Výsledky hledání

typ: zranitelnost× v celém archivu zrušit filtry

1790 karet z 1920 položek · strana 30 z 30 CZ · EN/orig

2

1

3

Murrelektronik Devices Vulnerable to SNMP GETBULK Reflection DDoS

[VDE-2026-063] Multiple Murrelektronik network-enabled devices respond to SNMPv2c 'GETBULK' requests with disproportionately large response packets when the requesting party specifies a large max-repetitions value. This response amplification allows the affected devices to be misused as reflectors in distributed denial-of-service (DDoS) attacks against arbitrary third-party victims on the internet.

EPSS 0.05 CVE-2008-4309 Murrelektronik DE

tg: zranitelnost tp: DDoS

· CERT@VDE · Murrelektronik Devices Vulnerable to SNMP GETBULK Reflection DDoS

METTLER TOLEDO: Microsoft cumulative patches until March for FreshWay B/D

[VDE-2026-066] This update deploys cumulative Microsoft Windows security patches through March 2026 for LTSB 2016, LTSC 2019, and LTSC 2021.

EPSS 0.01 CVE-2026-23673 CVE-2026-25171 CVE-2026-25172 CVE-2026-25174 CVE-2026-25175 CVE-2026-25179 CVE-2026-25181 CVE-2026-25185 CVE-2026-26111 CVE-2026-26128 METTLER TOLEDO Microsoft DE

tg: zranitelnost tg: novinka v produktu

· CERT@VDE · METTLER TOLEDO: Microsoft cumulative patches until March for FreshWay B/D

Several Murrelektronik Devices use Default SNMP Community Names

[VDE-2026-062] Several Murrelektronik devices using Profinet are shipped with the default SNMP community names ('public' for read access and 'private' for write access). If these community strings remain unchanged in the field, an unauthenticated attacker with network access to the device can read its configuration and, depending on the writable OIDs, modify device settings.

EPSS 0.27 CVE-1999-0517 Murrelektronik DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · Several Murrelektronik Devices use Default SNMP Community Names

2

CODESYS EtherNetIP - Improper timeout handling

[Advisory2026-04_VDE-2026-040] CODESYS EtherNet/IP is an add‑on for the CODESYS Development System that provides a fully integrated EtherNet/IP protocol stack along with diagnostic capabilities. A flaw in the EtherNet/IP adapter protocol stack library results in a vulnerability within the generated application code. When an EtherNet/IP adapter is configured, this vulnerable protocol stack is downloaded to and executed by CODESYS Control runtime systems. Under certain non‑standard operating…

EPSS 0.00 CVE-2026-35225 CODESYS DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · CODESYS EtherNetIP - Improper timeout handling

WAGO: Early-Boot Diagnostic Exposure in WAGO System I/O Field Devices

[VDE-2026-031] Certain devices in the WAGO System I/O Field series enable an internal diagnostic capability during the initial stages of system startup. This behavior, which is not part of the publicly documented feature set, briefly allows access to system functions before the main operating environment becomes fully active. Under specific conditions, this could permit interactions with system components that are normally protected during regular operation.

EPSS 0.01 CVE-2026-4769 WAGO DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · WAGO: Early-Boot Diagnostic Exposure in WAGO System I/O Field Devices

1

1

JUMO: Allegro RomPager webserver vulnerability in JUMO mTRONT, DICON touch, AQUIS touch devices

[VDE-2026-071] Multiple products from JUMO are affected by webserver vulnerability "CVE-2013-6786, CVE-2014-9222, CVE-2014-9223. This vulnerability leads to DOS of the device by using a misfortune cookie and reflected XSS attacks.

EPSS 0.64 CVE-2013-6786 CVE-2014-9222 CVE-2014-9223 JUMO Allegro DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · JUMO: Allegro RomPager webserver vulnerability in JUMO mTRONT, DICON touch, AQUIS touch devices

2

MBS: Several security vulnerabilities in the UGW web GUI

[VDE-2026-039] The MBS Universal Gateways (UGW-A-Series, UGW-X-Series) connect devices using various digital communication protocols within the field of building automation. Several security vulnerabilities have been identified in the UGW web GUI and the underlying firmware, affecting version V6_0_0_5 and earlier. Among other things, several CGI methods are affected by insufficient input validation and a lack of bounds checking. These flaws allow authorized attackers to perform arbitrary file…

EPSS 0.00 CVE-2026-35075 CVE-2026-35076 CVE-2026-35077 CVE-2026-35078 CVE-2026-35079 CVE-2026-35080 CVE-2026-35081 CVE-2026-35082 CVE-2026-35083 CVE-2026-35084 CVE-2026-35085 MBS DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · MBS: Several security vulnerabilities in the UGW web GUI

1

1

SPOJENO PŘES CVE VEGA: Missing Authentication for critical function in VEGAPULS two- and four-wire products

[VDE-2026-046] Vulnerable components expose sensitive information to unauthorized actors through an unsecured configuration interface. Vulnerable firmware releases contain an unsecured configuration interface that allows retrieval of sensitive information such as hashed credentials. It was found that users with no or low rights can access information from devices that should not be available to them. An attacker can use this information to impersonate authorized users.

EPSS 0.00 CVE-2026-3323 VEGA DE

tg: zranitelnost tp: identita tp: průmyslové systémy

· CERT@VDE · VEGA: Missing Authentication for critical function in VEGAPULS two- and four-wire products

2

SPOJENO PŘES CVE Helmholz: Authenticated unintended access to critical program parameters in myREX24V2/myREX24V2.virtual

[VDE-2026-070] There is a vulnerability in myREX24V2/myREX24V2.virtual that allows an authenticated remote attacker to access a hidden configuration method, that should not be accessible by any user, to modify critical program parameters.

EPSS 0.01 CVE-2026-10521 Helmholz MB connect line DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · Helmholz: Authenticated unintended access to critical program parameters in myREX24V2/myREX24V2.virtual

4

CODESYS Control V3 - Untrusted boot application

[Advisory2026-02_VDE-2026-011] The CODESYS Control runtime system provides a user management mechanism with multiple privilege groups. While only the privileged Administrators and Developer groups are intended to load or debug applications on the controller, users in the restricted Service group are allowed to perform maintenance operations, including explicitly replacing the boot application. In addition to access control, the CODESYS Control runtime system includes an optional application…

EPSS 0.00 CVE-2025-41660 CODESYS DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · CODESYS Control V3 - Untrusted boot application

CODESYS Control V3 - Externally-controlled format string in Auditlog

[Advisory2026-03_VDE-2026-018] The CODESYS Control runtime system's CmpAuditLog component allows potentially unauthenticated remote attackers to control the format string of processed log messages. Due to the internal processing logic, the impact is limited to a crash of the CODESYS Control runtime.

EPSS 0.00 CVE-2026-3509 CODESYS DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · CODESYS Control V3 - Externally-controlled format string in Auditlog

CODESYS Control - Incorrect Authorization

[Advisory2026-08_VDE-2026-056] The CODESYS Control runtime system provides a user management mechanism with multiple privilege groups including the visualization administrators group, which is intended solely to manage visualization users. Due to insufficient authorization checks an authenticated remote user with low-privileged visualization administrator access can delete higher-privileged accounts. However, independent mechanisms protect the deletion of the last remaining device admin user,…

EPSS 0.00 CVE-2026-8046 CODESYS DE

tg: zranitelnost tp: identita tp: průmyslové systémy

· CERT@VDE · CODESYS Control - Incorrect Authorization

CODESYS Control - Out-of-bounds Write

[Advisory2026-10_VDE-2026-057] The CmpWebServer component in the CODESYS Control Runtime allows users to create browser-based visualizations for monitoring and controlling industrial processes. Due to improper bounds checking, a specially crafted HTTP request from an unauthenticated remote attacker may lead to a size-limited out-of-bounds write, causing a denial of service of the affected device. The CODESYS Control runtime system is only affected if the web server is active, which by default…

EPSS 0.00 CVE-2026-8047 CODESYS DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · CODESYS Control - Out-of-bounds Write

1

1

Ivanti June Security Update

Rilasciati gli aggiornamenti di sicurezza di giugno che risolvono 4 nuove vulnerabilità, di cui due con gravità “critica” e due con gravità “alta”, in diversi prodotti Ivanti. Tra queste, si evidenzia la CVE-2026-10520, per la quale risulta disponibile un Proof of Concept (PoC) in rete.

KEV ✓ EPSS 1.00 CVE-2026-10520 Ivanti IT

tg: zranitelnost

· CSIRT Itálie (ACN) · Ivanti June Security Update

1

METTLER TOLEDO: LabX Standard Report on External Component Analysis - v21.3

[VDE-2026-064] Multiple vulnerabilities have been discovered in LabX Standard v21.3.22. Most of the vulnerabilities are fixed in LabX Standard v21.4.23. The Vulnerabilities CVE-2025-69419, CVE-2026-0915, CVE-2025-15467 and CVE-2025-58187 are not yet fixed. The fix will be available in the upcoming releases. Notice: LabX Standard was formerly known as LabX Cloud Local.

EPSS 0.48 CVE-2025-15467 CVE-2025-58187 CVE-2025-69419 CVE-2026-0915 METTLER TOLEDO DE

tg: zranitelnost

· CERT@VDE · METTLER TOLEDO: LabX Standard Report on External Component Analysis - v21.3

2

Phoenix Contact: PLCnext Firmware Security Issues Related to APPs and Configuration Files

[VDE-2026-050] This advisory addresses security issues in PLCnext firmware versions prior to 2026.0.3 that are related to APP handling and the processing of configuration files. The identified vulnerabilities affect APP installation authenticity as well as the handling of configuration data in writable directories. Successful exploitation may allow authenticated attackers with different privilege levels to compromise integrity, availability, and system security of affected PLCnext Control. Both…

EPSS 0.00 CVE-2025-41669 CVE-2025-41670 Phoenix Contact DE

tg: zranitelnost tg: novinka v produktu tp: průmyslové systémy

· CERT@VDE · Phoenix Contact: PLCnext Firmware Security Issues Related to APPs and Configuration Files

3

CODESYS Development System - Incorrect Default Permissions

[Advisory2026-09_VDE-2026-055] Two local privilege escalation vulnerabilities were identified in the CODESYS Development System. Specifically, the PackageManager and the IPM create temporary directories with insecure default permissions when executed with administrative privileges. This allows low-privileged local users to modify a temporary bootstrap file to force the deployment of arbitrary components, or to exploit a Time-of-Check to Time-of-Use (TOCTOU) race condition to replace digitally…

EPSS 0.00 CVE-2026-44468 CVE-2026-44469 CODESYS DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · CODESYS Development System - Incorrect Default Permissions

JUMO: Multiple products affected by nodejs vulnerability

[VDE-2026-009] A vulnerability in the REST API of the JUMO device allows an attacker to trigger a denial‑of‑service (DoS) condition. Due to an incorrect implementation of the arrayLimit option in the Node.js qs module, limits for incoming request parameters are not properly enforced. As a result, an attacker can send specially crafted requests containing excessively large or deeply nested arrays, causing the web server to become unresponsive. This condition leads to a crash of the web server,…

EPSS 0.00 CVE-2025-15284 JUMO DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · JUMO: Multiple products affected by nodejs vulnerability

1

1

CODESYS Visualization - Insufficiently Protected Credentials

[Advisory2026-07_VDE-2026-052] A vulnerability in the CODESYS Visualization login dialog has been identified. During logins within the CODESYS Visualization, authentication data may not be sufficiently isolated when multiple users perform login operations concurrently. As a result, an authenticated visualization user may be able to obtain credentials entered by another visualization user. The issue affects only login operations within an active visualization session and can be triggered via…

EPSS 0.00 CVE-2026-0393 CODESYS DE

tg: zranitelnost tp: identita tp: průmyslové systémy

· CERT@VDE · CODESYS Visualization - Insufficiently Protected Credentials

1

Pepperl+Fuchs: ICE2- * and ICE3- * are affected by multiple vulnerabilities

[VDE-2024-017] Critical vulnerabilities have been discovered in the product due to outdated software components.The impact of the vulnerabilities on the affected device may result in Denial of service Bypassing of authentication Information disclosure

EPSS 0.80 CVE-1999-0524 CVE-2002-20001 CVE-2004-0230 CVE-2011-3389 CVE-2020-7070 CVE-2021-21707 CVE-2022-31629 CVE-2022-40735 Pepperl+Fuchs DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · Pepperl+Fuchs: ICE2- * and ICE3- * are affected by multiple vulnerabilities

2

CODESYS Modbus TCP Server - Improper resource management

[Advisory2026-05_VDE-2026-042] CODESYS Modbus is an add‑on for the CODESYS Development System that provides a fully integrated Modbus protocol stack along with diagnostic capabilities. A flaw in the CODESYS Modbus TCP Server protocol stack library results in a vulnerability. When a Modbus TCP server is configured, this vulnerable protocol stack is downloaded to and executed by CODESYS Control runtime systems. The vulnerability is caused by a resource management issue in the Modbus TCP server…

EPSS 0.00 CVE-2026-35227 CODESYS DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · CODESYS Modbus TCP Server - Improper resource management

1

1

2

1

Phoenix Contact: Several products are affected by vulnerabilities found in OpenSSL

[VDE-2026-023] Attacks are possible when installing key files and digitally signed objects. These attacks can only be carried out if these files are uploaded and installed by a logged-in user with high privileges.

EPSS 0.48 CVE-2025-15467 CVE-2025-69419 Phoenix Contact OpenSSL DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · Phoenix Contact: Several products are affected by vulnerabilities found in OpenSSL

2

1

1

2

Baade M2M-Products GmbH: ubusd heap buffer overflow vulnerability in OpenWRT prior to version 24.10.4

[VDE-2025-098] OpenWrt Project is a Linux operating system targeting embedded devices. Prior to version 24.10.4, ubusd contains a heap buffer overflow in the event registration parsing code. This allows an attacker to modify the head and potentially execute arbitrary code in the context of the ubus daemon. The affected code is executed before running the ACL checks, all ubus clients are able to send such messages. In addition to the heap corruption, the crafted subscription also results in a…

EPSS 0.00 CVE-2025-62526 Baade M2M-Products OpenWrt DE

tg: zranitelnost

· CERT@VDE · Baade M2M-Products GmbH: ubusd heap buffer overflow vulnerability in OpenWRT prior to version 24.10.4

2

Endress+Hauser: Multiple products prone to multiple vulnerabilities in e!Runtime and CODESYS V3 Runtime

[VDE-2026-003] Multiple Endress+Hauser devices are prone to vulnerabilities found in e!Runtime and the CODESYS V3 framework.

EPSS 0.02 CVE-2022-47378 CVE-2022-47379 CVE-2022-47380 CVE-2022-47381 CVE-2022-47382 CVE-2022-47383 CVE-2022-47384 CVE-2022-47385 CVE-2022-47386 CVE-2022-47387 CVE-2022-47388 CVE-2022-47389 CVE-2022-47390 CVE-2022-47391 CVE-2022-47392 CVE-2022-47393 Endress+Hauser DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · Endress+Hauser: Multiple products prone to multiple vulnerabilities in e!Runtime and CODESYS V3 Runtime

Elastic releases detections for the Axios supply chain compromise

Elastic Security Labs is releasing an initial triage and detection rules for the Axios supply-chain compromise. We have released a detailed analysis on the Axios compromise RAT and payloads. Elastic Security Labs filed a GitHub Security Advisory to the axios repository on March 31, 2026 at 01:50 AM UTC to coordinate disclosure and ensure the maintainers and npm registry could act on the compromised versions. Introduction We are currently tracking a supply chain attack involving malicious Axios…

axios US

tg: zranitelnost tg: rozbor tp: malware tp: dodavatelský řetězec

· Elastic Security · Elastic releases detections for the Axios supply chain compromise

2

2