Advisories

Für CVSS 2.0, 3.0 und 3.2
VDE-2018-002
Mai 14, 2025, 2:28 nachm.
Critical vulnerabilities within several CPUs have been identified by security researchers. These hardware vulnerabilities allow programs to learn about the contents of a system's memory, using side-channel attacks. Potential attack …
VDE-2021-036
Mai 14, 2025, 2:28 nachm.
Please consult the CVE entries above for more details.
VDE-2024-074
Mai 14, 2025, 2:28 nachm.
A security researcher discovered that in the affected products an authenticated (administration privileges) SQL injection has been found on the administration panel allowing access to a database. The database that …
VDE-2024-009
Mai 14, 2025, 2:28 nachm.
Welotec has closed two vulnerabilities in the TK500v1 router series and advises to update the routers to firmware version r5542 or later. An exploitation of the vulnerabilities can allow an …
VDE-2020-027
Mai 14, 2025, 2:28 nachm.
The Web-Based Management (WBM) of WAGOs programmable logic controller (PLC) is typically used for administration, commissioning and updates. With special crafted requests it is possible to change some special parameters …
VDE-2020-025
Mai 14, 2025, 2:28 nachm.
The build settings of a PLCnext Engineer project (.pcwex) can be manipulated in a way that can result in the execution of remote code. The attacker needs to get access …
VDE-2021-013
Mai 14, 2025, 2:28 nachm.
The Web-Based Management (WBM) of WAGOs industrial managed switches is typically used for administration, commissioning and updates. The reported vulnerabilities allow an attacker with access to the device and the …
VDE-2020-041
Mai 14, 2025, 2:28 nachm.
WIBU-SYSTEMS report multiple vulnerabilities in their CodeMeter Runtime software. As part of the Weidmüller u-create studio installation the WIBU-SYSTEMS CodeMeter is installed by default. As the u-create studio installation bundle …