Advisories

For CVSS 2.0, 3.0 and 3.2
VDE-2022-046
May 22, 2025, 3:03 PM
UPDATE A: Two devices (ENERGY AXC PU, SMARTRTU AXC SG) added (24.11.2022) Update for PLCnext Firmware containing fixes for recent vulnerability findings in Linux components and security enhancements. PLCnext Control …
VDE-2022-043
Nov. 7, 2022, 1:14 PM
Multiple Wiesemann & Theis product families are affected by multiple vulnerabilities in the web interface.
VDE-2022-049
May 22, 2025, 3:03 PM
TruControl laser control software from versions 1.60.0 to 3.40.0 use a vulnerable X.Org server versions. The affected X.Org vulnerability is not validating the request length properly for the handler 'ProcXkbSetGeometry'. …
VDE-2022-023
Oct. 17, 2022, 12:00 PM
During the installation of specific TRUMPF Windows applications, privileged local users with default usernames and passwords are created. An adversary could use these users to access and compromise the affected …
VDE-2022-040
Sept. 22, 2023, 2:39 PM
UPDATE A: Solution has updated release datesUPDATE B: Solution has updated release datesThis Advisory is published with reference to: CODESYS Advisory 2022-11 (Security update for CODESYS Control V2) CODESYS Advisory …
VDE-2022-042
Oct. 17, 2022, 10:00 AM
The MAC address filter as part of the firewall has a flaw, which prevents the MAC address filter to be active after restart. In this way a remote attacker is …
VDE-2022-047
Oct. 12, 2022, 10:00 AM
The FTP server does not properly release memory resources that were reserved for incomplete connection attempts by FTP clients. This could allow a remote attacker to generate a denial of …
VDE-2022-029
May 14, 2025, 3:00 PM
The UWP 3.0 family of Monitoring Gateways and Controllers and the CPY Car Park Server are affected by multiple vulnerabilities in their set-up software, runtime firmware, embedded Web interface.