Advisories

Für CVSS 2.0, 3.0 und 3.2
VDE-2024-075
Juni 17, 2025, 8:00 vorm.
A security researcher discovered that in the affected products a clickjacking vulnerability in the web frontend exists. An attacker could lure the user to click on a malicious website which …
VDE-2025-001
Juni 5, 2025, 3:31 nachm.
The CODESYS Key USB dongle, which is based on WIBU CodeMeter technology, is affected by a physical side-channel vulnerability.
VDE-2024-070
Mai 14, 2025, 3:00 nachm.
Improper file permission handling allows an authenticated low privileged user to gain root access.
VDE-2025-005
Mai 14, 2025, 3:00 nachm.
A vulnerability has been found in a cryptographic library of Infineon Technologies that is part of the firmware of the CmDongles. The exploitation of this vulnerability has been classified as …
VDE-2024-073
Mai 22, 2025, 3:03 nachm.
Multiple Linux component vulnerabilities fixed in latest PLCnext Firmware release 2024.0.6 LTS
VDE-2024-071
Mai 22, 2025, 3:03 nachm.
Multiple Linux component vulnerabilities fixed in latest PLCnext Firmware release 2024.0.6 LTS
VDE-2024-072
Dez. 3, 2024, 12:00 nachm.
The following firmware versions installed on several devices are vulnerable due to a vulnerability in the CODESYS Control V3 web server.
VDE-2024-059
Dez. 3, 2024, 3:00 nachm.
An unauthenticated attacker would be able to send crafted requests to cause the CODESYS Gateway Server V2 to allocate excessive memory or consume all available TCP client connections. Besides, passwords …