Advisories

Für CVSS 2.0, 3.0 und 3.2
VDE-2021-052
Mai 22, 2025, 3:03 nachm.
PC Worx / -Express is vulnerable to a 'zip slip' style vulnerability when loading a project file.
VDE-2024-047
Mai 22, 2025, 3:03 nachm.
Nozomi reported eight vulnerabilities to WAGO affecting different firmwares installed on several devices.
VDE-2020-026
Mai 22, 2025, 3:03 nachm.
A timeout during a TLS handshake can result in the connection failing to terminate. This can result in a Niagara thread hanging and requires a manual restart to correct.
VDE-2022-051
Mai 22, 2025, 3:03 nachm.
A denial of service of the HTTPS management interface of PHOENIX CONTACT FL MGUARD and TC MGUARD devices can be triggered by a larger number of unauthenticated HTTPS connections originating …
VDE-2020-005
Mai 22, 2025, 3:03 nachm.
The coupler's function could be inhibited by an attack.
VDE-2022-045
Mai 22, 2025, 3:03 nachm.
PAS4000 is the software platform for the Automation System PSS 4000. PAS 4000 does not properly check pathnames contained in archives. An attacker can utilise this vulnerability to write arbitrary …
VDE-2020-012
Mai 22, 2025, 3:03 nachm.
The Phoenix Contact application 'PC WORX SRT' is installed as service. The installation path of the application is configured to have insecure permissions which allows any unprivileged user to write …
VDE-2018-007
Mai 22, 2025, 3:03 nachm.
An attacker may exploit a 'long cookie' related vulnerability to cause a buffer overflow that allows unauthorized access to the switches operating system files. The attacker can then insert executable …