Advisories

Für CVSS 2.0, 3.0 und 3.2
VDE-2020-030
Sept. 9, 2020, 8:22 vorm.
Several vulnerabilities have been discovered in WIBU-SYSTEMS CodeMeter and published 08 September 2020. Phoenix Contact is only affected by a subset of these vulnerabilities. Phoenix Contact products are not affected …
VDE-2020-026
Mai 22, 2025, 3:03 nachm.
A timeout during a TLS handshake can result in the connection failing to terminate. This can result in a Niagara thread hanging and requires a manual restart to correct.
VDE-2020-025
Mai 14, 2025, 2:28 nachm.
The build settings of a PLCnext Engineer project (.pcwex) can be manipulated in a way that can result in the execution of remote code. The attacker needs to get access …
VDE-2020-024
Mai 14, 2025, 2:28 nachm.
For process data documentation purposes the laboratory washers, thermal disinfectors and washer-disinfectors can be integrated in a TCP/IP network by utilizing the affected communication module. The communication module is separate …
VDE-2020-023
Mai 14, 2025, 2:28 nachm.
Manipulated PC Worx projects could lead to a remote code execution due to insufficient input data validation. The attacker needs to get access to an original PC Worx project to …
VDE-2020-019
Mai 22, 2025, 3:03 nachm.
Beckhoff's TwinCAT RT network driver for Intel 8254x and 8255x is providing EtherCAT functionality. The driver implements real-time features. Except for Ethernet frames sent from real-time functionality, all other Ethernet …
VDE-2020-020
Mai 14, 2025, 2:28 nachm.
WAGO PLCs uses Linux as operating system and offers the ambitious user the opportunity to make their own modifications to expand the functionality of the PLC. For this reason the …
VDE-2020-015
Juni 10, 2020, 10:00 vorm.
The Web-Based Management (WBM) of WAGOs programmable logic controller (PLC) is typically used for administration, commissioning and updates. An attacker needs an authorized login with administrative privileges on the device …