Advisories

Für CVSS 2.0, 3.0 und 3.2
VDE-2021-061
April 26, 2022, 12:00 nachm.
The software product PMC programming tool from Pilz is based on the software CODESYS Development System from CODESYS GmbH. This software is affected by several vulnerabilities, which an attacker can …
VDE-2021-054
April 26, 2022, 12:00 nachm.
Several Pilz products use Versions V2 and V3 of the CODESYS runtime system from CODESYS GmbH, which enables the execution of IEC 61131-3 PLC programs. These runtime environments contain several …
VDE-2021-047
April 26, 2022, 12:00 nachm.
Bender is publishing this advisory to inform customers about multiple security vulnerabilities in the Charge Controller product families.Bender has analysed the weaknesses and determined that the electrical safety of the …
VDE-2021-055
April 26, 2022, 12:00 nachm.
The software product PMC programming tool from Pilz is based on the software CODESYS Development System from CODESYS GmbH. This software is affected by several vulnerabilities, which an attacker can …
VDE-2022-014
Mai 22, 2025, 3:03 nachm.
Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling. For the mGuard Device …
VDE-2022-013
Mai 14, 2025, 3:00 nachm.
FL MGUARD and TC MGUARD devices are affected by a possible infinite loop within a OpenSSL library method for parsing elliptic curve parameters. This method is used on parsing cryptographic …
VDE-2022-010
Mai 22, 2025, 3:03 nachm.
PLCnext Control AXC F x152 is certified according to IEC 62443-4-1 and IEC 62443-4-2. This certification requires that all third-party components used in the firmware are regularly checked for known …
VDE-2022-008
April 7, 2022, 8:00 vorm.
Multiple issues have been found in the affected products. See CVE descriptions for details.