Advisories

Für CVSS 2.0, 3.0 und 3.2
VDE-2021-056
Mai 22, 2025, 3:03 nachm.
Multiple vulnerabilities were reported in CODESYS 2.3 Runtime. The CODESYS 2.3 Runtime is an essential component in several WAGO PLCs. All vulnerable PLCs are listed in chapter 'Affected Products'. https://www.codesys.com/security/security-reports.html
VDE-2021-046
Nov. 10, 2021, 8:23 vorm.
Cross-site scripting in web-based management and memory leak in the remote logging function of FL MGUARD 1102 and FL MGUARD 1105. CVE-2021-34582: The file upload functionality in the web-based management …
VDE-2021-052
Mai 22, 2025, 3:03 nachm.
PC Worx / -Express is vulnerable to a 'zip slip' style vulnerability when loading a project file.
VDE-2021-035
Mai 22, 2025, 3:03 nachm.
Access to the Apache web server being installed as part of the FL MGUARD DM on Microsoft Windows does not require login credentials even if configured during installation.
VDE-2021-029
Mai 14, 2025, 2:28 nachm.
A device on the same network as the controller sending a special crafted JSON request to the /auth/access-token endpoint may cause the controller to restart (CWE-20). UPDATE A The CVSS …
VDE-2021-032
Mai 22, 2025, 3:03 nachm.
Third party Niche Ethernet stack has several vulnerabilities announced by the security researcher's community. Phoenix Contact Classic Line industrial controllers are developed and designed for the use in closed industrial …
VDE-2021-036
Mai 14, 2025, 2:28 nachm.
Please consult the CVE entries above for more details.
VDE-2021-025
Mai 14, 2025, 2:28 nachm.
A Denial of Service and a CA Check Problem have been identified in multiple openSSL 1.1.1 versions, which are utilized in the Phoenix Contact products listed above.