Advisories

Für CVSS 2.0, 3.0 und 3.2
VDE-2023-048
Mai 22, 2025, 3:03 nachm.
Several Pilz products use the 3rd-party component 'libwebp' for decoding of images in WebP format. This component is affected by a vulnerability, which may enable an attacker to gain full …
VDE-2017-002
Mai 22, 2025, 3:03 nachm.
Multiple security issues and vulnerabilities in Oracle Java SE possibly affecting mGuard device manager (mdm / FL MGUARD DM) 1.8.0 and older.
VDE-2024-013
Mai 22, 2025, 3:03 nachm.
CVE-2024-24781: If the above mentioned products are loaded with Wire speed (1Gbit/s or 100Mbit/s) the resources of the Ethernet-Controller are exhausted and it must be reset by the system automatically …
VDE-2018-010
Mai 22, 2025, 3:03 nachm.
An unauthenticated user can exploit a vulnerability (CVE-2018-12981) to inject code in the WBM via reflected cross-site scripting (XSS), if he is able trick a user to open a special …
VDE-2024-050
Mai 22, 2025, 3:03 nachm.
By default, TwinCAT/BSD-based products have a device-specific web interface for web-based management (WBM) enabled, developed by Beckhoff and known as Beckhoff Device Manager UI. It can be accessed remotely or …
VDE-2024-004
Mai 22, 2025, 3:03 nachm.
The versions of TRUMPF products stated below are including a version of log4net that's prone to XXE (External XML Entities) attacks under certain circumstances. This means, the log4net code can …
VDE-2023-032
Mai 22, 2025, 3:03 nachm.
Multiple Weidmueller products are affected by recent WIBU vulnerability.
VDE-2019-020
Mai 22, 2025, 3:03 nachm.
If MAC-based port security or 802.1x port security is enabled, the FL NAT 2xxx will unintentionally grant access to unauthorized devices in case of routed transmission. ''' Subnet 2---(Ports belonging …