Advisories

Für CVSS 2.0, 3.0 und 3.2
VDE-2024-042
Aug. 17, 2023, 2:00 nachm.
Several Red Lion Europe products are vulnerable to a possible race condition vulnerability in OpenSSH named "regreSSHion".
VDE-2023-012
Aug. 17, 2023, 2:00 nachm.
A stored XXS vulnerability has been found in mbNET and mbNET/.rokey in all versions before 7.3.2.
VDE-2023-029
Aug. 17, 2023, 2:00 nachm.
A stored XXS vulnerability has been found in REX 200 and REX 250 in all versions before 7.3.2.
VDE-2023-027
Aug. 7, 2023, 11:35 vorm.
A reflected cross-site scripting vulnerability exists in the System Diagnostics Manager (SDM) component of SIMA² Master Stations.
VDE-2023-025
Aug. 3, 2023, 1:18 nachm.
The CODESYS Control V3 runtime system does not restrict the memory accesses of the PLC application code to the PLC application data and does not sufficiently check the integrity of …
VDE-2023-023
Aug. 3, 2023, 1:08 nachm.
The CODESYS Development System does not limit the number of attempts to guess the password within an import dialog.
VDE-2023-022
Aug. 3, 2023, 12:52 nachm.
The Notification Center of the CODESYS Development System receives messages without ensuring that the message was not modified during transmission. This finally enables MITMs code execution when the user clicks …
VDE-2023-021
Aug. 3, 2023, 12:48 nachm.
The CODESYS Development System is vulnerable to the execution of malicious binaries from the current working directory.