Advisories

For CVSS 2.0, 3.0 and 3.2
VDE-2023-048
May 22, 2025, 3:03 PM
Several Pilz products use the 3rd-party component 'libwebp' for decoding of images in WebP format. This component is affected by a vulnerability, which may enable an attacker to gain full …
VDE-2017-002
May 22, 2025, 3:03 PM
Multiple security issues and vulnerabilities in Oracle Java SE possibly affecting mGuard device manager (mdm / FL MGUARD DM) 1.8.0 and older.
VDE-2024-013
May 22, 2025, 3:03 PM
CVE-2024-24781: If the above mentioned products are loaded with Wire speed (1Gbit/s or 100Mbit/s) the resources of the Ethernet-Controller are exhausted and it must be reset by the system automatically …
VDE-2018-010
May 22, 2025, 3:03 PM
An unauthenticated user can exploit a vulnerability (CVE-2018-12981) to inject code in the WBM via reflected cross-site scripting (XSS), if he is able trick a user to open a special …
VDE-2024-050
May 22, 2025, 3:03 PM
By default, TwinCAT/BSD-based products have a device-specific web interface for web-based management (WBM) enabled, developed by Beckhoff and known as Beckhoff Device Manager UI. It can be accessed remotely or …
VDE-2024-004
May 22, 2025, 3:03 PM
The versions of TRUMPF products stated below are including a version of log4net that's prone to XXE (External XML Entities) attacks under certain circumstances. This means, the log4net code can …
VDE-2023-032
May 22, 2025, 3:03 PM
Multiple Weidmueller products are affected by recent WIBU vulnerability.
VDE-2019-020
May 22, 2025, 3:03 PM
If MAC-based port security or 802.1x port security is enabled, the FL NAT 2xxx will unintentionally grant access to unauthorized devices in case of routed transmission. ''' Subnet 2---(Ports belonging …