<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from csaf_trumpfsecokg</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 12:13:25 +0000</lastBuildDate>
    <item>
      <title>VDE-2020-039 — TRUMPF: Multiple products prone to WIBU CodeMeter vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2020-039</link>
      <description>&lt;p&gt;A number of TRUMPF CAD/CAM software tools use the CodeMeter Runtime application from WIBU-SYSTEMS AG to manage licences. This application contains a number of vulnerabilities, which enable an attacker to prevent normal operation of CodeMeter, resulting in a Denial-of-Service and potentially execute arbitrary code.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A number of TRUMPF CAD/CAM software tools use the CodeMeter Runtime application from WIBU-SYSTEMS AG to manage licences. This application contains a number of vulnerabilities, which enable an attacker to prevent normal operation of CodeMeter, resulting in a Denial-of-Service and potentially execute arbitrary code.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2020-039</guid>
      <pubDate>Tue, 27 Oct 2020 10:28:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2021-011 — TRUMPF Laser GmbH: TruControl 2.14.0 to 3.14.0 affected by recent sudo vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2021-011</link>
      <description>&lt;p&gt;TruControl laser control software from versions 2.14.0 to 3.14.0 use sudo versions affected by CVE-2021-3156. The affected sudo has a heap-based buffer overflow, allowing privilege escalation to root via &amp;#34;sudoedit -s&amp;#34; and a command-line argument that ends with a single backslash character.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;TruControl laser control software from versions 2.14.0 to 3.14.0 use sudo versions affected by CVE-2021-3156. The affected sudo has a heap-based buffer overflow, allowing privilege escalation to root via &amp;#34;sudoedit -s&amp;#34; and a command-line argument that ends with a single backslash character.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2021-011</guid>
      <pubDate>Mon, 22 Mar 2021 08:59:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2021-033 — TRUMPF Laser GmbH: multiple products prone to codesys runtime vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2021-033</link>
      <description>&lt;p&gt;The TruControl laser control software (versions 1.04 to 3.0.0) uses CODESYS runtime versions affected by multiple CVEs:&lt;/p&gt;
&lt;p&gt;**CVE list:**&lt;/p&gt;
&lt;p&gt;- CVE-2021-29242
- CVE-2021-29241
- CVE-2019-5105
- CVE-2020-7052
- CVE-2019-9012
- CVE-2019-9010
- CVE-2019-9009
- CVE-2018-10612&lt;/p&gt;
&lt;p&gt;In addition to the CVEs listed above, the affected products are also vulnerable to the following issues without a CVE ID:&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### **CODESYS Advisory 2018-07**&lt;/p&gt;
&lt;p&gt;A crafted communication request may cause an access violation in the affected CODESYS products and may result in a denial-of-service condition.&lt;/p&gt;
&lt;p&gt;- **CVSS v3.0 base score:** 6.5  
- **CVSS v3.0 vector:** `CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H`&lt;/p&gt;
&lt;p&gt;🔗 [Link to advisory](https://customers.codesys.com/index.php?eID=dumpFile&amp;amp;t=f&amp;amp;f=12928&amp;amp;token=6d1dcea05a15aeef7ad48eadc64c8eca5d4f07b2&amp;amp;download=)&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### **CODESYS Advisory 2018-04**&lt;/p&gt;
&lt;p&gt;The CODESYS runtime system allows access to files outside the restricted working directory of the controller by online services.&lt;/p&gt;
&lt;p&gt;- **CVSS v3.0 base score:** 9.9  
- **CVSS v3.0 vector:** `CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H`&lt;/p&gt;
&lt;p&gt;🔗 [Link to advisory](https://customers.codesys.com/index.php?eID=dumpFile&amp;amp;t=f&amp;amp;f=12925&amp;amp;token=50e7240fa947ea215311e3db441f82152f1109b6&amp;amp;download=)&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### **CODESYS Advisory 2017-03**&lt;/p&gt;
&lt;p&gt;A crafted request may cause an access violation in the affected CODESYS products and may result in a denial-of-service condition.&lt;/p&gt;
&lt;p&gt;- **CVSS v3.0 base score:** 7.5  
- **CVSS v3.0 vector:** `CVSS:3.0/AV:N/AC:L/PR:N/…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The TruControl laser control software (versions 1.04 to 3.0.0) uses CODESYS runtime versions affected by multiple CVEs:&lt;/p&gt;
&lt;p&gt;**CVE list:**&lt;/p&gt;
&lt;p&gt;- CVE-2021-29242
- CVE-2021-29241
- CVE-2019-5105
- CVE-2020-7052
- CVE-2019-9012
- CVE-2019-9010
- CVE-2019-9009
- CVE-2018-10612&lt;/p&gt;
&lt;p&gt;In addition to the CVEs listed above, the affected products are also vulnerable to the following issues without a CVE ID:&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### **CODESYS Advisory 2018-07**&lt;/p&gt;
&lt;p&gt;A crafted communication request may cause an access violation in the affected CODESYS products and may result in a denial-of-service condition.&lt;/p&gt;
&lt;p&gt;- **CVSS v3.0 base score:** 6.5  
- **CVSS v3.0 vector:** `CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H`&lt;/p&gt;
&lt;p&gt;🔗 [Link to advisory](https://customers.codesys.com/index.php?eID=dumpFile&amp;amp;t=f&amp;amp;f=12928&amp;amp;token=6d1dcea05a15aeef7ad48eadc64c8eca5d4f07b2&amp;amp;download=)&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### **CODESYS Advisory 2018-04**&lt;/p&gt;
&lt;p&gt;The CODESYS runtime system allows access to files outside the restricted working directory of the controller by online services.&lt;/p&gt;
&lt;p&gt;- **CVSS v3.0 base score:** 9.9  
- **CVSS v3.0 vector:** `CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H`&lt;/p&gt;
&lt;p&gt;🔗 [Link to advisory](https://customers.codesys.com/index.php?eID=dumpFile&amp;amp;t=f&amp;amp;f=12925&amp;amp;token=50e7240fa947ea215311e3db441f82152f1109b6&amp;amp;download=)&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### **CODESYS Advisory 2017-03**&lt;/p&gt;
&lt;p&gt;A crafted request may cause an access violation in the affected CODESYS products and may result in a denial-of-service condition.&lt;/p&gt;
&lt;p&gt;- **CVSS v3.0 base score:** 7.5  
- **CVSS v3.0 vector:** `CVSS:3.0/AV:N/AC:L/PR:N/…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2021-033</guid>
      <pubDate>Thu, 12 Aug 2021 13:02:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2022-016 — TRUMPF: TruTops Fab, TruTops Boost prone to vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2022-016</link>
      <description>&lt;p&gt;A service function in the stated TRUMPF products is exposed without necessary authentication. Execution of this function may result in unauthorized access to, change of data or disruption of the whole service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A service function in the stated TRUMPF products is exposed without necessary authentication. Execution of this function may result in unauthorized access to, change of data or disruption of the whole service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2022-016</guid>
      <pubDate>Mon, 02 May 2022 10:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2022-034 — TRUMPF: Products prone to Unified Automation vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2022-034</link>
      <description>&lt;p&gt;A number of TRUMPF software tools use the OPC UA Server in C++ based OPC UA SDK by Unified Automation. The application contains several vulnerabilities, which enable an attacker to send malicious data to the application, resulting in a Denial-of-Service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A number of TRUMPF software tools use the OPC UA Server in C++ based OPC UA SDK by Unified Automation. The application contains several vulnerabilities, which enable an attacker to send malicious data to the application, resulting in a Denial-of-Service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2022-034</guid>
      <pubDate>Mon, 15 Aug 2022 10:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2022-023 — TRUMPF TruTops prone to improper access control</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2022-023</link>
      <description>&lt;p&gt;Multiple Trumpf Products in multiple versions use default privileged Windows users and passwords. An adversary may use these accounts to remotely gain full access to the system.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple Trumpf Products in multiple versions use default privileged Windows users and passwords. An adversary may use these accounts to remotely gain full access to the system.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2022-023</guid>
      <pubDate>Mon, 17 Oct 2022 10:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2022-049 — TRUMPF: Multiple products prone to X.Org server vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2022-049</link>
      <description>&lt;p&gt;TruControl laser control software from versions 1.60.0 to 3.40.0 use a vulnerable  X.Org server versions. The affected X.Org vulnerability is not validating the request length properly for the handler &amp;#39;ProcXkbSetGeometry&amp;#39;. An authenticated Attacker could craft a request which could lead to memory out-of bounds write.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;TruControl laser control software from versions 1.60.0 to 3.40.0 use a vulnerable  X.Org server versions. The affected X.Org vulnerability is not validating the request length properly for the handler &amp;#39;ProcXkbSetGeometry&amp;#39;. An authenticated Attacker could craft a request which could lead to memory out-of bounds write.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2022-049</guid>
      <pubDate>Mon, 07 Nov 2022 11:43:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2023-031 — Trumpf: Multiple Products affected by WIBU Codemeter Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2023-031</link>
      <description>&lt;p&gt;The TRUMPF CAD/CAM software tools mentioned above use the vulnerable CodeMeter Runtime (up to version 7.60b) application from WIBU-SYSTEMS AG to manage licenses within the component TRUMPF License Expert. This CodeMeter application contains new vulnerabilities, which may enable an attacker to gain full access to the server or workstation on which the TRUMPF License Expert has been installed on. A new version of the TRUMPF License Expert which fixes this vulnerability is available.Machines with a running and correctly installed mGuard hardware firewall cannot be exploited by this vulnerability if used as intended (according to the manual).&lt;/p&gt;
&lt;p&gt;Update A, 2023-11-13
Removed CVE-2023-4701 because it was revoked.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The TRUMPF CAD/CAM software tools mentioned above use the vulnerable CodeMeter Runtime (up to version 7.60b) application from WIBU-SYSTEMS AG to manage licenses within the component TRUMPF License Expert. This CodeMeter application contains new vulnerabilities, which may enable an attacker to gain full access to the server or workstation on which the TRUMPF License Expert has been installed on. A new version of the TRUMPF License Expert which fixes this vulnerability is available.Machines with a running and correctly installed mGuard hardware firewall cannot be exploited by this vulnerability if used as intended (according to the manual).&lt;/p&gt;
&lt;p&gt;Update A, 2023-11-13
Removed CVE-2023-4701 because it was revoked.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2023-031</guid>
      <pubDate>Wed, 13 Sep 2023 10:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2024-003 — TRUMPF: Multiple products include a vulnerable version of Notepad++</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2024-003</link>
      <description>&lt;p&gt;The TRUMPF products that are listed above contain a vulnerable version of Notepad++. This version isbeing installed for support purposes only, so there is no danger of triggering this vulnerability inNotepad++ during normal operations. Nevertheless, TRUMPF recommends mitigation of thisvulnerability.When editing a specially crafted file containing UTF-8 characters in Notepad++ (Versions up to 8.5.6) and converting that file to UTF-16, a buffer overflow vulnerability can be exploited that allows an attacker to execute arbitrary code to take over the whole system.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The TRUMPF products that are listed above contain a vulnerable version of Notepad++. This version isbeing installed for support purposes only, so there is no danger of triggering this vulnerability inNotepad++ during normal operations. Nevertheless, TRUMPF recommends mitigation of thisvulnerability.When editing a specially crafted file containing UTF-8 characters in Notepad++ (Versions up to 8.5.6) and converting that file to UTF-16, a buffer overflow vulnerability can be exploited that allows an attacker to execute arbitrary code to take over the whole system.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2024-003</guid>
      <pubDate>Tue, 23 Jan 2024 07:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2024-005 — TRUMPF: Multiple products contain vulnerable version of 7-zip</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2024-005</link>
      <description>&lt;p&gt;Under certain circumstances, opening a specially crafted 7-zip package can exploit an integer
underflow vulnerability in 7-zip versions up to and including 22.x&lt;/p&gt;
&lt;p&gt;This vulnerability allows for a remote code execution, resulting in unauthorized (remote) access to,
change of data or disruption of the whole service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Under certain circumstances, opening a specially crafted 7-zip package can exploit an integer
underflow vulnerability in 7-zip versions up to and including 22.x&lt;/p&gt;
&lt;p&gt;This vulnerability allows for a remote code execution, resulting in unauthorized (remote) access to,
change of data or disruption of the whole service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2024-005</guid>
      <pubDate>Tue, 23 Jan 2024 07:00:00 +0000</pubDate>
    </item>
  </channel>
</rss>
