.60.0 to 3.40.0 use a vulnerable  X.Org server versions. The affected X.Org vulnerability is not validating the request length properly for the handler &amp;#39;ProcXkbSetGeometry&amp;#39;. An authenticated Attacker could craft a request which could lead to memory out-of bounds write.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2022-049</guid>
      <pubDate>Mon, 07 Nov 2022 11:43:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2020-039 — TRUMPF: Multiple products prone to WIBU CodeMeter vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2020-039</link>
      <description>&lt;p&gt;A number of TRUMPF CAD/CAM software tools use the CodeMeter Runtime application from WIBU-SYSTEMS AG to manage licences. This application contains a number of vulnerabilities, which enable an attacker to prevent normal operation of CodeMeter, resulting in a Denial-of-Service and potentially execute arbitrary code.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A number of TRUMPF CAD/CAM software tools use the CodeMeter Runtime application from WIBU-SYSTEMS AG to manage licences. This application contains a number of vulnerabilities, which enable an attacker to prevent normal operation of CodeMeter, resulting in a Denial-of-Service and potentially execute arbitrary code.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2020-039</guid>
      <pubDate>Tue, 27 Oct 2020 10:28:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2024-040 — Multiple TRUMPF products prone to regreSSHion OpenSSH server vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2024-040</link>
      <description>&lt;p&gt;TruControl laser control software prior to version 1.60.0 uses an OpenSSH server version affected by CVE-2024-6387. The affected OpenSSH Server version could potentially lead to a remote code execution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;TruControl laser control software prior to version 1.60.0 uses an OpenSSH server version affected by CVE-2024-6387. The affected OpenSSH Server version could potentially lead to a remote code execution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2024-040</guid>
      <pubDate>Tue, 25 Jun 2024 10:00:00 +0000</pubDate>
    </item>
  </channel>
</rss>
