<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from csaf_vegagrieshaberkg</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 07:12:03 +0000</lastBuildDate>
    <item>
      <title>VDE-2026-048 — VEGA: Missing Authentication for critical function in VEGAPULS Bluetooth products</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2026-048</link>
      <description>&lt;p&gt;Vulnerable components expose sensitive information to unauthorized actors through an unsecured configuration interface. Vulnerable firmware releases contain an unsecured configuration interface that allows retrieval of sensitive information such as hashed credentials.&lt;/p&gt;
&lt;p&gt;It was found that users with no or low rights can access information from devices that should not be available to them.&lt;/p&gt;
&lt;p&gt;An attacker can use this information to impersonate authorized users.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Vulnerable components expose sensitive information to unauthorized actors through an unsecured configuration interface. Vulnerable firmware releases contain an unsecured configuration interface that allows retrieval of sensitive information such as hashed credentials.&lt;/p&gt;
&lt;p&gt;It was found that users with no or low rights can access information from devices that should not be available to them.&lt;/p&gt;
&lt;p&gt;An attacker can use this information to impersonate authorized users.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2026-048</guid>
      <pubDate>Mon, 04 May 2026 06:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2026-046 — VEGA: Missing Authentication for critical function in VEGAPULS two- and four-wire products</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2026-046</link>
      <description>&lt;p&gt;Vulnerable components expose sensitive information to unauthorized actors through an unsecured configuration interface. Vulnerable firmware releases contain an unsecured configuration interface that allows retrieval of sensitive information such as hashed credentials.&lt;/p&gt;
&lt;p&gt;It was found that users with no or low rights can access information from devices that should not be available to them.&lt;/p&gt;
&lt;p&gt;An attacker can use this information to impersonate authorized users.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Vulnerable components expose sensitive information to unauthorized actors through an unsecured configuration interface. Vulnerable firmware releases contain an unsecured configuration interface that allows retrieval of sensitive information such as hashed credentials.&lt;/p&gt;
&lt;p&gt;It was found that users with no or low rights can access information from devices that should not be available to them.&lt;/p&gt;
&lt;p&gt;An attacker can use this information to impersonate authorized users.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2026-046</guid>
      <pubDate>Mon, 04 May 2026 06:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2026-016 — VEGA: Unsecured Configuration Interface Allows Unauthorized Access Leading to Privilege Escalation</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2026-016</link>
      <description>&lt;p&gt;Vulnerable components expose sensitive information to unauthorized actors through an unsecured configuration interface. Vulnerable firmware releases contain an unsecured configuration interface that allows retrieval of sensitive information such as hashed credentials.&lt;/p&gt;
&lt;p&gt;It was found that users with no or low rights can access information from devices that should not be available to them.&lt;/p&gt;
&lt;p&gt;An attacker can use this information to impersonate authorized users.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Vulnerable components expose sensitive information to unauthorized actors through an unsecured configuration interface. Vulnerable firmware releases contain an unsecured configuration interface that allows retrieval of sensitive information such as hashed credentials.&lt;/p&gt;
&lt;p&gt;It was found that users with no or low rights can access information from devices that should not be available to them.&lt;/p&gt;
&lt;p&gt;An attacker can use this information to impersonate authorized users.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2026-016</guid>
      <pubDate>Wed, 22 Apr 2026 09:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2026-047 — VEGA: Missing Authentication for critical function in VEGAPULS Air products</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2026-047</link>
      <description>&lt;p&gt;Vulnerable components expose sensitive information to unauthorized actors through an unsecured configuration interface. Vulnerable firmware releases contain an unsecured configuration interface that allows retrieval of sensitive information such as hashed credentials.&lt;/p&gt;
&lt;p&gt;It was found that users with no or low rights can access information from devices that should not be available to them.&lt;/p&gt;
&lt;p&gt;An attacker can use this information to impersonate authorized users.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Vulnerable components expose sensitive information to unauthorized actors through an unsecured configuration interface. Vulnerable firmware releases contain an unsecured configuration interface that allows retrieval of sensitive information such as hashed credentials.&lt;/p&gt;
&lt;p&gt;It was found that users with no or low rights can access information from devices that should not be available to them.&lt;/p&gt;
&lt;p&gt;An attacker can use this information to impersonate authorized users.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2026-047</guid>
      <pubDate>Mon, 04 May 2026 06:00:00 +0000</pubDate>
    </item>
  </channel>
</rss>
