Výsledky hledání

téma: průmyslové systémy× v celém archivu zrušit filtry

116 karet z 126 položek · strana 2 z 2 CZ · EN/orig

1

[Control Systems] Siemens security advisory (AV26-864)

Serial Number: AV26-864Date: August 31, 2026 As of August 27, 2026, Siemens is affected by a vulnerability in the following products: Element maps-ng V47 Prior to V47.12.3 Element maps-ng V48 Prior to V48.11.3 Element maps-ng V49 Prior to V49.16.1 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. SSA-682041 CERT Services | Siemens

Siemens CA

tg: zranitelnost tp: průmyslové systémy

· Cyber Centre Kanada · [Control Systems] Siemens security advisory (AV26-864)

1

[Control Systems] National Instruments security advisory (AV26-856)

Serial Number: AV26-856Date: August 28, 2026 As of August 25, 2026, National Instruments is affected by vulnerabilities in the following product: LabVIEW Prior to 23.0.0 Prior to 23.3.10 Prior to 24.3.7 Prior to 25.3.5 Prior to 26.3.1 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Memory Corruption Vulnerabilities in NI LabVIEW - NI Integer Conversion Vulnerability Resulting in an Out of Bounds Read…

National Instruments výroba a průmysl energetika vodárenství telekomunikace CA

tg: zranitelnost tp: průmyslové systémy

· Cyber Centre Kanada · [Control Systems] National Instruments security advisory (AV26-856)

2

Murrelektronik: Vulnerability in 'Copy learned MAC Addresses' function enables MAC Spoofing on Xelity Switches

[VDE-2026-061] An information disclosure vulnerability in the web GUI of Murrelektronik Xelity switches causes MAC addresses from the device's MAC address table to be written into a server-side log that is exposed via the device's web interface to unauthenticated users. The leak is triggered when an authenticated administrator invokes the 'Copy learned MAC Addresses' function, which causes a syslog error that inserts the affected MAC addresses into the log output. Once the error has been…

EPSS 0.00 CVE-2026-8173 Murrelektronik výroba a průmysl DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · Murrelektronik: Vulnerability in 'Copy learned MAC Addresses' function enables MAC Spoofing on Xelity Switches

Weidmueller: Security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by multiple vulnerabilities

[VDE-2026-083] Weidmueller security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by an unauthenticated remote code execution vulnerability. IE-SR-2TX-WL-4G routers are also affected by a SMS password authorization bypass vulnerability. Weidmueller has released new firmware versions of the affected products to fix the vulnerabilities.

EPSS 0.01 CVE-2026-63586 CVE-2026-63587 Weidmüller DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · Weidmueller: Security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by multiple vulnerabilities

1

Frauscher: FDS102 for FAdC/FAdCi R2 has multiple vulnerabilities

[VDE-2026-078] Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2 is vulnerable to Unrestricted Upload of File with Dangerous Type, Path Traversal: '../filedir', Insertion of Sensitive Information into Log File, Incorrect Authorization, Insufficient Session Expiration, Cross-Site Request Forgery (CSRF), Missing Authentication for Critical Function, and Missing Authorization.

EPSS 0.01 CVE-2026-14946 CVE-2026-14947 CVE-2026-14948 CVE-2026-14949 CVE-2026-14950 CVE-2026-14951 CVE-2026-14952 CVE-2026-14953 Frauscher Sensortechnik doprava DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · Frauscher: FDS102 for FAdC/FAdCi R2 has multiple vulnerabilities

1

New Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cycles

You can’t patch everything. So what do you fix first? Findings in Q2 2026 have changed traditional answers.The latest Quarterly Threat Landscape Report from Rapid7 Labs shows vulnerability disclosures still surging while attackers use automation and AI-assisted tooling to compress the time between disclosure and exploitation. The gap that patch cycles were built to fill is closing. Speed and volume are overwhelming security teams that have relied on traditional patch cycles and reactive…

CVSS 7.0 Microsoft veřejná správa finance zdravotnictví výroba a průmysl US

tg: rozbor tp: ransomware tp: AI tp: špionáž tp: průmyslové systémy

· Rapid7 · New Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cycles

1

Phoenix Contact: Improper Input Validation Vulnerabilities in PLCnext Firmware

[vde-2025-056] This advisory addresses multiple security vulnerabilities in PLCnext firmware versions prior to 2026.0.3. The vulnerabilities may allow unauthenticated attackers to cause denial of service, trigger unexpected system behavior, or execute unauthorized SQL queries. Successful exploitation could impact the availability, integrity, and confidentiality of affected PLCnext Control devices. All issues are resolved in PLCnext firmware version 2026.0.3.

EPSS 0.01 CVE-2025-41769 CVE-2025-41770 CVE-2025-41771 Phoenix Contact DE

tg: zranitelnost tg: novinka v produktu tp: průmyslové systémy

· CERT@VDE · Phoenix Contact: Improper Input Validation Vulnerabilities in PLCnext Firmware

1

1

Pilz: Multiple Vulnerabilities affecting industrial PC IndustrialPI

[PPSA-2026-003] The Linux kernel used in the IndustrialPI, 'linux-image-revpi-v8', prior to version 6.12.91-revpi0-rpi-v8 contains multiple vulnerabilities. Successful exploitation of these vulnerabilities can give an attacker full control over the device.

KEV ✓ EPSS 1.00 CVE-2026-31431 CVE-2026-43284 CVE-2026-46300 Pilz výroba a průmysl DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · Pilz: Multiple Vulnerabilities affecting industrial PC IndustrialPI

2

3rd August – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Minnesota IT Services has confirmed coordinated cyberattacks affecting more than 30 community water utilities across the state. The incidents briefly disrupted a treatment plant in Braham and affected industrial control systems. Officials reported that drinking water safety was not affected. While the attack was not officially attributed, federal…

KEV ✓ · ransomware EPSS 0.87 CVSS 9.8 CVE-2026-20316 CVE-2026-42897 CVE-2026-59309 CVE-2026-59310 CVE-2026-59726 CVE-2026-63077 CVE-2026-66066 Cisco Broadcom JetBrains Microsoft vodárenství finance zdravotnictví telekomunikace IL

tg: incident tg: zranitelnost tg: přehled tp: phishing tp: únik dat tp: AI tp: průmyslové systémy

· Check Point Research · 3rd August – Threat Intelligence Report

3

Canada’s Bill C-8 is here: Why the 72-hour reporting rule will redefine critical infrastructure security

Canada’s new Critical Cyber Systems Protection Act (Bill C-8) introduces a strict 72-hour cyber incident reporting mandate. Find out how Tenable is helping critical national infrastructure operators bridge the IT/OT divide to ensure full compliance.Key takeaways:Bill C-8 introduces stringent new cyber incident reporting requirements and heavy financial penalties for critical infrastructure operators. Eliminating network blind spots with a hybrid IT/OT discovery approach, including Safe Active…

Tenable telekomunikace energetika doprava finance US

tg: regulace tg: návod tg: propagace tp: průmyslové systémy

· Tenable Research · Canada’s Bill C-8 is here: Why the 72-hour reporting rule will redefine critical infrastructure security

Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

[VDE-2026-008] Multiple vulnerabilities have been identified in the firmware of CHARX SEC-3xxx EV charging controllers, including the CHARX SEC-3000, SEC-3050, SEC-3100, and SEC-3150 models. The flaws could allow attackers to compromise the devices remotely, resulting in a complete loss of confidentiality, integrity, and availability.

Phoenix Contact energetika doprava DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · Phoenix Contact: Multiple vulnerabilities in the firmware of CHARX SEC3xxx charging controllers

SPOJENO PŘES CVE ZDI-26-522: Phoenix Contact CHARX SEC-3000 Insertion of Sensitive Information into Log File Information Disclosure Vulnerability

This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Phoenix Contact CHARX SEC-3000 devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.5. The following CVEs are assigned: CVE-2026-41032.

EPSS 0.00 CVSS 6.5 CVE-2026-41032 Phoenix Contact US DE

tg: zranitelnost tp: průmyslové systémy

· Zero Day Initiative · ZDI-26-522: Phoenix Contact CHARX SEC-3000 Insertion of Sensitive Information into Log File Information Disclosure Vulnerability · CERT@VDE · Phoenix Contact: Unauthenticated log download vulnerability in the firmware of CHARX SEC-3xxx charging controllers

1

CODESYS PROFINET Controller - Out-of-bounds Write

[Advisory2026-06_VDE-2026-041] CODESYS PROFINET is an add‑on for the CODESYS Development System that provides a fully integrated PROFINET protocol stack along with diagnostic capabilities. When a PROFINET Controller is configured, this vulnerable protocol stack is downloaded to and executed by CODESYS Control runtime systems. The vulnerability in the CODESYS PROFINET Controller is caused by an out‑of‑bounds write during the processing of received invalid PROFINET communication data. Triggering…

EPSS 0.00 CVE-2026-35226 CODESYS DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · CODESYS PROFINET Controller - Out-of-bounds Write

2

SPOJENO PŘES CVE ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

[VDE-2026-076] The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.

EPSS 0.03 CVE-2025-68160 CVE-2025-69418 CVE-2025-69419 CVE-2025-69420 CVE-2025-69421 CVE-2026-14167 CVE-2026-14168 CVE-2026-14169 CVE-2026-14171 CVE-2026-22795 CVE-2026-22796 CVE-2026-2291 CVE-2026-40510 CVE-2026-4893 CVE-2026-5172 ads-tec Industrial IT Weidmüller DE

tg: zranitelnost tg: novinka v produktu tp: průmyslové systémy

· CERT@VDE · ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products

2

27th July – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Nichirei, a Japan-based frozen-food supplier and logistics company, has experienced a ransomware attack that disrupted shipping operations and affected approximately 5,000 customers. KFC Japan warned of possible shortages. Nichirei confirmed personal data theft, while the RansomHouse group claimed responsibility and published a subset of the stolen…

KEV ✓ EPSS 0.85 CVE-2025-66376 CVE-2026-16232 CVE-2026-50522 Check Point Oracle Microsoft Zimbra energetika vodárenství doprava veřejná správa IL

tg: incident tg: zneužíváno tg: přehled tp: ransomware tp: únik dat tp: AI tp: průmyslové systémy

· Check Point Research · 27th July – Threat Intelligence Report

Lenze: Incorrect signature validation in the enable SSH routine

[VDE-2026-077] The affected products belong to the Controller or Servo Drive product family and contain a vulnerability in a security-critical activation mechanism for service access. The signature verification of a file used for SSH activation can be compromised, which could allow unauthorized access to the device.

EPSS 0.00 CVE-2026-14837 Lenze výroba a průmysl DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · Lenze: Incorrect signature validation in the enable SSH routine

1

Iran War Cyber Threat Landscape | A Midyear Assessment on What Matters

In April, SentinelLABS’ Tom Hegel published an initial assessment of the first five weeks of the conflict. Three months later, the evidence supports refinement. Executive Summary The cyber risk remains quieter than the public narrative. It rests on persistent access, trusted administration, service-provider pathways, selective disruption, and personas that magnify technical effects. Iran-linked activity is not a single threat set. MOIS, the IRGC Intelligence Organization, the IRGC Cyber…

US

tg: rozbor tp: AI tp: špionáž tp: průmyslové systémy

· SentinelLabs · Iran War Cyber Threat Landscape | A Midyear Assessment on What Matters

1

1

1

Several Murrelektronik Devices use Default SNMP Community Names

[VDE-2026-062] Several Murrelektronik devices using Profinet are shipped with the default SNMP community names ('public' for read access and 'private' for write access). If these community strings remain unchanged in the field, an unauthenticated attacker with network access to the device can read its configuration and, depending on the writable OIDs, modify device settings.

EPSS 0.27 CVE-1999-0517 Murrelektronik DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · Several Murrelektronik Devices use Default SNMP Community Names

2

CODESYS EtherNetIP - Improper timeout handling

[Advisory2026-04_VDE-2026-040] CODESYS EtherNet/IP is an add‑on for the CODESYS Development System that provides a fully integrated EtherNet/IP protocol stack along with diagnostic capabilities. A flaw in the EtherNet/IP adapter protocol stack library results in a vulnerability within the generated application code. When an EtherNet/IP adapter is configured, this vulnerable protocol stack is downloaded to and executed by CODESYS Control runtime systems. Under certain non‑standard operating…

EPSS 0.00 CVE-2026-35225 CODESYS DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · CODESYS EtherNetIP - Improper timeout handling

WAGO: Early-Boot Diagnostic Exposure in WAGO System I/O Field Devices

[VDE-2026-031] Certain devices in the WAGO System I/O Field series enable an internal diagnostic capability during the initial stages of system startup. This behavior, which is not part of the publicly documented feature set, briefly allows access to system functions before the main operating environment becomes fully active. Under specific conditions, this could permit interactions with system components that are normally protected during regular operation.

EPSS 0.01 CVE-2026-4769 WAGO DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · WAGO: Early-Boot Diagnostic Exposure in WAGO System I/O Field Devices

1

JUMO: Allegro RomPager webserver vulnerability in JUMO mTRONT, DICON touch, AQUIS touch devices

[VDE-2026-071] Multiple products from JUMO are affected by webserver vulnerability "CVE-2013-6786, CVE-2014-9222, CVE-2014-9223. This vulnerability leads to DOS of the device by using a misfortune cookie and reflected XSS attacks.

EPSS 0.64 CVE-2013-6786 CVE-2014-9222 CVE-2014-9223 JUMO Allegro DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · JUMO: Allegro RomPager webserver vulnerability in JUMO mTRONT, DICON touch, AQUIS touch devices

2

MBS: Several security vulnerabilities in the UGW web GUI

[VDE-2026-039] The MBS Universal Gateways (UGW-A-Series, UGW-X-Series) connect devices using various digital communication protocols within the field of building automation. Several security vulnerabilities have been identified in the UGW web GUI and the underlying firmware, affecting version V6_0_0_5 and earlier. Among other things, several CGI methods are affected by insufficient input validation and a lack of bounds checking. These flaws allow authorized attackers to perform arbitrary file…

EPSS 0.00 CVE-2026-35075 CVE-2026-35076 CVE-2026-35077 CVE-2026-35078 CVE-2026-35079 CVE-2026-35080 CVE-2026-35081 CVE-2026-35082 CVE-2026-35083 CVE-2026-35084 CVE-2026-35085 MBS DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · MBS: Several security vulnerabilities in the UGW web GUI

1

1

SPOJENO PŘES CVE VEGA: Missing Authentication for critical function in VEGAPULS two- and four-wire products

[VDE-2026-046] Vulnerable components expose sensitive information to unauthorized actors through an unsecured configuration interface. Vulnerable firmware releases contain an unsecured configuration interface that allows retrieval of sensitive information such as hashed credentials. It was found that users with no or low rights can access information from devices that should not be available to them. An attacker can use this information to impersonate authorized users.

EPSS 0.00 CVE-2026-3323 VEGA DE

tg: zranitelnost tp: identita tp: průmyslové systémy

· CERT@VDE · VEGA: Missing Authentication for critical function in VEGAPULS two- and four-wire products

1

SPOJENO PŘES CVE Helmholz: Authenticated unintended access to critical program parameters in myREX24V2/myREX24V2.virtual

[VDE-2026-070] There is a vulnerability in myREX24V2/myREX24V2.virtual that allows an authenticated remote attacker to access a hidden configuration method, that should not be accessible by any user, to modify critical program parameters.

EPSS 0.01 CVE-2026-10521 Helmholz MB connect line DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · Helmholz: Authenticated unintended access to critical program parameters in myREX24V2/myREX24V2.virtual

4

CODESYS Control V3 - Untrusted boot application

[Advisory2026-02_VDE-2026-011] The CODESYS Control runtime system provides a user management mechanism with multiple privilege groups. While only the privileged Administrators and Developer groups are intended to load or debug applications on the controller, users in the restricted Service group are allowed to perform maintenance operations, including explicitly replacing the boot application. In addition to access control, the CODESYS Control runtime system includes an optional application…

EPSS 0.00 CVE-2025-41660 CODESYS DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · CODESYS Control V3 - Untrusted boot application

CODESYS Control V3 - Externally-controlled format string in Auditlog

[Advisory2026-03_VDE-2026-018] The CODESYS Control runtime system's CmpAuditLog component allows potentially unauthenticated remote attackers to control the format string of processed log messages. Due to the internal processing logic, the impact is limited to a crash of the CODESYS Control runtime.

EPSS 0.00 CVE-2026-3509 CODESYS DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · CODESYS Control V3 - Externally-controlled format string in Auditlog

CODESYS Control - Incorrect Authorization

[Advisory2026-08_VDE-2026-056] The CODESYS Control runtime system provides a user management mechanism with multiple privilege groups including the visualization administrators group, which is intended solely to manage visualization users. Due to insufficient authorization checks an authenticated remote user with low-privileged visualization administrator access can delete higher-privileged accounts. However, independent mechanisms protect the deletion of the last remaining device admin user,…

EPSS 0.00 CVE-2026-8046 CODESYS DE

tg: zranitelnost tp: identita tp: průmyslové systémy

· CERT@VDE · CODESYS Control - Incorrect Authorization

CODESYS Control - Out-of-bounds Write

[Advisory2026-10_VDE-2026-057] The CmpWebServer component in the CODESYS Control Runtime allows users to create browser-based visualizations for monitoring and controlling industrial processes. Due to improper bounds checking, a specially crafted HTTP request from an unauthenticated remote attacker may lead to a size-limited out-of-bounds write, causing a denial of service of the affected device. The CODESYS Control runtime system is only affected if the web server is active, which by default…

EPSS 0.00 CVE-2026-8047 CODESYS DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · CODESYS Control - Out-of-bounds Write

1

2

Phoenix Contact: PLCnext Firmware Security Issues Related to APPs and Configuration Files

[VDE-2026-050] This advisory addresses security issues in PLCnext firmware versions prior to 2026.0.3 that are related to APP handling and the processing of configuration files. The identified vulnerabilities affect APP installation authenticity as well as the handling of configuration data in writable directories. Successful exploitation may allow authenticated attackers with different privilege levels to compromise integrity, availability, and system security of affected PLCnext Control. Both…

EPSS 0.00 CVE-2025-41669 CVE-2025-41670 Phoenix Contact DE

tg: zranitelnost tg: novinka v produktu tp: průmyslové systémy

· CERT@VDE · Phoenix Contact: PLCnext Firmware Security Issues Related to APPs and Configuration Files

2

CODESYS Development System - Incorrect Default Permissions

[Advisory2026-09_VDE-2026-055] Two local privilege escalation vulnerabilities were identified in the CODESYS Development System. Specifically, the PackageManager and the IPM create temporary directories with insecure default permissions when executed with administrative privileges. This allows low-privileged local users to modify a temporary bootstrap file to force the deployment of arbitrary components, or to exploit a Time-of-Check to Time-of-Use (TOCTOU) race condition to replace digitally…

EPSS 0.00 CVE-2026-44468 CVE-2026-44469 CODESYS DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · CODESYS Development System - Incorrect Default Permissions

JUMO: Multiple products affected by nodejs vulnerability

[VDE-2026-009] A vulnerability in the REST API of the JUMO device allows an attacker to trigger a denial‑of‑service (DoS) condition. Due to an incorrect implementation of the arrayLimit option in the Node.js qs module, limits for incoming request parameters are not properly enforced. As a result, an attacker can send specially crafted requests containing excessively large or deeply nested arrays, causing the web server to become unresponsive. This condition leads to a crash of the web server,…

EPSS 0.00 CVE-2025-15284 JUMO DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · JUMO: Multiple products affected by nodejs vulnerability

1

1

CODESYS Visualization - Insufficiently Protected Credentials

[Advisory2026-07_VDE-2026-052] A vulnerability in the CODESYS Visualization login dialog has been identified. During logins within the CODESYS Visualization, authentication data may not be sufficiently isolated when multiple users perform login operations concurrently. As a result, an authenticated visualization user may be able to obtain credentials entered by another visualization user. The issue affects only login operations within an active visualization session and can be triggered via…

EPSS 0.00 CVE-2026-0393 CODESYS DE

tg: zranitelnost tp: identita tp: průmyslové systémy

· CERT@VDE · CODESYS Visualization - Insufficiently Protected Credentials

1

Pepperl+Fuchs: ICE2- * and ICE3- * are affected by multiple vulnerabilities

[VDE-2024-017] Critical vulnerabilities have been discovered in the product due to outdated software components.The impact of the vulnerabilities on the affected device may result in Denial of service Bypassing of authentication Information disclosure

EPSS 0.80 CVE-1999-0524 CVE-2002-20001 CVE-2004-0230 CVE-2011-3389 CVE-2020-7070 CVE-2021-21707 CVE-2022-31629 CVE-2022-40735 Pepperl+Fuchs DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · Pepperl+Fuchs: ICE2- * and ICE3- * are affected by multiple vulnerabilities

1

CODESYS Modbus TCP Server - Improper resource management

[Advisory2026-05_VDE-2026-042] CODESYS Modbus is an add‑on for the CODESYS Development System that provides a fully integrated Modbus protocol stack along with diagnostic capabilities. A flaw in the CODESYS Modbus TCP Server protocol stack library results in a vulnerability. When a Modbus TCP server is configured, this vulnerable protocol stack is downloaded to and executed by CODESYS Control runtime systems. The vulnerability is caused by a resource management issue in the Modbus TCP server…

EPSS 0.00 CVE-2026-35227 CODESYS DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · CODESYS Modbus TCP Server - Improper resource management

1

1

1

Phoenix Contact: Several products are affected by vulnerabilities found in OpenSSL

[VDE-2026-023] Attacks are possible when installing key files and digitally signed objects. These attacks can only be carried out if these files are uploaded and installed by a logged-in user with high privileges.

EPSS 0.48 CVE-2025-15467 CVE-2025-69419 Phoenix Contact OpenSSL DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · Phoenix Contact: Several products are affected by vulnerabilities found in OpenSSL

2

1

1

1

Endress+Hauser: Multiple products prone to multiple vulnerabilities in e!Runtime and CODESYS V3 Runtime

[VDE-2026-003] Multiple Endress+Hauser devices are prone to vulnerabilities found in e!Runtime and the CODESYS V3 framework.

EPSS 0.02 CVE-2022-47378 CVE-2022-47379 CVE-2022-47380 CVE-2022-47381 CVE-2022-47382 CVE-2022-47383 CVE-2022-47384 CVE-2022-47385 CVE-2022-47386 CVE-2022-47387 CVE-2022-47388 CVE-2022-47389 CVE-2022-47390 CVE-2022-47391 CVE-2022-47392 CVE-2022-47393 Endress+Hauser DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · Endress+Hauser: Multiple products prone to multiple vulnerabilities in e!Runtime and CODESYS V3 Runtime

2

2