Advisories

For CVSS 2.0, 3.0 and 3.2
VDE-2023-031
Nov. 13, 2023, 12:00 PM
The TRUMPF CAD/CAM software tools mentioned above use the vulnerable CodeMeter Runtime (up to version 7.60b) application from WIBU-SYSTEMS AG to manage licenses within the component TRUMPF License Expert. This …
VDE-2022-049
May 22, 2025, 3:03 PM
TruControl laser control software from versions 1.60.0 to 3.40.0 use a vulnerable X.Org server versions. The affected X.Org vulnerability is not validating the request length properly for the handler 'ProcXkbSetGeometry'. …
VDE-2022-023
Oct. 17, 2022, 12:00 PM
During the installation of specific TRUMPF Windows applications, privileged local users with default usernames and passwords are created. An adversary could use these users to access and compromise the affected …
VDE-2022-034
Aug. 15, 2022, 12:00 PM
A number of TRUMPF software tools use the OPC UA Server in C++ based OPC UA SDK by Unified Automation. The application contains several vulnerabilities, which enable an attacker to …
VDE-2022-016
May 2, 2022, 12:00 PM
A service function in the stated TRUMPF products is exposed without necessary authentication. Execution of this function may result in unauthorized access to, change of data or disruption of the …
VDE-2021-033
Aug. 12, 2021, 3:02 PM
VDE-2020-039
May 14, 2025, 2:36 PM
A number of TRUMPF CAD/CAM software tools use the CodeMeter Runtime application from WIBU-SYSTEMS AG to manage licences. This application contains a number of vulnerabilities, which enable an attacker to …