<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from csaf_weidmuellerinterfacegmbhcokg</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 09:00:11 +0000</lastBuildDate>
    <item>
      <title>VDE-2022-008 — WEIDMUELLER: Multiple vulnerabilities in Modbus TCP/RTU Gateways</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2022-008</link>
      <description>&lt;p&gt;Multiple issues have been found in the affected products. See CVE descriptions for details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple issues have been found in the affected products. See CVE descriptions for details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2022-008</guid>
      <pubDate>Thu, 07 Apr 2022 06:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2021-004 — Weidmueller: EtherNet/IP Fieldbus Coupler out-of-bounds write</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2021-004</link>
      <description>&lt;p&gt;A critical vulnerability has been discovered in the utilized component EtherNet/IP Adapter Development Kit (EADK) by Pyramid Solutions, Inc.. For details refer to CVE(s).This vulnerability may allow an attacker to send a specially crafted packet that may result in a denial-of-service condition of the affected products.
The indicated firmware versions are only used on products of hardware version 01.xx.xx.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A critical vulnerability has been discovered in the utilized component EtherNet/IP Adapter Development Kit (EADK) by Pyramid Solutions, Inc.. For details refer to CVE(s).This vulnerability may allow an attacker to send a specially crafted packet that may result in a denial-of-service condition of the affected products.
The indicated firmware versions are only used on products of hardware version 01.xx.xx.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2021-004</guid>
      <pubDate>Tue, 21 Jun 2022 08:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2022-056 — Weidmueller: Multiple IoT and control products affected by JavaScript injection vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2022-056</link>
      <description>&lt;p&gt;A JavaScript injection vulnerability has been discovered in the XML editing system SCHEMA ST4 onlinehelp by Quanos Solutions GmbH. For details refer to CVE.This vulnerability may allow an attacker to inject JavaScript code via URL to the affected products&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A JavaScript injection vulnerability has been discovered in the XML editing system SCHEMA ST4 onlinehelp by Quanos Solutions GmbH. For details refer to CVE.This vulnerability may allow an attacker to inject JavaScript code via URL to the affected products&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2022-056</guid>
      <pubDate>Wed, 14 Dec 2022 07:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2025-023 — Weidmueller: OpenSSL vulnerability in industrial ethernet switches</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2025-023</link>
      <description>&lt;p&gt;Multiple Weidmueller products are affected by an OpenSSL vulnerability.&lt;/p&gt;
&lt;p&gt;Weidmüller has released new firmwares of the affected products to fix the vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple Weidmueller products are affected by an OpenSSL vulnerability.&lt;/p&gt;
&lt;p&gt;Weidmüller has released new firmwares of the affected products to fix the vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2025-023</guid>
      <pubDate>Wed, 05 Mar 2025 08:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2020-041 — Weidmueller: u-create studio &lt; 1.20.2 affected by WIBU-SYSTEMS CodeMeter vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2020-041</link>
      <description>&lt;p&gt;WIBU-SYSTEMS report multiple vulnerabilities in their CodeMeter Runtime software. As part of the Weidmüller u-create studio installation the WIBU-SYSTEMS CodeMeter is installed by default. As the u-create studio installation bundle contains vulnerable versions of WIBU-SYSTEMS CodeMeter, the u-create studio is affected by a subset of these vulnerabilities. For details refer to section &amp;#34;Impact&amp;#34;.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;WIBU-SYSTEMS report multiple vulnerabilities in their CodeMeter Runtime software. As part of the Weidmüller u-create studio installation the WIBU-SYSTEMS CodeMeter is installed by default. As the u-create studio installation bundle contains vulnerable versions of WIBU-SYSTEMS CodeMeter, the u-create studio is affected by a subset of these vulnerabilities. For details refer to section &amp;#34;Impact&amp;#34;.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2020-041</guid>
      <pubDate>Mon, 12 Oct 2020 09:14:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2021-002 — Weidmueller: WI Manager affected by fdtContainer vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2021-002</link>
      <description>&lt;p&gt;A vulnerability has been discovered in the fdtCONTAINER component and application by M&amp;amp;M Software GmbH.
As this software is part of the Weidmüller FDT/DTM Software with WI Manager, this Weidmueller software is affected by the above vulnerability as well.&lt;/p&gt;
&lt;p&gt;The fdtCONTAINER component exchanges binary data blobs with the WI Manager. The WI Manager saves these binary data blobs into a project file.&lt;/p&gt;
&lt;p&gt;If an attacker gets write access to the project file, the project file can be manipulated to contain malicious code.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability has been discovered in the fdtCONTAINER component and application by M&amp;amp;M Software GmbH.
As this software is part of the Weidmüller FDT/DTM Software with WI Manager, this Weidmueller software is affected by the above vulnerability as well.&lt;/p&gt;
&lt;p&gt;The fdtCONTAINER component exchanges binary data blobs with the WI Manager. The WI Manager saves these binary data blobs into a project file.&lt;/p&gt;
&lt;p&gt;If an attacker gets write access to the project file, the project file can be manipulated to contain malicious code.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2021-002</guid>
      <pubDate>Wed, 20 Jan 2021 13:32:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2021-016 — Weidmueller: Accidentally open network port in u-controls and IoT-Gateways</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2021-016</link>
      <description>&lt;p&gt;A network port intended only for device-internal usage is accidentally accessible via external network interfaces.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A network port intended only for device-internal usage is accidentally accessible via external network interfaces.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2021-016</guid>
      <pubDate>Tue, 04 May 2021 08:17:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2021-042 — Weidmueller: Remote I/O fieldbus couplers (IP20) affected by INFRA:HALT vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2021-042</link>
      <description>&lt;p&gt;The Weidmueller Remote I/O (IP20) fieldbus couplers (u-remote) are affected by several vulnerabilities of the third-party TCP/IP Niche stack. An attacker may use crafted IP packets to cause a denial of service or breach of integrity of the affected products. Weidmueller recommends restricting network access from the internet and also locally to reduce the attack vector to a manageable minimum.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Weidmueller Remote I/O (IP20) fieldbus couplers (u-remote) are affected by several vulnerabilities of the third-party TCP/IP Niche stack. An attacker may use crafted IP packets to cause a denial of service or breach of integrity of the affected products. Weidmueller recommends restricting network access from the internet and also locally to reduce the attack vector to a manageable minimum.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2021-042</guid>
      <pubDate>Mon, 18 Oct 2021 08:24:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2021-026 — Weidmueller: Multiple vulnerabilities in Industrial WLAN devices</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2021-026</link>
      <description>&lt;p&gt;Multiple issues in Weidmueller Industrial WLAN devices have been found.&lt;/p&gt;
&lt;p&gt;Initial publication date: 2021-06-23
Update A publication date: 2021-07-02&lt;/p&gt;
&lt;p&gt;Update A&lt;/p&gt;
&lt;p&gt;CVE-2021-33534&lt;/p&gt;
&lt;p&gt;CVSS: 7.2 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)
Description: An exploitable command injection vulnerability exists in the hostname functionality of Weidmueller Industrial WLAN devices. A specially crafted entry to network configuration information can cause execution of arbitrary system commands, resulting in full control of the device. An attacker can send various requests while authenticated as a high privilege user to trigger this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple issues in Weidmueller Industrial WLAN devices have been found.&lt;/p&gt;
&lt;p&gt;Initial publication date: 2021-06-23
Update A publication date: 2021-07-02&lt;/p&gt;
&lt;p&gt;Update A&lt;/p&gt;
&lt;p&gt;CVE-2021-33534&lt;/p&gt;
&lt;p&gt;CVSS: 7.2 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)
Description: An exploitable command injection vulnerability exists in the hostname functionality of Weidmueller Industrial WLAN devices. A specially crafted entry to network configuration information can cause execution of arbitrary system commands, resulting in full control of the device. An attacker can send various requests while authenticated as a high privilege user to trigger this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2021-026</guid>
      <pubDate>Wed, 23 Jun 2021 11:04:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2025-021 — Weidmueller: Authentication Vulnerability in PROCON-WIN 5</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2025-021</link>
      <description>&lt;p&gt;Weidmüller product PROCON-WIN is affected by hard-coded credentials.&lt;/p&gt;
&lt;p&gt;Weidmüller has released a new version of the affected product to fix the vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Weidmüller product PROCON-WIN is affected by hard-coded credentials.&lt;/p&gt;
&lt;p&gt;Weidmüller has released a new version of the affected product to fix the vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2025-021</guid>
      <pubDate>Wed, 05 Mar 2025 09:00:00 +0000</pubDate>
    </item>
  </channel>
</rss>
