Advisories

For CVSS 2.0, 3.0 and 3.2
VDE-2024-016
May 22, 2025, 3:03 PM
The affected products and versions present a vulnerability due to a vulnerable integrated software component the docker runc <= 1.1.11. In the worst-case scenario, the integrated Docker container environment …
VDE-2024-003
May 22, 2025, 3:03 PM
The TRUMPF products that are listed above contain a vulnerable version of Notepad++. This version isbeing installed for support purposes only, so there is no danger of triggering this vulnerability …
VDE-2019-018
May 22, 2025, 3:03 PM
Multiple issues have been found. Please check the CVEs for details.
VDE-2021-060
May 22, 2025, 3:03 PM
Apache Log4j is used for logging events in WAGO Smart Script in Version 4.2 and higher. Events logged by Log4j can contain JNDI references. An attacker who can control log …
VDE-2021-041
May 22, 2025, 3:03 PM
Critical vulnerabilities have been discovered in the utilized component log4net by Apache Software Foundation. UPDATE A: Remediation: added fixed VisuNet Products
VDE-2020-001
May 22, 2025, 3:03 PM
Phoenix Contact Emalytics Controller ILC 2050 BI are developed and designed for the use in protected building automation networks.An issue was discovered on Phoenix Contact Emalytics Controller ILC 2050 BI …
VDE-2025-002
May 22, 2025, 3:03 PM
An unauthenticated attacker could repeatedly send IPv6 packets, that include specially crafted packets, to a Windows machine which could enable remote code execution.
VDE-2022-046
May 22, 2025, 3:03 PM
UPDATE A: Two devices (ENERGY AXC PU, SMARTRTU AXC SG) added (24.11.2022) Update for PLCnext Firmware containing fixes for recent vulnerability findings in Linux components and security enhancements. PLCnext Control …