Advisories

For CVSS 2.0, 3.0 and 3.2
VDE-2021-051
May 22, 2025, 3:03 PM
Through specific nodes of the server configuration interface of the TwinCAT OPC UA Server administrators are able to remotely create and delete any files on the system which the server …
VDE-2023-018
May 22, 2025, 3:03 PM
Multiple vulnerabilities allow an attacker to read arbitrary files, inject commands and bypass authentication or access control. Furthermore, hardcoded session and encryption keys as well as a missing firmware update …
VDE-2021-035
May 22, 2025, 3:03 PM
Access to the Apache web server being installed as part of the FL MGUARD DM on Microsoft Windows does not require login credentials even if configured during installation.
VDE-2020-017
May 22, 2025, 3:03 PM
PACTware passwords are stored in a recoverable format (CVE-2020-9403) PACTware passwords may be modified without knowing the current password (CVE-2020-9404)
VDE-2024-054
May 22, 2025, 3:03 PM
Several vulnerabilities have been identified in the web-based management of WAGO devices utilized in Endress+Hauser IoT solutions. WAGO has provided fixes for these vulnerabilities, which have been integrated into the …
VDE-2021-059
May 22, 2025, 3:03 PM
The TCP/IP stack and of the networking component (Nucleus NET) in Nucleus Real-Time Operating System (RTOS) contain several vulnerabilities. Nucleus NET is utilized by BLUEMARK X1 / LED / CLED. …
VDE-2023-026
May 22, 2025, 3:03 PM
Multiple WAGO devices are prone to vulnerabilites in the used CODESYS V3 framework.
VDE-2022-026
May 22, 2025, 3:03 PM
ProConOS/ProConOS eCLR insufficiently verifies uploaded data.