VDE-2022-060
Feb. 27, 2023, 12:00 nachm.
The Web-Based Management (WBM) of WAGOs programmable logic controller (PLC) is typically used for administration, commissioning and updates. The configuration backend can in some cases be used without authentication and …
VDE-2022-055
Feb. 16, 2023, 2:43 nachm.
An unknown and undocumented configuration interface with limited functionality was identified on the affected devices.
VDE-2023-001
Juni 5, 2025, 3:28 nachm.
A new LTS Firmware release fixes known vulnerabilities in used open-source libraries. In addition, the following improvements have been implemented: HMI - Hardening against DoS attacks. - Hardening against memory …
VDE-2022-059
Mai 22, 2025, 3:03 nachm.
Unquoted Windows search path vulnerability in the below mentioned Software for Windows might allow local users to gain privileges via a malicious .exe file.
VDE-2022-054
Jan. 12, 2023, 8:52 vorm.
A vulnerability in the web-based management (WBM) of WAGOs programmable logic controller (PLC) could allow an unauthenticated remote attacker to retrieve sensitive information.
VDE-2022-056
Dez. 14, 2022, 8:00 vorm.
A JavaScript injection vulnerability has been discovered in the XML editing system SCHEMA ST4 onlinehelp by Quanos Solutions GmbH. For details refer to CVE.This vulnerability may allow an attacker to …
VDE-2022-038
Okt. 1, 2025, 12:50 nachm.
A vulnerability was reported in WIBU-SYSTEMS CodeMeter Runtime. WIBU-SYSTEMS CodeMeter Runtime is part of the installation packages of several Festo products.FluidDraw < 6.2c and CIROS <= 7.0.6 contain a …
VDE-2022-057
Mai 14, 2025, 3:00 nachm.
Multiple Wiesemann & Theis product families are affected by a vulnerability in the web interface. The device allows an unauthenticated attacker to get the session ID of a logged in …