Advisories

Für CVSS 2.0, 3.0 und 3.2
VDE-2024-031
Mai 14, 2025, 3:00 nachm.
The data24 service that is bundled with every installation of myREX24 V2/myREX24.virtual has two serious flaws in core components. These combined can lead to a complete loss of confidentiality, integrity …
VDE-2020-029
Mai 14, 2025, 3:00 nachm.
The Web-Based Management (WBM) of WAGOs programmable logic controller (PLC) is typically used for administration, commissioning and updates. The SNMP configuration page of the device is vulnerable for a persistent …
VDE-2020-028
Mai 14, 2025, 3:00 nachm.
The Web-Based Management (WBM) of WAGOs programmable logic controller (PLC) is typically used for administration, commissioning and updates. With special crafted requests it is possible to change some special parameters …
VDE-2021-028
Mai 14, 2025, 3:00 nachm.
Critical vulnerabilities have been discovered in the utilized component TRECK TCP/IP Stack by Digi International Inc. For more information see advisory by Digi International Inc.: Digi International Security Notice - …
VDE-2024-067
Mai 14, 2025, 3:00 nachm.
Vulnerabilities in .NET and Visual Studio functions System.Text.Json, System.Formats.Asn1, OPCFoundation.NetStandard.Opc.Ua.Core allow an remote attacker to execute a Denial-of-Servce attack.
VDE-2019-003
Mai 14, 2025, 3:00 nachm.
Multiple vulnerabilities for MEVIEW3 have been identified in PHOENIX CONTACT MEVIEW3, versions below 3.14.25 and 3.15.18
VDE-2018-003
Mai 14, 2025, 3:00 nachm.
Several CPUs manufactured by Intel, AMD or based on ARM technology may leak information due to their internal operation if attacked by specifically written software executed on the affected systems. …
VDE-2024-026
Mai 14, 2025, 3:00 nachm.
The CODESYS OPC UA stack of the CODESYS Control runtime system may incorrectly calculate the required buffer size for received requests/responses. This can lead to a crash of the CODESYS …