Advisories

For CVSS 2.0, 3.0 and 3.2
VDE-2020-025
May 14, 2025, 2:28 PM
The build settings of a PLCnext Engineer project (.pcwex) can be manipulated in a way that can result in the execution of remote code. The attacker needs to get access …
VDE-2020-024
May 14, 2025, 2:28 PM
For process data documentation purposes the laboratory washers, thermal disinfectors and washer-disinfectors can be integrated in a TCP/IP network by utilizing the affected communication module. The communication module is separate …
VDE-2020-023
May 14, 2025, 2:28 PM
Manipulated PC Worx projects could lead to a remote code execution due to insufficient input data validation. The attacker needs to get access to an original PC Worx project to …
VDE-2020-019
May 22, 2025, 3:03 PM
Beckhoff's TwinCAT RT network driver for Intel 8254x and 8255x is providing EtherCAT functionality. The driver implements real-time features. Except for Ethernet frames sent from real-time functionality, all other Ethernet …
VDE-2020-020
May 14, 2025, 2:28 PM
WAGO PLCs uses Linux as operating system and offers the ambitious user the opportunity to make their own modifications to expand the functionality of the PLC. For this reason the …
VDE-2020-015
June 10, 2020, 10:00 AM
The Web-Based Management (WBM) of WAGOs programmable logic controller (PLC) is typically used for administration, commissioning and updates. An attacker needs an authorized login with administrative privileges on the device …
VDE-2020-018
June 2, 2020, 10:42 AM
FL MGUARD, TC MGUARD, TC ROUTER and TC CLOUD CLIENT devices are affected by a buffer overflow vulnerability within the PPP service. The PPP service is not active by default, …
VDE-2020-017
May 22, 2025, 3:03 PM
PACTware passwords are stored in a recoverable format (CVE-2020-9403) PACTware passwords may be modified without knowing the current password (CVE-2020-9404)