Advisories

For CVSS 2.0, 3.0 and 3.2
VDE-2020-002
June 5, 2025, 3:28 PM
CVS-2019-12255 Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer = 0 that leads to …
VDE-2020-001
May 22, 2025, 3:03 PM
Phoenix Contact Emalytics Controller ILC 2050 BI are developed and designed for the use in protected building automation networks.An issue was discovered on Phoenix Contact Emalytics Controller ILC 2050 BI …
VDE-2019-022
Dec. 16, 2019, 10:00 AM
The reported vulnerabilities allow a remote attacker to change the setting, delete the application, set the device to factory defaults, code execution and to cause a system crash or denial …
VDE-2019-018
May 22, 2025, 3:03 PM
Multiple issues have been found. Please check the CVEs for details.
VDE-2019-020
May 22, 2025, 3:03 PM
If MAC-based port security or 802.1x port security is enabled, the FL NAT 2xxx will unintentionally grant access to unauthorized devices in case of routed transmission. ''' Subnet 2---(Ports belonging …
VDE-2019-016
May 14, 2025, 2:28 PM
Manipulated PC Worx or Config+ projects could lead to a remote code execution due to insufficient input data validation. The attacker needs to get access to an original PC Worx …
VDE-2019-019
May 14, 2025, 3:00 PM
In case TwinCAT is configured to use the Profinet driver, a denial of service of the controller could be reached by sending special packets to the device.
VDE-2019-017
May 14, 2025, 2:28 PM
The reported vulnerability allows a remote attacker to check paths and file names that are used in filesystem operations. **Update, 18.9.2019, 18:30** * fixed typo in modelname, replaced PCF with …