Advisories

Für CVSS 2.0, 3.0 und 3.2
VDE-2022-012
Mai 16, 2022, 4:15 nachm.
Critical vulnerabilities have been discovered in the utilized component Remote Desktop Client by Microsoft.For more information see: https://msrc.microsoft.com/update-guide/vulnerability/CVE- 2022-21990
VDE-2021-061
April 26, 2022, 12:00 nachm.
The software product PMC programming tool from Pilz is based on the software CODESYS Development System from CODESYS GmbH. This software is affected by several vulnerabilities, which an attacker can …
VDE-2021-054
April 26, 2022, 12:00 nachm.
Several Pilz products use Versions V2 and V3 of the CODESYS runtime system from CODESYS GmbH, which enables the execution of IEC 61131-3 PLC programs. These runtime environments contain several …
VDE-2021-047
April 26, 2022, 12:00 nachm.
Bender is publishing this advisory to inform customers about multiple security vulnerabilities in the Charge Controller product families.Bender has analysed the weaknesses and determined that the electrical safety of the …
VDE-2021-055
April 26, 2022, 12:00 nachm.
The software product PMC programming tool from Pilz is based on the software CODESYS Development System from CODESYS GmbH. This software is affected by several vulnerabilities, which an attacker can …
VDE-2022-014
Mai 22, 2025, 3:03 nachm.
Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling. For the mGuard Device …
VDE-2022-013
Mai 14, 2025, 3:00 nachm.
FL MGUARD and TC MGUARD devices are affected by a possible infinite loop within a OpenSSL library method for parsing elliptic curve parameters. This method is used on parsing cryptographic …
VDE-2022-010
Mai 22, 2025, 3:03 nachm.
PLCnext Control AXC F x152 is certified according to IEC 62443-4-1 and IEC 62443-4-2. This certification requires that all third-party components used in the firmware are regularly checked for known …