Advisories

For CVSS 2.0, 3.0 and 3.2
VDE-2024-044
May 14, 2025, 2:28 PM
Several Helmholz products are vulnerable to a possible race condition vulnerability in OpenSSH named "regreSSHion".
VDE-2024-068
May 14, 2025, 2:28 PM
Multiple vulnerabilities have been discovered in MB connect line products that could allow RCE or unauthorized file access. CVE-2024-45272 affects the mbCONNECT24 and mymbCONNECT24 products, while CVE-2024-45273 affects the mbNET/mbNET.rokey, …
VDE-2025-029
May 14, 2025, 2:28 PM
A denial of service (DoS) attack targeting port 80 (http service) can overload the device (CWE-770). This behaviour has been observed when running network security scanners.
VDE-2024-009
May 14, 2025, 2:28 PM
Welotec has closed two vulnerabilities in the TK500v1 router series and advises to update the routers to firmware version r5542 or later. An exploitation of the vulnerabilities can allow an …
VDE-2025-009
May 14, 2025, 2:28 PM
Several WAGO Firmwares are vulnerable to an incorrect calculation of the buffer size in the CODESYS OPC UA STACK. This can lead to a crash of the runtime of the …
VDE-2020-046
May 14, 2025, 2:28 PM
For mGuard devices with integrated switch on the LAN side, single switch ports can be disabled by device configuration. After a reboot these ports get functional independent from their configuration …
VDE-2019-016
May 14, 2025, 2:28 PM
Manipulated PC Worx or Config+ projects could lead to a remote code execution due to insufficient input data validation. The attacker needs to get access to an original PC Worx …
VDE-2018-016
May 14, 2025, 2:28 PM
An attacker may gain access (by elevated privileges) to CT50-Ex mobile computers through a vulnerability in a system service running the Android Operating System (OS). The system service improperly validates …