VDE-2025-039
Juli 1, 2025, 12:00 nachm.
The Pilz industrial PC IndustrialPI webstatus application is vulnerable to an authentication bypass.
VDE-2025-046
Juni 30, 2025, 12:00 nachm.
PiCtory, a web application to configure the Pilz industrial PC IndustrialPI, has three vulnerabilities with varying degrees of severity. The first two are of critical severity and can lead to …
VDE-2024-061
Juni 30, 2025, 12:00 nachm.
A vulnerability has been disclosed in PLC ifm AC4xxS that allows an attacker to trigger the safety state with the help of a specially crafted html request. This leads to …
VDE-2025-043
Juni 25, 2025, 12:00 nachm.
A security vulnerability was discovered in the PLC Designer V4 in the version 4.0.0 where the programmer of a Controller can set a password for the connected device. Here it …
VDE-2025-037
Juni 24, 2025, 12:00 nachm.
The mb24api endpoint reachable when connected via VPN is missing authentication for sensitive functions. This can lead to information disclosure of user- and device names and to DoS.
VDE-2025-035
Juni 24, 2025, 12:00 nachm.
Two vulnerabilities in mbCONNECT24/mymbCONNECT24 can lead to user enumeration an password bypass.
VDE-2025-038
Juni 24, 2025, 12:00 nachm.
Two vulnerabilities in myREX24/myREX24.virtual can lead to user enumeration an password bypass.
VDE-2025-034
Juni 24, 2025, 12:00 nachm.
The mb24api endpoint reachable when connected via VPN is missing authentication for sensitive functions. This can lead to information disclosure of user- and device names and to DoS.