Advisories

For CVSS 2.0, 3.0 and 3.2
VDE-2021-045
Aug. 26, 2025, 12:00 PM
The affected product families are cameras SBOC/SBOI and the Controller SBRD. The vulnerabilities are located within the Ethernet IP Stack from EIPStackGroup OpENer Ethernet/IP.
VDE-2022-022
Aug. 26, 2025, 12:00 PM
The Festo controller CECC product family is affected by multiple vulnerabilities in the CODESYS V3 runtime.
VDE-2025-076
Aug. 26, 2025, 9:00 AM
A hard-coded JWT secret in the egOS WebGUI backend is readable to the default user, allowing attackers to forge valid tokens and access protected API endpoints.
VDE-2025-067
Aug. 25, 2025, 12:00 PM
Motherbox 3 with firmware 1.44 to 1.48 allows an unauthenticated remote attacker read-only access to the internal DB with measurement values from other W&T sensor devices.
VDE-2025-050
Aug. 19, 2025, 12:00 PM
A security researcher discovered a data disclosure vulnerability in Sunny Portal powered by ennexOS, ennexos.sunnyportal.com. A regularly authenticated user can receive the name of an other registered Sunny Portal user …
VDE-2025-063
Aug. 12, 2025, 12:00 PM
A privilege escalation vulnerability exists in Phoenix Contact Device and Update Management prior to version 2025.3.1 due to misconfigured permissions on nssm.exe in the DAUM-WINDOWS-SERVICE. This misconfiguration allows a low-privileged …
VDE-2025-028
Aug. 5, 2025, 12:00 PM
A security vulnerability was identified in the ICMHelper service running on the system of an ICM installation. A low privileged local attacker could exploit this vulnerability to issue OS commands …
VDE-2025-049
Aug. 4, 2025, 12:00 PM
On certain operating systems (e.g., Linux), default file system permissions may allow read access to the files of the CODESYS Control runtime system for non-administrator users. The documentation provided with …