Advisories

For CVSS 2.0, 3.0 and 3.2
VDE-2025-061
Sept. 8, 2025, 9:00 AM
Bender is publishing this advisory to inform customers about a security vulnerability in the Charge Controller product families. Bender has analyzed the weakness and determined that the electrical safety of …
VDE-2025-084
Sept. 8, 2025, 9:00 AM
Bender is publishing this advisory to inform customers about a security vulnerability in the Charge Controller product families. Bender has analyzed the weakness and determined that the electrical safety of …
VDE-2025-048
Sept. 8, 2025, 9:00 AM
A design flaw in the file system management exposes internal system partitions - intended to be hidden - during brief moments when they are mounted by the firmware. These partitions …
VDE-2025-070
Sept. 1, 2025, 12:00 PM
A vulnerability in the CODESYS Control runtime system's CmpDevice component allows unauthenticated attackers to cause a denial-of-service (DoS) via specially crafted communication requests. The issue is triggered by a NULL …
VDE-2025-051
Sept. 1, 2025, 12:00 PM
A vulnerability in the CODESYS Control runtime system allows low-privileged remote attackers to access the PKI folder via CODESYS protocol, enabling them to read and write certificates and keys. This …
VDE-2025-078
Aug. 29, 2025, 12:00 PM
The TRUMPF remote support infrastructure selects an outdated encryption algorithm when setting up communication channels for machines. This cannot be prevented for old machines. For most machines it is possible …
VDE-2024-056
Aug. 27, 2025, 12:00 PM
Multiple vulnerabilities have been discovered in MB connect line mbNET.mini product allowing for RCE or unauthorized file access.
VDE-2025-011
Aug. 27, 2025, 12:00 PM
A stored cross-site scripting vulnerability has been discovered in the profinet gateway LB8122A.1.EL. An attacker can write an HTML tag with up to 32 characters in the message field of …