/
cyberknowledge
/
CVE
ОбзорДокументацияВойти
/
cyberknowledge
/
CVE
Код
Запросы
0
Задачи
Вики
Пакеты
0
Релизы
0
CI/CD
Аналитика
ДокументацияПоддержка
Политика конфиденциальностиПользовательское соглашениеПолитика использования «cookies»Согласие субъекта персональных данных
2026 ©
samples/circl_dumps.csv
101 строка1 MB

Zeros312

Rename sample/ to samples/; remove README from samples
30 июн 2026, 21:21
30 июн 2026, 21:2183c96cb
100 строк
csaf_frauschersensortechnikgmbh.ndjson
b86c045e2effbd30cc0a79c081dab58bb19706a522d7b95cb6125175f3f7e53c
{'document': {'lang': 'en-GB', 'notes': [{'text': 'Frauscher Diagnostic System FDS001 for FAdC R1 and FAdCi R1 v1.3.3 and all previous versions are vulnerable to a\xa0path traversal vulnerability of the web interface by a crafted URL without authentication.', 'title': 'Summary', 'category': 'summary'}, {'text': 'The attacker can read all files on the filesystem of the FDS001 device. Note: Orphaned SSH keys exist on the file system, but they cannot be used to log in to the machine.', 'title': 'Impact', 'category': 'description'}, {'text': 'Security-related application conditions SecRACThe railway operator must ensure that only authorised personnel or people in the company of authorised personnel have access to the Frauscher Diagnostic System FDS001.The recommendation is to connect the Frauscher Diagnostic System FDS001 to a network of category 2. If the Frauscher Diagnostic System FDS001 is connected to a network of category 3 (according to EN 50159:2010), then additional protective measures must be added.', 'title': 'Mitigation', 'category': 'description'}, {'text': 'For the Frauscher Diagnostic System FDS001 for FAdC R1 and FAdCi R1 no more firmware updates will be provided.', 'title': 'Remediation', 'category': 'description'}], 'title': 'Frauscher: Diagnostic System FDS001 for FAdC/FAdCi Path Traversal vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2023-011', 'status': 'final', 'aliases': ['VDE-2023-011'], 'version': '1', 'generator': {'date': '2025-04-29T17:20:57.199Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.24'}}, 'revision_history': [{'date': '2023-07-05T08:00:00.000Z', 'number': '1', 'summary': 'Initial revision.'}], 'current_release_date': '2023-07-05T08:00:00.000Z', 'initial_release_date': '2023-07-05T08:00:00.000Z'}, 'publisher': {'name': 'Frauscher Sensortechnik GmbH', 'category': 'vendor', 'namespace': 'https://www.frauscher.com', 'contact_details': 'psirt@frauscher.com'}, 'references': [{'url': 'https://certvde.com/en/advisories/VDE-2023-011/', 'summary': 'VDE-2023-011: Frauscher: Diagnostic System FDS001 for FAdC/FAdCi Path Traversal vulnerability - HTML', 'category': 'self'}, {'url': 'https://frauscher.csaf-tp.certvde.com/.well-known/csaf/white/2023/vde-2023-011.json', 'summary': 'VDE-2023-011: Frauscher: Diagnostic System FDS001 for FAdC/FAdCi Path Traversal vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.frauscher.com', 'summary': 'Vendor PSIRT', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/frauscher/', 'summary': 'CERT@VDE Security Advisories for Frauscher Sensortechnik GmbH', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}]}, 'product_tree': {'branches': [{'name': 'Frauscher', 'branches': [{'name': 'Software', 'branches': [{'name': 'Diagnostic System FDS101 for FAdC/FAdCi', 'branches': [{'name': '<=1.3.3', 'product': {'name': 'Diagnostic System FDS101 for FAdC/FAdCi <=1.3.3', 'product_id': 'CSAFPID-51001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2023-2880', 'cwe': {'id': 'CWE-22', 'name': "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"}, 'notes': [{'text': 'Frauscher Sensortechnik GmbH FDS001 for FAdC/FAdCi v1.3.3 and all previous versions are vulnerable to a path traversal vulnerability of the web interface by a crafted URL without authentication. This enables an remote attacker to read all files on the filesystem of the FDS001 device.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2023-2880', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'NONE', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': 'Security-related application conditions SecRACThe railway operator must ensure that only authorised personnel or people in the company of authorised personnel have access to the Frauscher Diagnostic System FDS001.The recommendation is to connect the Frauscher Diagnostic System FDS001 to a network of category 2. If the Frauscher Diagnostic System FDS001 is connected to a network of category 3 (according to EN 50159:2010), then additional protective measures must be added.\n\nFor the Frauscher Diagnostic System FDS001 for FAdC R1 and FAdCi R1 no more firmware updates will be provided.', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'For the Frauscher Diagnostic System FDS001 for FAdC R1 and FAdCi R1 no more firmware updates will be provided.\n\n', 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'known_affected': ['CSAFPID-51001']}}]}
2c076e01806e54b1e7911ea3f8f1ab65b642a5251a2b1a953d70ef443769b94d
2026-05-29 08:30:27.908488+03:00
2026-05-29 08:30:27.908488+03:00
csaf_frauschersensortechnikgmbh.ndjson
7e41f713afc10a69d91e839b253430cfe231edb90a7e525e1b4744dba321df19
{'document': {'lang': 'en-GB', 'notes': [{'text': 'Frauscher Sensortechnik GmbH FDS101 for FAdC/FAdCi v1.4.24 and all previous versions are\xa0prone\xa0to\xa0multiple vulnerabilities which\xa0could lead up to a full compromise of the FDS101 device.', 'title': 'Summary', 'category': 'summary'}, {'text': 'Please\xa0consult the CVE Entries above.', 'title': 'Impact', 'category': 'description'}, {'text': 'Security-related application conditions SecRAC\nThe railway operator must ensure that only authorised personnel or people in the company of authorised personnel have access to the Frauscher Diagnostic System FDS101.\nThe recommendation is to connect the Frauscher Diagnostic System FDS101 to a network of category 2.\nIf the Frauscher Diagnostic System FDS101 is connected to a network of category 3 (according to EN 50159:2010), then additional protective measures must be added.', 'title': 'Mitigation', 'category': 'description'}, {'text': 'Update to FDS102 v2.10.1', 'title': 'Remediation', 'category': 'description'}], 'title': 'Frauscher: Multiple Vulnerabilities in FDS101', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2023-038', 'status': 'final', 'aliases': ['VDE-2023-038'], 'version': '1', 'generator': {'date': '2025-04-30T09:30:14.935Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.24'}}, 'revision_history': [{'date': '2023-09-21T06:00:00.000Z', 'number': '1', 'summary': 'Initial revision.'}], 'current_release_date': '2023-09-21T06:00:00.000Z', 'initial_release_date': '2023-09-21T06:00:00.000Z'}, 'publisher': {'name': 'Frauscher Sensortechnik GmbH', 'category': 'vendor', 'namespace': 'https://www.frauscher.com', 'contact_details': 'psirt@frauscher.com'}, 'references': [{'url': 'https://certvde.com/en/advisories/VDE-2023-038/', 'summary': 'VDE-2023-038: Frauscher: Multiple Vulnerabilities in FDS101 - HTML', 'category': 'self'}, {'url': 'https://frauscher.csaf-tp.certvde.com/.well-known/csaf/white/2023/vde-2023-038.json', 'summary': 'VDE-2023-038: Frauscher: Multiple Vulnerabilities in FDS101 - CSAF', 'category': 'self'}, {'url': 'https://www.frauscher.com', 'summary': 'Vendor PSIRT', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/frauscher/', 'summary': 'CERT@VDE Security Advisories for Frauscher Sensortechnik GmbH', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}]}, 'product_tree': {'branches': [{'name': 'Frauscher', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'FDS101 for FAdC/FAdCi', 'product': {'name': 'FDS101 for FAdC/FAdCi', 'product_id': 'CSAFPID-11001'}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': '<=1.4.24', 'product': {'name': 'Firmware <=1.4.24', 'product_id': 'CSAFPID-21001'}, 'category': 'product_version_range'}, {'name': 'v2.10.1', 'product': {'name': 'Firmware v2.10.1', 'product_id': 'CSAFPID-22001'}, 'category': 'product_version'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=1.4.24 installed on FDS101 for FAdC/FAdCi', 'product_id': 'CSAFPID-31001'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware v2.10.1 installed on FDS101 for FAdC/FAdCi', 'product_id': 'CSAFPID-32001'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11001'}]}, 'vulnerabilities': [{'cve': 'CVE-2023-4292', 'cwe': {'id': 'CWE-89', 'name': "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')"}, 'notes': [{'text': 'Frauscher Sensortechnik GmbH FDS101 for FAdC/FAdCi v1.4.24 and all previous versions are vulnerable to a SQL injection vulnerability via manipulated parameters of the web interface without authentication. The database contains limited, non-critical log information.\n\n\n\n', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2023-4292', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N', 'temporalScore': 5.3, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 5.3, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-31001']}], 'remediations': [{'details': 'Security-related application conditions SecRAC\nThe railway operator must ensure that only authorised personnel or people in the company of authorised personnel have access to the Frauscher Diagnostic System FDS101.\nThe recommendation is to connect the Frauscher Diagnostic System FDS101 to a network of category 2.\nIf the Frauscher Diagnostic System FDS101 is connected to a network of category 3 (according to EN 50159:2010), then additional protective measures must be added.', 'category': 'mitigation', 'product_ids': ['CSAFPID-31001']}, {'details': 'Update to FDS102 v2.10.1', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31001']}], 'product_status': {'fixed': ['CSAFPID-32001'], 'known_affected': ['CSAFPID-31001']}}, {'cve': 'CVE-2023-4291', 'cwe': {'id': 'CWE-94', 'name': "Improper Control of Generation of Code ('Code Injection')"}, 'notes': [{'text': 'Frauscher Sensortechnik GmbH FDS101 for FAdC/FAdCi v1.4.24 and all previous versions are vulnerable to a remote code execution (RCE) vulnerability via manipulated parameters of the web interface without authentication.\xa0This could lead to a full compromise of the FDS101 device.\n\n\n', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2023-4291', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001']}], 'remediations': [{'details': 'Security-related application conditions SecRAC\nThe railway operator must ensure that only authorised personnel or people in the company of authorised personnel have access to the Frauscher Diagnostic System FDS101.\nThe recommendation is to connect the Frauscher Diagnostic System FDS101 to a network of category 2.\nIf the Frauscher Diagnostic System FDS101 is connected to a network of category 3 (according to EN 50159:2010), then additional protective measures must be added.', 'category': 'mitigation', 'product_ids': ['CSAFPID-31001']}, {'details': 'Update to FDS102 v2.10.1', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31001']}], 'product_status': {'fixed': ['CSAFPID-32001'], 'known_affected': ['CSAFPID-31001']}}, {'cve': 'CVE-2023-4152', 'cwe': {'id': 'CWE-22', 'name': "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"}, 'notes': [{'text': 'Frauscher Sensortechnik GmbH FDS101 for FAdC/FAdCi v1.4.24 and all previous versions are vulnerable to a path traversal vulnerability of the web interface by a crafted URL without authentication. This enables an remote attacker to read all files on the filesystem of the FDS101 device.\n', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2023-4152', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'NONE', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001']}], 'remediations': [{'details': 'Security-related application conditions SecRAC\nThe railway operator must ensure that only authorised personnel or people in the company of authorised personnel have access to the Frauscher Diagnostic System FDS101.\nThe recommendation is to connect the Frauscher Diagnostic System FDS101 to a network of category 2.\nIf the Frauscher Diagnostic System FDS101 is connected to a network of category 3 (according to EN 50159:2010), then additional protective measures must be added.', 'category': 'mitigation', 'product_ids': ['CSAFPID-31001']}, {'details': 'Update to FDS102 v2.10.1', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31001']}], 'product_status': {'fixed': ['CSAFPID-32001'], 'known_affected': ['CSAFPID-31001']}}]}
0de5cc473e636d402fd8d8f711a38d4dd0e627977bf984decb156b98968bcaae
2026-05-29 08:30:27.908488+03:00
2026-05-29 08:30:27.908488+03:00
csaf_frauschersensortechnikgmbh.ndjson
079aa87d3ea58cf2dd1980daebf6826a9d1c64745ab7e4bb5e4699c3edd4672b
{'document': {'lang': 'en-GB', 'notes': [{'text': 'Frauscher Sensortechnik GmbH FDS102 for FAdC/FAdCi v2.10.1 is vulnerable to a remote code execution (RCE) vulnerability via manipulated parameters of the web interface by using an authenticated session cookie.', 'title': 'Summary', 'category': 'summary'}, {'text': 'This vulnerability\xa0may lead to a full compromise of the FDS102 device.', 'title': 'Impact', 'category': 'description'}, {'text': 'Security-related application conditions SecRAC\n\nThe railway operator must ensure that only authorised personnel or people in the company of authorised personnel have access to the Frauscher Diagnostic System FDS102.\n\nThe recommendation is to connect the Frauscher Diagnostic System FDS102 to a network of category 2. If the Frauscher Diagnostic System FDS102 is connected to a network of category 3 (according to EN 50159:2010), then additional protective measures must be added.', 'title': 'Mitigation', 'category': 'description'}, {'text': 'Update to FDS102 v2.10.2', 'title': 'Remediation', 'category': 'description'}], 'title': 'Frauscher: FDS102 for FAdC/FAdCi remote code execution vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2023-049', 'status': 'final', 'aliases': ['VDE-2023-049'], 'version': '1', 'generator': {'date': '2025-05-05T08:24:30.960Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.24'}}, 'revision_history': [{'date': '2023-12-11T07:00:00.000Z', 'number': '1', 'summary': 'Initial revision.'}], 'current_release_date': '2023-12-11T07:00:00.000Z', 'initial_release_date': '2023-12-11T07:00:00.000Z'}, 'publisher': {'name': 'Frauscher Sensortechnik GmbH', 'category': 'vendor', 'namespace': 'https://www.frauscher.com', 'contact_details': 'psirt@frauscher.com'}, 'references': [{'url': 'https://certvde.com/en/advisories/VDE-2023-049/', 'summary': 'VDE-2023-049: Frauscher: FDS102 for FAdC/FAdCi remote code execution vulnerability - HTML', 'category': 'self'}, {'url': 'https://frauscher.csaf-tp.certvde.com/.well-known/csaf/white/2023/vde-2023-049.json', 'summary': 'VDE-2023-049: Frauscher: FDS102 for FAdC/FAdCi remote code execution vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.frauscher.com', 'summary': 'Vendor PSIRT', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/frauscher/', 'summary': 'CERT@VDE Security Advisories for Frauscher Sensortechnik GmbH', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}]}, 'product_tree': {'branches': [{'name': 'Frauscher', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'FDS102 for FAdC/FAdCi', 'product': {'name': 'FDS102 for FAdC/FAdCi', 'product_id': 'CSAFPID-11001'}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': '2.10.0<=2.10.1', 'product': {'name': 'Firmware 2.10.0<=2.10.1', 'product_id': 'CSAFPID-21001'}, 'category': 'product_version_range'}, {'name': 'v2.10.2', 'product': {'name': 'Firmware v2.10.2', 'product_id': 'CSAFPID-22001'}, 'category': 'product_version'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware 2.10.0<=2.10.1 installed on FDS102 for FAdC/FAdCi', 'product_id': 'CSAFPID-31001'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware v2.10.2 installed on FDS102 for FAdC/FAdCi', 'product_id': 'CSAFPID-32001'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11001'}]}, 'vulnerabilities': [{'cve': 'CVE-2023-5500', 'cwe': {'id': 'CWE-94', 'name': "Improper Control of Generation of Code ('Code Injection')"}, 'notes': [{'text': "This vulnerability allows an remote attacker with low privileges to misuse Improper Control of Generation of Code ('Code Injection') to gain full control of the affected device.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2023-5500', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 8.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 8.8, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001']}], 'remediations': [{'details': 'Security-related application conditions SecRAC\n\nThe railway operator must ensure that only authorised personnel or people in the company of authorised personnel have access to the Frauscher Diagnostic System FDS102.\n\nThe recommendation is to connect the Frauscher Diagnostic System FDS102 to a network of category 2. If the Frauscher Diagnostic System FDS102 is connected to a network of category 3 (according to EN 50159:2010), then additional protective measures must be added.', 'category': 'mitigation', 'product_ids': ['CSAFPID-31001']}, {'details': 'Update to FDS102 v2.10.2', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31001']}], 'product_status': {'fixed': ['CSAFPID-32001'], 'known_affected': ['CSAFPID-31001']}}]}
5cb64c444094dc2b1103df62ba566915be4ad81f1dcb361015c409e824e6c531
2026-05-29 08:30:27.908488+03:00
2026-05-29 08:30:27.908488+03:00
csaf_frauschersensortechnikgmbh.ndjson
23a51c13bbab8b5f7c8bac980653de7045870f266e66e8125ea3b8f5bd19f898
{'document': {'lang': 'en-GB', 'notes': [{'text': 'Frauscher Sensortechnik FDS101, FDS-SNMP101 and FDS102 for FAdC/FAdCi R2 and all previous versions are vulnerable to OS Command Injection via malicious configuration file.\n\nCVE-2025-3626 affects FDS102 versions v2.8.0 < v2.13.3.\n\nCVE-2025-3705 affects a broader range of products and versions. Specifically, it affects:\n* FDS102 versions < v2.13.3\n* FDS101 versions <= v1.4.25\n* FDS-SNMP101 versions <= v.2.3.9\n\n**Update 1.1.0, 29.07.2025:** The summary has been updated to include a mapping between CVEs and affected products, and the remediation section has been revised to include FDS101.', 'title': 'Summary', 'category': 'summary'}, {'text': 'This enables a remote or a local attacker to gain full control of the FDS101/FDS-SNMP101/FDS102 device.', 'title': 'Impact', 'category': 'description'}, {'text': 'Security-related application conditions SecRAC:\n\n* The railway operator must ensure that only authorised personnel or people in the company of\nauthorised personnel have access to the Frauscher Diagnostic System FDS101/FDS-SNMP101/FDS102. This applies for both vulnerabilities.\n\n* The recommendation is to connect the Frauscher Diagnostic System FDS102 to a network of category 2. If the Frauscher Diagnostic System FDS102 is connected to a network of category 3\n(according to EN 50159:2010), then additional protective measures must be added. This applies for CVE-2025-3626. ', 'title': 'Mitigation', 'category': 'description'}, {'text': 'Update FDS101 or FDS102 to FDS102 v2.13.3 or higher.', 'title': 'Remediation', 'category': 'description'}], 'title': 'Frauscher: FDS101, FDS-SNMP101 and FDS102 for FAdC/FAdCi are Vulnerable to OS Command Injection Vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2025-030', 'status': 'final', 'aliases': ['VDE-2025-030'], 'version': '1.1.0', 'generator': {'date': '2025-07-29T10:30:17.379Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.31'}}, 'revision_history': [{'date': '2025-07-07T10:00:00.000Z', 'number': '1.0.0', 'summary': 'Initial revision'}, {'date': '2025-07-29T10:00:00.000Z', 'number': '1.1.0', 'summary': 'The summary has been updated to include a mapping between CVEs and affected products, and the remediation section has been revised to include FDS101.'}], 'current_release_date': '2025-07-29T10:00:00.000Z', 'initial_release_date': '2025-07-07T10:00:00.000Z'}, 'publisher': {'name': 'Frauscher Sensortechnik GmbH', 'category': 'vendor', 'namespace': 'https://www.frauscher.com', 'contact_details': 'psirt@frauscher.com'}, 'references': [{'url': 'https://certvde.com/de/advisories/vendor/frauscher/', 'summary': 'Frauscher advisory overview at CERT@VDE', 'category': 'external'}, {'url': 'https://www.frauscher.com/en/psirt', 'summary': 'Frauscher PSIRT', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/VDE-2025-030/', 'summary': 'VDE-2025-030: Frauscher: FDS101, FDS-SNMP101 and FDS102 for FAdC/FAdCi are Vulnerable to OS Command Injection Vulnerability - HTML', 'category': 'self'}, {'url': 'https://frauscher.csaf-tp.certvde.com/.well-known/csaf/white/2025/vde-2025-030.json', 'summary': 'VDE-2025-030: Frauscher: FDS101, FDS-SNMP101 and FDS102 for FAdC/FAdCi are Vulnerable to OS Command Injection Vulnerability - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.first.org/cvss/v3.1/specification-document#Qualitative-Severity-Rating-Scale'}}, 'product_tree': {'branches': [{'name': 'Frauscher', 'branches': [{'name': 'Software', 'branches': [{'name': 'FDS', 'branches': [{'name': '102', 'branches': [{'name': 'v2.13.3', 'product': {'name': 'FDS102 v2.13.3', 'product_id': 'CSAFID-52001'}, 'category': 'product_version'}, {'name': '>=v2.8.0<v2.13.2', 'product': {'name': 'FDS102 >=v2.8.0<v2.13.3', 'product_id': 'CSAFID-51001'}, 'category': 'product_version_range'}, {'name': '<v2.13.3', 'product': {'name': 'FDS102 <v2.13.3', 'product_id': 'CSAFID-51002'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': '101', 'branches': [{'name': '<=v1.4.25', 'product': {'name': 'FDS101 <=v1.4.25', 'product_id': 'CSAFID-51003'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SNMP101', 'branches': [{'name': '<=v.2.3.9', 'product': {'name': 'FDS-SNMP101 <=v.2.3.9', 'product_id': 'CSAFID-51004'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'product_family'}], 'category': 'vendor'}], 'product_groups': [{'summary': 'Affected Products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFID-51001', 'CSAFID-51002', 'CSAFID-51003', 'CSAFID-51004']}]}, 'vulnerabilities': [{'cve': 'CVE-2025-3626', 'cwe': {'id': 'CWE-78', 'name': "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"}, 'notes': [{'text': "A remote attacker with administrator account can gain full control of the device due to improper neutralization of special elements used in an OS Command ('OS Command Injection') while uploading a config file via webUI.", 'title': 'Description', 'category': 'description'}], 'title': 'CVE-2025-3626', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 9.1, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H', 'temporalScore': 9.1, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.1, 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFID-51001']}], 'remediations': [{'details': 'Update to FDS102 v2.13.3', 'category': 'vendor_fix', 'product_ids': ['CSAFID-51001']}, {'details': 'Security-related application conditions SecRAC:\n\n* The railway operator must ensure that only authorised personnel or people in the company of\nauthorised personnel have access to the Frauscher Diagnostic System FDS102.\n\n* The recommendation is to connect the Frauscher Diagnostic System FDS102 to a network of category 2. If the Frauscher Diagnostic System FDS102 is connected to a network of category 3\n(according to EN 50159:2010), then additional protective measures must be added.', 'category': 'mitigation', 'product_ids': ['CSAFID-51001']}], 'product_status': {'fixed': ['CSAFID-52001'], 'known_affected': ['CSAFID-51001']}}, {'cve': 'CVE-2025-3705', 'cwe': {'id': 'CWE-78', 'name': "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"}, 'notes': [{'text': "A physical attacker with no privileges can gain full control of the affected device due to improper neutralization of special elements used in an OS Command ('OS Command Injection') when loading a config file from a USB drive.", 'title': 'Description', 'category': 'description'}], 'title': 'CVE-2025-3705', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.8, 'attackVector': 'PHYSICAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'HIGH', 'environmentalScore': 6.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFID-51002', 'CSAFID-51003', 'CSAFID-51004']}], 'remediations': [{'details': 'Update to FDS102 v2.13.3', 'category': 'vendor_fix', 'product_ids': ['CSAFID-51002', 'CSAFID-51003']}, {'details': 'Security-related application conditions SecRAC:\n\n* The railway operator must ensure that only authorised personnel or people in the company of\nauthorised personnel have access to the Frauscher Diagnostic System FDS101/FDS-SNMP101/FDS102.', 'category': 'mitigation', 'product_ids': ['CSAFID-51002', 'CSAFID-51003', 'CSAFID-51004']}], 'product_status': {'fixed': ['CSAFID-52001'], 'known_affected': ['CSAFID-51002', 'CSAFID-51003', 'CSAFID-51004']}}]}
3a5fde67b424d244ab14c02e3f2af1766be5236c6cf6e41628643dc714681874
2026-05-29 08:30:27.908488+03:00
2026-05-29 08:30:27.908488+03:00
csaf_ifmelectronicgmbh.ndjson
56130fea5fcee8c2beed2355fd477593ab085927ab843e8f4896a08f496704f8
{'document': {'lang': 'en-GB', 'notes': [{'text': "An unauthenticated remote attacker could reset the administrator's password with information from the default, self-signed certificate.", 'title': 'Summary', 'category': 'summary'}, {'text': 'An unathenticated attacker can remotely reset the administrator password.', 'title': 'Impact', 'category': 'description'}, {'text': 'The certificate is renewed by adjusting the hostname to an own customer-specific, so it does not contain the serial number.', 'title': 'Mitigation', 'category': 'description'}, {'text': 'The password-reset mechanism will be updated in a future version.\nWhen using automation components, make sure that no unauthorized access can take place. In addition, measures should be taken to ensure that the components do not have direct access to Internet resources and that they cannot be accessed from insecure networks. Use available security measures such as authentication and authorization groups.', 'title': 'Remediation', 'category': 'description'}], 'title': 'IFM: weak password recovery vulnerability in moneo appliance', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2022-050', 'status': 'final', 'aliases': ['VDE-2022-050'], 'version': '2.0.0', 'generator': {'date': '2026-01-30T08:42:49.132Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.42'}}, 'revision_history': [{'date': '2022-12-12T11:00:00.000Z', 'number': '1.0.0', 'summary': 'Initial revision.'}, {'date': '2026-01-06T11:00:00.000Z', 'number': '2.0.0', 'summary': 'fixed version range, added Hardware with relationship, changed vulnerability title to CVE description'}], 'current_release_date': '2026-01-06T11:00:00.000Z', 'initial_release_date': '2022-12-12T11:00:00.000Z'}, 'publisher': {'name': 'ifm electronic GmbH', 'category': 'vendor', 'namespace': 'https://www.ifm.com', 'contact_details': 'psirt@ifm.com'}, 'references': [{'url': 'https://certvde.com/en/advisories/VDE-2022-050/', 'summary': 'VDE-2022-050: IFM: weak password recovery vulnerability in moneo appliance - HTML', 'category': 'self'}, {'url': 'https://ifm.csaf-tp.certvde.com/.well-known/csaf/white/2022/vde-2022-050.json', 'summary': 'VDE-2022-050: IFM: weak password recovery vulnerability in moneo appliance - CSAF', 'category': 'self'}, {'url': 'https://www.ifm.com', 'summary': 'Vendor PSIRT', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/ifm/', 'summary': 'CERT@VDE Security Advisories for ifm electronic GmbH', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}, {'summary': 'reporting', 'organization': 'Aimon Dawson'}]}, 'product_tree': {'branches': [{'name': 'IFM', 'branches': [{'name': 'Software', 'branches': [{'name': 'moneo appliance', 'branches': [{'name': 'vers:semver/<=1.9.3', 'product': {'name': 'moneo appliance <=1.9.3', 'product_id': 'CSAFPID-51001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Hardware', 'branches': [{'name': 'QHA210', 'product': {'name': 'QHA210', 'product_id': 'CSAFPID-11001', 'product_identification_helper': {'cpe': 'cpe:2.3:h:ifm_electronic:qha210:*:*:*:*:*:*:*:*', 'model_numbers': ['QHA210']}}, 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'moneo appliance <=1.9.3 installed on QHA210', 'product_id': 'CSAFPID-31001'}, 'product_reference': 'CSAFPID-51001', 'relates_to_product_reference': 'CSAFPID-11001'}]}, 'vulnerabilities': [{'cve': 'CVE-2022-3485', 'cwe': {'id': 'CWE-640', 'name': 'Weak Password Recovery Mechanism for Forgotten Password'}, 'notes': [{'text': 'In IFM Moneo Appliance with version up to 1.9.3 an unauthenticated remote attacker can reset the administrator password by only supplying the serial number and thus gain full control of the device.\n', 'title': 'CVE Description', 'category': 'description'}], 'title': 'CVE-2022-3485', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001', 'CSAFPID-51001']}], 'remediations': [{'details': 'The certificate is renewed by adjusting the hostname to an own customer-specific, so it does not contain the serial number.', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001', 'CSAFPID-31001']}, {'details': 'The password-reset mechanism will be updated in a future version.\nWhen using automation components, make sure that no unauthorized access can take place. In addition, measures should be taken to ensure that the components do not have direct access to Internet resources and that they cannot be accessed from insecure networks. Use available security measures such as authentication and authorization groups.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001', 'CSAFPID-31001']}], 'product_status': {'known_affected': ['CSAFPID-31001', 'CSAFPID-51001']}}]}
c196bd38cd6f1bb049b77decbd22376f5598914d8c9c5c775aec1beead05910b
2026-05-29 08:30:28.356732+03:00
2026-05-29 08:30:28.356732+03:00
csaf_ifmelectronicgmbh.ndjson
c6bab76be5831e270cab875f9660b1e7f2eac0a201151ccb7a429ac571bcc103
{'document': {'lang': 'en-GB', 'notes': [{'text': 'In ifm Smart PLC firmware up to version 4.3.17 for Smart PLC controllers AC14xx and AC4xxS, an attacker can access the configuration by using the hardcoded credentials. The endpoint hosts a scripts capable of executing various commands.', 'title': 'Summary', 'category': 'summary'}, {'text': 'Please see the CVE description.', 'title': 'Impact', 'category': 'description'}, {'text': 'When using automation components, make sure that no unauthorized access can take place. Addition measures should be taken to ensure that the components do not have direct access to Internet resources and that they cannot be accessed from insecure networks. Use available security measures such as authentication and authorization groups.', 'title': 'Mitigation', 'category': 'description'}, {'text': 'Update to Firmware Version 6.1.8 or later.', 'title': 'Remediation', 'category': 'description'}], 'title': 'ifm: Vulnerabilities in ifm AC14 firmware', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2024-012', 'status': 'final', 'aliases': ['VDE-2024-012'], 'version': '3.0.0', 'generator': {'date': '2026-01-30T08:26:37.355Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.42'}}, 'revision_history': [{'date': '2024-07-09T07:00:00.000Z', 'number': '1.0.0', 'summary': 'Initial revision.'}, {'date': '2025-08-27T10:00:00.000Z', 'number': '1.1.0', 'summary': 'Update: CWE from CVE-2024-28751, Revision History'}, {'date': '2026-01-06T11:00:00.000Z', 'number': '2.0.0', 'summary': 'Fixed Version range, Added Score to Vulnerability CVE-2024-28750, deleted "firmware" from the full product name of the hardware, changed Vulnerability title to CVE description'}, {'date': '2026-01-15T11:00:00.000Z', 'number': '3.0.0', 'summary': 'Update Product information'}], 'current_release_date': '2026-01-15T11:00:00.000Z', 'initial_release_date': '2024-07-09T07:00:00.000Z'}, 'publisher': {'name': 'ifm electronic GmbH', 'category': 'vendor', 'namespace': 'https://www.ifm.com', 'contact_details': 'psirt@ifm.com'}, 'references': [{'url': 'https://certvde.com/en/advisories/VDE-2024-012/', 'summary': 'VDE-2024-012: ifm: Vulnerabilities in ifm AC14 firmware - HTML', 'category': 'self'}, {'url': 'https://ifm.csaf-tp.certvde.com/.well-known/csaf/white/2024/vde-2024-012.json', 'summary': 'VDE-2024-012: ifm: Vulnerabilities in ifm AC14 firmware - CSAF', 'category': 'self'}, {'url': 'https://www.ifm.com', 'summary': 'Vendor PSIRT', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/ifm/', 'summary': 'CERT@VDE Security Advisories for ifm electronic GmbH', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}, {'names': ['Logan Carpenter'], 'summary': 'reporting', 'organization': 'Dragos'}]}, 'product_tree': {'branches': [{'name': 'ifm', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'Smart PLC AC1401', 'product': {'name': 'Smart PLC AC1401', 'product_id': 'CSAFPID-11001', 'product_identification_helper': {'cpe': 'cpe:2.3:h:ifm_electronic:ac1401:*:*:*:*:*:*:*:*'}}, 'category': 'product_name'}, {'name': 'Smart PLC AC402s ', 'product': {'name': 'Smart PLC AC402s ', 'product_id': 'CSAFPID-11002', 'product_identification_helper': {'cpe': 'cpe:2.3:h:ifm_electronic:ac402s:*:*:*:*:*:*:*:*'}}, 'category': 'product_name'}, {'name': 'Smart PLC AC1402', 'product': {'name': 'Smart PLC AC1402', 'product_id': 'CSAFPID-32003', 'product_identification_helper': {'cpe': 'cpe:2.3:h:ifm_electronic:ac1402:*:*:*:*:*:*:*:*'}}, 'category': 'product_name'}, {'name': 'Smart PLC AC1403', 'product': {'name': 'Smart PLC AC1403', 'product_id': 'CSAFPID-32004', 'product_identification_helper': {'cpe': 'cpe:2.3:h:ifm_electronic:ac1403:*:*:*:*:*:*:*:*'}}, 'category': 'product_name'}, {'name': 'Smart PLC AC1404', 'product': {'name': 'Smart PLC AC1404', 'product_id': 'CSAFPID-32005', 'product_identification_helper': {'cpe': 'cpe:2.3:h:ifm_electronic:ac1404:*:*:*:*:*:*:*:*'}}, 'category': 'product_name'}, {'name': 'Smart PLC AC1411', 'product': {'name': 'Smart PLC AC1411', 'product_id': 'CSAFPID-32006', 'product_identification_helper': {'cpe': 'cpe:2.3:h:ifm_electronic:ac14011:*:*:*:*:*:*:*:*'}}, 'category': 'product_name'}, {'name': 'Smart PLC AC1412', 'product': {'name': 'Smart PLC AC1412', 'product_id': 'CSAFPID-32007', 'product_identification_helper': {'cpe': 'cpe:2.3:h:ifm_electronic:ac1412:*:*:*:*:*:*:*:*'}}, 'category': 'product_name'}, {'name': 'Smart PLC AC1421', 'product': {'name': 'Smart PLC AC1421', 'product_id': 'CSAFPID-32008', 'product_identification_helper': {'cpe': 'cpe:2.3:h:ifm_electronic:ac1421:*:*:*:*:*:*:*:*'}}, 'category': 'product_name'}, {'name': 'Smart PLC AC1422', 'product': {'name': 'Smart PLC AC1421', 'product_id': 'CSAFPID-32009', 'product_identification_helper': {'cpe': 'cpe:2.3:h:ifm_electronic:ac1422:*:*:*:*:*:*:*:*'}}, 'category': 'product_name'}, {'name': 'Smart PLC AC1423', 'product': {'name': 'Smart PLC AC1423', 'product_id': 'CSAFPID-32010', 'product_identification_helper': {'cpe': 'cpe:2.3:h:ifm_electronic:ac1423:*:*:*:*:*:*:*:*'}}, 'category': 'product_name'}, {'name': 'Smart PLC AC1424', 'product': {'name': 'Smart PLC AC1424', 'product_id': 'CSAFPID-32011', 'product_identification_helper': {'cpe': 'cpe:2.3:h:ifm_electronic:ac1424:*:*:*:*:*:*:*:*'}}, 'category': 'product_name'}, {'name': 'Smart PLC AC1433', 'product': {'name': 'Smart PLC AC1433', 'product_id': 'CSAFPID-32012', 'product_identification_helper': {'cpe': 'cpe:2.3:h:ifm_electronic:ac1433:*:*:*:*:*:*:*:*'}}, 'category': 'product_name'}, {'name': 'Smart PLC AC1434', 'product': {'name': 'Smart PLC AC1434', 'product_id': 'CSAFPID-32013', 'product_identification_helper': {'cpe': 'cpe:2.3:h:ifm_electronic:ac1434:*:*:*:*:*:*:*:*'}}, 'category': 'product_name'}, {'name': 'Smart PLC AC422s ', 'product': {'name': 'Smart PLC AC422s ', 'product_id': 'CSAFPID-32014', 'product_identification_helper': {'cpe': 'cpe:2.3:h:ifm_electronic:ac422s:*:*:*:*:*:*:*:*'}}, 'category': 'product_name'}, {'name': 'Smart PLC AC424s ', 'product': {'name': 'Smart PLC AC424s ', 'product_id': 'CSAFPID-32015', 'product_identification_helper': {'cpe': 'cpe:2.3:h:ifm_electronic:ac424s:*:*:*:*:*:*:*:*'}}, 'category': 'product_name'}, {'name': 'Smart PLC AC432s ', 'product': {'name': 'Smart PLC AC432s ', 'product_id': 'CSAFPID-32016', 'product_identification_helper': {'cpe': 'cpe:2.3:h:ifm_electronic:ac432s:*:*:*:*:*:*:*:*'}}, 'category': 'product_name'}, {'name': 'Smart PLC AC434s ', 'product': {'name': 'Smart PLC AC434s ', 'product_id': 'CSAFPID-32017', 'product_identification_helper': {'cpe': 'cpe:2.3:h:ifm_electronic:ac434s:*:*:*:*:*:*:*:*'}}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': 'vers:semver/<=4.3.17', 'product': {'name': 'Firmware <=V4.3.17', 'product_id': 'CSAFPID-21001'}, 'category': 'product_version_range'}, {'name': '6.1.8', 'product': {'name': 'Firmware 6.1.8', 'product_id': 'CSAFPID-22001', 'product_identification_helper': {'cpe': 'cpe:2.3:o:ifm_electronic:ac_firmware:6.1.8:*:*:*:*:*:*:*'}}, 'category': 'product_version'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=V4.3.17 installed on Smart PLC AC1401', 'product_id': 'CSAFPID-31001'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=V4.3.17 installed on Smart PLC AC402s ', 'product_id': 'CSAFPID-31002'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11002'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 6.1.8 installed on Smart PLC AC1401', 'product_id': 'CSAFPID-32001'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 6.1.8 installed on Smart PLC AC402s ', 'product_id': 'CSAFPID-32002'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11002'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=V4.3.17 installed on Smart PLC AC1412', 'product_id': 'CSAFPID-0001'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-32007'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=V4.3.17 installed on Smart PLC AC1402', 'product_id': 'CSAFPID-0004'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-32003'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=V4.3.17 installed on Smart PLC AC1403', 'product_id': 'CSAFPID-0005'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-32004'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=V4.3.17 installed on Smart PLC AC1404', 'product_id': 'CSAFPID-0006'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-32005'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=V4.3.17 installed on Smart PLC AC1411', 'product_id': 'CSAFPID-0007'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-32006'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=V4.3.17 installed on Smart PLC AC1412', 'product_id': 'CSAFPID-0008'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-32007'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=V4.3.17 installed on Smart PLC AC1423', 'product_id': 'CSAFPID-0009'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-32010'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=V4.3.17 installed on Smart PLC AC1424', 'product_id': 'CSAFPID-0010'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-32011'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=V4.3.17 installed on Smart PLC AC1433', 'product_id': 'CSAFPID-0011'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-32012'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=V4.3.17 installed on Smart PLC AC1434', 'product_id': 'CSAFPID-0012'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-32013'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=V4.3.17 installed on Smart PLC AC422s ', 'product_id': 'CSAFPID-0013'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-32014'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=V4.3.17 installed on Smart PLC AC424s ', 'product_id': 'CSAFPID-0014'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-32015'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=V4.3.17 installed on Smart PLC AC434s ', 'product_id': 'CSAFPID-0015'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-32017'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=V4.3.17 installed on Smart PLC AC432s ', 'product_id': 'CSAFPID-0016'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-32016'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=V4.3.17 installed on Smart PLC AC1421', 'product_id': 'CSAFPID-0017'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-32008'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 6.1.8 installed on Smart PLC AC1402', 'product_id': 'CSAFPID-0018'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-32003'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 6.1.8 installed on Smart PLC AC1403', 'product_id': 'CSAFPID-0019'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-32004'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 6.1.8 installed on Smart PLC AC1404', 'product_id': 'CSAFPID-0020'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-32005'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 6.1.8 installed on Smart PLC AC1411', 'product_id': 'CSAFPID-0021'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-32006'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 6.1.8 installed on Smart PLC AC1411', 'product_id': 'CSAFPID-0023'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-32006'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 6.1.8 installed on Smart PLC AC1421', 'product_id': 'CSAFPID-0024'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-32008'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 6.1.8 installed on Smart PLC AC1421', 'product_id': 'CSAFPID-0025'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-32009'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 6.1.8 installed on Smart PLC AC1423', 'product_id': 'CSAFPID-0026'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-32010'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 6.1.8 installed on Smart PLC AC1424', 'product_id': 'CSAFPID-0027'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-32011'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 6.1.8 installed on Smart PLC AC1433', 'product_id': 'CSAFPID-0028'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-32012'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 6.1.8 installed on Smart PLC AC1434', 'product_id': 'CSAFPID-0029'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-32013'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 6.1.8 installed on Smart PLC AC422s ', 'product_id': 'CSAFPID-0030'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-32014'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 6.1.8 installed on Smart PLC AC424s ', 'product_id': 'CSAFPID-0031'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-32015'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 6.1.8 installed on Smart PLC AC432s ', 'product_id': 'CSAFPID-0032'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-32016'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 6.1.8 installed on Smart PLC AC434s ', 'product_id': 'CSAFPID-0033'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-32017'}], 'product_groups': [{'summary': 'Affected products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-0001', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017']}, {'summary': 'Fixed products.', 'group_id': 'CSAFGID-0002', 'product_ids': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0027', 'CSAFPID-0028', 'CSAFPID-0029', 'CSAFPID-0030', 'CSAFPID-0031', 'CSAFPID-0032', 'CSAFPID-0033']}]}, 'vulnerabilities': [{'cve': 'CVE-2024-28751', 'cwe': {'id': 'CWE-798', 'name': 'Use of Hard-coded Credentials'}, 'notes': [{'text': 'An high privileged remote attacker can enable telnet access that accepts hardcoded credentials. \n', 'title': 'CVE Description', 'category': 'description'}], 'title': 'CVE-2024-28751', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 9.1, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H', 'temporalScore': 9.1, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.1, 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-0001', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017']}], 'remediations': [{'details': 'When using automation components, make sure that no unauthorized access can take place. Addition measures should be taken to ensure that the components do not have direct access to Internet resources and that they cannot be accessed from insecure networks. Use available security measures such as authentication and authorization groups.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Update to Firmware Version 6.1.8 or later.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0027', 'CSAFPID-0028', 'CSAFPID-0029', 'CSAFPID-0030', 'CSAFPID-0031', 'CSAFPID-0032', 'CSAFPID-0033'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-0001', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017']}}, {'cve': 'CVE-2024-28750', 'cwe': {'id': 'CWE-78', 'name': "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"}, 'notes': [{'text': 'A remote attacker with high privileges may use a deleting file function to inject OS commands.\n', 'title': 'CVE Description', 'category': 'description'}], 'title': 'CVE-2024-28750', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.2, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 7.2, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.2, 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-0001', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017']}], 'remediations': [{'details': 'When using automation components, make sure that no unauthorized access can take place. Addition measures should be taken to ensure that the components do not have direct access to Internet resources and that they cannot be accessed from insecure networks. Use available security measures such as authentication and authorization groups.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Update to Firmware Version 6.1.8 or later.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0027', 'CSAFPID-0028', 'CSAFPID-0029', 'CSAFPID-0030', 'CSAFPID-0031', 'CSAFPID-0032', 'CSAFPID-0033'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-0001', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017']}}, {'cve': 'CVE-2024-28749', 'cwe': {'id': 'CWE-78', 'name': "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"}, 'notes': [{'text': 'A remote attacker with high privileges may use a writing file function to inject OS commands.\n', 'title': 'CVE Description', 'category': 'description'}], 'title': 'CVE-2024-28749', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.2, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 7.2, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.2, 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-0001', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017']}], 'remediations': [{'details': 'When using automation components, make sure that no unauthorized access can take place. Addition measures should be taken to ensure that the components do not have direct access to Internet resources and that they cannot be accessed from insecure networks. Use available security measures such as authentication and authorization groups.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Update to Firmware Version 6.1.8 or later.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0027', 'CSAFPID-0028', 'CSAFPID-0029', 'CSAFPID-0030', 'CSAFPID-0031', 'CSAFPID-0032', 'CSAFPID-0033'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-0001', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017']}}, {'cve': 'CVE-2024-28748', 'cwe': {'id': 'CWE-78', 'name': "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"}, 'notes': [{'text': 'A remote attacker with high privileges may use a reading file function to inject OS commands.\n', 'title': 'CVE Description', 'category': 'description'}], 'title': 'CVE-2024-28748', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.2, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 7.2, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.2, 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-0001', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017']}], 'remediations': [{'details': 'When using automation components, make sure that no unauthorized access can take place. Addition measures should be taken to ensure that the components do not have direct access to Internet resources and that they cannot be accessed from insecure networks. Use available security measures such as authentication and authorization groups.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Update to Firmware Version 6.1.8 or later.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0027', 'CSAFPID-0028', 'CSAFPID-0029', 'CSAFPID-0030', 'CSAFPID-0031', 'CSAFPID-0032', 'CSAFPID-0033'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-0001', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017']}}, {'cve': 'CVE-2024-28747', 'cwe': {'id': 'CWE-798', 'name': 'Use of Hard-coded Credentials'}, 'notes': [{'text': 'An unauthenticated remote attacker can use the hard-coded credentials to access the SmartSPS devices with high privileges.\n', 'title': 'CVE Description', 'category': 'description'}], 'title': 'CVE-2024-28747', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-0001', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017']}], 'remediations': [{'details': 'When using automation components, make sure that no unauthorized access can take place. Addition measures should be taken to ensure that the components do not have direct access to Internet resources and that they cannot be accessed from insecure networks. Use available security measures such as authentication and authorization groups.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Update to Firmware Version 6.1.8 or later.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0027', 'CSAFPID-0028', 'CSAFPID-0029', 'CSAFPID-0030', 'CSAFPID-0031', 'CSAFPID-0032', 'CSAFPID-0033'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-0001', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017']}}]}
176078aa22961afd57b51f439fa5b3b7cf5195cc2e00451cd02a501875869dcb
2026-05-29 08:30:28.356732+03:00
2026-05-29 08:30:28.356732+03:00
csaf_ifmelectronicgmbh.ndjson
67978a41c95c41ced2561bf98e5b121bfb3cdf8f6dc06c08b66d07e9cca49f8d
{'document': {'lang': 'en-GB', 'notes': [{'text': 'moneo \\"Forgot Password\\" function has a vulnerability which allows gaining privileged access.', 'title': 'Summary', 'category': 'summary'}, {'text': 'In a moneo appliance with no mailserver configured, an unauthorized attacker can reset a password to the new user default value.', 'title': 'Impact', 'category': 'description'}, {'text': 'The correct configuration of a mail server prevents the exploitation of the vulnerability.', 'title': 'Mitigation', 'category': 'description'}, {'text': 'Update to moneo version 1.13.5 or later.', 'title': 'Remediation', 'category': 'description'}, {'text': 'When using automation components, make sure that no unauthorized access can take place. In addition, measures should be taken to ensure that the components do not have direct access to Internet resources and that they cannot be accessed from insecure networks. Use available security measures such as authentication and authorization groups.', 'title': 'General Recommendation', 'category': 'general'}, {'text': 'THIS DOCUMENT IS PROVIDED ON AN \\"AS IS\\" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. IFM RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME. A standalone copy or paraphrase of the text of this document that omits the distribution URL is an uncontrolled copy and may lack important information or contain factual errors. The information in this document is intended for end users of ifm products.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}], 'title': 'ifm moneo password reset can be exploited', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2024-028', 'status': 'final', 'aliases': ['VDE-2024-028'], 'version': '11.0.0', 'generator': {'date': '2026-01-30T08:32:05.707Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.42'}}, 'revision_history': [{'date': '2024-05-06T10:00:00.000Z', 'number': '1.0.0', 'summary': 'initial revision'}, {'date': '2024-05-24T10:00:00.000Z', 'number': '2.0.0', 'summary': 'final draft'}, {'date': '2024-05-27T10:00:00.000Z', 'number': '3.0.0', 'summary': 'Update'}, {'date': '2024-06-03T09:00:00.000Z', 'number': '4.0.0', 'summary': 'Update after review'}, {'date': '2024-10-30T11:00:00.000Z', 'number': '5.0.0', 'summary': 'no security relevant changes\nchanged URLs from cert-vde.com to certvde.com\nrevamped product tree'}, {'date': '2024-11-06T11:27:01.000Z', 'number': '6.0.0', 'summary': 'Fix: added self-reference'}, {'date': '2025-01-28T11:00:00.000Z', 'number': '7.0.0', 'summary': 'Update: changed affected products group'}, {'date': '2025-02-03T11:00:00.000Z', 'number': '8.0.0', 'summary': 'fix TLP to white'}, {'date': '2025-02-28T11:00:00.000Z', 'number': '9.0.0', 'summary': 'fixed: \n * initial release date\n * spacing in version ranges\n * reference category'}, {'date': '2026-01-06T11:00:00.000Z', 'number': '10.0.0', 'summary': 'changed Windows form product name to product family and fixed the version range, added CPEs'}, {'date': '2026-01-15T11:00:00.000Z', 'number': '11.0.0', 'summary': 'add cpe product identifier to Hardware and Software'}], 'current_release_date': '2026-01-15T11:00:00.000Z', 'initial_release_date': '2024-05-06T10:00:00.000Z'}, 'publisher': {'name': 'ifm electronic GmbH', 'category': 'vendor', 'namespace': 'https://www.ifm.com', 'contact_details': 'psirt@ifm.com'}, 'references': [{'url': 'https://certvde.com/en/advisories/VDE-2024-028', 'summary': 'VDE-2024-028: ifm moneo password reset can be exploited - HTML', 'category': 'self'}, {'url': 'https://certvde.com/en/advisories/vendor/ifm/', 'summary': 'CERT@VDE Security Advisories for ifm products', 'category': 'external'}, {'url': 'https://ifm.csaf-tp.certvde.com/.well-known/csaf/white/2024/vde-2024-028.json', 'summary': 'VDE-2024-028: ifm moneo password reset can be exploited - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}]}, 'product_tree': {'branches': [{'name': 'ifm electronic GmbH', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'QVA200', 'product': {'name': 'QVA200', 'product_id': 'CSAFPID-11001', 'product_identification_helper': {'cpe': 'cpe:2.3:h:ifm_electronic:qha200:*:*:*:*:*:*:*:*'}}, 'category': 'product_name'}, {'name': 'QHA210', 'product': {'name': 'QHA210', 'product_id': 'CSAFPID-11002', 'product_identification_helper': {'cpe': 'cpe:2.3:h:ifm_electronic:qha210:*:*:*:*:*:*:*:*'}}, 'category': 'product_name'}, {'name': 'QHA300', 'product': {'name': 'QHA300', 'product_id': 'CSAFPID-11003', 'product_identification_helper': {'cpe': 'cpe:2.3:h:ifm_electronic:qha300:*:*:*:*:*:*:*:*'}}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Software', 'branches': [{'name': 'moneo', 'branches': [{'name': 'vers:semver/<1.13.5', 'product': {'name': 'moneo <1.13.5', 'product_id': 'CSAFPID-51001'}, 'category': 'product_version_range'}, {'name': '1.13.5', 'product': {'name': 'moneo 1.13.5', 'product_id': 'CSAFPID-52001', 'product_identification_helper': {'cpe': 'cpe:2.3:a:ifm_electronic:moneo:1.13.5:*:*:*:*:*:*:*'}}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}, {'name': 'Microsoft ', 'branches': [{'name': 'OS', 'branches': [{'name': 'Windows ', 'product': {'name': 'Microsoft Windows', 'product_id': 'CSAFPID-90001', 'product_identification_helper': {'cpe': 'cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*'}}, 'category': 'product_family'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'moneo <1.13.5 installed on QVA200', 'product_id': 'CSAFPID-3101'}, 'product_reference': 'CSAFPID-51001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'moneo <1.13.5 installed on QHA210', 'product_id': 'CSAFPID-3102'}, 'product_reference': 'CSAFPID-51001', 'relates_to_product_reference': 'CSAFPID-11002'}, {'category': 'installed_on', 'full_product_name': {'name': 'moneo <1.13.5 installed on QHA300', 'product_id': 'CSAFPID-3103'}, 'product_reference': 'CSAFPID-51001', 'relates_to_product_reference': 'CSAFPID-11003'}, {'category': 'installed_on', 'full_product_name': {'name': 'moneo 1.13.5 installed on QVA200', 'product_id': 'CSAFPID-3201'}, 'product_reference': 'CSAFPID-52001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'moneo 1.13.5 installed on QHA210', 'product_id': 'CSAFPID-3202'}, 'product_reference': 'CSAFPID-52001', 'relates_to_product_reference': 'CSAFPID-11002'}, {'category': 'installed_on', 'full_product_name': {'name': 'moneo <1.13.5 installed on Microsoft Windows', 'product_id': 'CSAFPID-3104'}, 'product_reference': 'CSAFPID-51001', 'relates_to_product_reference': 'CSAFPID-90001'}, {'category': 'installed_on', 'full_product_name': {'name': 'moneo 1.13.5 installed on Microsoft Windows', 'product_id': 'CSAFPID-3204'}, 'product_reference': 'CSAFPID-52001', 'relates_to_product_reference': 'CSAFPID-90001'}, {'category': 'installed_on', 'full_product_name': {'name': 'moneo 1.13.5 installed on QHA300', 'product_id': 'CSAFPID-3203'}, 'product_reference': 'CSAFPID-52001', 'relates_to_product_reference': 'CSAFPID-11003'}], 'product_groups': [{'summary': 'Affected products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-3101', 'CSAFPID-3102', 'CSAFPID-3103', 'CSAFPID-3104']}, {'summary': 'Fixed products.', 'group_id': 'CSAFGID-0003', 'product_ids': ['CSAFPID-3201', 'CSAFPID-3202', 'CSAFPID-3203', 'CSAFPID-3204']}]}, 'vulnerabilities': [{'cve': 'CVE-2024-5404', 'cwe': {'id': 'CWE-640', 'name': 'Weak Password Recovery Mechanism for Forgotten Password'}, 'notes': [{'text': 'An unauthenticated remote attacker can change the admin password in a moneo appliance due to weak password recovery mechanism.', 'title': 'Description', 'category': 'description'}], 'title': 'CVE-2024-5404', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-3101', 'CSAFPID-3102', 'CSAFPID-3103', 'CSAFPID-3104']}], 'release_date': '2024-06-03T09:00:00.000Z', 'remediations': [{'date': '2024-06-06T09:00:00.000Z', 'details': 'Update to moneo version 1.13.5 or later.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-3201', 'CSAFPID-3202', 'CSAFPID-3203', 'CSAFPID-3204'], 'known_affected': ['CSAFPID-3101', 'CSAFPID-3102', 'CSAFPID-3103', 'CSAFPID-3104']}}]}
34636e97b584e957605c06a809d1507693fcb7a0cd4f4d3700ea650ce270ef7a
2026-05-29 08:30:28.356732+03:00
2026-05-29 08:30:28.356732+03:00
csaf_ifmelectronicgmbh.ndjson
928a164016d7bb1c13e8d63865db64d3f09e528a4518ed4d8b49b7eeffe4f120
{'document': {'lang': 'en-GB', 'notes': [{'text': 'A vulnerability has been disclosed in PLC ifm AC4xxS that allows an attacker to trigger the safety state with the help of a specially crafted html request. This leads to a loss of availability.', 'title': 'Summary', 'category': 'summary'}, {'text': 'An unauthorized attacker can exploit this vulnerability to issue malicious commands to the PLC, potentially disrupting or damaging the production line. ', 'title': 'Impact', 'category': 'description'}, {'text': 'When using automation components, make sure that no unauthorized access can take place. In addition, measures should be taken to ensure that the components do not have direct access to Internet resources and that they cannot be accessed from insecure networks. Use available security measures such as authentication and authorization groups.\n\nPLC with firmware V6.1.8 http interface can be disabled.', 'title': 'Mitigation', 'category': 'description'}], 'title': 'ifm: Improper Access Control vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2024-061', 'status': 'final', 'aliases': ['VDE-2024-061', 'ifm-23082024'], 'version': '2.0.1', 'generator': {'date': '2026-02-18T07:57:21.164Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.43'}}, 'revision_history': [{'date': '2025-06-30T10:00:00.000Z', 'number': '1.0.0', 'summary': 'Initial release.', 'legacy_version': '1'}, {'date': '2026-02-16T15:00:00.000Z', 'number': '2.0.0', 'summary': 'Updated content and product names.'}, {'date': '2026-02-18T08:00:00.000Z', 'number': '2.0.1', 'summary': 'Fixed Typo.'}], 'current_release_date': '2026-02-18T08:00:00.000Z', 'initial_release_date': '2025-06-30T10:00:00.000Z'}, 'publisher': {'name': 'ifm electronic GmbH', 'category': 'vendor', 'namespace': 'https://www.ifm.com', 'contact_details': 'psirt@ifm.com'}, 'references': [{'url': 'https://certvde.com/en/advisories/vendor/ifm', 'summary': 'CERT@VDE Security Advisories for ifm electronic GmbH', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/VDE-2024-061', 'summary': 'VDE-2024-061: ifm: Improper Access Control vulnerability - HTML', 'category': 'self'}, {'url': 'https://ifm.csaf-tp.certvde.com/.well-known/csaf/white/2025/vde-2024-061.json', 'summary': 'VDE-2024-061: ifm: Improper Access Control vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.ifm.com/de/en/shared/service/technischer-support/product-security-overview', 'summary': 'ifm electronic GmbH PSIRT', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}, {'urls': ['https://kpi.ua/en'], 'names': ['Dmytro Kryhin'], 'summary': 'reporting', 'organization': 'National Technical University of Ukraine "Igor Sikorsky Kyiv Polytechnic Institute"'}], 'aggregate_severity': {'text': 'High', 'namespace': 'https://www.first.org/cvss/v3.1/specification-document#Qualitative-Severity-Rating-Scale'}}, 'product_tree': {'branches': [{'name': 'ifm', 'branches': [{'name': 'Smart PLC', 'branches': [{'name': 'AC402s', 'product': {'name': 'ifm Smart PLC AC402s', 'product_id': 'CSAFPID-0010', 'product_identification_helper': {'cpe': 'cpe:2.3:h:ifm_electronic:ac402s:*:*:*:*:*:*:*:*'}}, 'category': 'product_name'}, {'name': 'AC422s', 'product': {'name': 'ifm Smart PLC AC422s', 'product_id': 'CSAFPID-0011', 'product_identification_helper': {'cpe': 'cpe:2.3:h:ifm_electronic:ac422s:*:*:*:*:*:*:*:*'}}, 'category': 'product_name'}, {'name': 'AC424s', 'product': {'name': 'ifm Smart PLC AC424s', 'product_id': 'CSAFPID-0012', 'product_identification_helper': {'cpe': 'cpe:2.3:h:ifm_electronic:ac424s:*:*:*:*:*:*:*:*'}}, 'category': 'product_name'}, {'name': 'AC432s', 'product': {'name': 'ifm Smart PLC AC432s', 'product_id': 'CSAFPID-0013', 'product_identification_helper': {'cpe': 'cpe:2.3:h:ifm_electronic:ac432s:*:*:*:*:*:*:*:*'}}, 'category': 'product_name'}, {'name': 'AC434s', 'product': {'name': 'ifm Smart PLC AC434s', 'product_id': 'CSAFPID-0014', 'product_identification_helper': {'cpe': 'cpe:2.3:h:ifm_electronic:ac434s:*:*:*:*:*:*:*:*'}}, 'category': 'product_name'}], 'category': 'product_name'}, {'name': 'Firmware', 'branches': [{'name': 'vers:generic/4.04<4.3.17', 'product': {'name': 'Firmware 4.04<4.3.17', 'product_id': 'CSAFPID-0003'}, 'category': 'product_version_range'}, {'name': '6.1.8', 'product': {'name': 'Firmware 6.1.8', 'product_id': 'CSAFPID-0004', 'product_identification_helper': {'cpe': 'cpe:2.3:o:ifm_electronic:ac4xxS:6.1.8:*:*:*:*:*:*:*'}}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware 4.04<4.3.17 installed on ifm Smart PLC AC402s', 'product_id': 'CSAFPID-0015'}, 'product_reference': 'CSAFPID-0003', 'relates_to_product_reference': 'CSAFPID-0010'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 4.04<4.3.17 installed on ifm Smart PLC AC422s', 'product_id': 'CSAFPID-0016'}, 'product_reference': 'CSAFPID-0003', 'relates_to_product_reference': 'CSAFPID-0011'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 4.04<4.3.17 installed on ifm Smart PLC AC424s', 'product_id': 'CSAFPID-0017'}, 'product_reference': 'CSAFPID-0003', 'relates_to_product_reference': 'CSAFPID-0012'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 4.04<4.3.17 installed on ifm Smart PLC AC432s', 'product_id': 'CSAFPID-0018'}, 'product_reference': 'CSAFPID-0003', 'relates_to_product_reference': 'CSAFPID-0013'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 4.04<4.3.17 installed on ifm Smart PLC AC434s', 'product_id': 'CSAFPID-0019'}, 'product_reference': 'CSAFPID-0003', 'relates_to_product_reference': 'CSAFPID-0014'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 6.1.8 installed on ifm Smart PLC AC402s', 'product_id': 'CSAFPID-0020'}, 'product_reference': 'CSAFPID-0004', 'relates_to_product_reference': 'CSAFPID-0010'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 6.1.8 installed on ifm Smart PLC AC422s', 'product_id': 'CSAFPID-0021'}, 'product_reference': 'CSAFPID-0004', 'relates_to_product_reference': 'CSAFPID-0011'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 6.1.8 installed on ifm Smart PLC AC424s', 'product_id': 'CSAFPID-0022'}, 'product_reference': 'CSAFPID-0004', 'relates_to_product_reference': 'CSAFPID-0012'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 6.1.8 installed on ifm Smart PLC AC432s', 'product_id': 'CSAFPID-0023'}, 'product_reference': 'CSAFPID-0004', 'relates_to_product_reference': 'CSAFPID-0013'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 6.1.8 installed on ifm Smart PLC AC434s', 'product_id': 'CSAFPID-0024'}, 'product_reference': 'CSAFPID-0004', 'relates_to_product_reference': 'CSAFPID-0014'}], 'product_groups': [{'summary': 'Affected products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024']}]}, 'vulnerabilities': [{'cve': 'CVE-2024-8419', 'cwe': {'id': 'CWE-306', 'name': 'Missing Authentication for Critical Function'}, 'notes': [{'text': 'The endpoint hosts a script that allows an unauthorized remote attacker to put the system in a fail-safe state over the network due to missing authentication.', 'title': 'CVE Description', 'audience': 'all', 'category': 'description'}], 'title': 'Improper Access Control vulnerability in AC4xxS devices', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024']}], 'remediations': [{'details': 'When using automation components, make sure that no unauthorized access can take place. In addition, measures should be taken to ensure that the components do not have direct access to Internet resources and that they cannot be accessed from insecure networks. Use available security measures such as authentication and authorization groups.\n\nPLC with firmware V6.1.8 http interface can be disabled.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001'], 'product_ids': ['CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024']}], 'product_status': {'known_affected': ['CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024']}}]}
8aa9ddbfde2c3779128154e54f6b5ab41806f496c70f6370798d74ee28882a2a
2026-05-29 08:30:28.356732+03:00
2026-05-29 08:30:28.356732+03:00
csaf_ifmelectronicgmbh.ndjson
e949a41165dce90f168e59c56f6cdb8c5fd93968f90064241c33f93a9a9f9d85
{'document': {'lang': 'en-US', 'notes': [{'text': 'The Firmware installed on the CR3171 is impacted by various CODESYS vulnerabilities.', 'title': 'Summary', 'category': 'summary'}, {'text': 'THIS DOCUMENT IS PROVIDED ON AN \\\\\\"AS IS\\\\\\" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. IFM RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME. A standalone copy or paraphrase of the text of this document that omits the distribution URL is an uncontrolled copy and may lack important information or contain factual errors. The information in this document is intended for end users of ifm products.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'When using automation components, make sure that no unauthorized access can take place. In addition, measures should be taken to ensure that the components do not have direct access to Internet resources and that they cannot be accessed from insecure networks. Use available security measures such as authentication and authorization groups.', 'title': 'General Recommendation', 'category': 'general'}, {'text': 'Update to the Firmware Version 3.3', 'title': 'Remediation', 'category': 'description'}, {'text': 'CVE-2025-41659 : Unauthorized access to PKI files allows attackers to extract sensitive cryptographic keys and manipulate trusted certificates. This compromises system integrity, confidentiality and partially affects availability.\n\nCVE-2025-41658 : The affected products do not explicitly restrict read permissions for other local operating system users, potentially allowing unauthorized access to sensitive runtime files.\n\nCVE-2025-41691 : Exploitation of this vulnerability can lead to a denial-of-service (DoS) condition on affected PLCs, disrupting industrial control systems.', 'title': 'Impact', 'category': 'description'}, {'text': 'CVE-2025-41659 : The vulnerability affects devices running firmware versions prior to 3.3. Due to the nature of the issue, no configuration changes, operational workarounds, or compensating controls are available that would sufficiently reduce the associated risk. Therefore, it is essential to update the affected device to firmware version 3.3.\nOperating the device on earlier firmware versions results in continued exposure to the vulnerability. Once firmware version 3.3 is installed, the vulnerability is considered fully resolved.\n\nCVE-2025-41658 : If the CODESYS Control runtime system is operated on an operating system with multi-user support, other users may potentially gain access to runtime-related files. Thus, it is essential to configure the storage locations for CODESYS Control runtime files in accordance with the operating system\'s security best practices. These locations should, by default, restrict access to unauthorized users. If the operating system does not support such access control mechanisms or if implementing them is not feasible, an alternative approach is to explicitly revoke read and write permissions for all non-administrative users on the directories used by the CODESYS Control runtime system.\n\nThe following directories must be secured:\n* The directory containing configuration files\n* The directory containing binary files\n* The working directory used by the runtime system\n\nNote: Protecting individual files is not sufficient. The entire directories must be secured to ensure that any files created in the future are also protected.\n\nAs possible countermeasures, it can be examined whether avoiding the use of the CODESYS environment in one\'s own application design is feasible.\n\nAlternatively, where applicable, all non-administrative user accounts can be removed from the system, and their re-creation should be prevented. Additionally, it is recommended to disable remote access methods that allow file access (e.g., SSH) wherever possible, in order to reduce the overall attack surface.\n\nBest practice recommendations for Linux and QNX Systems:\n* Create a dedicated privileged group for accessing the above-mentioned directories, and add the user account under which the runtime process is executed to this group.\n* Set the file system permissions for these directories to deny access to "other" users (e.g., chmod o-rx).\n* If access for additional users is required, they can be added to the privileged group as needed.\n\nCVE-2025-41691 : The vulnerability can be mitigated by restricting the allowed login authentication type "CmpUserMgr/UserLogin_AuthenticationType" to "ONLY_ASYMMETRIC". This can be configured either via the Device Security Settings dialog in the CODESYS Development System or directly in the configuration file of the CODESYS Control runtime system (CODESYSControl.cfg) by adding the following setting:\n\n[CmpUserMgr]\nSECURITY.UserLogin_AuthenticationType=ONLY_ASYMMETRIC\n\nWith this configuration in place, both potential attackers and legacy CODESYS protocol clients (prior to version 3.5.16.0) will be blocked from logging in, thereby preventing execution of the vulnerable code path.\n\nAs possible countermeasures, it can be examined whether avoiding the use of the CODESYS environment in one\'s own application design is feasible.', 'title': 'Mitigation', 'category': 'description'}], 'title': 'ifm: Multiple Vulnerabilities in CR3171', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2026-005', 'status': 'final', 'aliases': ['VDE-2026-005'], 'version': '1.0.0', 'generator': {'date': '2026-05-06T07:53:36.480Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.44'}}, 'revision_history': [{'date': '2026-05-06T08:00:00.000Z', 'number': '1.0.0', 'summary': 'initial release'}], 'current_release_date': '2026-05-06T08:00:00.000Z', 'initial_release_date': '2026-05-06T08:00:00.000Z'}, 'publisher': {'name': 'ifm electronic GmbH', 'category': 'vendor', 'namespace': 'https://www.ifm.com', 'contact_details': 'psirt@ifm.com'}, 'references': [{'url': 'https://certvde.com/de/advisories/vendor/ifm/', 'summary': 'ifm advisory overview at CERT@VDE', 'category': 'external'}, {'url': 'https://ifm.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-005.json', 'summary': 'VDE-2026-005: ifm: Multiple Vulnerabilities in CR3171 - CSAF', 'category': 'self'}, {'url': 'https://certvde.com/en/advisories/VDE-2026-005', 'summary': 'VDE-2026-005: ifm: Multiple Vulnerabilities in CR3171 - HTML', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'summary': 'coordination', 'organization': 'CERT@VDE'}]}, 'product_tree': {'branches': [{'name': 'ifm electronic gmbh', 'branches': [{'name': 'Firmware', 'branches': [{'name': '3.1', 'product': {'name': 'Firmware 3.1', 'product_id': 'CSAFPID-21001', 'product_identification_helper': {'cpe': 'cpe:2.3:o:ifm_electronic:cr3171_firmware:3.1:*:*:*:*:*:*:*'}}, 'category': 'product_version'}, {'name': '3.2', 'product': {'name': 'Firmware 3.2', 'product_id': 'CSAFPID-22001', 'product_identification_helper': {'cpe': 'cpe:2.3:o:ifm_electronic:cr3171_firmware:3.2:*:*:*:*:*:*:*'}}, 'category': 'product_version'}, {'name': '3.3', 'product': {'name': 'ifm electronic gmbh Firmware 3.3', 'product_id': 'CSAFPID-22002', 'product_identification_helper': {'cpe': 'cpe:2.3:o:ifm_electronic:cr3171_firmware:3.3:*:*:*:*:*:*:*'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Hardware', 'branches': [{'name': 'CR3171', 'product': {'name': 'CR3171', 'product_id': 'CSAFPID-11001', 'product_identification_helper': {'cpe': 'cpe:2.3:h:ifm_electronic:cr3171:*:*:*:*:*:*:*:*'}}, 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware 3.1 installed on CR3171', 'product_id': 'CSAFPID-0003', 'product_identification_helper': {'cpe': 'cpe:2.3:o:ifm_electronic:cr3171_firmware:3.1:*:*:*:*:*:*:*'}}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 3.2 installed on CR3171', 'product_id': 'CSAFPID-0004', 'product_identification_helper': {'cpe': 'cpe:2.3:o:ifm_electronic:cr3171_firmware:3.2:*:*:*:*:*:*:*'}}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'ifm electronic gmbh Firmware 3.3 installed on CR3171', 'product_id': 'CSAFPID-0002', 'product_identification_helper': {'cpe': 'cpe:2.3:o:ifm_electronic:cr3171_firmware:3.3:*:*:*:*:*:*:*'}}, 'product_reference': 'CSAFPID-22002', 'relates_to_product_reference': 'CSAFPID-11001'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-41691', 'cwe': {'id': 'CWE-476', 'name': 'NULL Pointer Dereference'}, 'notes': [{'text': 'An unauthenticated remote attacker may trigger a NULL pointer dereference in the affected CODESYS Control runtime systems by sending specially crafted communication requests, potentially leading to a denial-of-service (DoS) condition.', 'title': 'CVE description', 'category': 'description'}], 'title': 'CODESYS Control DoS via Unauthenticated NULL Pointer Dereference', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['CSAFPID-0003', 'CSAFPID-0004']}], 'remediations': [{'url': 'https://www.ifm.com/de/en/product/CR3171#documents', 'details': 'will be fixed in Firmware Version 3.3', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003', 'CSAFPID-0004']}, {'details': 'deactivate CodeSys enviroment on device', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003', 'CSAFPID-0004']}], 'product_status': {'fixed': ['CSAFPID-0002'], 'known_affected': ['CSAFPID-0003', 'CSAFPID-0004']}}, {'cve': 'CVE-2025-41659', 'cwe': {'id': 'CWE-732', 'name': 'Incorrect Permission Assignment for Critical Resource'}, 'notes': [{'text': 'A low-privileged attacker can remotely access the PKI folder of the CODESYS Control runtime system and thus read and write certificates and its keys. This allows sensitive data to be extracted or to accept certificates as trusted. Although all services remain available, only unencrypted communication is possible if the certificates are deleted.', 'title': 'CVE description', 'category': 'description'}], 'title': 'CODESYS Control PKI Exposure Enables Remote Certificate Access', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L'}, 'products': ['CSAFPID-0003', 'CSAFPID-0004']}], 'remediations': [{'url': 'https://www.ifm.com/de/en/product/CR3171#documents', 'details': 'will be fixed in Firmware Version 3.3', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003', 'CSAFPID-0004']}, {'details': 'deactivate CodeSys enviroment on device', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003', 'CSAFPID-0004']}], 'product_status': {'fixed': ['CSAFPID-0002'], 'known_affected': ['CSAFPID-0003', 'CSAFPID-0004']}}, {'cve': 'CVE-2025-41658', 'cwe': {'id': 'CWE-276', 'name': 'Incorrect Default Permissions'}, 'notes': [{'text': 'CODESYS Runtime Toolkit-based products may expose sensitive files to local low-privileged operating system users due to default file permissions.', 'title': 'CVE description', 'category': 'description'}], 'title': 'CODESYS Toolkit Exposes Sensitive Files via Default Permissions', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}, 'products': ['CSAFPID-0003', 'CSAFPID-0004']}], 'remediations': [{'url': 'https://www.ifm.com/de/en/product/CR3171#documents', 'details': 'will be fixed in Firmware Version 3.3', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003', 'CSAFPID-0004']}, {'details': 'deactivate CodeSys enviroment on device', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003', 'CSAFPID-0004']}], 'product_status': {'fixed': ['CSAFPID-0002'], 'known_affected': ['CSAFPID-0003', 'CSAFPID-0004']}}]}
5c1dcd5bc4914cb40267a67a4e6566ae353463fd93039fcde9d5919cc85fce0b
2026-05-29 08:30:28.356732+03:00
2026-05-29 08:30:28.356732+03:00
csaf_adstecindustrialitgmbh.ndjson
7ad702452539e7ebdc2835e5f25930c16e84340f80e0efc484aa2d476211b2ed
{'document': {'lang': 'en-GB', 'notes': [{'text': "The affected products integrate the vulnerable libraries in a way so that the vulnerabilities can't be exploited remotely without prior authentication.", 'title': 'Impact', 'category': 'description'}, {'text': 'It is recommended to disable all user accounts with restricted configuration write permissions if the update to the latest released version cannot be installed immediately.It is further recommended to use best practice password policies.', 'title': 'Mitigation', 'category': 'description'}, {'text': 'Update firmware to the latest version available.\xa0The issues have been resolved with IRF1000 version 1.5.0, IRF2000 version 4.4.0 and IRF3000 version 1.2.0.', 'title': 'Remediation', 'category': 'description'}], 'title': 'ads-tec: Multiple Vulnerabilities in IRF1000, IRF2000 and IRF3000', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2023-009', 'status': 'final', 'aliases': ['VDE-2023-009'], 'version': '1', 'generator': {'date': '2025-04-14T08:26:31.923Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.23'}}, 'revision_history': [{'date': '2023-05-08T13:37:00.000Z', 'number': '1', 'summary': 'Initial revision.'}], 'current_release_date': '2023-05-08T13:37:00.000Z', 'initial_release_date': '2023-05-08T13:37:00.000Z'}, 'publisher': {'name': 'ads-tec Industrial IT GmbH', 'category': 'vendor', 'namespace': 'https://www.ads-tec-iit.com', 'contact_details': 'psirt@ads-tec.de'}, 'references': [{'url': 'https://certvde.com/en/advisories/VDE-2023-009/', 'summary': 'VDE-2023-009: ads-tec: Multiple Vulnerabilities in IRF1000, IRF2000 and IRF3000 - HTML', 'category': 'self'}, {'url': 'https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2023/vde-2023-009.json', 'summary': 'VDE-2023-009: ads-tec: Multiple Vulnerabilities in IRF1000, IRF2000 and IRF3000 - CSAF', 'category': 'self'}, {'url': 'https://www.ads-tec-iit.com', 'summary': 'Vendor PSIRT', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/ads-tec-iit/', 'summary': 'CERT@VDE Security Advisories for ads-tec Industrial IT GmbH', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}]}, 'product_tree': {'branches': [{'name': 'ads-tec Industrial IT', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'IRF1000', 'product': {'name': 'IRF1000', 'product_id': 'CSAFPID-11001', 'product_identification_helper': {'model_numbers': ['DVG-IRF1401, DVG-IRF1421']}}, 'category': 'product_name'}, {'name': 'IRF2000', 'product': {'name': 'IRF2000', 'product_id': 'CSAFPID-11002', 'product_identification_helper': {'model_numbers': ['DVG-IRF2200, DVG-IRF2100, DVG-IRF2220, DVG-IRF2621, DVG-IRF2601']}}, 'category': 'product_name'}, {'name': 'IRF3000', 'product': {'name': 'IRF3000', 'product_id': 'CSAFPID-11003', 'product_identification_helper': {'model_numbers': ['DVG-IRF3401, DVG-IRF3421, DVG-IRF3801. DVG-IRF3821']}}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': '<1.5.0', 'product': {'name': 'Firmware <1.5.0', 'product_id': 'CSAFPID-21001'}, 'category': 'product_version_range'}, {'name': '<4.4.0', 'product': {'name': 'Firmware <4.4.0', 'product_id': 'CSAFPID-21002'}, 'category': 'product_version_range'}, {'name': '<1.2.0', 'product': {'name': 'Firmware <1.2.0', 'product_id': 'CSAFPID-21003'}, 'category': 'product_version_range'}, {'name': '1.5.0', 'product': {'name': 'Firmware 1.5.0', 'product_id': 'CSAFPID-22001'}, 'category': 'product_version'}, {'name': '4.4.0', 'product': {'name': 'Firmware 4.4.0', 'product_id': 'CSAFPID-22002'}, 'category': 'product_version'}, {'name': '1.2.0', 'product': {'name': 'Firmware 1.2.0', 'product_id': 'CSAFPID-22003'}, 'category': 'product_version'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware <1.5.0 installed on IRF1000', 'product_id': 'CSAFPID-31001'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <4.4.0 installed on IRF2000', 'product_id': 'CSAFPID-31002'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11002'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <1.2.0 installed on IRF3000', 'product_id': 'CSAFPID-31003'}, 'product_reference': 'CSAFPID-21003', 'relates_to_product_reference': 'CSAFPID-11003'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 1.5.0 installed on IRF1000', 'product_id': 'CSAFPID-32001'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 4.4.0 installed on IRF2000', 'product_id': 'CSAFPID-32002'}, 'product_reference': 'CSAFPID-22002', 'relates_to_product_reference': 'CSAFPID-11002'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 1.2.0 installed on IRF3000', 'product_id': 'CSAFPID-32003'}, 'product_reference': 'CSAFPID-22003', 'relates_to_product_reference': 'CSAFPID-11003'}], 'product_groups': [{'summary': 'Affected products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003']}, {'summary': 'Fixed products.', 'group_id': 'CSAFGID-0002', 'product_ids': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003']}]}, 'vulnerabilities': [{'cve': 'CVE-2014-9425', 'notes': [{'text': 'Double free vulnerability in the zend_ts_hash_graceful_destroy function in zend_ts_hash.c in the Zend Engine in PHP through 5.5.20 and 5.6.x through 5.6.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2014-9425', 'remediations': [{'details': 'It is recommended to disable all user accounts with restricted configuration write permissions if the update to the latest released version cannot be installed immediately.It is further recommended to use best practice password policies.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Update firmware to the latest version available.\xa0The issues have been resolved with IRF1000 version 1.5.0, IRF2000 version 4.4.0 and IRF3000 version 1.2.0.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003']}}, {'cve': 'CVE-2014-8142', 'notes': [{'text': 'Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.36, 5.5.x before 5.5.20, and 5.6.x before 5.6.4 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate keys within the serialized properties of an object, a different vulnerability than CVE-2004-1019.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2014-8142', 'remediations': [{'details': 'It is recommended to disable all user accounts with restricted configuration write permissions if the update to the latest released version cannot be installed immediately.It is further recommended to use best practice password policies.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Update firmware to the latest version available.\xa0The issues have been resolved with IRF1000 version 1.5.0, IRF2000 version 4.4.0 and IRF3000 version 1.2.0.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003']}}, {'cve': 'CVE-2015-2787', 'notes': [{'text': 'Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages use of the unset function within an __wakeup function, a related issue to CVE-2015-0231.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2015-2787', 'remediations': [{'details': 'It is recommended to disable all user accounts with restricted configuration write permissions if the update to the latest released version cannot be installed immediately.It is further recommended to use best practice password policies.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Update firmware to the latest version available.\xa0The issues have been resolved with IRF1000 version 1.5.0, IRF2000 version 4.4.0 and IRF3000 version 1.2.0.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003']}}, {'cve': 'CVE-2015-2348', 'notes': [{'text': 'The move_uploaded_file implementation in ext/standard/basic_functions.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 truncates a pathname upon encountering a \\x00 character, which allows remote attackers to bypass intended extension restrictions and create files with unexpected names via a crafted second argument. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-7243.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2015-2348', 'remediations': [{'details': 'It is recommended to disable all user accounts with restricted configuration write permissions if the update to the latest released version cannot be installed immediately.It is further recommended to use best practice password policies.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Update firmware to the latest version available.\xa0The issues have been resolved with IRF1000 version 1.5.0, IRF2000 version 4.4.0 and IRF3000 version 1.2.0.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003']}}, {'cve': 'CVE-2014-3669', 'notes': [{'text': 'Integer overflow in the object_custom function in ext/standard/var_unserializer.c in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an argument to the unserialize function that triggers calculation of a large length value.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2014-3669', 'remediations': [{'details': 'It is recommended to disable all user accounts with restricted configuration write permissions if the update to the latest released version cannot be installed immediately.It is further recommended to use best practice password policies.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Update firmware to the latest version available.\xa0The issues have been resolved with IRF1000 version 1.5.0, IRF2000 version 4.4.0 and IRF3000 version 1.2.0.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003']}}, {'cve': 'CVE-2015-0231', 'notes': [{'text': 'Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate numerical keys within the serialized properties of an object. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-8142.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2015-0231', 'remediations': [{'details': 'It is recommended to disable all user accounts with restricted configuration write permissions if the update to the latest released version cannot be installed immediately.It is further recommended to use best practice password policies.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Update firmware to the latest version available.\xa0The issues have been resolved with IRF1000 version 1.5.0, IRF2000 version 4.4.0 and IRF3000 version 1.2.0.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003']}}, {'cve': 'CVE-2015-3415', 'cwe': {'id': 'CWE-404', 'name': 'Improper Resource Shutdown or Release'}, 'notes': [{'text': 'The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly implement comparison operators, which allows context-dependent attackers to cause a denial of service (invalid free operation) or possibly have unspecified other impact via a crafted CHECK clause, as demonstrated by CHECK(0&O>O) in a CREATE TABLE statement.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2015-3415', 'remediations': [{'details': 'It is recommended to disable all user accounts with restricted configuration write permissions if the update to the latest released version cannot be installed immediately.It is further recommended to use best practice password policies.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Update firmware to the latest version available.\xa0The issues have been resolved with IRF1000 version 1.5.0, IRF2000 version 4.4.0 and IRF3000 version 1.2.0.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003']}}, {'cve': 'CVE-2015-3414', 'cwe': {'id': 'CWE-908', 'name': 'Use of Uninitialized Resource'}, 'notes': [{'text': 'SQLite before 3.8.9 does not properly implement the dequoting of collation-sequence names, which allows context-dependent attackers to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other impact via a crafted COLLATE clause, as demonstrated by COLLATE"""""""" at the end of a SELECT statement.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2015-3414', 'remediations': [{'details': 'It is recommended to disable all user accounts with restricted configuration write permissions if the update to the latest released version cannot be installed immediately.It is further recommended to use best practice password policies.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Update firmware to the latest version available.\xa0The issues have been resolved with IRF1000 version 1.5.0, IRF2000 version 4.4.0 and IRF3000 version 1.2.0.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003']}}, {'cve': 'CVE-2015-8876', 'notes': [{'text': 'Zend/zend_exceptions.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 does not validate certain Exception objects, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or trigger unintended method execution via crafted serialized data.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2015-8876', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003']}], 'remediations': [{'details': 'It is recommended to disable all user accounts with restricted configuration write permissions if the update to the latest released version cannot be installed immediately.It is further recommended to use best practice password policies.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Update firmware to the latest version available.\xa0The issues have been resolved with IRF1000 version 1.5.0, IRF2000 version 4.4.0 and IRF3000 version 1.2.0.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003']}}, {'cve': 'CVE-2015-6835', 'notes': [{'text': 'The session deserializer in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 mishandles multiple php_var_unserialize calls, which allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via crafted session content.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2015-6835', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003']}], 'remediations': [{'details': 'It is recommended to disable all user accounts with restricted configuration write permissions if the update to the latest released version cannot be installed immediately.It is further recommended to use best practice password policies.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Update firmware to the latest version available.\xa0The issues have been resolved with IRF1000 version 1.5.0, IRF2000 version 4.4.0 and IRF3000 version 1.2.0.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003']}}, {'cve': 'CVE-2015-4602', 'notes': [{'text': 'The __PHP_Incomplete_Class function in ext/standard/incomplete_class.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an unexpected data type, related to a "type confusion" issue.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2015-4602', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003']}], 'remediations': [{'details': 'It is recommended to disable all user accounts with restricted configuration write permissions if the update to the latest released version cannot be installed immediately.It is further recommended to use best practice password policies.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Update firmware to the latest version available.\xa0The issues have been resolved with IRF1000 version 1.5.0, IRF2000 version 4.4.0 and IRF3000 version 1.2.0.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003']}}, {'cve': 'CVE-2016-7411', 'cwe': {'id': 'CWE-119', 'name': 'Improper Restriction of Operations within the Bounds of a Memory Buffer'}, 'notes': [{'text': 'ext/standard/var_unserializer.re in PHP before 5.6.26 mishandles object-deserialization failures, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via an unserialize call that references a partially constructed object.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2016-7411', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003']}], 'remediations': [{'details': 'It is recommended to disable all user accounts with restricted configuration write permissions if the update to the latest released version cannot be installed immediately.It is further recommended to use best practice password policies.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Update firmware to the latest version available.\xa0The issues have been resolved with IRF1000 version 1.5.0, IRF2000 version 4.4.0 and IRF3000 version 1.2.0.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003']}}, {'cve': 'CVE-2016-7124', 'cwe': {'id': 'CWE-502', 'name': 'Deserialization of Untrusted Data'}, 'notes': [{'text': 'ext/standard/var_unserializer.c in PHP before 5.6.25 and 7.x before 7.0.10 mishandles certain invalid objects, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data that leads to a (1) __destruct call or (2) magic method call.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2016-7124', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003']}], 'remediations': [{'details': 'It is recommended to disable all user accounts with restricted configuration write permissions if the update to the latest released version cannot be installed immediately.It is further recommended to use best practice password policies.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Update firmware to the latest version available.\xa0The issues have been resolved with IRF1000 version 1.5.0, IRF2000 version 4.4.0 and IRF3000 version 1.2.0.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003']}}, {'cve': 'CVE-2016-9138', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'PHP through 5.6.27 and 7.x through 7.0.12 mishandles property modification during __wakeup processing, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data, as demonstrated by Exception::__toString with DateInterval::__wakeup.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2016-9138', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003']}], 'remediations': [{'details': 'It is recommended to disable all user accounts with restricted configuration write permissions if the update to the latest released version cannot be installed immediately.It is further recommended to use best practice password policies.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Update firmware to the latest version available.\xa0The issues have been resolved with IRF1000 version 1.5.0, IRF2000 version 4.4.0 and IRF3000 version 1.2.0.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003']}}, {'cve': 'CVE-2016-10161', 'cwe': {'id': 'CWE-125', 'name': 'Out-of-bounds Read'}, 'notes': [{'text': 'The object_common1 function in ext/standard/var_unserializer.c in PHP before 5.6.30, 7.0.x before 7.0.15, and 7.1.x before 7.1.1 allows remote attackers to cause a denial of service (buffer over-read and application crash) via crafted serialized data that is mishandled in a finish_nested_data call.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2016-10161', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003']}], 'remediations': [{'details': 'It is recommended to disable all user accounts with restricted configuration write permissions if the update to the latest released version cannot be installed immediately.It is further recommended to use best practice password policies.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Update firmware to the latest version available.\xa0The issues have been resolved with IRF1000 version 1.5.0, IRF2000 version 4.4.0 and IRF3000 version 1.2.0.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003']}}, {'cve': 'CVE-2017-8923', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': "The zend_string_extend function in Zend/zend_string.h in PHP through 7.1.5 does not prevent changes to string objects that result in a negative length, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact by leveraging a script's use of .= with a long string.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2017-8923', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003']}], 'remediations': [{'details': 'It is recommended to disable all user accounts with restricted configuration write permissions if the update to the latest released version cannot be installed immediately.It is further recommended to use best practice password policies.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Update firmware to the latest version available.\xa0The issues have been resolved with IRF1000 version 1.5.0, IRF2000 version 4.4.0 and IRF3000 version 1.2.0.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003']}}, {'cve': 'CVE-2017-12933', 'cwe': {'id': 'CWE-125', 'name': 'Out-of-bounds Read'}, 'notes': [{'text': 'The finish_nested_data function in ext/standard/var_unserializer.re in PHP before 5.6.31, 7.0.x before 7.0.21, and 7.1.x before 7.1.7 is prone to a buffer over-read while unserializing untrusted data. Exploitation of this issue can have an unspecified impact on the integrity of PHP.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2017-12933', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003']}], 'remediations': [{'details': 'It is recommended to disable all user accounts with restricted configuration write permissions if the update to the latest released version cannot be installed immediately.It is further recommended to use best practice password policies.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Update firmware to the latest version available.\xa0The issues have been resolved with IRF1000 version 1.5.0, IRF2000 version 4.4.0 and IRF3000 version 1.2.0.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003']}}, {'cve': 'CVE-2017-11142', 'cwe': {'id': 'CWE-400', 'name': 'Uncontrolled Resource Consumption'}, 'notes': [{'text': 'In PHP before 5.6.31, 7.x before 7.0.17, and 7.1.x before 7.1.3, remote attackers could cause a CPU consumption denial of service attack by injecting long form variables, related to main/php_variables.c.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2017-11142', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003']}], 'remediations': [{'details': 'It is recommended to disable all user accounts with restricted configuration write permissions if the update to the latest released version cannot be installed immediately.It is further recommended to use best practice password policies.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Update firmware to the latest version available.\xa0The issues have been resolved with IRF1000 version 1.5.0, IRF2000 version 4.4.0 and IRF3000 version 1.2.0.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003']}}]}
6539eaebf7c7baa2f7f77be3e3810368dbc7c9ae878edcbcafd8aca703fa2d4e
2026-05-29 08:30:28.788138+03:00
2026-05-29 08:30:28.788138+03:00
csaf_adstecindustrialitgmbh.ndjson
00792cb01375a6c70181e5502975a028f8def47a307d542f7d10776fdb8cee82
{'document': {'lang': 'en-GB', 'notes': [{'text': "The affected products and versions present a vulnerability due to a vulnerable integrated software component the docker runc <= 1.1.11. In the worst-case scenario, the integrated Docker container environment could be compromised, potentially enabling the execution of arbitrary code within the Docker environment or neighboring Docker containers if dockerfiles or Docker images from untrusted sources are utilized.\n\nIt's crucial to emphasize that while the Docker environment is vulnerable, the host operating system remains\nunharmed due to its isolation from the Docker environment within the ads-tec products.\n\nUsing Docker images or Dockerfiles from untrusted sources poses a risk. This advice is especially pertinent for Docker use in productive operational technology (OT) environments, and it's our expectation that our customers adhere strictly to this guidance anyway.", 'title': 'Summary', 'category': 'summary'}, {'text': 'In ads-tec products, Docker is integrated using a rootless mode, altering the impact of vulnerabilities. A potential attacker\'s ability to compromise the Docker environment is confined to the Docker user level and the writable, isolated ("chrooted") filesystem environment. As a result, while the attacker may affect all Docker containers on the system and potentially cause a denial of service (DoS) on the main operating system, they cannot directly compromise the main operating system\'s integrity.', 'title': 'Impact', 'category': 'description'}, {'text': "Follow the suggestions of the Docker project:\nIf you are unable to update to an unaffected version promptly after it is released, follow these best practices to mitigate risk:\n\n- Only use trusted Docker images\n- Don't build Docker images from untrusted sources or untrusted Dockerfiles.\n\nFor users who wish to ensure their device remains secure and there is an indication that the device may have\nbeen compromised, we recommend updating the device firmware and reinstalling all Docker images. The update process for the device will clear and reset the writable parts of the chroot filesystem environment, ensuring no remnants are left behind. This precautionary measure is advised only if there's evidence suggesting that the docker environment on the device might be compromised.", 'title': 'Mitigation', 'category': 'description'}, {'text': 'The issue is resolved with IRF1000 version 1.6.10 and IRF3000 version 1.3.10', 'title': 'Remediation', 'category': 'description'}], 'title': 'ADS-TEC Industrial IT: Docker vulnerability affects multiple products', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2024-016', 'status': 'final', 'aliases': ['VDE-2024-016'], 'version': '2', 'generator': {'date': '2025-04-24T07:23:02.245Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.23'}}, 'revision_history': [{'date': '2024-02-19T07:00:00.000Z', 'number': '1', 'summary': 'Initial revision.'}, {'date': '2025-05-22T13:03:10.000Z', 'number': '2', 'summary': 'Fix: quotation mark'}], 'current_release_date': '2025-05-22T13:03:10.000Z', 'initial_release_date': '2024-02-19T07:00:00.000Z'}, 'publisher': {'name': 'ads-tec Industrial IT GmbH', 'category': 'vendor', 'namespace': 'https://www.ads-tec-iit.com', 'contact_details': 'psirt@ads-tec.de'}, 'references': [{'url': 'https://certvde.com/en/advisories/VDE-2024-016/', 'summary': 'VDE-2024-016: ADS-TEC Industrial IT: Docker vulnerability affects multiple products - HTML', 'category': 'self'}, {'url': 'https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2024/vde-2024-016.json', 'summary': 'VDE-2024-016: ADS-TEC Industrial IT: Docker vulnerability affects multiple products - CSAF', 'category': 'self'}, {'url': 'https://www.ads-tec-iit.com', 'summary': 'Vendor PSIRT', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/ads-tec-iit/', 'summary': 'CERT@VDE Security Advisories for ads-tec Industrial IT GmbH', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}]}, 'product_tree': {'branches': [{'name': 'ads-tec Industrial IT', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'IRF1000', 'product': {'name': 'IRF1000', 'product_id': 'CSAFPID-11001', 'product_identification_helper': {'model_numbers': ['DVG-IRF1401, DVG-IRF1421']}}, 'category': 'product_name'}, {'name': 'IRF3000', 'product': {'name': 'IRF3000', 'product_id': 'CSAFPID-11002', 'product_identification_helper': {'model_numbers': ['DVG-IRF3401, DVG-IRF3421, DVG-IRF3801. DVG-IRF3821']}}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': '<=1.6.9', 'product': {'name': 'Firmware <=1.6.9', 'product_id': 'CSAFPID-21001'}, 'category': 'product_version_range'}, {'name': '<=1.3.9', 'product': {'name': 'Firmware <=1.3.9', 'product_id': 'CSAFPID-21002'}, 'category': 'product_version_range'}, {'name': '1.6.10', 'product': {'name': 'Firmware 1.6.10', 'product_id': 'CSAFPID-22001'}, 'category': 'product_version'}, {'name': '1.3.10', 'product': {'name': 'Firmware 1.3.10', 'product_id': 'CSAFPID-22002'}, 'category': 'product_version'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=1.6.9 installed on IRF1000', 'product_id': 'CSAFPID-31001'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=1.3.9 installed on IRF3000', 'product_id': 'CSAFPID-31002'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11002'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 1.6.10 installed on IRF1000', 'product_id': 'CSAFPID-32001'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 1.3.10 installed on IRF3000', 'product_id': 'CSAFPID-32002'}, 'product_reference': 'CSAFPID-22002', 'relates_to_product_reference': 'CSAFPID-11002'}], 'product_groups': [{'summary': 'Affected products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-31001', 'CSAFPID-31002']}, {'summary': 'Fixed products.', 'group_id': 'CSAFGID-0002', 'product_ids': ['CSAFPID-32001', 'CSAFPID-32002']}]}, 'vulnerabilities': [{'cve': 'CVE-2024-21626', 'cwe': {'id': 'CWE-668', 'name': 'Exposure of Resource to Wrong Sphere'}, 'notes': [{'text': 'runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem ("attack 2"). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run ("attack 1"). Variants of attacks 1 and 2 could be also be used to overwrite semi-arbitrary host binaries, allowing for complete container escapes ("attack 3a" and "attack 3b"). runc 1.1.12 includes patches for this issue. ', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-21626', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 8.6, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H', 'temporalScore': 8.6, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 8.6, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002']}], 'remediations': [{'details': "Follow the suggestions of the Docker project:If you are unable to update to an unaffected version promptly after it is released, follow these best practices to mitigate risk:\n\nOnly use trusted Docker images\nDon't build Docker images from untrusted sources or untrusted Dockerfiles.\n\nFor users who wish to ensure their device remains secure and there is an indication that the device may havebeen compromised, we recommend updating the device firmware and reinstalling all Docker images. The update process for the device will clear and reset the writable parts of the chroot filesystem environment, ensuring no remnants are left behind. This precautionary measure is advised only if there's evidence suggesting that the docker environment on the device might be compromised.", 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'The issue is resolved with IRF1000 version 1.6.10 and IRF3000 version 1.3.10', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002']}}]}
d621ac0ceffb01c20b7e527f99f7fa23de635da3b01de17d9510a8a25f59f8be
2026-05-29 08:30:28.788138+03:00
2026-05-29 08:30:28.788138+03:00
csaf_adstecindustrialitgmbh.ndjson
1404d801298e20d92d902a1881bdbf7a29af690e0c257e23fdfc5c2453726605
{'document': {'lang': 'en-GB', 'notes': [{'text': 'The ADS-TEC firewall products IRF1000, IRF2000, and IRF3000 include Eclipse Mosquitto, affected by multiple vulnerabilities. Exploitation requires a compromised upstream MQTT broker, limiting direct device exposure.', 'title': 'Summary', 'category': 'summary'}, {'text': 'Exploitation could result in denial-of-service (DoS) or Mosquitto crashes. Remote code execution (RCE) is theoretically possible but mitigated by security hardening and user-level process isolation.', 'title': 'Impact', 'category': 'description'}, {'text': 'Disable MQTT publishing or ensure connections are made only to trusted and TLS-secured MQTT brokers.', 'title': 'Mitigation', 'category': 'description'}, {'text': 'Update to firmware IRF1000 v2.1.0, IRF2000 v6.1.0, IRF3000 v2.1.0 or later.', 'title': 'Remediation', 'category': 'description'}], 'title': 'ads-tec Industrial IT: Mosquitto MQTT Client Vulnerability in ADS-TEC IRF Products', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2025-033', 'status': 'final', 'aliases': ['VDE-2025-033', 'ADS2025001'], 'version': '1', 'generator': {'date': '2025-04-04T07:52:10.569Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.21'}}, 'revision_history': [{'date': '2025-04-14T10:00:00.000Z', 'number': '1', 'summary': 'Initial revision'}], 'current_release_date': '2025-04-14T10:00:00.000Z', 'initial_release_date': '2025-04-14T10:00:00.000Z'}, 'publisher': {'name': 'ads-tec Industrial IT GmbH', 'category': 'vendor', 'namespace': 'https://www.ads-tec-iit.com', 'contact_details': 'psirt@ads-tec.de'}, 'references': [{'url': 'https://certvde.com/en/advisories/VDE-2025-033/', 'summary': 'VDE-2025-033: ads-tec Industrial IT: Mosquitto MQTT Client Vulnerability in ADS-TEC IRF Products - HTML', 'category': 'self'}, {'url': 'https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2025/vde-2025-033.json', 'summary': 'VDE-2025-033: ads-tec Industrial IT: Mosquitto MQTT Client Vulnerability in ADS-TEC IRF Products - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com/en/'], 'summary': 'Coordination', 'organization': 'CERTVDE'}], 'aggregate_severity': {'text': 'Medium', 'namespace': 'https://www.first.org/cvss/v3-1/specification-document'}}, 'product_tree': {'branches': [{'name': 'ads-tec Industrial IT GmbH', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'IRF1000', 'branches': [{'name': 'DVG-IRF1401', 'product': {'name': 'DVG-IRF1401', 'product_id': 'CSAFPID-11001'}, 'category': 'product_name'}, {'name': 'DVG-IRF1421', 'product': {'name': 'DVG-IRF1421', 'product_id': 'CSAFPID-11002'}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'IRF2000', 'branches': [{'name': 'DVG-IRF2200', 'product': {'name': 'DVG-IRF2200', 'product_id': 'CSAFPID-11003'}, 'category': 'product_name'}, {'name': 'DVG-IRF2100', 'product': {'name': 'DVG-IRF2100', 'product_id': 'CSAFPID-11004'}, 'category': 'product_name'}, {'name': 'DVG-IRF2220', 'product': {'name': 'DVG-IRF2220', 'product_id': 'CSAFPID-11005'}, 'category': 'product_name'}, {'name': 'DVG-IRF2621', 'product': {'name': 'DVG-IRF2621', 'product_id': 'CSAFPID-11006'}, 'category': 'product_name'}, {'name': 'DVG-IRF2601', 'product': {'name': 'DVG-IRF2601', 'product_id': 'CSAFPID-11007'}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'IRF3000', 'branches': [{'name': 'DVG-IRF3401', 'product': {'name': 'DVG-IRF3401', 'product_id': 'CSAFPID-11008'}, 'category': 'product_name'}, {'name': 'DVG-IRF3421', 'product': {'name': 'DVG-IRF3421', 'product_id': 'CSAFPID-11009'}, 'category': 'product_name'}, {'name': ' DVG-IRF3801', 'product': {'name': 'DVG-IRF3801', 'product_id': 'CSAFPID-11010'}, 'category': 'product_name'}, {'name': ' DVG-IRF3821', 'product': {'name': 'DVG-IRF3821', 'product_id': 'CSAFPID-11011'}, 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': '<2.1.0', 'product': {'name': 'Firmware <2.1.0', 'product_id': 'CSAFPID-21001'}, 'category': 'product_version_range'}, {'name': '<6.1.0', 'product': {'name': 'Firmware <6.1.0', 'product_id': 'CSAFPID-21002'}, 'category': 'product_version_range'}, {'name': '2.1.0', 'product': {'name': 'Firmware 2.1.0', 'product_id': 'CSAFPID-22001'}, 'category': 'product_version'}, {'name': '6.1.0', 'product': {'name': 'Firmware 6.1.0', 'product_id': 'CSAFPID-22002'}, 'category': 'product_version'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware <2.1.0 installed on DVG-IRF1401', 'product_id': 'CSAFPID-31001'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <2.1.0 installed on DVG-IRF1421', 'product_id': 'CSAFPID-31002'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11002'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <6.1.0 installed on DVG-IRF2200', 'product_id': 'CSAFPID-31003'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11003'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <6.1.0 installed on DVG-IRF2100', 'product_id': 'CSAFPID-31004'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11004'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <6.1.0 installed on DVG-IRF2220', 'product_id': 'CSAFPID-31005'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11005'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <6.1.0 installed on DVG-IRF2621', 'product_id': 'CSAFPID-31006'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11006'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <6.1.0 installed on DVG-IRF2601', 'product_id': 'CSAFPID-31007'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11007'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <2.1.0 installed on DVG-IRF3401', 'product_id': 'CSAFPID-31008'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11008'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <2.1.0 installed on DVG-IRF3421', 'product_id': 'CSAFPID-31009'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11009'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <2.1.0 installed on DVG-IRF3801', 'product_id': 'CSAFPID-31010'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11010'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <2.1.0 installed on DVG-IRF3821', 'product_id': 'CSAFPID-31011'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11011'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 2.1.0 installed on DVG-IRF1401', 'product_id': 'CSAFPID-32001'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 2.1.0 installed on DVG-IRF1421', 'product_id': 'CSAFPID-32002'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11002'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 6.1.0 installed on DVG-IRF2200', 'product_id': 'CSAFPID-32003'}, 'product_reference': 'CSAFPID-22002', 'relates_to_product_reference': 'CSAFPID-11003'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 6.1.0 installed on DVG-IRF2100', 'product_id': 'CSAFPID-32004'}, 'product_reference': 'CSAFPID-22002', 'relates_to_product_reference': 'CSAFPID-11004'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 6.1.0 installed on DVG-IRF2220', 'product_id': 'CSAFPID-32005'}, 'product_reference': 'CSAFPID-22002', 'relates_to_product_reference': 'CSAFPID-11005'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 6.1.0 installed on DVG-IRF2621', 'product_id': 'CSAFPID-32006'}, 'product_reference': 'CSAFPID-22002', 'relates_to_product_reference': 'CSAFPID-11006'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 6.1.0 installed on DVG-IRF2601', 'product_id': 'CSAFPID-32007'}, 'product_reference': 'CSAFPID-22002', 'relates_to_product_reference': 'CSAFPID-11007'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 2.1.0 installed on DVG-IRF3401', 'product_id': 'CSAFPID-32008'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11008'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 2.1.0 installed on DVG-IRF3421', 'product_id': 'CSAFPID-32009'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11009'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 2.1.0 installed on DVG-IRF3801', 'product_id': 'CSAFPID-32010'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11010'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 2.1.0 installed on DVG-IRF3821', 'product_id': 'CSAFPID-32011'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11011'}], 'product_groups': [{'summary': 'Affected products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007', 'CSAFPID-31008', 'CSAFPID-31009', 'CSAFPID-31010', 'CSAFPID-31011']}, {'summary': 'Fixed products.', 'group_id': 'CSAFGID-0002', 'product_ids': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-32004', 'CSAFPID-32005', 'CSAFPID-32006', 'CSAFPID-32007', 'CSAFPID-32008', 'CSAFPID-32009', 'CSAFPID-32010', 'CSAFPID-32011']}]}, 'vulnerabilities': [{'cve': 'CVE-2024-3935', 'cwe': {'id': 'CWE-415', 'name': 'Double Free'}, 'notes': [{'text': 'In Eclipse Mosquito, versions from 2.0.0 through 2.0.18, if a Mosquitto broker is configured to create an outgoing\nbridge connection, and that bridge connection has an incoming topic configured that makes use of topic remapping, then if the remote connection sends a crafted PUBLISH packet to the broker a double free will occur\nwith a subsequent crash of the broker.', 'title': 'Vulnerability Description', 'audience': 'all', 'category': 'description'}, {'text': 'Adjusted CVSS Score (Product Context): \nBase Score: 5.3 (Medium) \nVector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H\n\nJustification: \nAC:H (High): Attacks on the product must be carried out via the MQTT server. This means the attack cannot be directly repeated across different setups, as a new server must be compromised each time.', 'title': 'Vulnerability Characterisation', 'audience': 'all', 'category': 'details'}], 'title': 'CVE-2024-3935', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 6.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'HIGH', 'environmentalScore': 6.5, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007', 'CSAFPID-31008', 'CSAFPID-31009', 'CSAFPID-31010', 'CSAFPID-31011']}], 'remediations': [{'details': 'Disable MQTT publishing or ensure connections are made only to trusted and TLS-secured MQTT brokers.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Update to firmware IRF1000 v2.1.0, IRF2000 v6.1.0, IRF3000 v2.1.0 or later.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-32004', 'CSAFPID-32005', 'CSAFPID-32006', 'CSAFPID-32007', 'CSAFPID-32008', 'CSAFPID-32009', 'CSAFPID-32010', 'CSAFPID-32011'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007', 'CSAFPID-31008', 'CSAFPID-31009', 'CSAFPID-31010', 'CSAFPID-31011']}}, {'cve': 'CVE-2024-8376', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'In Eclipse Mosquitto up to version 2.0.18a, an attacker can achieve memory leaking, segmentation fault or heapuse-after-free by sending specific sequences of "CONNECT", "DISCONNECT", "SUBSCRIBE", "UNSUBSCRIBE"\nand "PUBLISH" packets', 'title': 'Vulnerability Description', 'audience': 'all', 'category': 'description'}, {'text': 'Adjusted CVSS Score (Product Context): \nBase Score: 5.9 (Medium)\nVector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H\n\nJustification: \nAC:H (High): Attacks on the product must be carried out via the MQTT server. This means the attack cannot be directly repeated across different setups, as a new server must be compromised each time.', 'title': 'Vulnerability Characterisation', 'audience': 'all', 'category': 'details'}], 'title': 'CVE-2024-8376', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007', 'CSAFPID-31008', 'CSAFPID-31009', 'CSAFPID-31010', 'CSAFPID-31011']}], 'remediations': [{'details': 'Disable MQTT publishing or ensure connections are made only to trusted and TLS-secured MQTT brokers.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Update to firmware IRF1000 v2.1.0, IRF2000 v6.1.0, IRF3000 v2.1.0 or later.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-32004', 'CSAFPID-32005', 'CSAFPID-32006', 'CSAFPID-32007', 'CSAFPID-32008', 'CSAFPID-32009', 'CSAFPID-32010', 'CSAFPID-32011'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007', 'CSAFPID-31008', 'CSAFPID-31009', 'CSAFPID-31010', 'CSAFPID-31011']}}, {'cve': 'CVE-2024-10525', 'cwe': {'id': 'CWE-122', 'name': 'Heap-based Buffer Overflow'}, 'notes': [{'text': 'In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet\nwith no reason codes, a client using libmosquitto may make out of bounds memory access when acting in its\non_subscribe callback. This affects the mosquitto_sub and mosquitto_rr clients.', 'title': 'Vulnerability Description', 'audience': 'all', 'category': 'description'}, {'text': 'Adjusted CVSS Score (Product Context): \nBase Score: 5.6 (Medium)\nVector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L\n\nJustification: \nAC:H (High): Attacks on the product must be carried out via the MQTT server. This means the attack cannot be directly repeated across different setups, as a new server must be compromised each time. \nC/I/A: Downgraded from High to Low due to process sandboxing and reduced privileges.', 'title': 'Vulnerability Characterisation', 'audience': 'all', 'category': 'details'}], 'title': 'CVE-2024-10525', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007', 'CSAFPID-31008', 'CSAFPID-31009', 'CSAFPID-31010', 'CSAFPID-31011']}], 'remediations': [{'details': 'Disable MQTT publishing or ensure connections are made only to trusted and TLS-secured MQTT brokers.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Update to firmware IRF1000 v2.1.0, IRF2000 v6.1.0, IRF3000 v2.1.0 or later.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-32004', 'CSAFPID-32005', 'CSAFPID-32006', 'CSAFPID-32007', 'CSAFPID-32008', 'CSAFPID-32009', 'CSAFPID-32010', 'CSAFPID-32011'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007', 'CSAFPID-31008', 'CSAFPID-31009', 'CSAFPID-31010', 'CSAFPID-31011']}}]}
ebdec3eadb38106ea9390b0721ba94ca11a1128b96697cb77de19af2d7cc618d
2026-05-29 08:30:28.788138+03:00
2026-05-29 08:30:28.788138+03:00
csaf_bendergmbhcokg.ndjson
1253cc7f0d45bc2072f4121f9cac431176f5bb216a5f35e81a9122142d147006
{'document': {'lang': 'en-GB', 'notes': [{'text': 'Bender is publishing this advisory to inform customers about a security vulnerability in all devices running the COMTRAXX software.\n\nThe user authorization is validated for most, but not all routes in the system. A user with knowledge about the routes can read and write configuration data without prior authorization.', 'title': 'Summary', 'category': 'summary'}, {'text': 'The vulnerability allows a malicious entity to bypass credential check.', 'title': 'Impact', 'category': 'description'}, {'text': '• restrict network access to the above-mentioned devices\n\n• install latest software update', 'title': 'Mitigation', 'category': 'description'}, {'text': 'Please install V4.2.0. (https://www.bender.de/service-support/downloadbereich)', 'title': 'Remediation', 'category': 'description'}], 'title': 'Bender: COMTRAXX < 4.2.0 affected by inadquate credentials check vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2020-043', 'status': 'final', 'aliases': ['VDE-2020-043'], 'version': '1', 'generator': {'date': '2025-03-24T11:31:57.923Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.21'}}, 'revision_history': [{'date': '2020-10-16T06:54:00.000Z', 'number': '1', 'summary': 'Initial revision.'}], 'current_release_date': '2020-10-16T06:54:00.000Z', 'initial_release_date': '2020-10-16T06:54:00.000Z'}, 'publisher': {'name': 'Bender GmbH & Co. KG', 'category': 'vendor', 'namespace': 'https://www.bender.de', 'contact_details': 'psirt@bender.de'}, 'references': [{'url': 'https://certvde.com/en/advisories/vendor/bender', 'summary': 'CERT@VDE Security Advisories for Bender GmbH & Co. KG', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/VDE-2020-043', 'summary': 'VDE-2020-043: Bender: COMTRAXX < 4.2.0 affected by inadquate credentials check vulnerability - HTML', 'category': 'self'}, {'url': 'https://bender.csaf-tp.certvde.com/.well-known/csaf/white/2020/vde-2020-043.json', 'summary': 'VDE-2020-043: Bender: COMTRAXX < 4.2.0 affected by inadquate credentials check vulnerability - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}, {'summary': 'reporting', 'organization': 'Maxim Rupp'}]}, 'product_tree': {'branches': [{'name': 'Bender', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'COM465DP', 'product': {'name': 'COM465DP', 'product_id': 'CSAFPID-11001', 'product_identification_helper': {'model_numbers': ['95061060', '95061061']}}, 'category': 'product_name'}, {'name': 'COM465ID', 'product': {'name': 'COM465ID', 'product_id': 'CSAFPID-11002', 'product_identification_helper': {'model_numbers': ['95061070']}}, 'category': 'product_name'}, {'name': 'COM465IP', 'product': {'name': 'COM465IP', 'product_id': 'CSAFPID-11003', 'product_identification_helper': {'model_numbers': ['95061065', '95061066']}}, 'category': 'product_name'}, {'name': 'CP700', 'product': {'name': 'CP700', 'product_id': 'CSAFPID-11004', 'product_identification_helper': {'model_numbers': ['95061030']}}, 'category': 'product_name'}, {'name': 'CP907', 'product': {'name': 'CP907', 'product_id': 'CSAFPID-11005', 'product_identification_helper': {'model_numbers': ['95061080']}}, 'category': 'product_name'}, {'name': 'CP915', 'product': {'name': 'CP915', 'product_id': 'CSAFPID-11006', 'product_identification_helper': {'model_numbers': ['95061081', '95061085', '95061092']}}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': '<4.2.0', 'product': {'name': 'Firmware <4.2.0', 'product_id': 'CSAFPID-21001'}, 'category': 'product_version_range'}, {'name': '4.2.0', 'product': {'name': 'Firmware 4.2.0', 'product_id': 'CSAFPID-22001'}, 'category': 'product_version'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware 4.2.0 installed on CP915', 'product_id': 'CSAFPID-32001'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11006'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 4.2.0 installed on COM465ID', 'product_id': 'CSAFPID-32002'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11002'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 4.2.0 installed on COM465IP', 'product_id': 'CSAFPID-32003'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11003'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 4.2.0 installed on CP700', 'product_id': 'CSAFPID-32004'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11004'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 4.2.0 installed on CP907', 'product_id': 'CSAFPID-32005'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11005'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 4.2.0 installed on CP915', 'product_id': 'CSAFPID-32006'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11006'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <4.2.0 installed on CP915', 'product_id': 'CSAFPID-31001'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11006'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <4.2.0 installed on COM465ID', 'product_id': 'CSAFPID-31002'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11002'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <4.2.0 installed on COM465IP', 'product_id': 'CSAFPID-31003'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11003'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <4.2.0 installed on CP700', 'product_id': 'CSAFPID-31004'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11004'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <4.2.0 installed on CP907', 'product_id': 'CSAFPID-31005'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11005'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <4.2.0 installed on CP915', 'product_id': 'CSAFPID-31006'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11006'}], 'product_groups': [{'summary': 'Affected Products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006']}, {'summary': 'Fixed Products.', 'group_id': 'CSAFGID-0002', 'product_ids': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-32004', 'CSAFPID-32005', 'CSAFPID-32006']}]}, 'vulnerabilities': [{'cve': 'CVE-2019-19885', 'cwe': {'id': 'CWE-862', 'name': 'Missing Authorization'}, 'notes': [{'text': 'In Bender COMTRAXX, user authorization is validated for most, but not all, routes in the system. A user with knowledge about the routes can read and write configuration data without prior authorization. This affects COM465IP, COM465DP, COM465ID, CP700, CP907, and CP915 devices before 4.2.0.', 'title': 'Vulnerability Description', 'audience': 'all', 'category': 'description'}], 'title': 'CVE-2019-19885', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.1, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N', 'temporalScore': 9.1, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'NONE', 'environmentalScore': 9.1, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006']}], 'remediations': [{'details': '• restrict network access to the above-mentioned devices\n\n• install latest software update', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Please install V4.2.0. (https://www.bender.de/service-support/downloadbereich)', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-32004', 'CSAFPID-32005', 'CSAFPID-32006'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006']}}]}
bf3dbd4f5826fb63fc91b0106a75637b183c0c01d083841dcec8f0a5d8c079c8
2026-05-29 08:30:29.154030+03:00
2026-05-29 08:30:29.154030+03:00
csaf_bendergmbhcokg.ndjson
219db087ccf5c6ed6a0ee79a093b6a99a064bc977bc66057e00e801373a89d6c
{'document': {'lang': 'en-GB', 'notes': [{'text': 'Bender is publishing this advisory to inform customers about multiple security vulnerabilities in the Charge Controller product families.Bender has\xa0analysed the weaknesses and determined that the electrical safety of the devices is not concerned. To\xa0Benders knowledge, proof-of-concept code or exploits for the weaknesses are not available to the public.Bender considers some weaknesses to be critical and thus need to be patched immediately. Therefore, patches are provided as maintenance branch versions 5.11.2, 5.12.5, 5.13.2 and 5.20.2. Future software releases will of course already include these patches.', 'title': 'Summary', 'category': 'summary'}, {'text': 'The vulnerability allows a malicious entity to bypass credential check and escalate privileges.', 'title': 'Impact', 'category': 'description'}, {'text': 'Restrict network access to the above-mentioned devices.', 'title': 'Mitigation', 'category': 'description'}, {'text': 'Install latest software update.', 'title': 'Remediation', 'category': 'description'}], 'title': 'Bender/ebee: Multiple Charge Controller Vulnerabilities', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2021-047', 'status': 'final', 'aliases': ['VDE-2021-047'], 'version': '1', 'generator': {'date': '2025-04-23T09:07:13.872Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.23'}}, 'revision_history': [{'date': '2022-04-26T10:00:00.000Z', 'number': '1', 'summary': 'Initial revision.'}], 'current_release_date': '2022-04-26T10:00:00.000Z', 'initial_release_date': '2022-04-26T10:00:00.000Z'}, 'publisher': {'name': 'Bender GmbH & Co. KG', 'category': 'vendor', 'namespace': 'https://www.bender.de', 'contact_details': 'psirt@bender.de'}, 'references': [{'url': 'https://certvde.com/en/advisories/VDE-2021-047/', 'summary': 'VDE-2021-047: Bender/ebee: Multiple Charge Controller Vulnerabilities - HTML', 'category': 'self'}, {'url': 'https://bender.csaf-tp.certvde.com/.well-known/csaf/white/2022/vde-2021-047.json', 'summary': 'VDE-2021-047: Bender/ebee: Multiple Charge Controller Vulnerabilities - CSAF', 'category': 'self'}, {'url': 'https://www.bender.de', 'summary': 'Vendor PSIRT', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/bender/', 'summary': 'CERT@VDE Security Advisories for Bender GmbH & Co. KG', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}, {'summary': 'reporting', 'organization': 'OpenSource Security GmbH'}, {'summary': 'reporting', 'organization': 'Qianxin StarV Security Lab, China'}]}, 'product_tree': {'branches': [{'name': 'Bender/ebee', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'CC612', 'product': {'name': 'CC612', 'product_id': 'CSAFPID-11001'}, 'category': 'product_name'}, {'name': 'CC613', 'product': {'name': 'CC613', 'product_id': 'CSAFPID-11002'}, 'category': 'product_name'}, {'name': 'ICC15xx', 'product': {'name': 'ICC15xx', 'product_id': 'CSAFPID-11003'}, 'category': 'product_name'}, {'name': 'ICC16xx', 'product': {'name': 'ICC16xx', 'product_id': 'CSAFPID-11004'}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': '<5.20.2', 'product': {'name': 'Firmware <5.20.2', 'product_id': 'CSAFPID-21001'}, 'category': 'product_version_range'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware <5.20.2 installed on CC612', 'product_id': 'CSAFPID-31001'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <5.20.2 installed on CC613', 'product_id': 'CSAFPID-31002'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11002'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <5.20.2 installed on ICC15xx', 'product_id': 'CSAFPID-31003'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11003'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <5.20.2 installed on ICC16xx', 'product_id': 'CSAFPID-31004'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11004'}], 'product_groups': [{'summary': 'Affected products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004']}]}, 'vulnerabilities': [{'cve': 'CVE-2021-34589', 'cwe': {'id': 'CWE-200', 'name': 'Exposure of Sensitive Information to an Unauthorized Actor'}, 'notes': [{'text': 'In Bender/ebee Charge Controllers in multiple versions are prone to an RFID leak. The RFID of the last charge event can be read without authentication via the web interface.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2021-34589', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'NONE', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004']}], 'remediations': [{'details': 'Restrict network access to the above-mentioned devices.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Install latest software update.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004']}}, {'cve': 'CVE-2021-34591', 'cwe': {'id': 'CWE-250', 'name': 'Execution with Unnecessary Privileges'}, 'notes': [{'text': 'In Bender/ebee Charge Controllers in multiple versions are prone to Local privilege Escalation. An authenticated attacker could get root access via the suid applications socat, ip udhcpc and ifplugd.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2021-34591', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 7.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.8, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004']}], 'remediations': [{'details': 'Restrict network access to the above-mentioned devices.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Install latest software update.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004']}}, {'cve': 'CVE-2021-34590', 'cwe': {'id': 'CWE-79', 'name': "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"}, 'notes': [{'text': 'In Bender/ebee Charge Controllers in multiple versions are prone to Cross-site Scripting. An authenticated attacker could write HTML Code into configuration values. These values are not properly escaped when displayed.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2021-34590', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 5.4, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N', 'temporalScore': 5.4, 'integrityImpact': 'LOW', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 5.4, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'LOW', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004']}], 'remediations': [{'details': 'Restrict network access to the above-mentioned devices.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Install latest software update.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004']}}, {'cve': 'CVE-2021-34602', 'cwe': {'id': 'CWE-78', 'name': "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"}, 'notes': [{'text': 'In Bender/ebee Charge Controllers in multiple versions are prone to Command injection via Web interface. An authenticated attacker could enter shell commands into some input fields that are executed with root privileges.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2021-34602', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 8.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 8.8, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004']}], 'remediations': [{'details': 'Restrict network access to the above-mentioned devices.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Install latest software update.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004']}}, {'cve': 'CVE-2021-34601', 'cwe': {'id': 'CWE-798', 'name': 'Use of Hard-coded Credentials'}, 'notes': [{'text': 'In Bender/ebee Charge Controllers in multiple versions are prone to Hardcoded Credentials. Bender charge controller CC612 in version 5.20.1 and below is prone to hardcoded ssh credentials. An attacker may use the password to gain administrative access to the web-UI.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2021-34601', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004']}], 'remediations': [{'details': 'Restrict network access to the above-mentioned devices.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Install latest software update.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004']}}, {'cve': 'CVE-2021-34588', 'cwe': {'id': 'CWE-425', 'name': "Direct Request ('Forced Browsing')"}, 'notes': [{'text': 'In Bender/ebee Charge Controllers in multiple versions are prone to unprotected data export. Backup export is protected via a random key. The key is set at user login. It is empty after reboot .', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2021-34588', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 8.6, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N', 'temporalScore': 8.6, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'NONE', 'environmentalScore': 8.6, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004']}], 'remediations': [{'details': 'Restrict network access to the above-mentioned devices.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Install latest software update.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004']}}, {'cve': 'CVE-2021-34587', 'cwe': {'id': 'CWE-121', 'name': 'Stack-based Buffer Overflow'}, 'notes': [{'text': 'In Bender/ebee Charge Controllers in multiple versions a long URL could lead to webserver crash. The URL is used as input of an sprintf to a stack variable.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2021-34587', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L', 'temporalScore': 5.3, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'LOW', 'environmentalScore': 5.3, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004']}], 'remediations': [{'details': 'Restrict network access to the above-mentioned devices.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Install latest software update.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004']}}]}
bd71089c19fc0056f88edb72067c69ec9f3ce912b027030c80c113f4c8d50754
2026-05-29 08:30:29.154030+03:00
2026-05-29 08:30:29.154030+03:00
csaf_bendergmbhcokg.ndjson
87a87a33c7debaf011a802dc9c6ec36fdded7bf7f0eb02fbdbd957ebd701777c
{'document': {'lang': 'en-GB', 'notes': [{'text': 'Bender is publishing this advisory to inform customers about a security vulnerability in the Charge Controller product families. Bender has analyzed the weakness and determined that the electrical safety of the devices is not affected. Bender considers the weakness to be of high risk and it should be patched immediately.', 'title': 'Summary', 'category': 'summary'}, {'text': 'The vulnerability allows an authenticated user with lower privileges to obtain credentials stored on the charge controller including the manufacturer password.', 'title': 'Impact', 'category': 'description'}, {'text': 'To prevent an authenticated user from obtaining stored credentials install version 5.33.3 or later.', 'title': 'Remediation', 'category': 'description'}], 'title': 'Bender Charge Controller Vulnerability - Disclosure Of Stored Credentials When Authenticated', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2025-061', 'status': 'final', 'aliases': ['VDE-2025-061'], 'version': '1', 'generator': {'date': '2025-09-05T09:02:01.467Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.34'}}, 'revision_history': [{'date': '2025-09-08T07:00:00.000Z', 'number': '1', 'summary': 'initial version'}], 'current_release_date': '2025-09-08T07:00:00.000Z', 'initial_release_date': '2025-09-08T07:00:00.000Z'}, 'publisher': {'name': 'Bender GmbH & Co. KG', 'category': 'vendor', 'namespace': 'https://www.bender.de', 'contact_details': 'psirt@bender.de'}, 'references': [{'url': 'https://certvde.com/en/advisories/VDE-2025-061/', 'summary': 'VDE-2025-061: Bender Charge Controller Vulnerability - Disclosure Of Stored Credentials When Authenticated - HTML', 'category': 'self'}, {'url': 'https://bender.csaf-tp.certvde.com/.well-known/csaf/white/2025/vde-2025-061.json', 'summary': 'VDE-2025-061: Bender Charge Controller Vulnerability - Disclosure Of Stored Credentials When Authenticated - CSAF', 'category': 'self'}, {'url': 'https://www.bender.de', 'summary': 'Vendor PSIRT', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/bender/', 'summary': 'CERT@VDE Security Advisories for Bender GmbH & Co. KG', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}, {'urls': ['https://www.syss.de'], 'names': ['Dr. Matthias Kesenheimer', 'Sebastian Hamann'], 'summary': 'reporting', 'organization': ' SySS GmbH'}], 'aggregate_severity': {'text': 'High', 'namespace': 'https://www.first.org/cvss/v3.1/specification-document#Qualitative-Severity-Rating-Scale'}}, 'product_tree': {'branches': [{'name': 'Bender', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'CC612', 'product': {'name': 'CC612', 'product_id': 'CSAFPID-11001'}, 'category': 'product_name'}, {'name': 'CC613', 'product': {'name': 'CC613', 'product_id': 'CSAFPID-11002'}, 'category': 'product_name'}, {'name': 'ICC16xx', 'product': {'name': 'ICC16xx', 'product_id': 'CSAFPID-11003'}, 'category': 'product_name'}, {'name': 'ICC13xx', 'product': {'name': 'ICC13xx', 'product_id': 'CSAFPID-11004'}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': '5.30.2<5.33.3', 'product': {'name': 'Firmware 5.30.2<5.33.3', 'product_id': 'CSAFPID-21001'}, 'category': 'product_version_range'}, {'name': '5.33.3', 'product': {'name': 'Firmware 5.33.3', 'product_id': 'CSAFPID-22001'}, 'category': 'product_version'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware 5.30.2<5.33.3 installed on CC612', 'product_id': 'CSAFPID-31001'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 5.30.2<5.33.3 installed on CC613', 'product_id': 'CSAFPID-31002'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11002'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 5.30.2<5.33.3 installed on ICC16xx', 'product_id': 'CSAFPID-31003'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11003'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 5.30.2<5.33.3 installed on ICC13xx', 'product_id': 'CSAFPID-31004'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11004'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 5.33.3 installed on CC612', 'product_id': 'CSAFPID-32001'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 5.33.3 installed on CC613', 'product_id': 'CSAFPID-32002'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11002'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 5.33.3 installed on ICC16xx', 'product_id': 'CSAFPID-32003'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11003'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 5.33.3 installed on ICC13xx', 'product_id': 'CSAFPID-32004'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11004'}], 'product_groups': [{'summary': 'Affected products', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004']}, {'summary': 'Fixed products', 'group_id': 'CSAFGID-0002', 'product_ids': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-32004']}]}, 'vulnerabilities': [{'cve': 'CVE-2025-41682', 'cwe': {'id': 'CWE-522', 'name': 'Insufficiently Protected Credentials'}, 'notes': [{'text': 'An authenticated, low-privileged attacker can obtain credentials stored on the charge controller including the manufacturer password.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-41682', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 8.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 8.8, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004']}], 'remediations': [{'details': 'Install software update 5.33.3 or later.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-32004'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004']}}]}
a0ab7ab7f804160301dca9d11982441ff8f63e3646295635e36727a63fd11502
2026-05-29 08:30:29.154030+03:00
2026-05-29 08:30:29.154030+03:00
csaf_bendergmbhcokg.ndjson
f78e1d0a4bdcd9c193ad485da4d6f2388324b2d2f367cbce11a2fd704a885cef
{'document': {'lang': 'en-GB', 'notes': [{'text': 'Bender is publishing this advisory to inform customers about a security vulnerability in the Charge Controller product families. Bender has analyzed the weakness and determined that the electrical safety of the devices is not affected. Bender considers the weakness to be of high risk and it should be patched immediately.', 'title': 'Summary', 'category': 'summary'}, {'text': 'Due to an unsecure default configuration HTTP is used instead of HTTPS for the web interface.', 'title': 'Impact', 'category': 'description'}, {'text': 'To use HTTPS on the web interface, enable it in the settings.', 'title': 'Mitigation', 'category': 'description'}], 'title': 'Bender Charge Controller Vulnerability - Unsecure Communication', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2025-084', 'status': 'final', 'aliases': ['VDE-2025-084'], 'version': '1', 'generator': {'date': '2025-08-31T06:46:46.505Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.33'}}, 'revision_history': [{'date': '2025-09-08T07:00:00.000Z', 'number': '1', 'summary': 'initial version'}], 'current_release_date': '2025-09-08T07:00:00.000Z', 'initial_release_date': '2025-09-08T07:00:00.000Z'}, 'publisher': {'name': 'Bender GmbH & Co. KG', 'category': 'vendor', 'namespace': 'https://www.bender.de', 'contact_details': 'psirt@bender.de'}, 'references': [{'url': 'https://certvde.com/en/advisories/VDE-2025-084/', 'summary': 'VDE-2025-084: Bender Charge Controller Vulnerability - Unsecure Communication - HTML', 'category': 'self'}, {'url': 'https://bender.csaf-tp.certvde.com/.well-known/csaf/white/2025/vde-2025-084.json', 'summary': 'VDE-2025-084: Bender Charge Controller Vulnerability - Unsecure Communication - CSAF', 'category': 'self'}, {'url': 'https://www.bender.de', 'summary': 'Vendor PSIRT', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/bender/', 'summary': 'CERT@VDE Security Advisories for Bender GmbH & Co. KG', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}, {'urls': ['https://www.syss.de'], 'names': ['Dr. Matthias Kesenheimer', 'Sebastian Hamann'], 'summary': 'reporting', 'organization': ' SySS GmbH'}], 'aggregate_severity': {'text': 'High', 'namespace': 'https://www.first.org/cvss/v3.1/specification-document#Qualitative-Severity-Rating-Scale'}}, 'product_tree': {'branches': [{'name': 'Bender', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'CC612', 'product': {'name': 'CC612', 'product_id': 'CSAFPID-11001'}, 'category': 'product_name'}, {'name': 'CC613', 'product': {'name': 'CC613', 'product_id': 'CSAFPID-11002'}, 'category': 'product_name'}, {'name': 'ICC15xx', 'product': {'name': 'ICC15xx', 'product_id': 'CSAFPID-11003'}, 'category': 'product_name'}, {'name': 'ICC16xx', 'product': {'name': 'ICC16xx', 'product_id': 'CSAFPID-11004'}, 'category': 'product_name'}, {'name': 'ICC13xx', 'product': {'name': 'ICC13xx', 'product_id': 'CSAFPID-11005'}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'Firmware vers:all/*', 'product_id': 'CSAFPID-21001'}, 'category': 'product_version'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware vers:all/* installed on CC612', 'product_id': 'CSAFPID-31001'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware vers:all/* installed on CC613', 'product_id': 'CSAFPID-31002'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11002'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware vers:all/* installed on ICC15xx', 'product_id': 'CSAFPID-31003'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11003'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware vers:all/* installed on ICC16xx', 'product_id': 'CSAFPID-31004'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11004'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware vers:all/* installed on ICC13xx', 'product_id': 'CSAFPID-31005'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11005'}], 'product_groups': [{'summary': 'Affected products', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}]}, 'vulnerabilities': [{'cve': 'CVE-2025-41708', 'cwe': {'id': 'CWE-319', 'name': 'Cleartext Transmission of Sensitive Information'}, 'notes': [{'text': 'Due to an unsecure default configuration HTTP is used instead of HTTPS for the web interface. An unauthenticated attacker on the same network could exploit this to learn sensitive data during transmission.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-41708', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.4, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N', 'temporalScore': 7.4, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'NONE', 'environmentalScore': 7.4, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}], 'remediations': [{'details': 'Enable use of HTTPS in the charge controller configuration Web UI settings>system>https', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}}]}
414a2c3f85b61241fa72d494cabfe6f713055338503a0b34e25c419fc7c0733c
2026-05-29 08:30:29.154030+03:00
2026-05-29 08:30:29.154030+03:00
csaf_janitzaelectronicsgmbh.ndjson
a01d08db5e768d2ac631d9bbde678a3b6f1094d25537af933af108213cbf63be
{'document': {'lang': 'en-GB', 'notes': [{'text': 'An unauthenticated remote attacker can exploit several vulnerabilities in Janitza UMG 96RM-E devices to ultimately gain full system access and remote code execution.', 'title': 'Summary', 'category': 'summary'}, {'text': 'These vulnerabilities in combination allow an unauthenticated remote attacker to fully compromise the system including remote code execution. Further details on each separate vulnerability can be found under vulnerability details.', 'title': 'Impact', 'category': 'description'}, {'text': 'It is strongly advised to update to the newest version. The vulnerabilities are fixed in version 3.14.', 'title': 'Remediation', 'category': 'description'}], 'title': 'Janitza: Multiple vulnerabilities in UMG 96RM-E', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2025-079', 'status': 'final', 'aliases': ['VDE-2025-079'], 'version': '1.0.0', 'generator': {'date': '2026-03-09T12:49:32.090Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.44'}}, 'revision_history': [{'date': '2026-03-10T07:00:00.000Z', 'number': '1.0.0', 'summary': 'Initial Revision'}], 'current_release_date': '2026-03-10T07:00:00.000Z', 'initial_release_date': '2026-03-10T07:00:00.000Z'}, 'publisher': {'name': 'Janitza electronics GmbH', 'category': 'vendor', 'namespace': 'https://www.janitza.com', 'contact_details': 'security@janitza.de'}, 'references': [{'url': 'https://www.janitza.com/de-de/service-support/security-issue-ticket', 'summary': 'Janitza PSIRT contact', 'category': 'external'}, {'url': 'https://certvde.com/de/advisories/vendor/janitza/', 'summary': 'Janitza advisory overview at CERT@VDE', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/VDE-2025-079', 'summary': 'VDE-2025-079: Janitza: Multiple vulnerabilities in UMG 96RM-E - HTML', 'category': 'self'}, {'url': 'https://janitza.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2025-079.json', 'summary': 'VDE-2025-079: Janitza: Multiple vulnerabilities in UMG 96RM-E - CSAF', 'category': 'self'}, {'url': 'https://github.security.telekom.com/2025/11/multiple-vulnerabilities-in-janitza-umg96rm-e.html', 'summary': 'Telekom Security Advisory: Multiple vulnerabilities in Janitza UMG 96RM-E', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com/en/'], 'summary': 'Coordination', 'organization': 'CERT@VDE'}, {'urls': ['https://github.security.telekom.com/'], 'summary': 'Reporting', 'organization': 'Deutsche Telekom Security (DT Security)'}]}, 'product_tree': {'branches': [{'name': 'Janitza', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'UMG 96RM-E', 'product': {'name': 'UMG 96RM-E 24V', 'product_id': 'CSAFPID-11001', 'product_identification_helper': {'cpe': 'cpe:2.3:h:janitza:umg_96rm_e_24:*:*:*:*:*:*:*:*', 'model_numbers': ['5222063']}}, 'category': 'product_name'}, {'name': 'UMG 96RM-E', 'product': {'name': 'UMG 96RM-E 230V', 'product_id': 'CSAFPID-11002', 'product_identification_helper': {'cpe': 'cpe:2.3:h:janitza:umg_96rm_e_230:*:*:*:*:*:*:*:*', 'model_numbers': ['5222062']}}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': '3.13', 'product': {'name': 'Firmware 3.13', 'product_id': 'CSAFPID-21001', 'product_identification_helper': {'cpe': 'cpe:2.3:o:janitza:umg_96rm_e_firmware:3.13:*:*:*:*:*:*:*'}}, 'category': 'product_version'}, {'name': '3.14', 'product': {'name': 'Firmware 3.14', 'product_id': 'CSAFPID-21002', 'product_identification_helper': {'cpe': 'cpe:2.3:o:janitza:umg_96rm_e_firmware:3.14:*:*:*:*:*:*:*'}}, 'category': 'product_version'}, {'name': 'vers:generic/<=3.13', 'product': {'name': 'Firmware <=3.13', 'product_id': 'CSAFPID-21003'}, 'category': 'product_version_range'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware 3.13 installed on UMG 96RM-E 24V', 'product_id': 'CSAFPID-31001', 'product_identification_helper': {'cpe': 'cpe:2.3:o:janitza:umg_96rm_e_24v_firmware:3.13:*:*:*:*:*:*:*'}}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 3.13 installed on UMG 96RM-E 230V', 'product_id': 'CSAFPID-31002', 'product_identification_helper': {'cpe': 'cpe:2.3:o:janitza:umg_96rm_e_230v_firmware:3.13:*:*:*:*:*:*:*'}}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11002'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 3.14 installed on UMG 96RM-E 24V', 'product_id': 'CSAFPID-32001', 'product_identification_helper': {'cpe': 'cpe:2.3:o:janitza:umg_96rm_e_24v_firmware:3.14:*:*:*:*:*:*:*'}}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 3.14 installed on UMG 96RM-E 230V', 'product_id': 'CSAFPID-32002', 'product_identification_helper': {'cpe': 'cpe:2.3:o:janitza:umg_96rm_e_230v_firmware:3.14:*:*:*:*:*:*:*'}}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11002'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=3.13 installed on UMG 96RM-E 24V', 'product_id': 'CSAFPID-31003', 'product_identification_helper': {'cpe': 'cpe:2.3:o:janitza:umg_96rm_e_24v_firmware:3.13:*:*:*:*:*:*:*'}}, 'product_reference': 'CSAFPID-21003', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=3.13 installed on UMG 96RM-E 230V', 'product_id': 'CSAFPID-31004', 'product_identification_helper': {'cpe': 'cpe:2.3:o:janitza:umg_96rm_e_230v_firmware:3.13:*:*:*:*:*:*:*'}}, 'product_reference': 'CSAFPID-21003', 'relates_to_product_reference': 'CSAFPID-11002'}], 'product_groups': [{'summary': 'Affected products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004']}, {'summary': 'Fixed products.', 'group_id': 'CSAFGID-0002', 'product_ids': ['CSAFPID-32001', 'CSAFPID-32002']}]}, 'vulnerabilities': [{'cve': 'CVE-2025-41709', 'cwe': {'id': 'CWE-78', 'name': "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"}, 'notes': [{'text': 'An unauthenticated remote attacker can perform a command injection via Modbus-TCP or Modbus-RTU to gain read and write access on the affected device.', 'title': 'CVE Description', 'category': 'description'}], 'title': 'Command injection in power analyzer via Modbus-TCP and Modbus-RTU', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004']}], 'remediations': [{'details': 'It is strongly advised to update to the newest version. The vulnerabilities are fixed in version 3.14.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004']}}, {'cve': 'CVE-2025-41710', 'cwe': {'id': 'CWE-798', 'name': 'Use of Hard-coded Credentials'}, 'notes': [{'text': 'An unauthenticated remote attacker may use hardcodes credentials to get access to the previously activated FTP Server with limited read and write privileges.', 'title': 'CVE Description', 'category': 'description'}], 'title': 'Use of Hard-coded Credentials in power analyzer', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N', 'temporalScore': 6.5, 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 6.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004']}], 'remediations': [{'details': 'It is strongly advised to update to the newest version. The vulnerabilities are fixed in version 3.14.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004']}}, {'cve': 'CVE-2025-41711', 'cwe': {'id': 'CWE-327', 'name': 'Use of a Broken or Risky Cryptographic Algorithm'}, 'notes': [{'text': 'An unauthenticated remote attacker can use firmware images to extract password hashes and brute force plaintext passwords of accounts with limited access. ', 'title': 'CVE Description', 'category': 'description'}], 'title': 'Use of a Broken or Risky Cryptographic Algorithm for firmware images of power analyzer', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N', 'temporalScore': 5.3, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 5.3, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004']}], 'remediations': [{'details': 'It is strongly advised to update to the newest version. The vulnerabilities are fixed in version 3.14.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004']}}, {'cve': 'CVE-2025-41712', 'cwe': {'id': 'CWE-732', 'name': 'Incorrect Permission Assignment for Critical Resource'}, 'notes': [{'text': 'An unauthenticated remote attacker who tricks a user to upload a manipulated HTML file can get access to sensitive information on the device. This is a result of incorrect permission assignment for the web server.', 'title': 'CVE Description', 'category': 'description'}], 'title': 'Incorrect Permission Assignment on power analyzer', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N', 'temporalScore': 6.5, 'integrityImpact': 'NONE', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 6.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004']}], 'remediations': [{'details': 'It is strongly advised to update to the newest version. The vulnerabilities are fixed in version 3.14.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004']}}]}
f1bb1f71e272d397894c1d04c4eb3c34105e21993683eee1c4a55c457fbab588
2026-05-29 08:30:29.548963+03:00
2026-05-29 08:30:29.548963+03:00
csaf_janitzaelectronicsgmbh.ndjson
018f0d430ce5191e29e4df6ee476c30ab90d6eb8d59a0920c47afa80e98a650d
{'document': {'lang': 'en-GB', 'notes': [{'text': 'A vulnerability in the devices UMG 96-PA and UMG 96-PA-MID+ enables an unauthenticated remote attacker to cause the device to become unavailable.', 'title': 'Summary', 'category': 'summary'}, {'text': "When exploiting the vulnerability the device becomes unavailable. It will not continue to work as expected including not responding to further requests. Additionally it's measurement functionalities stop working effectively making the device unavailable until the next restart.", 'title': 'Impact', 'category': 'description'}, {'text': 'It is strongly advised to operate the device in a closed network protected by a suitable firewall. Network access to the device should be limited to only enable necessary components to access it. Special focus should be on the Modbus protocol as the core communication protocol of the device.', 'title': 'Mitigation', 'category': 'description'}, {'text': 'It is strongly advised to update to the newest version. The vulnerability is fixed in version 3.54.', 'title': 'Remediation', 'category': 'description'}], 'title': 'Janitza: Vulnerability in Modbus interface of UMG 96-PA and UMG 96-PA-MID+', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2025-094', 'status': 'final', 'aliases': ['VDE-2025-094'], 'version': '1.0.0', 'generator': {'date': '2025-11-24T11:11:03.153Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.40'}}, 'revision_history': [{'date': '2025-11-24T12:00:00.000Z', 'number': '1.0.0', 'summary': 'Initial release.'}], 'current_release_date': '2025-11-24T12:00:00.000Z', 'initial_release_date': '2025-11-24T12:00:00.000Z'}, 'publisher': {'name': 'Janitza electronics GmbH', 'category': 'vendor', 'namespace': 'https://www.janitza.com', 'contact_details': 'security@janitza.de'}, 'references': [{'url': 'https://www.janitza.com/de-de/service-support/security-issue-ticket', 'summary': 'Janitza PSIRT contact', 'category': 'external'}, {'url': 'https://certvde.com/de/advisories/vendor/janitza/', 'summary': 'Janitza advisory overview at CERT@VDE', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/VDE-2025-094', 'summary': 'VDE-2025-094: Janitza: Vulnerability in Modbus interface of UMG 96-PA and UMG 96-PA-MID+ - HTML', 'category': 'self'}, {'url': 'https://janitza.csaf-tp.certvde.com/.well-known/csaf/white/2025/vde-2025-094.json', 'summary': 'VDE-2025-094: Janitza: Vulnerability in Modbus interface of UMG 96-PA and UMG 96-PA-MID+ - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com/en/'], 'summary': 'Coordination', 'organization': 'CERTVDE'}, {'summary': 'Reporting', 'organization': 'Milence - Commercial Vehicle Charging Europe B.V.'}], 'aggregate_severity': {'text': 'Medium', 'namespace': 'https://www.first.org/cvss/v3.1/specification-document#Qualitative-Severity-Rating-Scale'}}, 'product_tree': {'branches': [{'name': 'Janitza', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'UMG 96-PA', 'product': {'name': 'UMG 96-PA', 'product_id': 'CSAFPID-11001', 'product_identification_helper': {'model_numbers': ['1761.8057']}}, 'category': 'product_name'}, {'name': 'UMG 96-PA-MID+', 'product': {'name': 'UMG 96-PA-MID+', 'product_id': 'CSAFPID-11002'}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': '<3.54', 'product': {'name': 'Firmware <3.54', 'product_id': 'CSAFPID-21001'}, 'category': 'product_version_range'}, {'name': '3.54', 'product': {'name': 'Firmware 3.54', 'product_id': 'CSAFPID-22001'}, 'category': 'product_version'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware <3.54 installed on UMG 96-PA', 'product_id': 'CSAFPID-31001'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 3.54 installed on UMG 96-PA', 'product_id': 'CSAFPID-32001'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <3.54 installed on UMG 96-PA-MID+', 'product_id': 'CSAFPID-31002'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11002'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 3.54 installed on UMG 96-PA-MID+', 'product_id': 'CSAFPID-32002'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11002'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-41729', 'cwe': {'id': 'CWE-1287', 'name': 'Improper Validation of Specified Type of Input'}, 'notes': [{'text': 'An unauthenticated remote attacker can send a specially crafted Modbus read command to the device which leads to a denial of service.', 'title': 'Description', 'category': 'description'}], 'title': 'DoS via Modbus Read Command', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002']}], 'remediations': [{'details': 'It is strongly advised to operate the device in a closed network protected by a suitable firewall. Network access to the device should be limited to only enable necessary components to access it. Special focus should be on the Modbus protocol as the core communication protocol of the device.', 'category': 'mitigation', 'product_ids': ['CSAFPID-31001', 'CSAFPID-31002']}, {'details': 'It is strongly advised to update to the newest version. The vulnerability is fixed in version 3.54.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-21001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002']}}]}
7b36ce26d2f17eeac515f142e555b00886f6e4d55fd0630c0df642bf10ca2a50
2026-05-29 08:30:29.548963+03:00
2026-05-29 08:30:29.548963+03:00
csaf_mettlertoledogmbh.ndjson
17c6ab65f003baade8b3ccdf9bdfb666afdf82589c279d2cb0d1528aaed2ff65
{'document': {'lang': 'en-GB', 'notes': [{'text': 'LabX 21.2.12 (formerly known as LabX Cloud 1.2.12) is affected by the ASP.NET core vulnerability CVE-2025-55315.', 'title': 'Summary', 'category': 'summary'}, {'text': 'HTTP Request Smuggling flaw in ASP.NET Core allows an attacker to achieve an authenticity bypass by sending ambiguous requests that circumvent access controls. This directly leads to a high impact on confidentiality. Furthermore, integrity is severely compromised because the attacker can smuggle malicious commands, enabling injection attacks and unauthorized data manipulation.', 'title': 'Impact', 'category': 'description'}, {'text': 'Update to LabX version 21.3.22, which includes a fix for the ASP.NET Core vulnerability CVE-2025-55315.', 'title': 'Remediation', 'category': 'description'}, {'text': 'Your use of the information on this document or materials linked from this document is at your own risk. METTLER TOLEDO makes reasonable efforts to ensure the accuracy of the information but does not grant any warranty, express or implied, including warranties of merchantability or fitness for a particular purpose. To the extent permitted by applicable law, METTLER TOLEDO excludes liability for any loss, claim, expense or damage arising from or related to the statements in this document. METTLER TOLEDO reserves the right to change or update this document at any time.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}], 'title': 'METTLER TOLEDO: ASP.NET core vulnerability in LabX', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2026-001', 'status': 'final', 'aliases': ['VDE-2026-001'], 'version': '1.0.0', 'generator': {'date': '2026-03-04T07:21:51.091Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.43'}}, 'revision_history': [{'date': '2026-03-04T07:00:00.000Z', 'number': '1.0.0', 'summary': 'Initial revision'}], 'current_release_date': '2026-03-04T07:00:00.000Z', 'initial_release_date': '2026-03-04T07:00:00.000Z'}, 'publisher': {'name': 'Mettler-Toledo GmbH', 'category': 'vendor', 'namespace': 'https://www.mt.com', 'contact_details': 'psirt@mt.com'}, 'references': [{'url': 'https://www.mt.com/ph/en/home/site_content/product-security.html', 'summary': 'Product security website of METTLER TOLEDO', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/mettler-toledo/', 'summary': 'CERT@VDE Security Advisories for METTLER TOLEDO', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/VDE-2026-001/', 'summary': 'VDE-2026-001: METTLER TOLEDO: ASP.NET core vulnerability in LabX - HTML', 'category': 'self'}, {'url': 'https://mettler-toledo.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-001.json', 'summary': 'VDE-2026-001: METTLER TOLEDO: ASP.NET core vulnerability in LabX - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}], 'aggregate_severity': {'text': 'critical', 'namespace': 'https://www.first.org/cvss/v3.1/specification-document#Qualitative-Severity-Rating-Scale'}}, 'product_tree': {'branches': [{'name': 'METTLER TOLEDO', 'branches': [{'name': 'Software', 'branches': [{'name': 'LabX Cloud', 'branches': [{'name': '1.2.12', 'product': {'name': 'LabX Cloud 1.2.12', 'product_id': 'CSAFPID-51000', 'product_identification_helper': {'cpe': 'cpe:2.3:a:mettler_toledo:labx_cloud:1.2.12:*:*:*:*:*:*:*'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'LabX', 'branches': [{'name': '21.2.12', 'product': {'name': 'LabX 21.2.12', 'product_id': 'CSAFPID-51001', 'product_identification_helper': {'cpe': 'cpe:2.3:a:mettler_toledo:labx:21.2.12:*:*:*:*:*:*:*'}}, 'category': 'product_version'}, {'name': '21.3.22', 'product': {'name': 'LabX 21.3.22', 'product_id': 'CSAFPID-52000', 'product_identification_helper': {'cpe': 'cpe:2.3:a:mettler_toledo:labx:21.3.22:*:*:*:*:*:*:*'}}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-55315', 'cwe': {'id': 'CWE-444', 'name': "Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')"}, 'notes': [{'text': "Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.", 'title': 'CVE Description', 'category': 'description'}, {'text': 'ASP.NET Core 8.0.20 introduces the vulnerability.', 'title': 'Preconditions', 'category': 'description'}], 'title': 'ASP.NET Core vulnerability', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 9.9, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L', 'temporalScore': 9.9, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'LOW', 'environmentalScore': 9.9, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-51000', 'CSAFPID-51001']}], 'threats': [{'details': 'HTTP Request Smuggling flaw in ASP.NET Core allows an attacker to achieve an authenticity bypass by sending ambiguous requests that circumvent access controls. This directly leads to a high impact on Confidentiality. Furthermore, integrity is severely compromised because the attacker can smuggle malicious commands, enabling injection attacks and unauthorized data manipulation.', 'category': 'impact', 'product_ids': ['CSAFPID-51000', 'CSAFPID-51001']}], 'remediations': [{'details': 'Update to the LabX version 21.3.22, which includes a fix for the ASP.NET Core vulnerability CVE-2025-55315 ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51000', 'CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52000'], 'recommended': ['CSAFPID-52000'], 'known_affected': ['CSAFPID-51000', 'CSAFPID-51001']}}]}
b0cf796f9905c609bfc8a2be71b150a3750006d5d1d9f1c19ef3a2845be91b15
2026-05-29 08:30:29.934966+03:00
2026-05-29 08:30:29.934966+03:00
csaf_mettlertoledogmbh.ndjson
3b965659408a462b3430ad9c7929e8692790ae81790810f6e8e630d2df16648a
{'document': {'lang': 'en-GB', 'notes': [{'text': 'MX/MR firmware V2.0.0 or earlier is affected by the OpenSSL vulnerability CVE-2025-15467.', 'title': 'Summary', 'category': 'summary'}, {'text': 'A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution.', 'title': 'Impact', 'category': 'description'}, {'text': 'Update MX/MR firmware to version 2.1.0', 'title': 'Remediation', 'category': 'description'}, {'text': 'Your use of the information on this document or materials linked from this document is at your own risk. METTLER TOLEDO makes reasonable efforts to ensure the accuracy of the information but does not grant any warranty, express or implied, including warranties of merchantability or fitness for a particular purpose. To the extent permitted by applicable law, METTLER TOLEDO excludes liability for any loss, claim, expense or damage arising from or related to the statements in this document. METTLER TOLEDO reserves the right to change or update this document at any time.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}], 'title': 'METTLER TOLEDO: OpenSSL vulnerability in MX and MR balances', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2026-029', 'status': 'final', 'aliases': ['VDE-2026-029'], 'version': '1.0.0', 'generator': {'date': '2026-04-23T10:41:48.109Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.44'}}, 'revision_history': [{'date': '2026-04-23T10:00:00.000Z', 'number': '1.0.0', 'summary': 'Initial revision'}], 'current_release_date': '2026-04-23T10:00:00.000Z', 'initial_release_date': '2026-04-23T10:00:00.000Z'}, 'publisher': {'name': 'Mettler-Toledo GmbH', 'category': 'vendor', 'namespace': 'https://www.mt.com', 'contact_details': 'psirt@mt.com'}, 'references': [{'url': 'https://www.mt.com/ph/en/home/site_content/product-security.html', 'summary': 'Product security website of METTLER TOLEDO', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/mettler-toledo/', 'summary': 'CERT@VDE Security Advisories for METTLER TOLEDO', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/VDE-2026-029/', 'summary': 'VDE-2026-029: METTLER TOLEDO: OpenSSL vulnerability in MX and MR balances - HTML', 'category': 'self'}, {'url': 'https://mettler-toledo.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-029.json', 'summary': 'VDE-2026-029: METTLER TOLEDO: OpenSSL vulnerability in MX and MR balances - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}], 'aggregate_severity': {'text': 'Medium', 'namespace': 'https://www.first.org/cvss/v3.1/specification-document#Qualitative-Severity-Rating-Scale'}}, 'product_tree': {'branches': [{'name': 'METTLER TOLEDO', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'MX balance', 'product': {'name': 'MX balance', 'product_id': 'CSAFPID-11000', 'product_identification_helper': {'cpe': 'cpe:2.3:h:mettler_toledo:mx_balance:*:*:*:*:*:*:*:*', 'model_numbers': ['MX*']}}, 'category': 'product_name'}, {'name': 'MR balance', 'product': {'name': 'MR balance', 'product_id': 'CSAFPID-11001', 'product_identification_helper': {'cpe': 'cpe:2.3:h:mettler_toledo:mr_balance:*:*:*:*:*:*:*:*', 'model_numbers': ['MR*']}}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': '2.1.0', 'product': {'name': 'Firmware V2.1.0', 'product_id': 'CSAFPID-22000'}, 'category': 'product_version'}, {'name': 'vers:generic/<2.1.0', 'product': {'name': 'Firmware <2.1.0', 'product_id': 'CSAFPID-21000'}, 'category': 'product_version_range'}], 'category': 'product_family'}], 'category': 'vendor'}, {'name': 'Debian Project', 'branches': [{'name': 'openssl debian package', 'branches': [{'name': '3.0.18-1~deb12u1', 'product': {'name': 'openssl 3.0.18-1~deb12u1', 'product_id': 'CSAFPID-51002', 'product_identification_helper': {'purl': 'pkg:deb/debian/openssl@3.0.18-1~deb12u1'}}, 'category': 'product_version'}, {'name': '3.0.18-1~deb12u2', 'product': {'name': 'openssl 3.0.18-1~deb12u2', 'product_id': 'CSAFPID-52002', 'product_identification_helper': {'purl': 'pkg:deb/debian/openssl@3.0.18-1~deb12u2'}}, 'category': 'product_version'}], 'category': 'service_pack'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware <2.1.0 installed on MX balance', 'product_id': 'CSAFPID-31000'}, 'product_reference': 'CSAFPID-21000', 'relates_to_product_reference': 'CSAFPID-11000'}, {'category': 'installed_with', 'full_product_name': {'name': 'Firmware <2.1.0 installed on MR balance', 'product_id': 'CSAFPID-31001'}, 'product_reference': 'CSAFPID-21000', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware V2.1.0 installed on MX balance', 'product_id': 'CSAFPID-32000', 'product_identification_helper': {'cpe': 'cpe:2.3:o:mettler_toledo:mx_balance_firmware:2.1.0:*:*:*:*:*:*:*'}}, 'product_reference': 'CSAFPID-22000', 'relates_to_product_reference': 'CSAFPID-11000'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware V2.1.0 installed on MR balance', 'product_id': 'CSAFPID-32001', 'product_identification_helper': {'cpe': 'cpe:2.3:o:mettler_toledo:mr_balance_firmware:2.1.0:*:*:*:*:*:*:*'}}, 'product_reference': 'CSAFPID-22000', 'relates_to_product_reference': 'CSAFPID-11001'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-15467', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution. When parsing CMS (Auth)EnvelopedData structures that use AEAD ciphers such as AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is copied into a fixed-size stack buffer without verifying that its length fits the destination. An attacker can supply a crafted CMS message with an oversized IV, causing a stack-based out-of-bounds write before any authentication or tag verification occurs. Applications and services that parse untrusted CMS or PKCS#7 content using AEAD ciphers (e.g., S/MIME (Auth)EnvelopedData with AES-GCM) are vulnerable. Because the overflow occurs prior to authentication, no valid key material is required to trigger it. While exploitability to remote code execution depends on platform and toolchain mitigations, the stack-based write primitive represents a severe risk. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue. OpenSSL 1.1.1 and 1.0.2 are not affected by this issue.', 'title': 'CVE Description', 'audience': 'all', 'category': 'description'}, {'text': "Vulnerability potentially exploitable with manipulated SW upgrade package on USB memory.\nThe vulnerability is fixed in openssl debian package 3.0.18-1~deb12u2.\n\nIn the device context, there are deviations from the original CVSS assessment. Attack vector is set to 'local' because firmware upgrades are only possible though an attached USB memory, not through the network.", 'title': 'Vulnerability Characterisation', 'audience': 'operational management and system administrators', 'category': 'description'}], 'title': 'OpenSSL vulnerability affecting SW upgrade packages', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'temporalScore': 8.8, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 8.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51002']}, {'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'temporalScore': 7.8, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31000', 'CSAFPID-31001']}], 'remediations': [{'details': 'Update MX Firmware to version 2.1.0', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31000']}, {'details': 'Update MR Firmware to version 2.1.0', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31001']}, {'details': 'Vulnerable debian openssl package shall be updated to openssl package version \t3.0.18-1~deb12u2 ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51002']}], 'product_status': {'fixed': ['CSAFPID-32000', 'CSAFPID-32001', 'CSAFPID-52002'], 'recommended': ['CSAFPID-32000', 'CSAFPID-32001', 'CSAFPID-52002'], 'known_affected': ['CSAFPID-31000', 'CSAFPID-31001', 'CSAFPID-51002']}}]}
801df071d090fc3e653aab6b310535f553b1f7736dd41757989b6018b54a6306
2026-05-29 08:30:29.934966+03:00
2026-05-29 08:30:29.934966+03:00
csaf_mettlertoledogmbh.ndjson
afcb0b7a441c94b3f949246098a3df7de325394c3092ce4cfebd0dafd65fb3ac
{'document': {'lang': 'en-GB', 'notes': [{'text': 'Titration software versions prior to 2.0.2.6 are affected by libpng vulnerabilities CVE-2026-33416 and CVE-2026-33636.', 'title': 'Summary', 'category': 'summary'}, {'text': 'When an EVA Karl Fischer titrator connects to a LabX server for authentication, a crafted PNG image processed during this flow could trigger the vulnerability in the underlying libpng library, potentially causing a denial of service, information disclosure, heap corruption, or code execution.', 'title': 'Impact', 'category': 'description'}, {'text': 'Update to Titration software version 2.0.2.6, which includes fixes for CVE-2026-33416 and CVE-2026-33636.', 'title': 'Remediation', 'category': 'description'}, {'text': 'Your use of the information on this document or materials linked from this document is at your own risk. METTLER TOLEDO makes reasonable efforts to ensure the accuracy of the information but does not grant any warranty, express or implied, including warranties of merchantability or fitness for a particular purpose. To the extent permitted by applicable law, METTLER TOLEDO excludes liability for any loss, claim, expense or damage arising from or related to the statements in this document. METTLER TOLEDO reserves the right to change or update this document at any time.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}], 'title': 'METTLER TOLEDO: EVA Karl Fischer titrators affected by libpng vulnerabilities', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2026-053', 'status': 'final', 'aliases': ['VDE-2026-053'], 'version': '1.0.0', 'generator': {'date': '2026-05-21T09:27:10.358Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.44'}}, 'revision_history': [{'date': '2026-05-26T10:00:00.000Z', 'number': '1.0.0', 'summary': 'Initial revision'}], 'current_release_date': '2026-05-26T10:00:00.000Z', 'initial_release_date': '2026-05-26T10:00:00.000Z'}, 'publisher': {'name': 'Mettler-Toledo GmbH', 'category': 'vendor', 'namespace': 'https://www.mt.com', 'contact_details': 'psirt@mt.com'}, 'references': [{'url': 'https://www.mt.com/ph/en/home/site_content/product-security.html', 'summary': 'Product security website of METTLER TOLEDO', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/mettler-toledo/', 'summary': 'CERT@VDE Security Advisories for METTLER TOLEDO', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/VDE-2026-053/', 'summary': 'VDE-2026-053: METTLER TOLEDO: EVA Karl Fischer titrators affected by libpng vulnerabilities - HTML', 'category': 'self'}, {'url': 'https://mettler-toledo.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-053.json', 'summary': 'VDE-2026-053: METTLER TOLEDO: EVA Karl Fischer titrators affected by libpng vulnerabilities - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}], 'aggregate_severity': {'text': 'high', 'namespace': 'https://www.first.org/cvss/v3.1/specification-document#Qualitative-Severity-Rating-Scale'}}, 'product_tree': {'branches': [{'name': 'METTLER TOLEDO', 'branches': [{'name': 'Software', 'branches': [{'name': 'Titration Software', 'branches': [{'name': 'vers:intdot/<2.0.2.6', 'product': {'name': 'Titration Software version <2.0.2.6', 'product_id': 'CSAFPID-51001', 'product_identification_helper': {'cpe': 'cpe:2.3:a:mettler_toledo:eva_titration:*:*:*:*:*:*:*:*'}}, 'category': 'product_version_range'}, {'name': '2.0.2.6', 'product': {'name': 'Titration Software version 2.0.2.6', 'product_id': 'CSAFPID-52001', 'product_identification_helper': {'cpe': 'cpe:2.3:a:mettler_toledo:eva_titration:2.0.2.6:*:*:*:*:*:*:*'}}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Hardware', 'branches': [{'name': 'EVA V1 Volumetric Karl Fischer Titrator', 'product': {'name': 'EVA V1 Volumetric Karl Fischer Titrator', 'product_id': 'CSAFPID-11001', 'product_identification_helper': {'cpe': 'cpe:2.3:h:mettler_toledo:volumetric_kf_titrator_eva_v1:*:*:*:*:*:*:*:*'}}, 'category': 'product_name'}, {'name': 'EVA V3 Volumetric Karl Fischer Titrator', 'product': {'name': 'EVA V3 Volumetric Karl Fischer Titrator', 'product_id': 'CSAFPID-11002', 'product_identification_helper': {'cpe': 'cpe:2.3:h:mettler_toledo:volumetric_kf_titrator_eva_v3:*:*:*:*:*:*:*:*'}}, 'category': 'product_name'}, {'name': 'EVA C1 Coulometric Karl Fischer Titrator', 'product': {'name': 'EVA C1 Coulometric Karl Fischer Titrator', 'product_id': 'CSAFPID-11003', 'product_identification_helper': {'cpe': 'cpe:2.3:h:mettler_toledo:coulometric_kf_titrator_eva_c1:*:*:*:*:*:*:*:*'}}, 'category': 'product_name'}, {'name': 'EVA C3 Coulometric Karl Fischer Titrator', 'product': {'name': 'EVA C3 Coulometric Karl Fischer Titrator', 'product_id': 'CSAFPID-11004', 'product_identification_helper': {'cpe': 'cpe:2.3:h:mettler_toledo:coulometric_kf_titrator_eva_c3:*:*:*:*:*:*:*:*'}}, 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Titration Software version <2.0.2.6 installed on EVA V1 Volumetric Karl Fischer Titrator', 'product_id': 'CSAFPID-31001', 'product_identification_helper': {'cpe': 'cpe:2.3:o:mettler_toledo:volumetric_kf_titrator_eva_v1:*:*:*:*:*:*:*:*'}}, 'product_reference': 'CSAFPID-51001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Titration Software version <2.0.2.6 installed on EVA V3 Volumetric Karl Fischer Titrator', 'product_id': 'CSAFPID-31002', 'product_identification_helper': {'cpe': 'cpe:2.3:o:mettler_toledo:volumetric_kf_titrator_eva_v3:*:*:*:*:*:*:*:*'}}, 'product_reference': 'CSAFPID-51001', 'relates_to_product_reference': 'CSAFPID-11002'}, {'category': 'installed_on', 'full_product_name': {'name': 'Titration Software version <2.0.2.6 installed on EVA C1 Coulometric Karl Fischer Titrator', 'product_id': 'CSAFPID-31003', 'product_identification_helper': {'cpe': 'cpe:2.3:o:mettler_toledo:coulometric_kf_titrator_eva_c1:*:*:*:*:*:*:*:*'}}, 'product_reference': 'CSAFPID-51001', 'relates_to_product_reference': 'CSAFPID-11003'}, {'category': 'installed_on', 'full_product_name': {'name': 'Titration Software version <2.0.2.6 installed on EVA C3 Coulometric Karl Fischer Titrator', 'product_id': 'CSAFPID-31004', 'product_identification_helper': {'cpe': 'cpe:2.3:o:mettler_toledo:coulometric_kf_titrator_eva_c3:*:*:*:*:*:*:*:*'}}, 'product_reference': 'CSAFPID-51001', 'relates_to_product_reference': 'CSAFPID-11004'}, {'category': 'installed_on', 'full_product_name': {'name': 'Titration Software version 2.0.2.6 installed on EVA V1 Volumetric Karl Fischer Titrator', 'product_id': 'CSAFPID-32001', 'product_identification_helper': {'cpe': 'cpe:2.3:o:mettler_toledo:volumetric_kf_titrator_eva_v1:2.0.2.6:*:*:*:*:*:*:*'}}, 'product_reference': 'CSAFPID-52001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Titration Software version 2.0.2.6 installed on EVA V3 Volumetric Karl Fischer Titrator', 'product_id': 'CSAFPID-32002', 'product_identification_helper': {'cpe': 'cpe:2.3:o:mettler_toledo:volumetric_kf_titrator_eva_v3:2.0.2.6:*:*:*:*:*:*:*'}}, 'product_reference': 'CSAFPID-52001', 'relates_to_product_reference': 'CSAFPID-11002'}, {'category': 'installed_on', 'full_product_name': {'name': 'Titration Software version 2.0.2.6 installed on EVA C1 Coulometric Karl Fischer Titrator', 'product_id': 'CSAFPID-32003', 'product_identification_helper': {'cpe': 'cpe:2.3:o:mettler_toledo:coulometric_kf_titrator_eva_c1:2.0.2.6:*:*:*:*:*:*:*'}}, 'product_reference': 'CSAFPID-52001', 'relates_to_product_reference': 'CSAFPID-11003'}, {'category': 'installed_on', 'full_product_name': {'name': 'Titration Software version 2.0.2.6 installed on EVA C3 Coulometric Karl Fischer Titrator', 'product_id': 'CSAFPID-32004', 'product_identification_helper': {'cpe': 'cpe:2.3:o:mettler_toledo:coulometric_kf_titrator_eva_c3:2.0.2.6:*:*:*:*:*:*:*'}}, 'product_reference': 'CSAFPID-52001', 'relates_to_product_reference': 'CSAFPID-11004'}], 'product_groups': [{'summary': 'affected products', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004']}, {'summary': 'fixed products', 'group_id': 'CSAFGID-0002', 'product_ids': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-32004']}]}, 'vulnerabilities': [{'cve': 'CVE-2026-33636', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': "LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. In versions 1.6.36 through 1.6.55, an out-of-bounds read and write exists in libpng's ARM/AArch64 Neon-optimized palette expansion path. When expanding 8-bit paletted rows to RGB or RGBA, the Neon loop processes a final partial chunk without verifying that enough input pixels remain. Because the implementation works backward from the end of the row, the final iteration dereferences pointers before the start of the row buffer (OOB read) and writes expanded pixel data to the same underflowed positions (OOB write). This is reachable via normal decoding of attacker-controlled PNG input if Neon is enabled. Version 1.6.56 fixes the issue.", 'title': 'CVE Description', 'category': 'description'}, {'text': 'The EVA Karl Fischer titrator must receive a crafted paletted PNG image during the LabX login flow.', 'title': 'Vulnerability Characterisation', 'category': 'description'}], 'title': 'LIBPNG has ARM NEON Palette Expansion Out-of-Bounds Read on AArch64', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.6, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H', 'temporalScore': 7.6, 'integrityImpact': 'LOW', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.6, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004']}], 'remediations': [{'details': 'Update to Titration software version 2.0.2.6, which includes a fix for CVE-2026-33636.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-32004'], 'recommended': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-32004'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004']}}, {'cve': 'CVE-2026-33416', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. In versions 1.2.1 through 1.6.55, `png_set_tRNS` and `png_set_PLTE` each alias a heap-allocated buffer between `png_struct` and `png_info`, sharing a single allocation across two structs with independent lifetimes. The `trans_alpha` aliasing has been present since at least libpng 1.0, and the `palette` aliasing since at least 1.2.1. Both affect all prior release lines `png_set_tRNS` sets `png_ptr->trans_alpha = info_ptr->trans_alpha` (256-byte buffer) and `png_set_PLTE` sets `info_ptr->palette = png_ptr->palette` (768-byte buffer). In both cases, calling `png_free_data` (with `PNG_FREE_TRNS` or `PNG_FREE_PLTE`) frees the buffer through `info_ptr` while the corresponding `png_ptr` pointer remains dangling. Subsequent row-transform functions dereference and, in some code paths, write to the freed memory. A second call to `png_set_tRNS` or `png_set_PLTE` has the same effect, because both functions call `png_free_data` internally before reallocating the `info_ptr` buffer. Version 1.6.56 fixes the issue.', 'title': 'CVE Description', 'category': 'description'}, {'text': 'The EVA Karl Fischer titrator must receive a crafted PNG image during the LabX login flow.', 'title': 'Vulnerability Characterisation', 'category': 'description'}], 'title': 'LIBPNG has use-after-free via pointer aliasing in `png_set_tRNS` and `png_set_PLTE`', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H', 'temporalScore': 7.5, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'HIGH', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004']}], 'remediations': [{'details': 'Update to Titration software version 2.0.2.6, which includes a fix for CVE-2026-33416.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-32004'], 'recommended': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-32004'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004']}}]}
fc7ac78feea96dfc93312e46edb9a51614d3b68ba0aeee12dccc71974fb59f64
2026-05-29 08:30:29.934966+03:00
2026-05-29 08:30:29.934966+03:00
csaf_himapaulhildebrandtgmbh.ndjson
361bb9af62af132b792f527102b605bab95321a024b4c94794f7f9ecced9929e
{'document': {'lang': 'en-GB', 'notes': [{'text': 'Unquoted Windows search path vulnerability in the below mentioned Software for Windows might allow local users to gain privileges via a malicious .exe file.', 'title': 'Summary', 'category': 'summary'}, {'text': 'The vulnerability can be used to run a malicious file with administrator privileges while being logged in as a normal user. Therefore, any action which is not restricted by other measures could be taken.\n\nDue to the security manual HIMA recommends to run the OPC Server and the programming environment on different PCs.\n\nThe OPC can only influence the data defined in the project. It does not have the ability to change the project. For this reason HIMA estimates the influence of the OPC Server on the program of the safety PLC (Programmable Logic Controller) as unlikely.', 'title': 'Impact', 'category': 'description'}, {'text': "Ensure that Registry can only be accessed with administrator privileges.\nHOPCS: Install in a path without spaces and/or select a user with low privileges in the DCOM settings dcomcnfg/Identity.\nWhen using X-OPC or X-OTS it is recommended to protect the user program, with the system variables (see Automation Security Manual '3.2.2.2 Access Restrictions'):\n\n- Forcing Deactivation\n- Read-only in RUN\n- Reload Deactivation", 'title': 'Mitigation', 'category': 'description'}, {'text': 'All present products will be fixed. Updates are under development.Note: HOPCS is not suitable for present HIMA Products and is not planned to be fixed.', 'title': 'Remediation', 'category': 'description'}], 'title': 'HIMA: unquoted path vulnerabilities in X-OPC and X-OTS', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2022-059', 'status': 'final', 'aliases': ['VDE-2022-059'], 'version': '2', 'generator': {'date': '2025-05-05T09:01:00.460Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.24'}}, 'revision_history': [{'date': '2023-01-16T09:00:00.000Z', 'number': '1', 'summary': 'Initial revision.'}, {'date': '2025-05-22T13:03:10.000Z', 'number': '2', 'summary': 'Fix: quotation mark'}], 'current_release_date': '2025-05-22T13:03:10.000Z', 'initial_release_date': '2023-01-16T09:00:00.000Z'}, 'publisher': {'name': 'HIMA Paul Hildebrandt GmbH', 'category': 'vendor', 'namespace': 'https://www.hima.com', 'contact_details': 'hima-cert@hima.com'}, 'references': [{'url': 'https://certvde.com/en/advisories/VDE-2022-059/', 'summary': 'VDE-2022-059: HIMA: unquoted path vulnerabilities in X-OPC and X-OTS - HTML', 'category': 'self'}, {'url': 'https://hima.csaf-tp.certvde.com/.well-known/csaf/white/2023/vde-2022-059.json', 'summary': 'VDE-2022-059: HIMA: unquoted path vulnerabilities in X-OPC and X-OTS - CSAF', 'category': 'self'}, {'url': 'https://www.hima.com', 'summary': 'Vendor PSIRT', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/hima/', 'summary': 'CERT@VDE Security Advisories for HIMA Paul Hildebrandt GmbH', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}]}, 'product_tree': {'branches': [{'name': 'Hima', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'HOPCS', 'product': {'name': 'HOPCS', 'product_id': 'CSAFPID-11001', 'product_identification_helper': {'model_numbers': ['892042400']}}, 'category': 'product_name'}, {'name': 'X-OPC A+E', 'product': {'name': 'X-OPC A+E', 'product_id': 'CSAFPID-11002', 'product_identification_helper': {'model_numbers': ['894000016']}}, 'category': 'product_name'}, {'name': 'X-OPC DA', 'product': {'name': 'X-OPC DA', 'product_id': 'CSAFPID-11003', 'product_identification_helper': {'model_numbers': ['894000015']}}, 'category': 'product_name'}, {'name': 'X-OTS', 'product': {'name': 'X-OTS', 'product_id': 'CSAFPID-11004', 'product_identification_helper': {'model_numbers': ['895900001']}}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': '<=3.56.4', 'product': {'name': 'Firmware <=3.56.4', 'product_id': 'CSAFPID-21001'}, 'category': 'product_version_range'}, {'name': '<=5.6.1210', 'product': {'name': 'Firmware <=5.6.1210', 'product_id': 'CSAFPID-21002'}, 'category': 'product_version_range'}, {'name': '<=1.32.550', 'product': {'name': 'Firmware <=1.32.550', 'product_id': 'CSAFPID-21003'}, 'category': 'product_version_range'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=3.56.4 installed on HOPCS', 'product_id': 'CSAFPID-31001'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=5.6.1210 installed on X-OPC A+E', 'product_id': 'CSAFPID-31002'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11002'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=5.6.1210 installed on X-OPC DA', 'product_id': 'CSAFPID-31003'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11003'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=1.32.550 installed on X-OTS', 'product_id': 'CSAFPID-31004'}, 'product_reference': 'CSAFPID-21003', 'relates_to_product_reference': 'CSAFPID-11004'}], 'product_groups': [{'summary': 'Affected products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004']}]}, 'vulnerabilities': [{'cve': 'CVE-2022-4258', 'cwe': {'id': 'CWE-428', 'name': 'Unquoted Search Path or Element'}, 'notes': [{'text': 'In multiple versions of HIMA PC based Software an unquoted Windows search path vulnerability\xa0might allow local users to gain privileges via a malicious .exe file and gain full access to the system.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2022-4258', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 7.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.8, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004']}], 'remediations': [{'details': "Ensure that Registry can only be accessed with administrator privileges.\nHOPCS: Install in a path without spaces and/or select a user with low privileges in the DCOM settings dcomcnfg/Identity.\nWhen using X-OPC or X-OTS it is recommended to protect the user program, with the system variables (see Automation Security Manual '3.2.2.2 Access Restrictions'):\n\n- Forcing Deactivation\n- Read-only in RUN\n- Reload Deactivation", 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'All present products will be fixed. Updates are under development.Note: HOPCS is not suitable for present HIMA Products and is not planned to be fixed.', 'category': 'no_fix_planned', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004']}}]}
db608a25501023e6e9b2a3482daed7dd243579a34713a57a47f9f9a00ecbf586
2026-05-29 08:30:30.287740+03:00
2026-05-29 08:30:30.287740+03:00
csaf_himapaulhildebrandtgmbh.ndjson
978bb17da892c2071cf8a627615ecc0a7ed44c913593e4e773df5521beebfa92
{'document': {'lang': 'en-GB', 'notes': [{'text': "CVE-2024-24781: If the above mentioned products are loaded with Wire speed (1Gbit/s or 100Mbit/s) the resources of the Ethernet-Controller are exhausted and it must be reset by the system automatically after load disappears. This leads to an interruption (DoS) of all other communications of the affected Ethernet-Controller.\n\nCVE-2024-24782: Most of the above mentioned products offer a VLAN feature. This helps to segregate ports of the switch included in each of the products. VLAN are meant to segregate networks. Furthermore a MAC-learning mode called 'conservative' is provided. In this mode the ARP table is updated earliest within 1..2 times ARP aging time.\n\nX-SB 01 (985210207) is not affected by this CVE.", 'title': 'Summary', 'category': 'summary'}, {'text': 'Please consult the above CVEs.', 'title': 'Impact', 'category': 'description'}, {'text': "CVE-2024-24781: All load limiting measures are helpful (e.g. in external devices or also in the switch of the above mentioned products). Please check whether the reduced speed is still sufficient for the desired application. Protect the network with segregation measures and restrict the access of unauthorized network participants (e.g. close unused ports)\n\nCVE-2024-24782: Switching the MAC-learning from 'conservative' to 'tolerant' mitigates the above described vulnerability but leads to potential IP-Spoofing and ARP-Poisoning and should therefore be avoided. HIMax and HIQuad X systems can be setup in the way that real physical segregation (between different modules) is used. E.g. it is impossible to ping from one X-COM to another X-COM in the same Rack. HIMatrix should be used in that way that CPU and COM are NOT connected via VLAN e.g. CPU connected to Port 1 and 2, COM Connected to Port 3 and 4.", 'title': 'Mitigation', 'category': 'description'}], 'title': 'HIMA: Multiple products affected by DoS and Port-Based-VLAN Crossing', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2024-013', 'status': 'final', 'aliases': ['VDE-2024-013'], 'version': '2', 'generator': {'date': '2025-04-24T19:43:36.937Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.24'}}, 'revision_history': [{'date': '2024-02-13T07:00:00.000Z', 'number': '1', 'summary': 'Initial revision.'}, {'date': '2025-05-22T13:03:10.000Z', 'number': '2', 'summary': 'Fix: quotation mark'}], 'current_release_date': '2025-05-22T13:03:10.000Z', 'initial_release_date': '2024-02-13T07:00:00.000Z'}, 'publisher': {'name': 'HIMA Paul Hildebrandt GmbH', 'category': 'vendor', 'namespace': 'https://www.hima.com', 'contact_details': 'hima-cert@hima.com'}, 'references': [{'url': 'https://certvde.com/en/advisories/VDE-2024-013/', 'summary': 'VDE-2024-013: HIMA: Multiple products affected by DoS and Port-Based-VLAN Crossing - HTML', 'category': 'self'}, {'url': 'https://hima.csaf-tp.certvde.com/.well-known/csaf/white/2024/vde-2024-013.json', 'summary': 'VDE-2024-013: HIMA: Multiple products affected by DoS and Port-Based-VLAN Crossing - CSAF', 'category': 'self'}, {'url': 'https://www.hima.com', 'summary': 'Vendor PSIRT', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/hima/', 'summary': 'CERT@VDE Security Advisories for HIMA Paul Hildebrandt GmbH', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}, {'names': ['Michael Klassen', 'Dr. Martin Floeck'], 'summary': 'reporting', 'organization': 'BASF'}]}, 'product_tree': {'branches': [{'name': 'HIMA', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'F30 03X YY (COM) all variants', 'product': {'name': 'F30 03X YY (COM) all variants', 'product_id': 'CSAFPID-11001'}, 'category': 'product_name'}, {'name': 'F30 03X YY (CPU) all variants', 'product': {'name': 'F30 03X YY (CPU) all variants', 'product_id': 'CSAFPID-11002'}, 'category': 'product_name'}, {'name': 'F35 03X YY (COM) all variants', 'product': {'name': 'F35 03X YY (COM) all variants', 'product_id': 'CSAFPID-11003'}, 'category': 'product_name'}, {'name': 'F35 03X YY (CPU) all variants', 'product': {'name': 'F35 03X YY (CPU) all variants', 'product_id': 'CSAFPID-11004'}, 'category': 'product_name'}, {'name': 'F60 CPU 03X YY (COM) all variants', 'product': {'name': 'F60 CPU 03X YY (COM) all variants', 'product_id': 'CSAFPID-11005'}, 'category': 'product_name'}, {'name': 'F60 CPU 03X YY (CPU) all variants', 'product': {'name': 'F60 CPU 03X YY (CPU) all variants', 'product_id': 'CSAFPID-11006'}, 'category': 'product_name'}, {'name': 'F-COM 01', 'product': {'name': 'F-COM 01', 'product_id': 'CSAFPID-11007', 'product_identification_helper': {'model_numbers': ['984867200']}}, 'category': 'product_name'}, {'name': 'F-COM 01 coated', 'product': {'name': 'F-COM 01 coated', 'product_id': 'CSAFPID-11008', 'product_identification_helper': {'model_numbers': ['984867202']}}, 'category': 'product_name'}, {'name': 'F-CPU 01', 'product': {'name': 'F-CPU 01', 'product_id': 'CSAFPID-11009', 'product_identification_helper': {'model_numbers': ['984866100']}}, 'category': 'product_name'}, {'name': 'F-CPU 01 coated', 'product': {'name': 'F-CPU 01 coated', 'product_id': 'CSAFPID-11010', 'product_identification_helper': {'model_numbers': ['984866102']}}, 'category': 'product_name'}, {'name': 'X-COM 01 E YY all variants', 'product': {'name': 'X-COM 01 E YY all variants', 'product_id': 'CSAFPID-11011'}, 'category': 'product_name'}, {'name': 'X-COM 01 YY all variants', 'product': {'name': 'X-COM 01 YY all variants', 'product_id': 'CSAFPID-11012'}, 'category': 'product_name'}, {'name': 'X-CPU 01', 'product': {'name': 'X-CPU 01', 'product_id': 'CSAFPID-11013', 'product_identification_helper': {'model_numbers': ['985210211']}}, 'category': 'product_name'}, {'name': 'X-CPU 31', 'product': {'name': 'X-CPU 31', 'product_id': 'CSAFPID-11014', 'product_identification_helper': {'model_numbers': ['985210246']}}, 'category': 'product_name'}, {'name': 'X-SB 01', 'product': {'name': 'X-SB 01', 'product_id': 'CSAFPID-11015', 'product_identification_helper': {'model_numbers': ['985210207']}}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': '<=24.14', 'product': {'name': 'Firmware <=24.14', 'product_id': 'CSAFPID-21001'}, 'category': 'product_version_range'}, {'name': '<=18.6', 'product': {'name': 'Firmware <=18.6', 'product_id': 'CSAFPID-21002'}, 'category': 'product_version_range'}, {'name': '<=14.12', 'product': {'name': 'Firmware <=14.12', 'product_id': 'CSAFPID-21003'}, 'category': 'product_version_range'}, {'name': '<=14.6', 'product': {'name': 'Firmware <=14.6', 'product_id': 'CSAFPID-21004'}, 'category': 'product_version_range'}, {'name': '<=15.14', 'product': {'name': 'Firmware <=15.14', 'product_id': 'CSAFPID-21005'}, 'category': 'product_version_range'}, {'name': '<=7.54', 'product': {'name': 'Firmware <=7.54', 'product_id': 'CSAFPID-21006'}, 'category': 'product_version_range'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=24.14 installed on F30 03X YY (COM) all variants', 'product_id': 'CSAFPID-31001'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=18.6 installed on F30 03X YY (CPU) all variants', 'product_id': 'CSAFPID-31002'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11002'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=24.14 installed on F35 03X YY (COM) all variants', 'product_id': 'CSAFPID-31003'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11003'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=18.6 installed on F35 03X YY (CPU) all variants', 'product_id': 'CSAFPID-31004'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11004'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=24.14 installed on F60 CPU 03X YY (COM) all variants', 'product_id': 'CSAFPID-31005'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11005'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=18.6 installed on F60 CPU 03X YY (CPU) all variants', 'product_id': 'CSAFPID-31006'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11006'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=14.12 installed on F-COM 01', 'product_id': 'CSAFPID-31007'}, 'product_reference': 'CSAFPID-21003', 'relates_to_product_reference': 'CSAFPID-11007'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=14.12 installed on F-COM 01 coated', 'product_id': 'CSAFPID-31008'}, 'product_reference': 'CSAFPID-21003', 'relates_to_product_reference': 'CSAFPID-11008'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=14.6 installed on F-CPU 01', 'product_id': 'CSAFPID-31009'}, 'product_reference': 'CSAFPID-21004', 'relates_to_product_reference': 'CSAFPID-11009'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=14.6 installed on F-CPU 01 coated', 'product_id': 'CSAFPID-31010'}, 'product_reference': 'CSAFPID-21004', 'relates_to_product_reference': 'CSAFPID-11010'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=15.14 installed on X-COM 01 E YY all variants', 'product_id': 'CSAFPID-31011'}, 'product_reference': 'CSAFPID-21005', 'relates_to_product_reference': 'CSAFPID-11011'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=14.12 installed on X-COM 01 YY all variants', 'product_id': 'CSAFPID-31012'}, 'product_reference': 'CSAFPID-21003', 'relates_to_product_reference': 'CSAFPID-11012'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=14.6 installed on X-CPU 01', 'product_id': 'CSAFPID-31013'}, 'product_reference': 'CSAFPID-21004', 'relates_to_product_reference': 'CSAFPID-11013'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=14.6 installed on X-CPU 31', 'product_id': 'CSAFPID-31014'}, 'product_reference': 'CSAFPID-21004', 'relates_to_product_reference': 'CSAFPID-11014'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=7.54 installed on X-SB 01', 'product_id': 'CSAFPID-31015'}, 'product_reference': 'CSAFPID-21006', 'relates_to_product_reference': 'CSAFPID-11015'}], 'product_groups': [{'summary': 'Affected products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007', 'CSAFPID-31008', 'CSAFPID-31009', 'CSAFPID-31010', 'CSAFPID-31011', 'CSAFPID-31012', 'CSAFPID-31013', 'CSAFPID-31014', 'CSAFPID-31015']}]}, 'vulnerabilities': [{'cve': 'CVE-2024-24781', 'cwe': {'id': 'CWE-400', 'name': 'Uncontrolled Resource Consumption'}, 'notes': [{'text': 'An unauthenticated remote attacker can use an uncontrolled resource consumption vulnerability to DoS the affected devices through excessive traffic on a single ethernet port.\xa0', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-24781', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007', 'CSAFPID-31008', 'CSAFPID-31009', 'CSAFPID-31010', 'CSAFPID-31011', 'CSAFPID-31012', 'CSAFPID-31013', 'CSAFPID-31014', 'CSAFPID-31015']}], 'remediations': [{'details': "CVE-2024-24781: All load limiting measures are helpful (e.g. in external devices or also in the switch of the above mentioned products). Please check whether the reduced speed is still sufficient for the desired application. Protect the network with segregation measures and restrict the access of unauthorized network participants (e.g. close unused ports)\n\nCVE-2024-24782: Switching the MAC-learning from 'conservative' to 'tolerant' mitigates the above described vulnerability but leads to potential IP-Spoofing and ARP-Poisoning and should therefore be avoided. HIMax and HIQuad X systems can be setup in the way that real physical segregation (between different modules) is used. E.g. it is impossible to ping from one X-COM to another X-COM in the same Rack. HIMatrix should be used in that way that CPU and COM are NOT connected via VLAN e.g. CPU connected to Port 1 and 2, COM Connected to Port 3 and 4.", 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007', 'CSAFPID-31008', 'CSAFPID-31009', 'CSAFPID-31010', 'CSAFPID-31011', 'CSAFPID-31012', 'CSAFPID-31013', 'CSAFPID-31014', 'CSAFPID-31015']}}, {'cve': 'CVE-2024-24782', 'cwe': {'id': 'CWE-346', 'name': 'Origin Validation Error'}, 'notes': [{'text': 'An unauthenticated attacker can send a ping request from one network to another through an error in the origin verification even though the ports are separated by VLAN.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2024-24782', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 4.3, 'attackVector': 'ADJACENT_NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N', 'temporalScore': 4.3, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 4.3, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007', 'CSAFPID-31008', 'CSAFPID-31009', 'CSAFPID-31010', 'CSAFPID-31011', 'CSAFPID-31012', 'CSAFPID-31013', 'CSAFPID-31014', 'CSAFPID-31015']}], 'remediations': [{'details': "CVE-2024-24781: All load limiting measures are helpful (e.g. in external devices or also in the switch of the above mentioned products). Please check whether the reduced speed is still sufficient for the desired application. Protect the network with segregation measures and restrict the access of unauthorized network participants (e.g. close unused ports)\n\nCVE-2024-24782: Switching the MAC-learning from 'conservative' to 'tolerant' mitigates the above described vulnerability but leads to potential IP-Spoofing and ARP-Poisoning and should therefore be avoided. HIMax and HIQuad X systems can be setup in the way that real physical segregation (between different modules) is used. E.g. it is impossible to ping from one X-COM to another X-COM in the same Rack. HIMatrix should be used in that way that CPU and COM are NOT connected via VLAN e.g. CPU connected to Port 1 and 2, COM Connected to Port 3 and 4.", 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007', 'CSAFPID-31008', 'CSAFPID-31009', 'CSAFPID-31010', 'CSAFPID-31011', 'CSAFPID-31012', 'CSAFPID-31013', 'CSAFPID-31014', 'CSAFPID-31015']}}]}
326b59142ed88621e9b3c714cae3e29715f596c7370dc758518ca14d56f083f8
2026-05-29 08:30:30.287740+03:00
2026-05-29 08:30:30.287740+03:00
csaf_carlogavazziautomation.ndjson
b9e7ba923bd19cc9a2962531500214eb83fee42a1068b59e44694664f0098b4e
{'document': {'lang': 'en-GB', 'notes': [{'text': '\nThe UWP 3.0 family of Monitoring Gateways and Controllers and the CPY Car Park Server are affected by multiple vulnerabilities in their set-up software, runtime firmware, embedded Web interface.', 'title': 'Summary', 'category': 'summary'}, {'text': 'An attacker can get full access to the affected devices. See the vulnerability descriptions for details.', 'title': 'Impact', 'category': 'description'}, {'text': 'Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside\nUse firewalls to protect and separate the control system network from other networks\nUse VPN (Virtual Private Networks) tunnels if remote access is required\nActivate and apply user management and password features\nUse encrypted communication links\nLimit the access to both set-up and control system by physical means, operating system features, etc.\nProtect the set-up and control system by using up to date virus detecting solutions', 'title': 'General recommendations', 'category': 'description'}, {'text': 'Please update to software/firmware versions as described below:\n| Article Nr. | Product Name and Description | Fixed in version |\n|------------------|---------------------------------------------------------------|--------------------------|\n| UWP30RSEXXX | UWP 3.0 Monitoring Gateway and Controller | >= 8.5.0.3 (available from April 27th, 2022) |\n| UWP30RSEXXXSE | UWP 3.0 Monitoring Gateway and Controller – Security Enhanced | >= 8.5.0.3 (available from April 27th, 2022) |\n| UWP30RSEXXXEDP | UWP 3.0 Monitoring Gateway and Controller – EDP version | >= 8.5.0.3 (available from April 27th, 2022) |\n| SBP2CPY24 | CPY Car Park Server | >= 2.8.3 (available from June 28th, 2022) |\n', 'title': 'Remediation', 'category': 'description'}], 'title': 'Carlo Gavazzi Controls: Multiple Vulnerabilities in Controller UWP 3.0', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2022-029', 'status': 'final', 'aliases': ['VDE-2022-029'], 'version': '5.0.0', 'generator': {'date': '2025-04-14T07:43:06.985Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.23'}}, 'revision_history': [{'date': '2022-09-26T08:00:00.000Z', 'number': '1.0.0', 'summary': 'Initial revision.'}, {'date': '2024-11-06T11:27:01.000Z', 'number': '2.0.0', 'summary': 'Fix: added self-reference'}, {'date': '2025-04-11T07:00:00.000Z', 'number': '3.0.0', 'summary': 'Fix: version range, remove Issuing authority'}, {'date': '2025-05-14T13:00:15.000Z', 'number': '4.0.0', 'summary': 'Fix: added distribution'}, {'date': '2026-03-02T11:00:00.000Z', 'number': '5.0.0', 'summary': 'Fixed publisher name and switched to semver versioning'}], 'current_release_date': '2026-03-02T11:00:00.000Z', 'initial_release_date': '2022-09-26T08:00:00.000Z'}, 'publisher': {'name': 'Carlo Gavazzi Automation', 'category': 'vendor', 'namespace': 'https://www.gavazziautomation.com', 'contact_details': 'cybersecurity.cgc@gavazziacbu.it'}, 'references': [{'url': 'https://certvde.com/de/advisories/VDE-2022-029/', 'summary': 'VDE-2022-029: Carlo Gavazzi Controls: Multiple Vulnerabilities in Controller UWP 3.0 - HTML', 'category': 'self'}, {'url': 'https://certvde.com/de/advisories/vendor/gavazzi-controls/', 'summary': 'CERT@VDE Security Advisories for Carlo Gavazzi Controls SpA'}, {'url': 'https://gavazziautomation.csaf-tp.certvde.com/.well-known/csaf/white/2022/vde-2022-029.json', 'summary': 'VDE-2022-029: Carlo Gavazzi Controls: Multiple Vulnerabilities in Controller UWP 3.0 - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'summary': 'coordination and support with this publication', 'organization': 'CERT@VDE'}, {'names': ['Vera Mens'], 'summary': 'reporting', 'organization': 'Claroty Research'}]}, 'product_tree': {'branches': [{'name': 'Carlo Gavazzi Controls', 'branches': [{'name': 'Software', 'branches': [{'name': 'CPY Car Park Server', 'branches': [{'name': '<2.8.3', 'product': {'name': 'Software CPY Car Park Server <2.8.3', 'product_id': 'CSAFPID-51001'}, 'category': 'product_version_range'}, {'name': '2.8.3', 'product': {'name': 'Software CPY Car Park Server 2.8.3', 'product_id': 'CSAFPID-52001'}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Hardware', 'branches': [{'name': 'UWP 3.0 Monitoring Gateway and Controller', 'product': {'name': 'Hardware UWP 3.0 Monitoring Gateway and Controller', 'product_id': 'CSAFPID-11001', 'product_identification_helper': {'model_numbers': ['UWP30RSEXXX']}}, 'category': 'product_name'}, {'name': 'UWP 3.0 Monitoring Gateway and Controller – Security Enhanced', 'product': {'name': 'Hardware UWP 3.0 Monitoring Gateway and Controller – Security Enhanced', 'product_id': 'CSAFPID-11002', 'product_identification_helper': {'model_numbers': ['UWP30RSEXXXSE']}}, 'category': 'product_name'}, {'name': 'UWP 3.0 Monitoring Gateway and Controller – EDP version', 'product': {'name': 'Hardware UWP 3.0 Monitoring Gateway and Controller – EDP version', 'product_id': 'CSAFPID-11003', 'product_identification_helper': {'model_numbers': ['UWP30RSEXXXEDP']}}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': '<8.5.0.3', 'product': {'name': 'Firmware <8.5.0.3', 'product_id': 'CSAFPID-21001'}, 'category': 'product_version_range'}, {'name': '8.5.0.3', 'product': {'name': 'Firmware 8.5.0.3', 'product_id': 'CSAFPID-22001'}, 'category': 'product_version'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware <8.5.0.3 installed on Hardware UWP 3.0 Monitoring Gateway and Controller', 'product_id': 'CSAFPID-31001'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <8.5.0.3 installed on Hardware UWP 3.0 Monitoring Gateway and Controller – Security Enhanced', 'product_id': 'CSAFPID-31002'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11002'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <8.5.0.3 installed on Hardware UWP 3.0 Monitoring Gateway and Controller – EDP version', 'product_id': 'CSAFPID-31003'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11003'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 8.5.0.3 installed on Hardware UWP 3.0 Monitoring Gateway and Controller', 'product_id': 'CSAFPID-32001'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 8.5.0.3 installed on Hardware UWP 3.0 Monitoring Gateway and Controller – Security Enhanced', 'product_id': 'CSAFPID-32002'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11002'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 8.5.0.3 installed on Hardware UWP 3.0 Monitoring Gateway and Controller – EDP version', 'product_id': 'CSAFPID-32003'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11003'}], 'product_groups': [{'summary': 'Affected products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-51001']}, {'group_id': 'CSAFGID-0002', 'product_ids': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-52001']}]}, 'vulnerabilities': [{'cve': 'CVE-2022-22522', 'cwe': {'id': 'CWE-798', 'name': 'Use of Hard-coded Credentials'}, 'notes': [{'text': 'In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of hard-coded credentials to gain full access to the device.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2022-22522', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-51001']}], 'remediations': [{'details': 'Please update to software/firmware versions as described below:\n| Article Nr. | Product Name and Description | Fixed in version |\n|------------------|---------------------------------------------------------------|--------------------------|\n| UWP30RSEXXX | UWP 3.0 Monitoring Gateway and Controller | >= 8.5.0.3 (available from April 27th, 2022) |\n| UWP30RSEXXXSE | UWP 3.0 Monitoring Gateway and Controller – Security Enhanced | >= 8.5.0.3 (available from April 27th, 2022) |\n| UWP30RSEXXXEDP | UWP 3.0 Monitoring Gateway and Controller – EDP version | >= 8.5.0.3 (available from April 27th, 2022) |\n| SBP2CPY24 | CPY Car Park Server | >= 2.8.3 (available from June 28th, 2022) |', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-52001'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-51001']}}, {'cve': 'CVE-2022-22526', 'cwe': {'id': 'CWE-306', 'name': 'Missing Authentication for Critical Function'}, 'notes': [{'text': 'In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a missing authentication allows for full access via API.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2022-22526', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-51001']}], 'remediations': [{'details': 'Please update to software/firmware versions as described below:\n| Article Nr. | Product Name and Description | Fixed in version |\n|------------------|---------------------------------------------------------------|--------------------------|\n| UWP30RSEXXX | UWP 3.0 Monitoring Gateway and Controller | >= 8.5.0.3 (available from April 27th, 2022) |\n| UWP30RSEXXXSE | UWP 3.0 Monitoring Gateway and Controller – Security Enhanced | >= 8.5.0.3 (available from April 27th, 2022) |\n| UWP30RSEXXXEDP | UWP 3.0 Monitoring Gateway and Controller – EDP version | >= 8.5.0.3 (available from April 27th, 2022) |\n| SBP2CPY24 | CPY Car Park Server | >= 2.8.3 (available from June 28th, 2022) |', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-52001'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-51001']}}, {'cve': 'CVE-2022-28811', 'cwe': {'id': 'CWE-78', 'name': "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"}, 'notes': [{'text': 'In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could utilize an improper input validation on an API-submitted parameter to execute arbitrary OS commands.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2022-28811', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-51001']}], 'remediations': [{'details': 'Please update to software/firmware versions as described below:\n| Article Nr. | Product Name and Description | Fixed in version |\n|------------------|---------------------------------------------------------------|--------------------------|\n| UWP30RSEXXX | UWP 3.0 Monitoring Gateway and Controller | >= 8.5.0.3 (available from April 27th, 2022) |\n| UWP30RSEXXXSE | UWP 3.0 Monitoring Gateway and Controller – Security Enhanced | >= 8.5.0.3 (available from April 27th, 2022) |\n| UWP30RSEXXXEDP | UWP 3.0 Monitoring Gateway and Controller – EDP version | >= 8.5.0.3 (available from April 27th, 2022) |\n| SBP2CPY24 | CPY Car Park Server | >= 2.8.3 (available from June 28th, 2022) |', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-52001'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-51001']}}, {'cve': 'CVE-2022-28812', 'cwe': {'id': 'CWE-798', 'name': 'Use of Hard-coded Credentials'}, 'notes': [{'text': 'n Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of hard-coded credentials to gain SuperUser access to the device.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2022-28812', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-51001']}], 'remediations': [{'details': 'Please update to software/firmware versions as described below:\n| Article Nr. | Product Name and Description | Fixed in version |\n|------------------|---------------------------------------------------------------|--------------------------|\n| UWP30RSEXXX | UWP 3.0 Monitoring Gateway and Controller | >= 8.5.0.3 (available from April 27th, 2022) |\n| UWP30RSEXXXSE | UWP 3.0 Monitoring Gateway and Controller – Security Enhanced | >= 8.5.0.3 (available from April 27th, 2022) |\n| UWP30RSEXXXEDP | UWP 3.0 Monitoring Gateway and Controller – EDP version | >= 8.5.0.3 (available from April 27th, 2022) |\n| SBP2CPY24 | CPY Car Park Server | >= 2.8.3 (available from June 28th, 2022) |', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-52001'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-51001']}}, {'cve': 'CVE-2022-28814', 'cwe': {'id': 'CWE-23', 'name': 'Relative Path Traversal'}, 'notes': [{'text': 'In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in multiple versions was discovered to be vulnerable to a relative path traversal vulnerability which enables remote attackers to read arbitrary files and gain full control of the device.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2022-28814', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-51001']}], 'remediations': [{'details': 'Please update to software/firmware versions as described below:\n| Article Nr. | Product Name and Description | Fixed in version |\n|------------------|---------------------------------------------------------------|--------------------------|\n| UWP30RSEXXX | UWP 3.0 Monitoring Gateway and Controller | >= 8.5.0.3 (available from April 27th, 2022) |\n| UWP30RSEXXXSE | UWP 3.0 Monitoring Gateway and Controller – Security Enhanced | >= 8.5.0.3 (available from April 27th, 2022) |\n| UWP30RSEXXXEDP | UWP 3.0 Monitoring Gateway and Controller – EDP version | >= 8.5.0.3 (available from April 27th, 2022) |\n| SBP2CPY24 | CPY Car Park Server | >= 2.8.3 (available from June 28th, 2022) |', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-52001'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-51001']}}, {'cve': 'CVE-2022-22524', 'cwe': {'id': 'CWE-89', 'name': "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')"}, 'notes': [{'text': 'In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 an unauthenticated remote attacker could utilize a SQL-Injection vulnerability to gain full database access, modify users and stop services .', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2022-22524', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-51001']}], 'remediations': [{'details': 'Please update to software/firmware versions as described below:\n| Article Nr. | Product Name and Description | Fixed in version |\n|------------------|---------------------------------------------------------------|--------------------------|\n| UWP30RSEXXX | UWP 3.0 Monitoring Gateway and Controller | >= 8.5.0.3 (available from April 27th, 2022) |\n| UWP30RSEXXXSE | UWP 3.0 Monitoring Gateway and Controller – Security Enhanced | >= 8.5.0.3 (available from April 27th, 2022) |\n| UWP30RSEXXXEDP | UWP 3.0 Monitoring Gateway and Controller – EDP version | >= 8.5.0.3 (available from April 27th, 2022) |\n| SBP2CPY24 | CPY Car Park Server | >= 2.8.3 (available from June 28th, 2022) |', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-52001'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-51001']}}, {'cve': 'CVE-2022-22523', 'cwe': {'id': 'CWE-287', 'name': 'Improper Authentication'}, 'notes': [{'text': 'An improper authentication vulnerability exists in the Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 Web-App which allows an authentication bypass to the context of an unauthorised user if free-access is disabled.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2022-22523', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-51001']}], 'remediations': [{'details': 'Please update to software/firmware versions as described below:\n| Article Nr. | Product Name and Description | Fixed in version |\n|------------------|---------------------------------------------------------------|--------------------------|\n| UWP30RSEXXX | UWP 3.0 Monitoring Gateway and Controller | >= 8.5.0.3 (available from April 27th, 2022) |\n| UWP30RSEXXXSE | UWP 3.0 Monitoring Gateway and Controller – Security Enhanced | >= 8.5.0.3 (available from April 27th, 2022) |\n| UWP30RSEXXXEDP | UWP 3.0 Monitoring Gateway and Controller – EDP version | >= 8.5.0.3 (available from April 27th, 2022) |\n| SBP2CPY24 | CPY Car Park Server | >= 2.8.3 (available from June 28th, 2022) |', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-52001'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-51001']}}, {'cve': 'CVE-2022-28813', 'cwe': {'id': 'CWE-89', 'name': "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')"}, 'notes': [{'text': 'In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of an SQL-injection to gain access to a volatile temporary database with the current states of the device.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2022-28813', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-51001']}], 'remediations': [{'details': 'Please update to software/firmware versions as described below:\n| Article Nr. | Product Name and Description | Fixed in version |\n|------------------|---------------------------------------------------------------|--------------------------|\n| UWP30RSEXXX | UWP 3.0 Monitoring Gateway and Controller | >= 8.5.0.3 (available from April 27th, 2022) |\n| UWP30RSEXXXSE | UWP 3.0 Monitoring Gateway and Controller – Security Enhanced | >= 8.5.0.3 (available from April 27th, 2022) |\n| UWP30RSEXXXEDP | UWP 3.0 Monitoring Gateway and Controller – EDP version | >= 8.5.0.3 (available from April 27th, 2022) |\n| SBP2CPY24 | CPY Car Park Server | >= 2.8.3 (available from June 28th, 2022) |', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-52001'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-51001']}}, {'cve': 'CVE-2022-22525', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 an remote attacker with admin rights could execute arbitrary commands due to missing input sanitization in the backup restore function.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2022-22525', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-51001']}], 'remediations': [{'details': 'Please update to software/firmware versions as described below:\n| Article Nr. | Product Name and Description | Fixed in version |\n|------------------|---------------------------------------------------------------|--------------------------|\n| UWP30RSEXXX | UWP 3.0 Monitoring Gateway and Controller | >= 8.5.0.3 (available from April 27th, 2022) |\n| UWP30RSEXXXSE | UWP 3.0 Monitoring Gateway and Controller – Security Enhanced | >= 8.5.0.3 (available from April 27th, 2022) |\n| UWP30RSEXXXEDP | UWP 3.0 Monitoring Gateway and Controller – EDP version | >= 8.5.0.3 (available from April 27th, 2022) |\n| SBP2CPY24 | CPY Car Park Server | >= 2.8.3 (available from June 28th, 2022) |', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-52001'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-51001']}}, {'cve': 'CVE-2022-28816', 'cwe': {'id': 'CWE-79', 'name': "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"}, 'notes': [{'text': 'In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 the Sentilo Proxy is prone to reflected XSS which only affects the Sentilo service.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2022-28816', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-51001']}], 'remediations': [{'details': 'Please update to software/firmware versions as described below:\n| Article Nr. | Product Name and Description | Fixed in version |\n|------------------|---------------------------------------------------------------|--------------------------|\n| UWP30RSEXXX | UWP 3.0 Monitoring Gateway and Controller | >= 8.5.0.3 (available from April 27th, 2022) |\n| UWP30RSEXXXSE | UWP 3.0 Monitoring Gateway and Controller – Security Enhanced | >= 8.5.0.3 (available from April 27th, 2022) |\n| UWP30RSEXXXEDP | UWP 3.0 Monitoring Gateway and Controller – EDP version | >= 8.5.0.3 (available from April 27th, 2022) |\n| SBP2CPY24 | CPY Car Park Server | >= 2.8.3 (available from June 28th, 2022) |', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-52001'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-51001']}}, {'cve': 'CVE-2022-28815', 'cwe': {'id': 'CWE-89', 'name': "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')"}, 'notes': [{'text': 'In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 the Sentilo Proxy server was discovered to contain a SQL injection vulnerability allowing an attacker to query other tables of the Sentilo service.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2022-28815', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-51001']}], 'remediations': [{'details': 'Please update to software/firmware versions as described below:\n| Article Nr. | Product Name and Description | Fixed in version |\n|------------------|---------------------------------------------------------------|--------------------------|\n| UWP30RSEXXX | UWP 3.0 Monitoring Gateway and Controller | >= 8.5.0.3 (available from April 27th, 2022) |\n| UWP30RSEXXXSE | UWP 3.0 Monitoring Gateway and Controller – Security Enhanced | >= 8.5.0.3 (available from April 27th, 2022) |\n| UWP30RSEXXXEDP | UWP 3.0 Monitoring Gateway and Controller – EDP version | >= 8.5.0.3 (available from April 27th, 2022) |\n| SBP2CPY24 | CPY Car Park Server | >= 2.8.3 (available from June 28th, 2022) |', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-52001'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-51001']}}]}
886ddf6f561bfe5af52a1a0ecb9bd0eb985f313a58bacaf14f16a1aa9d14c8b9
2026-05-29 08:30:31.054713+03:00
2026-05-29 08:30:31.054713+03:00
csaf_aumariestergmbhcokg.ndjson
20f594cbd8e00308903330d129e3575354c285d118d213e96af3239df511d3ba
{'document': {'lang': 'en-GB', 'notes': [{'text': 'Improper buffer restrictions in the webserver used in SIMA² Master Station software versions < V 2.6 may allow an unauthenticated network-based attacker to stop the cyclic program on the device and cause a denial of service.', 'title': 'Summary', 'category': 'summary'}, {'text': 'The webserver component of the automation runtime used implements insufficient checks on handling file uploads. This implementation could result in a memory violation, which in turn affects the stability of automation runtime.\nAn attacker could leverage this vulnerability to potentially cause a denial of service of the device.', 'title': 'Impact', 'category': 'description'}, {'text': 'AUMA recommends the following specific workarounds and mitigations: The access to the SIMA² should be restricted to legitimate network partners, using e.g. a sufficient firewall setup and robust network segmentation. In general, AUMA recommends implementing the Product Security Guideline for uses on Cybersecurity for the SIMA² Master Station.', 'title': 'Mitigation', 'category': 'description'}, {'text': 'The described vulnerabilities have been fixed in the product versions with software version V 2.6 or higher. SIMA² Master Stations with software versions < V 2.6 can be upgraded. AUMA recommends applying a product update at the earliest convenience', 'title': 'Remediation', 'category': 'description'}], 'title': 'Auma: SIMA² Master Station Denial of Service Vulnerability on Automation Runtime Webserver', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2022-024', 'status': 'final', 'aliases': ['VDE-2022-024'], 'version': '2', 'generator': {'date': '2025-03-19T15:02:36.926Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.21'}}, 'revision_history': [{'date': '2022-06-15T10:00:00.000Z', 'number': '1', 'summary': 'initial revision'}, {'date': '2025-05-14T13:00:15.000Z', 'number': '2', 'summary': 'Fix: added distribution'}], 'current_release_date': '2025-05-14T13:00:15.000Z', 'initial_release_date': '2022-06-15T10:00:00.000Z'}, 'publisher': {'name': 'AUMA Riester GmbH & Co. KG', 'category': 'vendor', 'namespace': 'https://auma.com', 'contact_details': 'psirt@auma.com'}, 'references': [{'url': 'https://certvde.com/de/advisories/VDE-2022-024/', 'summary': 'VDE-2022-024: Auma: SIMA² Master Station Denial of Service Vulnerability on Automation Runtime Webserver - HTML', 'category': 'self'}, {'url': 'https://certvde.com/en/advisories/vendor/auma/', 'summary': 'CERT@VDE Security Advisories for AUMA Riester GmbH & Co. KG', 'category': 'external'}, {'url': 'https://auma.csaf-tp.certvde.com/.well-known/csaf/white/2022/vde-2022-024.json', 'summary': 'VDE-2022-024: Auma: SIMA² Master Station Denial of Service Vulnerability on Automation Runtime Webserver - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERTVDE'}]}, 'product_tree': {'branches': [{'name': 'AUMA Riester GmbH & Co. KG', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'SIMA² Master Station', 'product': {'name': 'SIMA² Master Station', 'product_id': 'CSAFPID-11001'}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': '<v2.6', 'product': {'name': 'Firmware <v2.6', 'product_id': 'CSAFPID-21001'}, 'category': 'product_version_range'}, {'name': 'v2.6', 'product': {'name': 'Firmware v2.6', 'product_id': 'CSAFPID-22001'}, 'category': 'product_version'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware <v2.6 installed on SIMA² Master Station', 'product_id': 'CSAFPID-31001'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware v2.6 installed on SIMA² Master Station', 'product_id': 'CSAFPID-32001'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11001'}]}, 'vulnerabilities': [{'cve': 'CVE-2021-22275', 'cwe': {'id': 'CWE-120', 'name': "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')"}, 'notes': [{'text': 'Buffer Overflow vulnerability in B&R Automation Runtime webserver allows an unauthenticated network-based attacker to stop the cyclic program on the device and cause a denial of service.', 'category': 'summary'}], 'title': 'CVE-2021-22275', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 8.6, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H', 'temporalScore': 8.6, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 8.6, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001']}], 'remediations': [{'details': 'AUMA recommends the following specific workarounds and mitigations:\n\nThe access to the SIMA² should be restricted to legitimate network partners, using e.g. a sufficient firewall setup and robust network segmentation.\nIn general, AUMA recommends implementing the Product Security Guideline for uses on Cybersecurity for the SIMA² Master Station.', 'category': 'mitigation', 'product_ids': ['CSAFPID-31001']}, {'details': 'The described vulnerabilities have been fixed in the product versions with software version V 2.6 or\nhigher. SIMA² Master Stations with software versions < V 2.6 can be upgraded. AUMA recommends applying a product update at the earliest convenience', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31001']}], 'product_status': {'fixed': ['CSAFPID-32001'], 'known_affected': ['CSAFPID-31001']}}]}
f3442c3b17acc86b925496b1598190ccec8c3470273966f01d0737a2ddcd282a
2026-05-29 08:30:31.564898+03:00
2026-05-29 08:30:31.564898+03:00
csaf_aumariestergmbhcokg.ndjson
cfa55e62e948af1f12a411b2498ac6b4db104f4a45632d6f1dd0b140cf3401a5
{'document': {'lang': 'en-GB', 'notes': [{'text': 'The SIMA2 Master Station features an NTP service based on ntpd, a reference implementation of the Network Time Protocol (NTP). Affected SIMA2 Master Stations with software version < V2.6 include an outdated version of ntpd which is affected by a large number of vulnerabilities', 'title': 'Summary', 'category': 'summary'}, {'text': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'title': 'Mitigation', 'category': 'description'}, {'text': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'title': 'Remediation', 'category': 'description'}], 'title': 'AUMA: Multiple Vulnerabilities in Automation Runtime NTP Service', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2022-032', 'status': 'final', 'aliases': ['VDE-2022-032'], 'version': '1', 'generator': {'date': '2025-05-05T07:36:58.640Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.24'}}, 'revision_history': [{'date': '2022-08-09T08:00:00.000Z', 'number': '1', 'summary': 'Initial revision.'}], 'current_release_date': '2022-08-09T08:00:00.000Z', 'initial_release_date': '2022-08-09T08:00:00.000Z'}, 'publisher': {'name': 'AUMA Riester GmbH & Co. KG', 'category': 'vendor', 'namespace': 'https://auma.com', 'contact_details': 'psirt@auma.com'}, 'references': [{'url': 'https://certvde.com/en/advisories/VDE-2022-032/', 'summary': 'VDE-2022-032: AUMA: Multiple Vulnerabilities in Automation Runtime NTP Service - HTML', 'category': 'self'}, {'url': 'https://auma.csaf-tp.certvde.com/.well-known/csaf/white/2022/vde-2022-032.json', 'summary': 'VDE-2022-032: AUMA: Multiple Vulnerabilities in Automation Runtime NTP Service - CSAF', 'category': 'self'}, {'url': 'https://www.auma.com/en_GB/service/psirt', 'summary': 'AUMA PSIRT', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/auma/', 'summary': 'CERT@VDE Security Advisories for AUMA Riester GmbH & Co. KG', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}]}, 'product_tree': {'branches': [{'name': 'AUMA', 'branches': [{'name': 'Software', 'branches': [{'name': 'SIMA² Master Station', 'branches': [{'name': '<V2.6', 'product': {'name': 'SIMA² Master Station < V2.6', 'product_id': 'CSAFPID-51001'}, 'category': 'product_version_range'}, {'name': 'V2.6', 'product': {'name': 'SIMA² Master Station V2.6', 'product_id': 'CSAFPID-52001'}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2009-3563', 'notes': [{'text': 'ntp_request.c in ntpd in NTP before 4.2.4p8, and 4.2.5, allows remote attackers to cause a denial of service (CPU and bandwidth consumption) by using MODE_PRIVATE to send a spoofed (1) request or (2) response packet that triggers a continuous exchange of MODE_PRIVATE error responses between two NTP daemons.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2009-3563', 'scores': [{'cvss_v2': {'version': '2.0', 'baseScore': 6.4, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:L/Au:N/C:N/I:P/A:P', 'temporalScore': 6.4, 'authentication': 'NONE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'LOW', 'availabilityImpact': 'PARTIAL', 'environmentalScore': 6.4, 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2013-5211', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service (traffic amplification) via forged (1) REQ_MON_GETLIST or (2) REQ_MON_GETLIST_1 requests, as exploited in the wild in December 2013.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2013-5211', 'scores': [{'cvss_v2': {'version': '2.0', 'baseScore': 5, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:L/Au:N/C:N/I:N/A:P', 'temporalScore': 5, 'authentication': 'NONE', 'integrityImpact': 'NONE', 'accessComplexity': 'LOW', 'availabilityImpact': 'PARTIAL', 'environmentalScore': 5, 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2014-9293', 'notes': [{'text': 'The config_auth function in ntpd in NTP before 4.2.7p11, when an auth key is not configured, improperly generates a key, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2014-9293', 'scores': [{'cvss_v2': {'version': '2.0', 'baseScore': 7.5, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:L/Au:N/C:P/I:P/A:P', 'temporalScore': 7.5, 'authentication': 'NONE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'LOW', 'availabilityImpact': 'PARTIAL', 'environmentalScore': 7.5, 'confidentialityImpact': 'PARTIAL'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2014-9294', 'notes': [{'text': 'util/ntp-keygen.c in ntp-keygen in NTP before 4.2.7p230 uses a weak RNG seed, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2014-9294', 'scores': [{'cvss_v2': {'version': '2.0', 'baseScore': 7.5, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:L/Au:N/C:P/I:P/A:P', 'temporalScore': 7.5, 'authentication': 'NONE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'LOW', 'availabilityImpact': 'PARTIAL', 'environmentalScore': 7.5, 'confidentialityImpact': 'PARTIAL'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2014-9295', 'cwe': {'id': 'CWE-119', 'name': 'Improper Restriction of Operations within the Bounds of a Memory Buffer'}, 'notes': [{'text': 'Multiple stack-based buffer overflows in ntpd in NTP before 4.2.8 allow remote attackers to execute arbitrary code via a crafted packet, related to (1) the crypto_recv function when the Autokey Authentication feature is used, (2) the ctl_putdata function, and (3) the configure function.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2014-9295', 'scores': [{'cvss_v2': {'version': '2.0', 'baseScore': 7.5, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:L/Au:N/C:P/I:P/A:P', 'temporalScore': 7.5, 'authentication': 'NONE', 'integrityImpact': 'PARTIAL', 'accessComplexity': 'LOW', 'availabilityImpact': 'PARTIAL', 'environmentalScore': 7.5, 'confidentialityImpact': 'PARTIAL'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2014-9296', 'notes': [{'text': 'The receive function in ntp_proto.c in ntpd in NTP before 4.2.8 continues to execute after detecting a certain authentication error, which might allow remote attackers to trigger an unintended association change via crafted packets.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2014-9296', 'scores': [{'cvss_v2': {'version': '2.0', 'baseScore': 5, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:L/Au:N/C:N/I:N/A:P', 'temporalScore': 5, 'authentication': 'NONE', 'integrityImpact': 'NONE', 'accessComplexity': 'LOW', 'availabilityImpact': 'PARTIAL', 'environmentalScore': 5, 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2014-9750', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'ntp_crypto.c in ntpd in NTP 4.x before 4.2.8p1, when Autokey Authentication is enabled, allows remote attackers to obtain sensitive information from process memory or cause a denial of service (daemon crash) via a packet containing an extension field with an invalid value for the length of its value field.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2014-9750', 'scores': [{'cvss_v2': {'version': '2.0', 'baseScore': 5.8, 'accessVector': 'NETWORK', 'vectorString': 'AV:N/AC:M/Au:N/C:P/I:N/A:P', 'temporalScore': 5.8, 'authentication': 'NONE', 'integrityImpact': 'NONE', 'accessComplexity': 'MEDIUM', 'availabilityImpact': 'PARTIAL', 'environmentalScore': 5.8, 'confidentialityImpact': 'PARTIAL'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2015-7691', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash) via crafted packets containing particular autokey operations. NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2015-7691', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2015-7692', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash). NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2015-7692', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2015-7702', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash). NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2015-7702', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 6.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'HIGH', 'environmentalScore': 6.5, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2015-7704', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service via a number of crafted "KOD" messages.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2015-7704', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2015-7849', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'Use-after-free vulnerability in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to possibly execute arbitrary code or cause a denial of service (crash) via crafted packets.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2015-7849', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 8.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 8.8, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2015-7850', 'cwe': {'id': 'CWE-835', 'name': "Loop with Unreachable Exit Condition ('Infinite Loop')"}, 'notes': [{'text': 'ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to cause a denial of service (infinite loop or crash) by pointing the key file at the log file.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2015-7850', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 6.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'HIGH', 'environmentalScore': 6.5, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2015-7851', 'cwe': {'id': 'CWE-22', 'name': "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"}, 'notes': [{'text': "Directory traversal vulnerability in the save_config function in ntpd in ntp_control.c in NTP before 4.2.8p4, when used on systems that do not use '\\' or '/' characters for directory separation such as OpenVMS, allows remote authenticated users to overwrite arbitrary files.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2015-7851', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N', 'temporalScore': 6.5, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 6.5, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2015-7852', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'ntpq in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash) via crafted mode 6 response packets.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2015-7852', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.9, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 5.9, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'HIGH', 'environmentalScore': 5.9, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2015-7854', 'cwe': {'id': 'CWE-120', 'name': "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')"}, 'notes': [{'text': 'Buffer overflow in the password management functionality in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted key file.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2015-7854', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 8.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 8.8, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2015-7855', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'The decodenetnum function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (assertion failure) via a 6 or mode 7 packet containing a long data value.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2015-7855', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 6.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'HIGH', 'environmentalScore': 6.5, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2015-7871', 'cwe': {'id': 'CWE-287', 'name': 'Improper Authentication'}, 'notes': [{'text': 'Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authentication.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2015-7871', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2015-7973', 'notes': [{'text': 'NTP before 4.2.8p6 and 4.3.x before 4.3.90, when configured in broadcast mode, allows man-in-the-middle attackers to conduct replay attacks by sniffing the network.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2015-7973', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H', 'temporalScore': 6.5, 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'HIGH', 'environmentalScore': 6.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2015-7974', 'cwe': {'id': 'CWE-287', 'name': 'Improper Authentication'}, 'notes': [{'text': 'NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted key, aka a "skeleton key."', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2015-7974', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 7.7, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N', 'temporalScore': 7.7, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'NONE', 'environmentalScore': 7.7, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2015-7975', 'cwe': {'id': 'CWE-119', 'name': 'Improper Restriction of Operations within the Bounds of a Memory Buffer'}, 'notes': [{'text': 'The nextvar function in NTP before 4.2.8p6 and 4.3.x before 4.3.90 does not properly validate the length of its input, which allows an attacker to cause a denial of service (application crash).', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2015-7975', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 6.2, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 6.2, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'HIGH', 'environmentalScore': 6.2, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2015-7976', 'notes': [{'text': 'The ntpq saveconfig command in NTP 4.1.2, 4.2.x before 4.2.8p6, 4.3, 4.3.25, 4.3.70, and 4.3.77 does not properly filter special characters, which allows attackers to cause unspecified impact via a crafted filename.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2015-7976', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 4.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N', 'temporalScore': 4.3, 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 4.3, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2015-7977', 'cwe': {'id': 'CWE-476', 'name': 'NULL Pointer Dereference'}, 'notes': [{'text': 'ntpd in NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (NULL pointer dereference) via a ntpdc reslist command.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2015-7977', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.9, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 5.9, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'HIGH', 'environmentalScore': 5.9, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2015-7978', 'cwe': {'id': 'CWE-400', 'name': 'Uncontrolled Resource Consumption'}, 'notes': [{'text': 'NTP before 4.2.8p6 and 4.3.0 before 4.3.90 allows a remote attackers to cause a denial of service (stack exhaustion) via an ntpdc relist command, which triggers recursive traversal of the restriction list.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2015-7978', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2015-7979', 'notes': [{'text': 'NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (client-server association tear down) by sending broadcast packets with invalid authentication to a broadcast client.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2015-7979', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2015-8138', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to bypass the origin timestamp validation via a packet with an origin timestamp set to zero.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2015-8138', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N', 'temporalScore': 5.3, 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 5.3, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2015-8139', 'cwe': {'id': 'CWE-284', 'name': 'Improper Access Control'}, 'notes': [{'text': 'ntpq in NTP before 4.2.8p7 allows remote attackers to obtain origin timestamps and then impersonate peers via unspecified vectors.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2015-8139', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N', 'temporalScore': 5.3, 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 5.3, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2015-8140', 'cwe': {'id': 'CWE-284', 'name': 'Improper Access Control'}, 'notes': [{'text': 'The ntpq protocol in NTP before 4.2.8p7 allows remote attackers to conduct replay attacks by sniffing the network.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2015-8140', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 4.8, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L', 'temporalScore': 4.8, 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'LOW', 'environmentalScore': 4.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2015-8158', 'notes': [{'text': 'The getresponse function in ntpq in NTP versions before 4.2.8p9 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (infinite loop) via crafted packets with incorrect values.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2015-8158', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 5.9, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 5.9, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'HIGH', 'environmentalScore': 5.9, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2016-1547', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'An off-path attacker can cause a preemptible client association to be demobilized in NTP 4.2.8p4 and earlier and NTPSec a5fb34b9cc89b92a8fef2f459004865c93bb7f92 by sending a crypto NAK packet to a victim client with a spoofed source address of an existing associated peer. This is true even if authentication is enabled.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2016-1547', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L', 'temporalScore': 5.3, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'LOW', 'environmentalScore': 5.3, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2016-1550', 'cwe': {'id': 'CWE-200', 'name': 'Exposure of Sensitive Information to an Unauthorized Actor'}, 'notes': [{'text': 'An exploitable vulnerability exists in the message authentication functionality of libntp in ntp 4.2.8p4 and NTPSec a5fb34b9cc89b92a8fef2f459004865c93bb7f92. An attacker can send a series of crafted messages to attempt to recover the message digest key.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2016-1550', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N', 'temporalScore': 5.3, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 5.3, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2016-2517', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'NTP before 4.2.8p7 and 4.3.x before 4.3.92 allows remote attackers to cause a denial of service (prevent subsequent authentication) by leveraging knowledge of the controlkey or requestkey and sending a crafted packet to ntpd, which changes the value of trustedkey, controlkey, or requestkey. NOTE: this vulnerability exists because of a CVE-2016-2516 regression.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2016-2517', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 5.3, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'HIGH', 'environmentalScore': 5.3, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2016-2518', 'cwe': {'id': 'CWE-125', 'name': 'Out-of-bounds Read'}, 'notes': [{'text': 'The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 allows remote attackers to cause an out-of-bounds reference via an addpeer request with a large hmode value.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2016-2518', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L', 'temporalScore': 5.3, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'LOW', 'environmentalScore': 5.3, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2016-4953', 'cwe': {'id': 'CWE-287', 'name': 'Improper Authentication'}, 'notes': [{'text': 'ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (ephemeral-association demobilization) by sending a spoofed crypto-NAK packet with incorrect authentication data at a certain time.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2016-4953', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2016-4954', 'cwe': {'id': 'CWE-362', 'name': "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')"}, 'notes': [{'text': 'The process_packet function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (peer-variable modification) by sending spoofed packets from many source IP addresses in a certain scenario, as demonstrated by triggering an incorrect leap indication.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2016-4954', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2016-4955', 'cwe': {'id': 'CWE-362', 'name': "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')"}, 'notes': [{'text': 'ntpd in NTP 4.x before 4.2.8p8, when autokey is enabled, allows remote attackers to cause a denial of service (peer-variable clearing and association outage) by sending (1) a spoofed crypto-NAK packet or (2) a packet with an incorrect MAC value at a certain time.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2016-4955', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.9, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 5.9, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'HIGH', 'environmentalScore': 5.9, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2016-7427', 'cwe': {'id': 'CWE-400', 'name': 'Uncontrolled Resource Consumption'}, 'notes': [{'text': 'The broadcast mode replay prevention functionality in ntpd in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (reject broadcast mode packets) via a crafted broadcast mode packet.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2016-7427', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 4.3, 'attackVector': 'ADJACENT_NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L', 'temporalScore': 4.3, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'LOW', 'environmentalScore': 4.3, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2016-7431', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'NTP before 4.2.8p9 allows remote attackers to bypass the origin timestamp protection mechanism via an origin timestamp of zero. NOTE: this vulnerability exists because of a CVE-2015-8138 regression.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2016-7431', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N', 'temporalScore': 5.3, 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 5.3, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2016-7433', 'cwe': {'id': 'CWE-682', 'name': 'Incorrect Calculation'}, 'notes': [{'text': 'NTP before 4.2.8p9 does not properly perform the initial sync calculations, which allows remote attackers to unspecified impact via unknown vectors, related to a "root distance that did not include the peer dispersion."', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2016-7433', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L', 'temporalScore': 5.3, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'LOW', 'environmentalScore': 5.3, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2016-7434', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a crafted mrulist query.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2016-7434', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2016-9310', 'cwe': {'id': 'CWE-400', 'name': 'Uncontrolled Resource Consumption'}, 'notes': [{'text': 'The control mode (mode 6) functionality in ntpd in NTP before 4.2.8p9 allows remote attackers to set or unset traps via a crafted control mode packet.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2016-9310', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L', 'temporalScore': 6.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'LOW', 'environmentalScore': 6.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2016-9311', 'cwe': {'id': 'CWE-476', 'name': 'NULL Pointer Dereference'}, 'notes': [{'text': 'ntpd in NTP before 4.2.8p9, when the trap service is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted packet.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2016-9311', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 5.9, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 5.9, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'HIGH', 'environmentalScore': 5.9, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2017-6451', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'The mx4200_send function in the legacy MX4200 refclock in NTP before 4.2.8p10 and 4.3.x before 4.3.94 does not properly handle the return value of the snprintf function, which allows local users to execute arbitrary code via unspecified vectors, which trigger an out-of-bounds memory write.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2017-6451', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 7.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.8, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2017-6458', 'cwe': {'id': 'CWE-119', 'name': 'Improper Restriction of Operations within the Bounds of a Memory Buffer'}, 'notes': [{'text': 'Multiple buffer overflows in the ctl_put* functions in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allow remote authenticated users to have unspecified impact via a long variable.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2017-6458', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 8.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 8.8, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2017-6460', 'cwe': {'id': 'CWE-119', 'name': 'Improper Restriction of Operations within the Bounds of a Memory Buffer'}, 'notes': [{'text': 'Stack-based buffer overflow in the reslist function in ntpq in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows remote servers have unspecified impact via a long flagstr variable in a restriction list response.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2017-6460', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 8.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 8.8, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2017-6462', 'cwe': {'id': 'CWE-119', 'name': 'Improper Restriction of Operations within the Bounds of a Memory Buffer'}, 'notes': [{'text': 'Buffer overflow in the legacy Datum Programmable Time Server (DPTS) refclock driver in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows local users to have unspecified impact via a crafted /dev/datum device.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2017-6462', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 7.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.8, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2017-6463', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows remote authenticated users to cause a denial of service (daemon crash) via an invalid setting in a :config directive, related to the unpeer option.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2017-6463', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 6.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'HIGH', 'environmentalScore': 6.5, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2017-6464', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows remote attackers to cause a denial of service (ntpd crash) via a malformed mode configuration directive.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2017-6464', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 6.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'HIGH', 'environmentalScore': 6.5, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2018-12327', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'Stack-based buffer overflow in ntpq and ntpdc of NTP version 4.2.8p11 allows an attacker to achieve code execution or escalate to higher privileges via a long string as the argument for an IPv4 or IPv6 command-line parameter. NOTE: It is unclear whether there are any common situations in which ntpq or ntpdc is used with a command line from an untrusted source.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2018-12327', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2018-7182', 'cwe': {'id': 'CWE-125', 'name': 'Out-of-bounds Read'}, 'notes': [{'text': 'The ctl_getitem method in ntpd in ntp-4.2.8p6 before 4.2.8p11 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mode 6 packet with a ntpd instance from 4.2.8p6 through 4.2.8p10.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2018-7182', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2018-7183', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'Buffer overflow in the decodearr function in ntpq in ntp 4.2.8p6 through 4.2.8p10 allows remote attackers to execute arbitrary code by leveraging an ntpq query and sending a response with a crafted array.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2018-7183', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2018-7184', 'notes': [{'text': 'ntpd in ntp 4.2.8p4 before 4.2.8p11 drops bad packets before updating the "received" timestamp, which allows remote attackers to cause a denial of service (disruption) by sending a packet with a zero-origin timestamp causing the association to reset and setting the contents of the packet as the most recent timestamp. This issue is a result of an incomplete fix for CVE-2015-7704.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2018-7184', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2018-7185', 'notes': [{'text': 'The protocol engine in ntp 4.2.6 before 4.2.8p11 allows a remote attackers to cause a denial of service (disruption) by continually sending a packet with a zero-origin timestamp and source IP address of the "other side" of an interleaved association causing the victim ntpd to reset its association.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2018-7185', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2018-8956', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': "ntpd in ntp 4.2.8p10, 4.2.8p11, 4.2.8p12 and 4.2.8p13 allow remote attackers to prevent a broadcast client from synchronizing its clock with a broadcast NTP server via soofed mode 3 and mode 5 packets. The attacker must either be a part of the same broadcast network or control a slave in that broadcast network that can capture certain required packets on the attacker's behalf and send them to the attacker.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2018-8956', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L', 'temporalScore': 5.3, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'LOW', 'environmentalScore': 5.3, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2019-8936', 'cwe': {'id': 'CWE-476', 'name': 'NULL Pointer Dereference'}, 'notes': [{'text': 'NTP through 4.2.8p12 has a NULL Pointer Dereference.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2019-8936', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2020-11868', 'cwe': {'id': 'CWE-346', 'name': 'Origin Validation Error'}, 'notes': [{'text': 'ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address, because transmissions are rescheduled even when a packet lacks a valid origin timestamp.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2020-11868', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2020-13817', 'cwe': {'id': 'CWE-330', 'name': 'Use of Insufficiently Random Values'}, 'notes': [{'text': "ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows remote attackers to cause a denial of service (daemon exit or system time change) by predicting transmit timestamps for use in spoofed packets. The victim must be relying on unauthenticated IPv4 time sources. There must be an off-path attacker who can query time from the victim's ntpd instance.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2020-13817', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.4, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H', 'temporalScore': 7.4, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.4, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2020-15025', 'cwe': {'id': 'CWE-401', 'name': 'Missing Release of Memory after Effective Lifetime'}, 'notes': [{'text': 'ntpd in ntp 4.2.8 before 4.2.8p15 and 4.3.x before 4.3.101 allows remote attackers to cause a denial of service (memory consumption) by sending packets, because memory is not freed in situations where a CMAC key is used and associated with a CMAC algorithm in the ntp.keys file.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2020-15025', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 4.9, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 4.9, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'HIGH', 'environmentalScore': 4.9, 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2015-7701', 'cwe': {'id': 'CWE-772', 'name': 'Missing Release of Resource after Effective Lifetime'}, 'notes': [{'text': 'Memory leak in the CRYPTO_ASSOC function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (memory consumption).', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2015-7701', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2015-5300', 'notes': [{'text': 'The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to an arbitrary time when started with the -g option, or to alter the time by up to 900 seconds otherwise by responding to an unspecified number of requests from trusted sources, and leveraging a resulting denial of service (abort and restart).', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2015-5300', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2015-7853', 'cwe': {'id': 'CWE-120', 'name': "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')"}, 'notes': [{'text': 'The datalen parameter in the refclock driver in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a negative input value.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2015-7853', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2015-7705', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to have unspecified impact via a large number of crafted requests.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2015-7705', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2015-7703', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'The "pidfile" or "driftfile" directives in NTP ntpd 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77, when ntpd is configured to allow remote configuration, allows remote attackers with an IP address that is allowed to send configuration requests, and with knowledge of the remote configuration password to write to arbitrary files via the :config command.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2015-7703', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N', 'temporalScore': 7.5, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'NONE', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2016-7429', 'notes': [{'text': 'NTP before 4.2.8p9 changes the peer structure to the interface it receives the response from a source, which allows remote attackers to cause a denial of service (prevent communication with a source) by sending a response for a source to an interface the source does not use.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2016-7429', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 3.7, 'attackVector': 'NETWORK', 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L', 'temporalScore': 3.7, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'temporalSeverity': 'LOW', 'availabilityImpact': 'LOW', 'environmentalScore': 3.7, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'LOW'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2016-7428', 'cwe': {'id': 'CWE-400', 'name': 'Uncontrolled Resource Consumption'}, 'notes': [{'text': 'ntpd in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (reject broadcast mode packets) via the poll interval in a broadcast packet.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2016-7428', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 4.3, 'attackVector': 'ADJACENT_NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L', 'temporalScore': 4.3, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'LOW', 'environmentalScore': 4.3, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2016-7426', 'cwe': {'id': 'CWE-400', 'name': 'Uncontrolled Resource Consumption'}, 'notes': [{'text': 'NTP before 4.2.8p9 rate limits responses received from the configured sources when rate limiting for all associations is enabled, which allows remote attackers to cause a denial of service (prevent responses from the sources) by sending responses with a spoofed source address.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2016-7426', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2016-4957', 'cwe': {'id': 'CWE-476', 'name': 'NULL Pointer Dereference'}, 'notes': [{'text': 'ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-1547.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2016-4957', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2016-4956', 'notes': [{'text': 'ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (interleaved-mode transition and time change) via a spoofed broadcast packet. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-1548.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2016-4956', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L', 'temporalScore': 5.3, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'LOW', 'environmentalScore': 5.3, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2016-2519', 'cwe': {'id': 'CWE-119', 'name': 'Improper Restriction of Operations within the Bounds of a Memory Buffer'}, 'notes': [{'text': 'ntpd in NTP before 4.2.8p7 and 4.3.x before 4.3.92 allows remote attackers to cause a denial of service (ntpd abort) by a large request data value, which triggers the ctl_getitem function to return a NULL value.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2016-2519', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 5.9, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 5.9, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'HIGH', 'environmentalScore': 5.9, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2016-2516', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'NTP before 4.2.8p7 and 4.3.x before 4.3.92, when mode7 is enabled, allows remote attackers to cause a denial of service (ntpd abort) by using the same IP address multiple times in an unconfig directive.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2016-2516', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 5.3, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'HIGH', 'environmentalScore': 5.3, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2016-1551', 'notes': [{'text': "ntpd in NTP 4.2.8p3 and NTPsec a5fb34b9cc89b92a8fef2f459004865c93bb7f92 relies on the underlying operating system to protect it from requests that impersonate reference clocks. Because reference clocks are treated like other peers and stored in the same structure, any packet with a source ip address of a reference clock (127.127.1.1 for example) that reaches the receive() function will match that reference clock's peer record and will be treated as a trusted peer. Any system that lacks the typical martian packet filtering which would block these packets is in danger of having its time controlled by an attacker.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2016-1551', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 3.7, 'attackVector': 'NETWORK', 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N', 'temporalScore': 3.7, 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'temporalSeverity': 'LOW', 'availabilityImpact': 'NONE', 'environmentalScore': 3.7, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'LOW'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2016-1549', 'notes': [{'text': "A malicious authenticated peer can create arbitrarily-many ephemeral associations in order to win the clock selection algorithm in ntpd in NTP 4.2.8p4 and earlier and NTPsec 3e160db8dc248a0bcb053b56a80167dc742d2b74 and a5fb34b9cc89b92a8fef2f459004865c93bb7f92 and modify a victim's clock.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2016-1549', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N', 'temporalScore': 6.5, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 6.5, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2016-1548', 'notes': [{'text': 'An attacker can spoof a packet from a legitimate ntpd server with an origin timestamp that matches the peer->dst timestamp recorded for that server. After making this switch, the client in NTP 4.2.8p4 and earlier and NTPSec aa48d001683e5b791a743ec9c575aaf7d867a2b0c will reject all future legitimate server responses. It is possible to force the victim client to move time after the mode has been changed. ntpq gives no indication that the mode has been switched.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2016-1548', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.0', 'baseScore': 7.2, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L', 'temporalScore': 7.2, 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'LOW', 'environmentalScore': 7.2, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': '1. If your SIMA2 does not need to provide time information to other systems or synchronize itself with an NTP server, disable the NTP client on those systems. Please note that the NTP client is disabled by default in SIMA2\n\n\n2. In case you must use the NTP server on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Allow NTP traffic to/from trusted NTP clients only\n\n- Monitor the network for malicious NTP traffic going to/coming from the SIMA2\n\n- Filter malicious NTP traffic going to/coming from the SIMA2 Monitor NTP server operations on your SIMA2 (server availability, correctness of advertised time, NTP-related log entries, etc.)\n\n\n3. In case you must use the NTP client on an SIMA2, choose from the following options to reduce NTP-based risks:\n\n- Use trusted NTP servers only\n\n- Allow NTP traffic to/from trusted NTP servers only\n\n- Monitor the network for malicious NTP traffic targeting the SIMA2\n\n- Filter malicious NTP traffic targeting the SIMA2\n\n- Monitor NTP client operations on your SIMA2 (correctness of system time, NTP-related log entries, etc.)', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Upgrade your\xa0SIMA2 to software version 2.6 or above. The NTP service of the\xa0SIMA2 Master Station with software version V2.6 and above includes a current, supported version of ntpd.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}]}
135202b7b45dbfc9d4f4e8541082bafc030aed7c3e845b58cba6cf92937be684
2026-05-29 08:30:31.564898+03:00
2026-05-29 08:30:31.564898+03:00
csaf_aumariestergmbhcokg.ndjson
51f7ed395835f60b92aeb3d25678b2fde93b30b80ebd3e60e09c29813caefe58
{'document': {'lang': 'en-GB', 'notes': [{'text': 'A\xa0reflected cross-site scripting vulnerability exists\xa0in the System Diagnostics Manager (SDM) component of SIMA² Master Stations.', 'title': 'Summary', 'category': 'summary'}, {'text': 'Please consult the CVE details.', 'title': 'Impact', 'category': 'description'}, {'text': 'Do not use Hyperlinks provided by untrusted 3rd party to access the SIMA² System Diagnostics Manager. Hyperlinks may be provided via:\n\n- Emails from unknown users\n- Social media channels\n- Messaging services\n- Webpages with comment functionality\n- QR Codes\n\nThe use of external Web Application Firewalls (WAF) can mitigate attacks using reflected cross-site scripting.', 'title': 'Mitigation', 'category': 'description'}], 'title': 'AUMA: Reflected Cross-Site Scripting Vulnerability in SIMA Master Stations', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2023-027', 'status': 'final', 'aliases': ['VDE-2023-027'], 'version': '1.0.0', 'generator': {'date': '2025-06-23T09:05:21.023Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.28'}}, 'revision_history': [{'date': '2023-08-07T09:35:00.000Z', 'number': '1.0.0', 'summary': 'Initial revision.'}], 'current_release_date': '2023-08-07T09:35:00.000Z', 'initial_release_date': '2023-08-07T09:35:00.000Z'}, 'publisher': {'name': 'AUMA Riester GmbH & Co. KG', 'category': 'vendor', 'namespace': 'https://auma.com', 'contact_details': 'psirt@auma.com'}, 'references': [{'url': 'https://certvde.com/en/advisories/VDE-2023-027/', 'summary': 'VDE-2023-027: AUMA: Reflected Cross-Site Scripting Vulnerability in SIMA Master Stations - HTML', 'category': 'self'}, {'url': 'https://auma.csaf-tp.certvde.com/.well-known/csaf/white/2023/vde-2023-027.json', 'summary': 'VDE-2023-027: AUMA: Reflected Cross-Site Scripting Vulnerability in SIMA Master Stations - CSAF', 'category': 'self'}, {'url': 'https://auma.com', 'summary': 'Vendor PSIRT', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/auma/', 'summary': 'CERT@VDE Security Advisories for AUMA Riester GmbH & Co. KG', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}]}, 'product_tree': {'branches': [{'name': 'AUMA', 'branches': [{'name': 'Software', 'branches': [{'name': 'SIMA² Master Station', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIMA² Master Station vers:all/*', 'product_id': 'CSAFPID-51001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2022-4286', 'cwe': {'id': 'CWE-79', 'name': "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"}, 'notes': [{'text': '\nA reflected cross-site scripting (XSS) vulnerability exists in System Diagnostics Manager of B&R Automation Runtime versions >=3.00 and <=C4.93 that enables a remote attacker to execute arbitrary JavaScript in the context of the users browser session.\n\n', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2022-4286', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 6.1, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N', 'temporalScore': 6.1, 'integrityImpact': 'LOW', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 6.1, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': 'Do not use Hyperlinks provided by untrusted 3rd party to access the SIMA² System Diagnostics Manager. Hyperlinks may be provided via:\n\n- Emails from unknown users\n- Social media channels\n- Messaging services\n- Webpages with comment functionality\n- QR Codes\n\nThe use of external Web Application Firewalls (WAF) can mitigate attacks using reflected cross-site scripting.', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'known_affected': ['CSAFPID-51001']}}]}
997fe0971cbbdfead904652df08225628ae85358debd493c84505d16bb8ffa06
2026-05-29 08:30:31.564898+03:00
2026-05-29 08:30:31.564898+03:00
csaf_aumariestergmbhcokg.ndjson
8d0b3e2a39bbb5f7b36b83f00740287d5d244dca72e751180af9bea280635ff3
{'document': {'lang': 'en-GB', 'notes': [{'text': 'Forescout Research Labs, partnering with JSOF Research, disclosed NAME:WRECK, a set of Domain Name System (DNS) vulnerabilities that have the potential to cause either Denial of Service (DoS) or Remote Code Execution, allowing attackers to take targeted devices offline or to gain control over them. The vulnerability could be exploited by an attacker on the same network or on a remote network by spoofing packets.', 'title': 'Summary', 'category': 'summary'}, {'text': 'This vulnerability may lead to a Denial of Service (DoS) or arbitrary code execution on affected SIMA² Master Stations. This may allow an adversary to take the device offline or to take over control of the device.', 'title': 'Impact', 'category': 'description'}, {'text': 'In case you cannot upgrade your SIMA² Master Station to software Version 2.6 or above, it is recommended to configure the use of internal DNS servers only and block external DNS traffic where possible. It is also recommended to segment networks and shield affected devices from untrusted networks, e.g., using firewalls. Network intrusion detection mechanisms can be used to filter malicious packets.', 'title': 'Mitigation', 'category': 'description'}, {'text': 'The described vulnerabilities have been fixed in the SIMA² Master Stations with software version V 2.6 or higher. SIMA² Master Stations with software versions < V 2.6 can be upgraded. AUMA recommends applying a product update at the earliest convenience.', 'title': 'Remediation', 'category': 'description'}], 'title': 'AUMA: SIMA Master Station affected by WRECK vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2023-028', 'status': 'final', 'aliases': ['VDE-2023-028'], 'version': '2', 'generator': {'date': '2025-03-19T14:52:53.167Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.21'}}, 'revision_history': [{'date': '2023-08-07T11:35:00.000Z', 'number': '1', 'summary': 'initial revision'}, {'date': '2025-05-14T13:00:15.000Z', 'number': '2', 'summary': 'Fix: added distribution'}], 'current_release_date': '2025-05-14T13:00:15.000Z', 'initial_release_date': '2023-08-07T11:35:00.000Z'}, 'publisher': {'name': 'AUMA Riester GmbH & Co. KG', 'category': 'vendor', 'namespace': 'https://auma.com', 'contact_details': 'psirt@auma.com'}, 'references': [{'url': 'https://certvde.com/de/advisories/VDE-2023-028/', 'summary': 'VDE-2023-028: AUMA: SIMA Master Station affected by WRECK vulnerability - HTML', 'category': 'self'}, {'url': 'https://certvde.com/en/advisories/vendor/auma/', 'summary': 'CERT@VDE Security Advisories for AUMA Riester GmbH & Co. KG', 'category': 'external'}, {'url': 'https://auma.csaf-tp.certvde.com/.well-known/csaf/white/2023/vde-2023-028.json', 'summary': 'VDE-2023-028: AUMA: SIMA Master Station affected by WRECK vulnerability - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERTVDE'}]}, 'product_tree': {'branches': [{'name': 'AUMA Riester GmbH & Co. KG', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'SIMA² Master Station', 'product': {'name': 'SIMA² Master Station', 'product_id': 'CSAFPID-11001'}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': '<v2.6', 'product': {'name': 'Firmware <v2.6', 'product_id': 'CSAFPID-21001'}, 'category': 'product_version_range'}, {'name': 'v2.6', 'product': {'name': 'Firmware v2.6', 'product_id': 'CSAFPID-22001'}, 'category': 'product_version'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware <v2.6 installed on SIMA² Master Station', 'product_id': 'CSAFPID-31001'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware v2.6 installed on SIMA² Master Station', 'product_id': 'CSAFPID-32001'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11001'}]}, 'vulnerabilities': [{'cve': 'CVE-2016-20009', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': '** UNSUPPORTED WHEN ASSIGNED ** A DNS client stack-based buffer overflow in ipdnsc_decode_name() affects Wind River VxWorks 6.5 through 7. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.', 'category': 'summary'}], 'title': 'CVE-2016-20009', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001']}], 'remediations': [{'details': 'In case you cannot upgrade your SIMA² Master Station to software Version 2.6 or above, it is recommended to configure the use of internal DNS servers only and block external DNS traffic where possible. It is also recommended to segment networks and shield affected devices from untrusted networks, e.g., using firewalls. Network intrusion detection mechanisms can be used to filter malicious packets.', 'category': 'mitigation', 'product_ids': ['CSAFPID-31001']}, {'details': 'The described vulnerabilities have been fixed in the SIMA² Master Stations with software version V 2.6 or higher. SIMA² Master Stations with software versions < V 2.6 can be upgraded. AUMA recommends applying a product update at the earliest convenience.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31001']}], 'product_status': {'fixed': ['CSAFPID-32001'], 'known_affected': ['CSAFPID-31001']}}]}
d37d0c5aefc7ad02cb85a231706f344898fce84c229eb394ec344ef62c26efe5
2026-05-29 08:30:31.564898+03:00
2026-05-29 08:30:31.564898+03:00
csaf_aumariestergmbhcokg.ndjson
6c62ad2f05e289a0d6d15cdaa02fb92aae1c7d925111fac54aced1640f10fe5f
{'document': {'lang': 'en-GB', 'notes': [{'text': 'Sending too much data in the service telegram of AUMA actuators leads to a buffer overflow in the actuator controls. Depending on the actuator, the service telegram is transmitted either via Bluetooth or RS232', 'title': 'Summary', 'category': 'summary'}, {'text': 'A buffer overflow can lead to an unexpected behaviour e.g. to restart of the actuator controls.', 'title': 'Impact', 'category': 'description'}, {'text': 'As the Bluetooth interface or the alternatively available RS-232 interface is not required for normal operation, it is advisable to only activate it or only use it when it is required, e.g. when configuring the actuator or reading diagnostic data. It should be deactivated under normal operation conditions.', 'title': 'Mitigation', 'category': 'description'}, {'text': 'For actuators with Bluetooh, it is recommended to update the firmware of the actuator controls to a new version in order to avoid a buffer overflow.\nFor actuators without Bluetooth, it is recommended to restrict physical access to the actuator and/or update the firmware if possible.', 'title': 'Remediation', 'category': 'description'}, {'text': 'If the actuator controls has a Bluetooth interface, we recommend switching off this interface, as the Bluetooth connection to AUMA actuators is only used for configuration and diagnostics in the context of service activities. If the actuator controls has an build-in RS-232 interface, we recommend restricting physical access to the actuator.', 'title': 'General Recommendation', 'category': 'general'}, {'text': 'AUMA is not liable for updates of its actuators', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Applies to all actuators which can be configured using either a Bluetooth interface or a RS-232 interface.', 'title': 'Product Description', 'category': 'description'}], 'title': 'AUMA Riester: Buffer overflow in service telegram', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2025-026', 'status': 'final', 'aliases': ['VDE-2025-026'], 'version': '2', 'generator': {'date': '2025-04-17T09:37:58.338Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.18'}}, 'revision_history': [{'date': '2025-05-12T06:00:00.000Z', 'number': '1', 'summary': 'Initial revision'}, {'date': '2025-05-14T13:00:14.000Z', 'number': '2', 'summary': 'Fix: added distribution'}], 'current_release_date': '2025-05-14T13:00:14.000Z', 'initial_release_date': '2025-05-12T10:00:00.000Z'}, 'publisher': {'name': 'AUMA Riester GmbH & Co. KG', 'category': 'vendor', 'namespace': 'https://auma.com', 'contact_details': 'psirt@auma.com'}, 'references': [{'url': 'https://www.auma.com/en_GB/service/psirt', 'summary': 'PSIRT at AUMA Riester GmbH & Co. KG', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/auma/', 'summary': 'CERT@VDE Security Advisories for AUMA', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/VDE-2025-026', 'summary': 'VDE-2025-026: AUMA Riester: Buffer overflow in service telegram - HTML', 'category': 'self'}, {'url': 'https://auma.csaf-tp.certvde.com/.well-known/csaf/white/2025/vde-2025-026.json', 'summary': 'VDE-2025-026: AUMA Riester: Buffer Overvflow in service telegram - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'for coordination', 'organization': 'CERT@VDE'}, {'urls': ['https://onekey.com'], 'names': ['Dennis Schaeffer'], 'summary': 'for discovering the vulnerability', 'organization': 'ONEKEY GmbH'}], 'aggregate_severity': {'text': 'High'}}, 'product_tree': {'branches': [{'name': 'AUMA Riester GmbH', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'AC1.2', 'product': {'name': 'AC1.2', 'product_id': 'CSAFPID-11001'}, 'category': 'product_family'}, {'name': 'PROFOX', 'product': {'name': 'PROFOX', 'product_id': 'CSAFPID-11011'}, 'category': 'product_family'}, {'name': 'TIGRON', 'product': {'name': 'TIGRON', 'product_id': 'CSAFPID-11021'}, 'category': 'product_family'}, {'name': 'TIGRON SIL', 'product': {'name': 'TIGRON SIL', 'product_id': 'CSAFPID-11031'}, 'category': 'product_family'}, {'name': 'SGx/SVx', 'product': {'name': 'SGx/SVx', 'product_id': 'CSAFPID-11041'}, 'category': 'product_family'}, {'name': 'MEC 03.01', 'product': {'name': 'MEC 03.01', 'product_id': 'CSAFPID-11051'}, 'category': 'product_family'}], 'category': 'product_name'}, {'name': 'Firmware', 'branches': [{'name': 'AC1.2', 'branches': [{'name': '>06.00.00<06.09.04', 'product': {'name': 'Firmware >06.00.00<06.09.04', 'product_id': 'CSAFPID-21001'}, 'category': 'product_version_range'}, {'name': '06.09.04', 'product': {'name': 'Firmware 06.09.04', 'product_id': 'CSAFPID-22001'}, 'category': 'product_version'}], 'category': 'product_family'}, {'name': 'PROFOX', 'branches': [{'name': '<01-01.10.00', 'product': {'name': 'Firmware <01-01.10.00', 'product_id': 'CSAFPID-21011'}, 'category': 'product_version_range'}, {'name': '01-01.10.00', 'product': {'name': 'Firmware 01-01.10.00', 'product_id': 'CSAFPID-22011'}, 'category': 'product_version'}], 'category': 'product_family'}, {'name': 'TIGRON', 'branches': [{'name': '<01-01.09.00', 'product': {'name': 'Firmware <01-01.09.00', 'product_id': 'CSAFPID-21021'}, 'category': 'product_version_range'}, {'name': '01-01.09.00', 'product': {'name': 'Firmware 01-01.09.00', 'product_id': 'CSAFPID-22021'}, 'category': 'product_version'}], 'category': 'product_family'}, {'name': 'TIGRON SIL', 'branches': [{'name': '<02-01.01.00', 'product': {'name': 'Firmware <02-01.01.00', 'product_id': 'CSAFPID-21031'}, 'category': 'product_version_range'}, {'name': '02-01.01.00', 'product': {'name': 'Firmware 02-01.01.00', 'product_id': 'CSAFPID-22031'}, 'category': 'product_version'}], 'category': 'product_family'}, {'name': 'Sxy', 'branches': [{'name': '>03.00.00<03.05.01', 'product': {'name': 'Firmware >03.00.00<03.05.01', 'product_id': 'CSAFPID-21041'}, 'category': 'product_version_range'}, {'name': '03.05.01', 'product': {'name': 'Firmware 03.05.01', 'product_id': 'CSAFPID-22041'}, 'category': 'product_version'}], 'category': 'product_family'}, {'name': 'MEC03.1', 'branches': [{'name': '<01.02.00', 'product': {'name': 'Firmware <01.02.00', 'product_id': 'CSAFPID-21051'}, 'category': 'product_version_range'}, {'name': '01.02.00', 'product': {'name': 'Firmware 01.02.00', 'product_id': 'CSAFPID-22051'}, 'category': 'product_version'}], 'category': 'product_family'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware >06.00.00<06.09.04 installed on AC1.2', 'product_id': 'CSAFPID-31001'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 06.09.04 installed on AC1.2', 'product_id': 'CSAFPID-32001'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <01-01.10.00 installed on PROFOX', 'product_id': 'CSAFPID-31002'}, 'product_reference': 'CSAFPID-21011', 'relates_to_product_reference': 'CSAFPID-11011'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 01-01.10.00 installed on PROFOX', 'product_id': 'CSAFPID-32002'}, 'product_reference': 'CSAFPID-22011', 'relates_to_product_reference': 'CSAFPID-11011'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <01-01.09.00 installed on TIGRON', 'product_id': 'CSAFPID-31003'}, 'product_reference': 'CSAFPID-21021', 'relates_to_product_reference': 'CSAFPID-11021'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 01-01.09.00 installed on TIGRON', 'product_id': 'CSAFPID-32003'}, 'product_reference': 'CSAFPID-22021', 'relates_to_product_reference': 'CSAFPID-11021'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <02-01.01.00 installed on TIGRON SIL', 'product_id': 'CSAFPID-31004'}, 'product_reference': 'CSAFPID-21031', 'relates_to_product_reference': 'CSAFPID-11031'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 02-01.01.00 installed on TIGRON SIL', 'product_id': 'CSAFPID-32004'}, 'product_reference': 'CSAFPID-22031', 'relates_to_product_reference': 'CSAFPID-11031'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware >03.00.00<03.05.01 installed on SGx/SVx', 'product_id': 'CSAFPID-31005'}, 'product_reference': 'CSAFPID-21041', 'relates_to_product_reference': 'CSAFPID-11041'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 03.05.01 installed on SGx/SVx', 'product_id': 'CSAFPID-32005'}, 'product_reference': 'CSAFPID-22041', 'relates_to_product_reference': 'CSAFPID-11041'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <01.02.00 installed on MEC 03.01', 'product_id': 'CSAFPID-31006'}, 'product_reference': 'CSAFPID-21051', 'relates_to_product_reference': 'CSAFPID-11051'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 01.02.00 installed on MEC 03.01', 'product_id': 'CSAFPID-32006'}, 'product_reference': 'CSAFPID-22051', 'relates_to_product_reference': 'CSAFPID-11051'}], 'product_groups': [{'summary': 'Affected Products', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006']}, {'summary': 'Fixed products.', 'group_id': 'CSAFGID-0002', 'product_ids': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-32004', 'CSAFPID-32005', 'CSAFPID-32006']}]}, 'vulnerabilities': [{'cve': 'CVE-2025-3496', 'cwe': {'id': 'CWE-120', 'name': "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')"}, 'notes': [{'text': 'An unauthenticated remote attacker can cause a buffer overflow which could lead to unexpected behaviour or DoS via Bluetooth or RS-232 interface.', 'title': 'Vulnerability Description', 'audience': 'all', 'category': 'description'}], 'title': 'CVE-2025-3496', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004']}, {'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 4.6, 'attackVector': 'PHYSICAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 4.6, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'HIGH', 'environmentalScore': 4.6, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-31005', 'CSAFPID-31006']}], 'remediations': [{'details': 'It is recommended to update to a new version, with which the error can no longer occur.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-32004', 'CSAFPID-32005', 'CSAFPID-32006'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006']}, 'acknowledgments': [{'urls': ['https://onekey.com'], 'names': ['Dennis Schaefer'], 'summary': 'for discovering the vulnerability', 'organization': 'ONEKEY GmbH'}]}]}
0f74ed502e7557983976d95e010f9ace465de000bb1ff526b7bed5b0c1958cc2
2026-05-29 08:30:31.564898+03:00
2026-05-29 08:30:31.564898+03:00
csaf_aumariestergmbhcokg.ndjson
e614e6bd4e0a42ad49689cc422a99a7b557eca2f0336b695e93f1e6a5e3fc8a1
{'document': {'lang': 'en-GB', 'notes': [{'text': 'For actuators with AC.2 controls and PROFOX actuators, a wrong configuration occurred for deliveries within the period from 01.01.2024 to 09.05.2025. Despite the ordered option "L90.00 = Bluetooth always deactivated", these actuators were delivered with an activated Bluetooth module which would allow an attacker to utilize the Bluetooth interface. It is possible to deactivate the Bluetooth interface of the affected actuators after the delivery using the standard procedures listed in the manuals.', 'title': 'Summary', 'category': 'summary'}, {'text': 'An unexpectedly activated Bluetooth module can lead to unwanted fingerprinting of the Bluetooth data by an attacker.', 'title': 'Impact', 'category': 'description'}, {'text': 'As the Bluetooth interface is not required for normal operation, it is advisable to only activate it or only use it once it is needed, e.g. when configuring the actuator or reading diagnosis data. Under normal operating conditions, it should be deactivated.', 'title': 'Remediation', 'category': 'description'}, {'text': 'As the Bluetooth interface is not required for normal operation, it is advisable to only activate it or to only use it once it is needed, e.g. when configuring the actuator or reading diagnosis data. Under normal operating conditions, it should be deactivated. The configuration "Bluetooth interface = Switched off" should be verified for its desired setting.', 'title': 'General Recommendation', 'category': 'general'}], 'title': 'AUMA: Incorrect delivery status of the Bluetooth configuration', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2025-047', 'status': 'final', 'aliases': ['VDE-2025-047'], 'version': '1', 'generator': {'date': '2025-06-02T09:05:11.065Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.24'}}, 'revision_history': [{'date': '2025-06-10T10:00:00.000Z', 'number': '1', 'summary': 'Initial revision'}], 'current_release_date': '2025-06-10T10:00:00.000Z', 'initial_release_date': '2025-06-10T10:00:00.000Z'}, 'publisher': {'name': 'AUMA Riester GmbH & Co. KG', 'category': 'vendor', 'namespace': 'https://auma.com', 'contact_details': 'psirt@auma.com'}, 'references': [{'url': 'https://www.auma.com/en_GB/service/psirt', 'summary': 'PSIRT at AUMA Riester GmbH & Co. KG', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/auma/', 'summary': 'CERT@VDE Security Advisories for AUMA', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/VDE-2025-047', 'summary': 'VDE-2025-047: AUMA: Incorrect delivery status of the Bluetooth configuration - HTML', 'category': 'self'}, {'url': 'https://auma.csaf-tp.certvde.com/.well-known/csaf/white/2025/vde-2025-047.json', 'summary': 'VDE-2025-047: AUMA Riester: Incorrect delivery status of the Bluetooth configuration - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'for coordination', 'organization': 'CERT@VDE'}], 'aggregate_severity': {'text': 'Low'}}, 'product_tree': {'branches': [{'name': 'AUMA Riester GmbH', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'AC1.2', 'branches': [{'name': '01.01.2024<09.05.2025', 'product': {'name': 'AC1.2 delivered between 01.01.2024<09.05.2025', 'product_id': 'CSAFPID-11001'}, 'category': 'product_version_range'}, {'name': '09.05.2025', 'product': {'name': 'AC1.2 delivered after 09.05.2025', 'product_id': 'CSAFPID-12001'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'PROFOX', 'branches': [{'name': '01.01.2024<09.05.2025', 'product': {'name': 'PROFOX delivered between 01.01.2024<09.05.2025', 'product_id': 'CSAFPID-11002'}, 'category': 'product_version_range'}, {'name': '09.05.2025', 'product': {'name': 'PROFOX delivered after 09.05.2025', 'product_id': 'CSAFPID-12002'}, 'category': 'product_version'}], 'category': 'product_family'}], 'category': 'product_name'}], 'category': 'vendor'}], 'product_groups': [{'summary': 'Affected Products', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-11001', 'CSAFPID-11002']}, {'summary': 'Fixed products', 'group_id': 'CSAFGID-0002', 'product_ids': ['CSAFPID-12001', 'CSAFPID-12002']}]}, 'vulnerabilities': [{'cve': 'CVE-2025-41657', 'cwe': {'id': 'CWE-207', 'name': 'Observable Behavioral Discrepancy With Equivalent Products'}, 'notes': [{'text': 'Due to an undocumented active bluetooth stack on products delivered within the period 01.01.2024 to 09.05.2025 fingerprinting is possible by an unauthenticated adjacent attacker.', 'title': 'Vulnerability Description', 'audience': 'all', 'category': 'description'}], 'title': 'CVE-2025-41657', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 4.3, 'attackVector': 'ADJACENT_NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N', 'temporalScore': 4.3, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 4.3, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-11001', 'CSAFPID-11002']}], 'remediations': [{'date': '2025-05-23T10:00:00.000Z', 'details': 'As the Bluetooth interface is not required for normal operation, it is advisable to only activate it or to only use it once it is needed, e.g. when configuring the actuator or reading diagnosis data. Under normal operating conditions, it should be deactivated. The configuration "Bluetooth interface = Switched off" should be verified for its desired setting', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-12001', 'CSAFPID-12002'], 'known_affected': ['CSAFPID-11001', 'CSAFPID-11002']}}]}
38b4822c5a4686beaa2666da396784184a0c4b855bc640ebf14d8dfcf38cf7a5
2026-05-29 08:30:31.564898+03:00
2026-05-29 08:30:31.564898+03:00
csaf_murrelektronikgmbh.ndjson
1d328aa2c3c0c44544964ee8801d7c3a2ad90b9604b4cfb8488b61fa9ec5e797
{'document': {'lang': 'en-GB', 'notes': [{'text': 'The embedded web interface of the MURRELEKTRONIK IMPACT67 Pro PN DIO8 IOL8\ntransmits login credentials over unencrypted HTTP using a GET request. The device does\nnot offer HTTPS/TLS support, exposing user credentials to passive interception by any attacker on the same network.', 'title': 'Summary', 'category': 'summary'}, {'text': 'User credentials, sent to the devices Webserver, are exposed to an attacker in the same network or network segment. The datas confidentiallity is compromised.', 'title': 'Impact', 'category': 'description'}, {'text': 'This document is provided on an "AS IS" basis and does not imply any kind of guarantee or warranty, including the warranties of merchantability or fitness for a particular use. Your use of the information on the document or materials linked from the document is at your own risk. The Murrelektronik GmbH reserves the right to change or update this document at any time.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}], 'title': 'Murrelektronik: Cleartext Transmission of Sensitive Information in IMPACT67 Pro', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2025-091', 'status': 'final', 'aliases': ['VDE-2025-091'], 'version': '1.0.0', 'generator': {'date': '2025-10-14T07:20:14.779Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.35'}}, 'revision_history': [{'date': '2025-10-14T10:00:00.000Z', 'number': '1.0.0', 'summary': 'initial release'}], 'current_release_date': '2025-10-14T10:00:00.000Z', 'initial_release_date': '2025-10-14T10:00:00.000Z'}, 'publisher': {'name': 'Murrelektronik GmbH', 'category': 'vendor', 'namespace': 'https://murrelektronik.com', 'contact_details': 'psirt@murrelektronik.de'}, 'references': [{'url': 'https://www.murrelektronik.com/de/kontakt/psirt/', 'summary': 'Murrelektronik Product Security Incident Response (PSIRT) Team', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/murrelektronik', 'summary': 'CERT@VDE Security Advisories for Murrelektronik', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/VDE-2025-091/', 'summary': 'VDE-2025-091: Murrelektronik: Cleartext Transmission of Sensitive Information in IMPACT67 Pro - HTML', 'category': 'self'}, {'url': 'https://murrelektronik.csaf-tp.certvde.com/.well-known/csaf/white/2025/vde-2025-091.json', 'summary': 'VDE-2025-091: Murrelektronik: Cleartext Transmission of Sensitive Information in IMPACT67 Pro - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}, {'names': ['Abhishek Pandey'], 'summary': 'Reporting and Analysing', 'organization': 'Payatu Security Consulting Pvt. Ltd.'}], 'aggregate_severity': {'text': 'low'}}, 'product_tree': {'branches': [{'name': 'Murrelektronik', 'branches': [{'name': 'Firmware', 'branches': [{'name': 'Impact67 Pro', 'branches': [{'name': '54630', 'branches': [{'name': '<=1.08.01', 'product': {'name': 'Murrelektronik Firmware Impact67 Pro 54630 <=1.08.01', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': '54620', 'branches': [{'name': '<=1.08.01', 'product': {'name': 'Murrelektronik Firmware Impact67 Pro 54620 <=1.08.01', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': '54631', 'branches': [{'name': '<=1.08.05', 'product': {'name': 'Murrelektronik Firmware Impact67 Pro 54631 <=1.08.05', 'product_id': 'CSAFPID-0003'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': '54632', 'branches': [{'name': '<=1.08.01', 'product': {'name': 'Murrelektronik Firmware Impact67 Pro 54632 <=1.08.01', 'product_id': 'CSAFPID-0004'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'product_family'}], 'category': 'vendor'}], 'product_groups': [{'summary': 'Known Affected', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004']}]}, 'vulnerabilities': [{'cve': 'CVE-2025-41718', 'cwe': {'id': 'CWE-319', 'name': 'Cleartext Transmission of Sensitive Information'}, 'notes': [{'text': 'A cleartext transmission of sensitive information vulnerability in the affected products allows an unauthorized remote attacker to gain login credentials and access the Web-UI.', 'title': 'Vulnerability Description', 'audience': 'all', 'category': 'description'}], 'title': 'Unprotected Transport of Credentials', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'NONE', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004']}], 'threats': [{'date': '2025-09-19T09:00:00.000Z', 'details': 'Leaked User Credentials results in the compromise of the leaked login. ', 'category': 'impact', 'group_ids': ['CSAFGID-0001']}, {'date': '2025-09-19T09:00:00.000Z', 'details': 'Leaked User Credentials can contain personal information of the regarding user. The confidentiality of personal data is endangered. ', 'category': 'impact', 'group_ids': ['CSAFGID-0001']}, {'date': '2025-09-19T09:00:00.000Z', 'details': 'Leaked user credentials can result in the compromise of other logins of this user, if he reuses the same password for other services. ', 'category': 'impact', 'group_ids': ['CSAFGID-0001']}], 'remediations': [{'date': '2025-09-19T09:00:00.000Z', 'details': 'Murrelektronik recommends:\n\n * Deactivating the Webserver will prevent any data from being sent unencrypted. \nMore information on how to disable the webserver can be found in the manual.\n * Deactivating all unused network ports in the unit will prevent data sniffing.\n * Segmenting the network strictly helps to minimize unauthorized access to network traffic. If the webserver must stay activated, this is recommended to reduce the security breaches impact.\n * Advise users of the system to not use personal data or standard passwords for the webserver accounts. This helps to prevent personal data leakage.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004']}, {'date': '2025-09-19T09:00:00.000Z', 'details': 'There is no fix available in the current versions. A permanent solution is planned to be implemented in the future.', 'category': 'none_available', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004']}], 'discovery_date': '2025-09-18T10:00:00.000Z', 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004']}, 'acknowledgments': [{'names': ['Abhishek Pandey'], 'summary': 'Reporting and investigating the vulnerability. ', 'organization': 'Payatu Security Consulting Pvt. Ltd. '}]}]}
4bea5509a18b3e6be58dbc7c767eafdb913a3be3ed106db73b36a13fa362c8d6
2026-05-29 08:30:32.069093+03:00
2026-05-29 08:30:32.069093+03:00
csaf_certvde.ndjson
d8d218d1bae0d096c32b0479334060c8fcb0f5cb06fd3fae061e29bb02e7db0d
{'document': {'lang': 'en-GB', 'notes': [{'text': "A security researcher discovered that the affected application doesn't properly restrict access to an endpoint that is responsible for saving settings, to a user with limited access rights. Based on the lack of adequately implemented access-control rules, by accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to change the application settings without authenticating at all, which violates originally laid ACL rules.", 'title': 'Summary', 'category': 'summary'}, {'text': 'This issue allows changing the configuration and get full access to the web-based configuration interface of the device wich includes all settings like passwords, alerting parameters and output states. That can adversely affect the planned operation of the equipment or can aid in further attacks on the industrial control process.', 'title': 'Impact', 'category': 'description'}, {'text': 'In secure environments disable port forwarding and remote access to the device otherwise disable network access completely.', 'title': 'Mitigation', 'category': 'description'}], 'title': 'TECSON/GOK: Improper Authentication and Access Control on multiple devices', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2019-012', 'status': 'final', 'aliases': ['VDE-2019-012'], 'version': '4', 'generator': {'date': '2024-07-17T18:08:01.483Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.8'}}, 'revision_history': [{'date': '2019-06-04T13:21:00.000Z', 'number': '1', 'summary': 'Initial revision.'}, {'date': '2024-11-06T11:27:01.000Z', 'number': '2', 'summary': 'Fix: correct certvde domain, added alias, added self-reference'}, {'date': '2025-04-10T13:00:00.000Z', 'number': '3', 'summary': 'Fixed version info using vers:/all'}, {'date': '2025-05-14T13:00:14.000Z', 'number': '4', 'summary': 'Fix: added distribution'}], 'current_release_date': '2025-05-14T13:00:14.000Z', 'initial_release_date': '2019-06-04T13:21:00.000Z'}, 'publisher': {'name': 'CERT@VDE', 'category': 'coordinator', 'namespace': 'https://certvde.com', 'contact_details': 'csaf@certvde.com'}, 'references': [{'url': 'https://certvde.com/en/advisories/vendor/tecsongok', 'summary': 'CERT@VDE Security Advisories for TECSON/GOK', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/VDE-2019-012', 'summary': 'VDE-2019-012: TECSON/GOK: Improper Authentication and Access Control on multiple devices - HTML', 'category': 'self'}, {'url': 'https://certvde.csaf-tp.certvde.com/.well-known/csaf/white/2019/vde-2019-012.json', 'summary': 'VDE-2019-012: TECSON/GOK: Improper Authentication and Access Control on multiple devices - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}, {'urls': ['https://rupp.it/'], 'summary': 'reporting', 'organization': 'Maxim Rupp'}]}, 'product_tree': {'branches': [{'name': 'TECSON', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'e-litro net', 'product': {'name': 'e-litro net', 'product_id': 'CSAFPID-11001'}, 'category': 'product_name'}, {'name': 'LX-Net', 'product': {'name': 'LX-Net', 'product_id': 'CSAFPID-11002'}, 'category': 'product_name'}, {'name': 'LX-Q-Net', 'product': {'name': 'LX-Q-Net', 'product_id': 'CSAFPID-11003'}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'Firmware all versions', 'product_id': 'CSAFPID-21001'}, 'category': 'product_version_range'}], 'category': 'product_family'}], 'category': 'vendor'}, {'name': 'GOK', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'SmartBox 4 LAN', 'product': {'name': 'SmartBox 4 LAN', 'product_id': 'CSAFPID-11004'}, 'category': 'product_name'}, {'name': 'SmartBox 4 LAN PRO', 'product': {'name': 'SmartBox 4 LAN PRO', 'product_id': 'CSAFPID-11005'}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'Firmware all version', 'product_id': 'CSAFPID-21002'}, 'category': 'product_version_range'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware all versions installed on e-litro net', 'product_id': 'CSAFPID-31001'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware all versions installed on LX-Net', 'product_id': 'CSAFPID-31002'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11002'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware all versions installed on LX-Q-Net', 'product_id': 'CSAFPID-31003'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11003'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware all versions installed on SmartBox 4 LAN', 'product_id': 'CSAFPID-31004'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11004'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware all version installed on SmartBox 4 LAN PRO', 'product_id': 'CSAFPID-31005'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11005'}], 'product_groups': [{'summary': 'Affected products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}]}, 'vulnerabilities': [{'cve': 'CVE-2019-12254', 'cwe': {'id': 'CWE-287', 'name': 'Improper Authentication'}, 'notes': [{'text': "A security researcher discovered that the affected application doesn't properly restrict access to an endpoint that is responsible for saving settings, to a user with limited access rights. Based on the lack of adequately implemented access-control rules, by accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to change the application settings without authenticating at all, which violates originally laid ACL rules.", 'title': 'Vulnerability Description', 'audience': 'all', 'category': 'description'}], 'title': 'CVE-2019-12254', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}], 'remediations': [{'details': 'In secure environments disable port forwarding and remote access to the device otherwise disable network access completely.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}}]}
ce62f89f9419a69bcfe1ce036151e4fed46aa8c9050be550fa6a013595c359ad
2026-05-29 08:30:32.458142+03:00
2026-05-29 08:30:32.458142+03:00
csaf_certvde.ndjson
e69b080a42a911e0426fe5c761870c6184d762a1d26ae0f9780c8d6a2daaabf5
{'document': {'lang': 'en-GB', 'notes': [{'text': 'A security vulnerability was identified in the ICMHelper service running on the system of an ICM installation. \nA low privileged local attacker could exploit this vulnerability to issue OS commands with the highest privileges.', 'title': 'Summary', 'category': 'summary'}, {'text': 'The vulnerability CVE-2025-41698 allows an attacker to gain full access to application, sensitive information, client system and server. This requires successful exploitation of CVE-2025-2810.\n', 'title': 'Impact', 'category': 'description'}, {'text': 'If you have any further questions related to the impact of the vulnerabilities, please contact your designated regional marketing manager. For reporting incidents and potential vulnerabilities in our devices, please refer to https://static.draeger.com/security to contact the Product Security team directly.\nThe full text of this advisory can be accessed through https://static.draeger.com/security.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'The issue has been fixed in ICMHelper version 2.0.1.0. ', 'title': 'Remediation', 'category': 'description'}], 'title': 'Draeger: ICMHelper is vulnerable to a privilege escalation', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2025-028', 'status': 'final', 'aliases': ['VDE-2025-028'], 'version': '3.0.0', 'generator': {'date': '2026-01-08T09:24:24.699Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.41'}}, 'revision_history': [{'date': '2025-08-05T10:00:00.000Z', 'number': '1.0.0', 'summary': 'Initial revision.'}, {'date': '2025-12-15T11:00:00.000Z', 'number': '2.0.0', 'summary': 'Changes to publisher\nAdded CPEs as product_identification_helper'}, {'date': '2026-01-06T11:00:00.000Z', 'number': '3.0.0', 'summary': 'fixed version range, fixed Aggregate severity, changed vulnerability Title to CVE description, fix CPE to have at least one for affected products'}], 'current_release_date': '2026-01-06T11:00:00.000Z', 'initial_release_date': '2025-08-05T10:00:00.000Z'}, 'publisher': {'name': 'CERT@VDE', 'category': 'coordinator', 'namespace': 'https://certvde.com', 'contact_details': 'csaf@certvde.com'}, 'references': [{'url': 'https://certvde.com/en/advisories/VDE-2025-028/', 'summary': 'VDE-2025-028: Draeger: ICMHelper is vulnerable to a privilege escalation - HTML', 'category': 'self'}, {'url': 'https://certvde.csaf-tp.certvde.com/.well-known/csaf/white/2025/vde-2025-028.json', 'summary': 'VDE-2025-028: Draeger: ICMHelper is vulnerable to a privilege escalation - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}, {'summary': 'responsible disclosure', 'organization': 'CODE WHITE GmbH'}], 'aggregate_severity': {'text': 'high', 'namespace': 'https://www.first.org/cvss/v3.1/specification-document#Qualitative-Severity-Rating-Scale'}}, 'product_tree': {'branches': [{'name': 'Draeger', 'branches': [{'name': 'Patient Monitoring', 'branches': [{'name': 'ICM', 'branches': [{'name': 'ICMHelper', 'branches': [{'name': 'vers:generic/<=1.4.0.1', 'product': {'name': 'Draeger ICMHelper <=1.4.0.1', 'product_id': 'CSAFPID-0001', 'product_identification_helper': {'cpe': 'cpe:2.3:a:Draeger:ICMHelper:1.4.0.1*:*:*:*:*:*:*:*'}}, 'category': 'product_version_range'}, {'name': '2.0.1.0', 'product': {'name': 'Draeger ICMHelper 2.0.1.0', 'product_id': 'CSAFPID-0002', 'product_identification_helper': {'cpe': 'cpe:2.3:a:Draeger:ICMHelper:2.0.1.0:*:*:*:*:*:*:*'}}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'product_family'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-2810', 'cwe': {'id': 'CWE-321', 'name': 'Use of Hard-coded Cryptographic Key'}, 'notes': [{'text': 'A low privileged local attacker can abuse the affected service by using a hardcoded cryptographic key.', 'title': 'CVE Description', 'audience': 'all', 'category': 'description'}], 'title': 'CVE-2025-2810', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N', 'temporalScore': 5.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 5.5, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-0001']}], 'remediations': [{'details': 'The issue has been fixed in ICMHelper version 2.0.1.0. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'fixed': ['CSAFPID-0002'], 'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-41698', 'cwe': {'id': 'CWE-862', 'name': 'Missing Authorization'}, 'notes': [{'text': 'A low privileged local attacker can interact with the affected service although user-interaction should not be allowed.', 'title': 'CVE Description', 'audience': 'all', 'category': 'description'}], 'title': 'CVE-2025-41698', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 7.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.8, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-0001']}], 'remediations': [{'details': 'The issue has been fixed in ICMHelper version 2.0.1.0. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'fixed': ['CSAFPID-0002'], 'known_affected': ['CSAFPID-0001']}}]}
c1e3a4064ad25850aa808d52bd8612ed8c272b22ec89c2beb5fe06547e6891f0
2026-05-29 08:30:32.458142+03:00
2026-05-29 08:30:32.458142+03:00
csaf_mieleciekg.ndjson
cb9ce0432355c808d3ce684d9b4fd693de29849104bc31cb0dcd6e5580173045
{'document': {'lang': 'en-US', 'notes': [{'text': 'Miele XGW 3000 is a ZigBee-TCP/IP gateway. The gateway connects Miele ZigBee-Appliances (called Miele@home) with local customer TCP/IP-Network and allows visualizing the appliance state on the web interface of the gateway, Miele SuperVision capable appliance, smartphone/tablet app or home automatization device.\n\nAn external security researcher reported two vulnerabilities in XGW 3000 gateway and provided a Proof-of-Concept. The combined exploitation of both vulnerabilities allow the circumvention of the authentication mechanisms of the XGW3000.\n\nThe Miele PSIRT managed to reproduce the findings and successfully exploited the gateway. Therefore, the existence of all vulnerabilities has been confirmed.', 'title': 'Summary', 'category': 'summary'}, {'text': 'Vulnerability ID (Miele): PSIRT-2019-001-VI_02\nCVSS-Score: 4.4 (AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C)\nVulnerability Type: CWE-285: Improper Authorization\nVulnerability / Issues: Bypass for "Password Change Function".In combination of vulnerability PSIRT-2019-001-VI_01 (CSRF), the administrator password can be changed without checking the old one\n\nVulnerability ID (Miele): PSIRT-2019-001-VI_01\nCVSS-Score: 4.4 (AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C)\nVulnerability Type: CWE-352: Cross-Site Request Forgery (CSRF)\nVulnerability / Issues: A malicious website visited by an authenticated admin user or a malicious mail are allowed to issue arbitrary changes in the "admin panel".', 'title': 'Impact', 'category': 'description'}, {'text': 'Install software version 2.4.0 via the automatic update function of the XGW 3000 ZigBee Gateway.\n\nTo do so, log into the local Miele@home Gateway Info Admin Panel. Afterwards, click on Settings -> Click on Update -> Click on Check for New Software. The latest version of the Gateway software will be suggested for installation. After the installation has been completed, verify if the installed version is 2.4.0 or larger. If this is not the case, the update process has to be started a second time.', 'title': 'Remediation', 'category': 'description'}], 'title': 'Miele: Multiple Vulnerabilities in XGW 3000 ZigBee Gateway', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2019-010', 'status': 'final', 'aliases': ['VDE-2019-010'], 'version': '2', 'generator': {'date': '2025-02-26T15:51:59.496Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.19'}}, 'revision_history': [{'date': '2019-05-20T06:58:00.000Z', 'number': '1', 'summary': 'Initial revision.'}, {'date': '2025-05-14T13:00:15.000Z', 'number': '2', 'summary': 'Fix: added distribution'}], 'current_release_date': '2025-05-14T13:00:15.000Z', 'initial_release_date': '2019-05-20T06:58:00.000Z'}, 'publisher': {'name': 'Miele & Cie KG', 'category': 'vendor', 'namespace': 'https://www.miele.com', 'contact_details': 'psirt@miele.com'}, 'references': [{'url': 'https://certvde.com/en/advisories/vendor/miele/', 'summary': 'Miele advisory overview at CERT@VDE', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/VDE-2019-010', 'summary': 'VDE-2019-010: Miele: Multiple Vulnerabilities in XGW 3000 ZigBee Gateway - HTML', 'category': 'self'}, {'url': 'https://miele.csaf-tp.certvde.com/.well-known/csaf/white/2019/vde-2019-010.json', 'summary': 'VDE-2019-010: Miele: Multiple Vulnerabilities in XGW 3000 ZigBee Gateway - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}, {'summary': 'reported', 'organization': 'Maxim Rupp'}]}, 'product_tree': {'branches': [{'name': 'Miele', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'XGW 3000', 'product': {'name': 'XGW 3000', 'product_id': 'CSAFPID-11001'}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Software', 'branches': [{'name': '<2.4.0', 'product': {'name': 'Software <2.4.0', 'product_id': 'CSAFPID-51001'}, 'category': 'product_version_range'}, {'name': '2.4.0', 'product': {'name': 'Software 2.4.0', 'product_id': 'CSAFPID-52001'}, 'category': 'product_version'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Software <2.4.0 installed on XGW 3000', 'product_id': 'CSAFPID-31001'}, 'product_reference': 'CSAFPID-51001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Software 2.4.0 installed on XGW 3000', 'product_id': 'CSAFPID-32001'}, 'product_reference': 'CSAFPID-52001', 'relates_to_product_reference': 'CSAFPID-11001'}]}, 'vulnerabilities': [{'cve': 'CVE-2019-20481', 'cwe': {'id': 'CWE-287', 'name': 'Improper Authentication'}, 'notes': [{'text': 'In MIELE XGW 3000 ZigBee Gateway before 2.4.0, the Password Change Function does not require knowledge of the old password. This can be exploited in conjunction with CVE-2019-20480.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2019-20481', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001']}], 'remediations': [{'details': 'Install software version 2.4.0 via the automatic update function of the XGW 3000 ZigBee Gateway.\n\nTo do so, log into the local Miele@home Gateway Info Admin Panel. Afterwards, click on Settings -> Click on Update -> Click on Check for New Software. The latest version of the Gateway software will be suggested for installation. After the installation has been completed, verify if the installed version is 2.4.0 or larger. If this is not the case, the update process has to be started a second time.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31001']}], 'product_status': {'fixed': ['CSAFPID-32001'], 'known_affected': ['CSAFPID-31001']}}, {'cve': 'CVE-2019-20480', 'cwe': {'id': 'CWE-352', 'name': 'Cross-Site Request Forgery (CSRF)'}, 'notes': [{'text': 'In MIELE XGW 3000 ZigBee Gateway before 2.4.0, a malicious website visited by an authenticated admin user or a malicious mail is allowed to make arbitrary changes in the "admin panel" because there is no CSRF protection.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2019-20480', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'temporalScore': 8.8, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 8.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001']}], 'remediations': [{'details': 'Install software version 2.4.0 via the automatic update function of the XGW 3000 ZigBee Gateway.\n\nTo do so, log into the local Miele@home Gateway Info Admin Panel. Afterwards, click on Settings -> Click on Update -> Click on Check for New Software. The latest version of the Gateway software will be suggested for installation. After the installation has been completed, verify if the installed version is 2.4.0 or larger. If this is not the case, the update process has to be started a second time.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31001']}], 'product_status': {'fixed': ['CSAFPID-32001'], 'known_affected': ['CSAFPID-31001']}}]}
9c3ca257e15162007bb179b3ef5ffb4c274c837baf48140a0e9608a8f7a91e24
2026-05-29 08:30:32.860956+03:00
2026-05-29 08:30:32.860956+03:00
pysec.ndjson
PYSEC-2023-94
{'id': 'PYSEC-2023-94', 'aliases': ['CVE-2023-34110', 'GHSA-jhpr-j7cq-3jp3'], 'details': 'Flask-AppBuilder is an application development framework, built on top of Flask. Prior to version 4.3.2, an authenticated malicious actor with Admin privileges, could by adding a special character on the add, edit User forms trigger a database error, this error is surfaced back to this actor on the UI. On certain database engines this error can include the entire user row including the pbkdf2:sha256 hashed password. This vulnerability has been fixed in version 4.3.2.\n', 'affected': [{'ranges': [{'repo': 'https://github.com/dpgaspar/Flask-AppBuilder', 'type': 'GIT', 'events': [{'introduced': '0'}, {'fixed': 'ae25ad4c87a9051ebe4a4e8f02aee73232642626'}]}, {'type': 'ECOSYSTEM', 'events': [{'introduced': '0'}, {'fixed': '4.3.2'}]}], 'package': {'name': 'flask-appbuilder', 'purl': 'pkg:pypi/flask-appbuilder', 'ecosystem': 'PyPI'}, 'versions': ['0.1.10', '0.1.11', '0.1.12', '0.1.13', '0.1.14', '0.1.15', '0.1.16', '0.1.17', '0.1.18', '0.1.19', '0.1.20', '0.1.21', '0.1.22', '0.1.23', '0.1.24', '0.1.25', '0.1.26', '0.1.27', '0.1.28', '0.1.29', '0.1.3', '0.1.33', '0.1.34', '0.1.35', '0.1.36', '0.1.37', '0.1.38', '0.1.4', '0.1.43', '0.1.44', '0.1.45', '0.1.46', '0.1.47', '0.1.5', '0.1.6', '0.1.7', '0.1.8', '0.1.9', '0.10.0', '0.10.1', '0.10.2', '0.10.3', '0.10.4', '0.10.5', '0.10.6', '0.10.7', '0.2.0', '0.2.1', '0.2.2', '0.3.0', '0.3.1', '0.3.10', '0.3.11', '0.3.12', '0.3.13', '0.3.14', '0.3.15', '0.3.16', '0.3.17', '0.3.2', '0.3.3', '0.3.4', '0.3.5', '0.3.6', '0.3.7', '0.3.8', '0.3.9', '0.4.0', '0.4.1', '0.4.2', '0.4.3', '0.5.0', '0.5.1', '0.5.2', '0.5.3', '0.5.4', '0.5.5', '0.5.6', '0.6.1', '0.6.10', '0.6.11', '0.6.12', '0.6.13', '0.6.14', '0.6.2', '0.6.3', '0.6.4', '0.6.5', '0.6.6', '0.6.7', '0.6.8', '0.6.9', '0.7.0', '0.7.1', '0.7.2', '0.7.3', '0.7.4', '0.7.5', '0.7.6', '0.7.7', '0.7.8', '0.8.0', '0.8.1', '0.8.2', '0.8.3', '0.8.4', '0.8.5', '0.9.0', '0.9.1', '0.9.2', '0.9.3', '1.0.0', '1.0.1', '1.1.0', '1.1.1', '1.1.2', '1.1.3', '1.10.0', '1.11.0', '1.11.1', '1.12.0', '1.12.1', '1.12.2', '1.12.3', '1.12.4', '1.12.5', '1.13.0', '1.13.1', '1.2.0', '1.2.1', '1.3.0', '1.3.1', '1.3.2', '1.3.3', '1.3.4', '1.3.5', '1.3.6', '1.3.7', '1.4.0', '1.4.1', '1.4.2', '1.4.3', '1.4.4', '1.4.5', '1.4.6', '1.4.7', '1.5.0', '1.6.0', '1.6.1', '1.6.2', '1.6.3', '1.7.0', '1.7.1', '1.8.0', '1.8.1', '1.9.0', '1.9.1', '1.9.2', '1.9.3', '1.9.4', '1.9.5', '1.9.6', '2.0.0', '2.1.0', '2.1.1', '2.1.10', '2.1.11', '2.1.12', '2.1.13', '2.1.2', '2.1.3', '2.1.4', '2.1.5', '2.1.6', '2.1.7', '2.1.8', '2.1.9', '2.2.0', '2.2.0rc1', '2.2.0rc2', '2.2.1', '2.2.1rc1', '2.2.1rc2', '2.2.1rc3', '2.2.2', '2.2.2rc1', '2.2.2rc2', '2.2.2rc3', '2.2.3', '2.2.3rc1', '2.2.3rc2', '2.2.3rc3', '2.2.3rc4', '2.2.3rc5', '2.2.3rc6', '2.2.4', '2.2.4rc1', '2.3.0', '2.3.0rc1', '2.3.0rc2', '2.3.0rc3', '2.3.0rc4', '2.3.1', '2.3.1rc1', '2.3.2', '2.3.2rc1', '2.3.3', '2.3.3rc1', '2.3.3rc2', '2.3.3rc3', '2.3.4', '2.3.4rc1', '3.0.0', '3.0.0rc1', '3.0.0rc2', '3.0.0rc3', '3.0.0rc4', '3.0.1', '3.0.1rc1', '3.1.0', '3.1.0rc1', '3.1.0rc2', '3.1.0rc3', '3.1.1', '3.1.1rc1', '3.1.1rc2', '3.1.1rc3', '3.2.0', '3.2.0rc1', '3.2.0rc2', '3.2.1', '3.2.1rc1', '3.2.2', '3.2.2rc1', '3.2.3', '3.2.3rc1', '3.2.3rc2', '3.3.0', '3.3.0rc1', '3.3.1', '3.3.1rc1', '3.3.2', '3.3.2rc1', '3.3.3', '3.3.3rc1', '3.3.4', '3.3.4rc1', '3.4.0', '3.4.0rc1', '3.4.0rc2', '3.4.1', '3.4.1rc1', '3.4.1rc2', '3.4.1rc3', '3.4.2', '3.4.2rc1', '3.4.3', '3.4.3rc1', '3.4.3rc2', '3.4.4', '3.4.4rc1', '3.4.5', '3.4.5rc1', '4.0.0', '4.0.0rc1', '4.0.0rc2', '4.0.0rc3', '4.0.1rc1', '4.1.0', '4.1.1', '4.1.1rc1', '4.1.2', '4.1.2rc1', '4.1.3', '4.1.3rc1', '4.1.4', '4.1.4rc1', '4.1.5', '4.1.5rc1', '4.1.6', '4.1.6rc1', '4.1.7rc1', '4.2.0', '4.2.0rc1', '4.2.1', '4.2.1rc1', '4.2.2rc1', '4.3.0', '4.3.0rc1', '4.3.1', '4.3.1rc1', '4.3.2rc1', '4.3.2rc2']}], 'modified': '2023-07-03T20:28:23.811646+00:00', 'published': '2023-06-22T23:15:00+00:00', 'references': [{'url': 'https://github.com/dpgaspar/Flask-AppBuilder/commit/ae25ad4c87a9051ebe4a4e8f02aee73232642626', 'type': 'FIX'}, {'url': 'https://github.com/dpgaspar/Flask-AppBuilder/releases/tag/v4.3.2', 'type': 'WEB'}, {'url': 'https://github.com/dpgaspar/Flask-AppBuilder/pull/2045', 'type': 'FIX'}, {'url': 'https://github.com/dpgaspar/Flask-AppBuilder/security/advisories/GHSA-jhpr-j7cq-3jp3', 'type': 'ADVISORY'}]}
305969b0606182d47c2f25448d03690a25463efc9e3c54d887c261bc2d215912
2026-05-29 08:31:41.726529+03:00
2026-05-29 08:31:41.726529+03:00
csaf_mieleciekg.ndjson
283c604857cf54912c8dcd6625731cb3f5f596de764d4a789cd4ec544ee7db8c
{'document': {'lang': 'en-GB', 'notes': [{'text': 'For process data documentation purposes the laboratory washers, thermal disinfectors and washer-disinfectors can be integrated in a TCP/IP network by utilizing the affected communication module.\n\nThe communication module is separate from the actual device control and uses a chipset from Digi International.\n\nThe TCP / IP stack required for networking is implemented in this chipset with the help of a 3rd party library from Treck. External security researchers have identified several security holes in this library called Ripple20. The most critical vulnerability allows an external attacker to execute arbitrary code on the chip and thus also on the communication module.\n\nThe above named communication module can be integrated into the following laboratory washers, thermal disinfectors and washer- disinfectors:\n\n- PG 8581\n- PG 8582\n- PG 8583\n- PG 8583 CD\n- PG 8591\n- PG 8582 CD\n- PG 8592\n- PG 8593\n- PG 8562', 'title': 'Summary', 'category': 'summary'}, {'text': 'The communication modules intended functionality (process documentation) cannot be guaranteed after a successful attack – authenticity availability and integrity of the data are at risk.\n\nThe security issue has no impact on the devices safety and cleaning and disinfection results of the laboratory washers, thermal disinfectors and washer-disinfectors.', 'title': 'Impact', 'category': 'description'}, {'text': 'A security patch will be installed on the devices during regular maintenance and device requalification by the Miele customer service or authorized service partners.', 'title': 'Remediation', 'category': 'description'}, {'text': 'The intended use of the devices and the networking functionalities do not require internet connection. Please operate the devices only in a secure local network to further reduce the risk.', 'title': 'Mitigation', 'category': 'description'}], 'title': 'Miele: Treck TCP/IP Vulnerabilities (Ripple20) affecting Communication Module XKM3000 L MED', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2020-024', 'status': 'final', 'aliases': ['VDE-2020-024'], 'version': '2', 'generator': {'date': '2024-11-13T14:53:10.377Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.13'}}, 'revision_history': [{'date': '2020-07-08T07:29:00.000Z', 'number': '1', 'summary': 'Initial revision.'}, {'date': '2025-05-14T12:28:19.000Z', 'number': '2', 'summary': 'Fix: version space'}], 'current_release_date': '2025-05-14T12:28:19.000Z', 'initial_release_date': '2020-07-08T07:29:00.000Z'}, 'publisher': {'name': 'Miele & Cie KG', 'category': 'vendor', 'namespace': 'https://www.miele.com', 'contact_details': 'psirt@miele.com'}, 'references': [{'url': 'https://certvde.com/en/advisories/VDE-2020-024/', 'summary': 'VDE-2020-024: Miele: Treck TCP/IP Vulnerabilities (Ripple20) affecting Communication Module XKM3000 L MED - HTML', 'category': 'self'}, {'url': 'https://certvde.com/de/advisories/vendor/miele/', 'summary': 'CERT@VDE Security Advisories for Miele', 'category': 'external'}, {'url': 'https://miele.csaf-tp.certvde.com/.well-known/csaf/white/2020/vde-2020-024.json', 'summary': 'VDE-2020-024: Miele: Treck TCP/IP Vulnerabilities (Ripple20) affecting Communication Module XKM3000 L MED - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}]}, 'product_tree': {'branches': [{'name': 'Miele', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'XKM3000 L MED', 'product': {'name': 'Hardware XKM3000 L MED', 'product_id': 'CSAFPID-11001', 'product_identification_helper': {'model_numbers': ['10440980', '09902230']}}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': '<=1.9.x', 'product': {'name': 'Firmware <=1.9.x', 'product_id': 'CSAFPID-21002'}, 'category': 'product_version_range'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=1.9.x installed on Hardware XKM3000 L MED', 'product_id': 'CSAFPID-31003'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11001'}]}, 'vulnerabilities': [{'cve': 'CVE-2020-11896', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'The Treck TCP/IP stack before 6.0.1.66 allows Remote Code Execution, related to IPv4 tunneling.', 'title': 'Description', 'category': 'description'}], 'title': 'CVE-2020-11896', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 10, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H', 'temporalScore': 10, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 10, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31003']}], 'remediations': [{'details': 'The intended use of the devices and the networking functionalities do not require internet connection. Please operate the devices only in a secure local network to further reduce the risk.', 'category': 'mitigation', 'product_ids': ['CSAFPID-31003']}, {'details': 'A security patch will be installed on the devices during regular maintenance and device requalification by the Miele customer service or authorized service partners.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31003']}], 'product_status': {'known_affected': ['CSAFPID-31003']}}, {'cve': 'CVE-2020-11897', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'The Treck TCP/IP stack before 5.0.1.35 has an Out-of-Bounds Write via multiple malformed IPv6 packets.', 'title': 'Description', 'category': 'description'}], 'title': 'CVE-2020-11897', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 10, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H', 'temporalScore': 10, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 10, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31003']}], 'remediations': [{'details': 'The intended use of the devices and the networking functionalities do not require internet connection. Please operate the devices only in a secure local network to further reduce the risk.', 'category': 'mitigation', 'product_ids': ['CSAFPID-31003']}, {'details': 'A security patch will be installed on the devices during regular maintenance and device requalification by the Miele customer service or authorized service partners.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31003']}], 'product_status': {'known_affected': ['CSAFPID-31003']}}, {'cve': 'CVE-2020-11898', 'cwe': {'id': 'CWE-200', 'name': 'Exposure of Sensitive Information to an Unauthorized Actor'}, 'notes': [{'text': 'The Treck TCP/IP stack before 6.0.1.66 improperly handles an IPv4/ICMPv4 Length Parameter Inconsistency, which might allow remote attackers to trigger an information leak.', 'title': 'Description', 'category': 'description'}], 'title': 'CVE-2020-11898', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.1, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H', 'temporalScore': 9.1, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.1, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31003']}], 'remediations': [{'details': 'The intended use of the devices and the networking functionalities do not require internet connection. Please operate the devices only in a secure local network to further reduce the risk.', 'category': 'mitigation', 'product_ids': ['CSAFPID-31003']}, {'details': 'A security patch will be installed on the devices during regular maintenance and device requalification by the Miele customer service or authorized service partners.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31003']}], 'product_status': {'known_affected': ['CSAFPID-31003']}}, {'cve': 'CVE-2020-11901', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'The Treck TCP/IP stack before 6.0.1.66 allows Remote Code execution via a single invalid DNS response.', 'title': 'Description', 'category': 'description'}], 'title': 'CVE-2020-11901', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 9, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H', 'temporalScore': 9, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.1, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31003']}], 'remediations': [{'details': 'The intended use of the devices and the networking functionalities do not require internet connection. Please operate the devices only in a secure local network to further reduce the risk.', 'category': 'mitigation', 'product_ids': ['CSAFPID-31003']}, {'details': 'A security patch will be installed on the devices during regular maintenance and device requalification by the Miele customer service or authorized service partners.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31003']}], 'product_status': {'known_affected': ['CSAFPID-31003']}}, {'cve': 'CVE-2020-11900', 'cwe': {'id': 'CWE-415', 'name': 'Double Free'}, 'notes': [{'text': 'The Treck TCP/IP stack before 6.0.1.41 has an IPv4 tunneling Double Free.', 'title': 'Description', 'category': 'description'}], 'title': 'CVE-2020-11900', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.2, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H', 'temporalScore': 8.2, 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 8.2, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31003']}], 'remediations': [{'details': 'The intended use of the devices and the networking functionalities do not require internet connection. Please operate the devices only in a secure local network to further reduce the risk.', 'category': 'mitigation', 'product_ids': ['CSAFPID-31003']}, {'details': 'A security patch will be installed on the devices during regular maintenance and device requalification by the Miele customer service or authorized service partners.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31003']}], 'product_status': {'known_affected': ['CSAFPID-31003']}}, {'cve': 'CVE-2020-11902', 'cwe': {'id': 'CWE-125', 'name': 'Out-of-bounds Read'}, 'notes': [{'text': 'The Treck TCP/IP stack before 6.0.1.66 has an IPv6OverIPv4 tunneling Out-of-bounds Read.', 'title': 'Description', 'category': 'description'}], 'title': 'CVE-2020-11902', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.3, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L', 'temporalScore': 7.3, 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'LOW', 'environmentalScore': 7.3, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31003']}], 'remediations': [{'details': 'The intended use of the devices and the networking functionalities do not require internet connection. Please operate the devices only in a secure local network to further reduce the risk.', 'category': 'mitigation', 'product_ids': ['CSAFPID-31003']}, {'details': 'A security patch will be installed on the devices during regular maintenance and device requalification by the Miele customer service or authorized service partners.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31003']}], 'product_status': {'known_affected': ['CSAFPID-31003']}}, {'cve': 'CVE-2020-11904', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'The Treck TCP/IP stack before 6.0.1.66 has an Integer Overflow during Memory Allocation that causes an Out-of-Bounds Write.', 'title': 'Description', 'category': 'description'}], 'title': 'CVE-2020-11904', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.3, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L', 'temporalScore': 7.3, 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'LOW', 'environmentalScore': 7.3, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31003']}], 'remediations': [{'details': 'The intended use of the devices and the networking functionalities do not require internet connection. Please operate the devices only in a secure local network to further reduce the risk.', 'category': 'mitigation', 'product_ids': ['CSAFPID-31003']}, {'details': 'A security patch will be installed on the devices during regular maintenance and device requalification by the Miele customer service or authorized service partners.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31003']}], 'product_status': {'known_affected': ['CSAFPID-31003']}}, {'cve': 'CVE-2020-11905', 'cwe': {'id': 'CWE-125', 'name': 'Out-of-bounds Read'}, 'notes': [{'text': 'The Treck TCP/IP stack before 6.0.1.66 has a DHCPv6 Out-of-bounds Read.', 'title': 'Description', 'category': 'description'}], 'title': 'CVE-2020-11905', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'ADJACENT_NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'temporalScore': 6.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 6.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-31003']}], 'remediations': [{'details': 'The intended use of the devices and the networking functionalities do not require internet connection. Please operate the devices only in a secure local network to further reduce the risk.', 'category': 'mitigation', 'product_ids': ['CSAFPID-31003']}, {'details': 'A security patch will be installed on the devices during regular maintenance and device requalification by the Miele customer service or authorized service partners.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31003']}], 'product_status': {'known_affected': ['CSAFPID-31003']}}, {'cve': 'CVE-2020-11903', 'cwe': {'id': 'CWE-125', 'name': 'Out-of-bounds Read'}, 'notes': [{'text': 'The Treck TCP/IP stack before 6.0.1.28 has a DHCP Out-of-bounds Read.', 'title': 'Description', 'category': 'description'}], 'title': 'CVE-2020-11903', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'ADJACENT_NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'temporalScore': 6.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 6.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-31003']}], 'remediations': [{'details': 'The intended use of the devices and the networking functionalities do not require internet connection. Please operate the devices only in a secure local network to further reduce the risk.', 'category': 'mitigation', 'product_ids': ['CSAFPID-31003']}, {'details': 'A security patch will be installed on the devices during regular maintenance and device requalification by the Miele customer service or authorized service partners.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31003']}], 'product_status': {'known_affected': ['CSAFPID-31003']}}, {'cve': 'CVE-2020-11906', 'cwe': {'id': 'CWE-191', 'name': 'Integer Underflow (Wrap or Wraparound)'}, 'notes': [{'text': 'The Treck TCP/IP stack before 6.0.1.66 has an Ethernet Link Layer Integer Underflow.', 'title': 'Description', 'category': 'description'}], 'title': 'CVE-2020-11906', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.3, 'attackVector': 'ADJACENT_NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L', 'temporalScore': 6.3, 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'LOW', 'environmentalScore': 6.3, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-31003']}], 'remediations': [{'details': 'The intended use of the devices and the networking functionalities do not require internet connection. Please operate the devices only in a secure local network to further reduce the risk.', 'category': 'mitigation', 'product_ids': ['CSAFPID-31003']}, {'details': 'A security patch will be installed on the devices during regular maintenance and device requalification by the Miele customer service or authorized service partners.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31003']}], 'product_status': {'known_affected': ['CSAFPID-31003']}}, {'cve': 'CVE-2020-11907', 'notes': [{'text': 'The Treck TCP/IP stack before 6.0.1.66 improperly handles a Length Parameter Inconsistency in TCP.', 'title': 'Description', 'category': 'description'}], 'title': 'CVE-2020-11907', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.3, 'attackVector': 'ADJACENT_NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L', 'temporalScore': 6.3, 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'LOW', 'environmentalScore': 6.3, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-31003']}], 'remediations': [{'details': 'The intended use of the devices and the networking functionalities do not require internet connection. Please operate the devices only in a secure local network to further reduce the risk.', 'category': 'mitigation', 'product_ids': ['CSAFPID-31003']}, {'details': 'A security patch will be installed on the devices during regular maintenance and device requalification by the Miele customer service or authorized service partners.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31003']}], 'product_status': {'known_affected': ['CSAFPID-31003']}}, {'cve': 'CVE-2020-11899', 'cwe': {'id': 'CWE-125', 'name': 'Out-of-bounds Read'}, 'notes': [{'text': 'The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.', 'title': 'Description', 'category': 'description'}], 'title': 'CVE-2020-11899', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.4, 'attackVector': 'ADJACENT_NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L', 'temporalScore': 5.4, 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'LOW', 'environmentalScore': 5.4, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-31003']}], 'remediations': [{'details': 'The intended use of the devices and the networking functionalities do not require internet connection. Please operate the devices only in a secure local network to further reduce the risk.', 'category': 'mitigation', 'product_ids': ['CSAFPID-31003']}, {'details': 'A security patch will be installed on the devices during regular maintenance and device requalification by the Miele customer service or authorized service partners.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31003']}], 'product_status': {'known_affected': ['CSAFPID-31003']}}, {'cve': 'CVE-2020-11910', 'cwe': {'id': 'CWE-125', 'name': 'Out-of-bounds Read'}, 'notes': [{'text': 'The Treck TCP/IP stack before 6.0.1.66 has an ICMPv4 Out-of-bounds Read.', 'title': 'Description', 'category': 'description'}], 'title': 'CVE-2020-11910', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N', 'temporalScore': 5.3, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 5.3, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-31003']}], 'remediations': [{'details': 'The intended use of the devices and the networking functionalities do not require internet connection. Please operate the devices only in a secure local network to further reduce the risk.', 'category': 'mitigation', 'product_ids': ['CSAFPID-31003']}, {'details': 'A security patch will be installed on the devices during regular maintenance and device requalification by the Miele customer service or authorized service partners.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31003']}], 'product_status': {'known_affected': ['CSAFPID-31003']}}, {'cve': 'CVE-2020-11909', 'cwe': {'id': 'CWE-191', 'name': 'Integer Underflow (Wrap or Wraparound)'}, 'notes': [{'text': 'The Treck TCP/IP stack before 6.0.1.66 has an IPv4 Integer Underflow.', 'title': 'Description', 'category': 'description'}], 'title': 'CVE-2020-11909', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N', 'temporalScore': 5.3, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 5.3, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-31003']}], 'remediations': [{'details': 'The intended use of the devices and the networking functionalities do not require internet connection. Please operate the devices only in a secure local network to further reduce the risk.', 'category': 'mitigation', 'product_ids': ['CSAFPID-31003']}, {'details': 'A security patch will be installed on the devices during regular maintenance and device requalification by the Miele customer service or authorized service partners.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31003']}], 'product_status': {'known_affected': ['CSAFPID-31003']}}, {'cve': 'CVE-2020-11912', 'cwe': {'id': 'CWE-125', 'name': 'Out-of-bounds Read'}, 'notes': [{'text': 'The Treck TCP/IP stack before 6.0.1.66 has a TCP Out-of-bounds Read.', 'title': 'Description', 'category': 'description'}], 'title': 'CVE-2020-11912', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L', 'temporalScore': 5.3, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'LOW', 'environmentalScore': 5.3, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-31003']}], 'remediations': [{'details': 'The intended use of the devices and the networking functionalities do not require internet connection. Please operate the devices only in a secure local network to further reduce the risk.', 'category': 'mitigation', 'product_ids': ['CSAFPID-31003']}, {'details': 'A security patch will be installed on the devices during regular maintenance and device requalification by the Miele customer service or authorized service partners.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31003']}], 'product_status': {'known_affected': ['CSAFPID-31003']}}, {'cve': 'CVE-2020-11913', 'cwe': {'id': 'CWE-125', 'name': 'Out-of-bounds Read'}, 'notes': [{'text': 'The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.', 'title': 'Description', 'category': 'description'}], 'title': 'CVE-2020-11913', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N', 'temporalScore': 5.3, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 5.3, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-31003']}], 'remediations': [{'details': 'The intended use of the devices and the networking functionalities do not require internet connection. Please operate the devices only in a secure local network to further reduce the risk.', 'category': 'mitigation', 'product_ids': ['CSAFPID-31003']}, {'details': 'A security patch will be installed on the devices during regular maintenance and device requalification by the Miele customer service or authorized service partners.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31003']}], 'product_status': {'known_affected': ['CSAFPID-31003']}}, {'cve': 'CVE-2020-11911', 'cwe': {'id': 'CWE-862', 'name': 'Missing Authorization'}, 'notes': [{'text': 'The Treck TCP/IP stack before 6.0.1.66 has Improper ICMPv4 Access Control.', 'title': 'Description', 'category': 'description'}], 'title': 'CVE-2020-11911', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N', 'temporalScore': 5.3, 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 5.3, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-31003']}], 'remediations': [{'details': 'The intended use of the devices and the networking functionalities do not require internet connection. Please operate the devices only in a secure local network to further reduce the risk.', 'category': 'mitigation', 'product_ids': ['CSAFPID-31003']}, {'details': 'A security patch will be installed on the devices during regular maintenance and device requalification by the Miele customer service or authorized service partners.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31003']}], 'product_status': {'known_affected': ['CSAFPID-31003']}}, {'cve': 'CVE-2020-11908', 'notes': [{'text': "The Treck TCP/IP stack before 4.7.1.27 mishandles '\\0' termination in DHCP.", 'title': 'Description', 'category': 'description'}], 'title': 'CVE-2020-11908', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 4.3, 'attackVector': 'ADJACENT_NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L', 'temporalScore': 4.3, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'LOW', 'environmentalScore': 4.3, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-31003']}], 'remediations': [{'details': 'The intended use of the devices and the networking functionalities do not require internet connection. Please operate the devices only in a secure local network to further reduce the risk.', 'category': 'mitigation', 'product_ids': ['CSAFPID-31003']}, {'details': 'A security patch will be installed on the devices during regular maintenance and device requalification by the Miele customer service or authorized service partners.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31003']}], 'product_status': {'known_affected': ['CSAFPID-31003']}}, {'cve': 'CVE-2020-11914', 'cwe': {'id': 'CWE-125', 'name': 'Out-of-bounds Read'}, 'notes': [{'text': 'The Treck TCP/IP stack before 6.0.1.66 has an ARP Out-of-bounds Read.', 'title': 'Description', 'category': 'description'}], 'title': 'CVE-2020-11914', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 4.3, 'attackVector': 'ADJACENT_NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N', 'temporalScore': 4.3, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 4.3, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-31003']}], 'remediations': [{'details': 'The intended use of the devices and the networking functionalities do not require internet connection. Please operate the devices only in a secure local network to further reduce the risk.', 'category': 'mitigation', 'product_ids': ['CSAFPID-31003']}, {'details': 'A security patch will be installed on the devices during regular maintenance and device requalification by the Miele customer service or authorized service partners.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31003']}], 'product_status': {'known_affected': ['CSAFPID-31003']}}]}
c5b277d827a4633001c7babdb2a849e2aff73682b48f61ded78111deaab01ec1
2026-05-29 08:30:32.860956+03:00
2026-05-29 08:30:32.860956+03:00
csaf_mieleciekg.ndjson
7e76a5c9e1d7428c9ddc22637d50b8c2333a13a694157755dc43119cf410d9e4
{'document': {'lang': 'en-GB', 'notes': [{'text': 'The Miele Benchmark Programming Tool on a Microsoft Windows operating system, selects a folder by default upon installation that is writable for all users (C:\\\\MIELE_SERVICE). After the installation of the tool, users without administrative privileges are able to exchange or delete executable files in this path.', 'title': 'Summary', 'category': 'summary'}, {'text': 'A new version (1.2.72) of the Benchmark Programming Tool, which closes the named vulnerability, is available for download on the Miele website:\xa0https://www.miele.de/p/miele-benchmark-programming-tool-2296.htm', 'title': 'Mitigation', 'category': 'description'}, {'text': 'As a further risk-minimizing measure, the write permissions of the installation folder C:\\\\Miele_Service\\\\ Miele Benchmark Programming Tool can be adjusted so that an exchange of files is only possible with administrative permissions. This is also possible without reinstalling or updating the tool. The procedure for adjusting the permissions depends on the Microsoft Windows operating system environment used and in most cases requires administrative rights.', 'title': 'Remediation', 'category': 'description'}], 'title': 'Miele: Security vulnerability in Benchmark Programming Tool', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2022-015', 'status': 'final', 'aliases': ['VDE-2022-015'], 'version': '1', 'generator': {'date': '2025-04-28T10:00:03.241Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.24'}}, 'revision_history': [{'date': '2022-04-27T12:00:00.000Z', 'number': '1', 'summary': 'Initial revision.'}], 'current_release_date': '2022-04-27T12:00:00.000Z', 'initial_release_date': '2022-04-27T12:00:00.000Z'}, 'publisher': {'name': 'Miele & Cie KG', 'category': 'vendor', 'namespace': 'https://www.miele.com', 'contact_details': 'psirt@miele.com'}, 'references': [{'url': 'https://certvde.com/en/advisories/VDE-2022-015/', 'summary': 'VDE-2022-015: Miele: Security vulnerability in Benchmark Programming Tool - HTML', 'category': 'self'}, {'url': 'https://miele.csaf-tp.certvde.com/.well-known/csaf/white/2022/vde-2022-015.json', 'summary': 'VDE-2022-015: Miele: Security vulnerability in Benchmark Programming Tool - CSAF', 'category': 'self'}, {'url': 'https://www.miele.com', 'summary': 'Vendor PSIRT', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/miele/', 'summary': 'CERT@VDE Security Advisories for Miele & Cie KG', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}, {'summary': 'reporting', 'organization': 'SEC Consult Vulnerability Lab'}]}, 'product_tree': {'branches': [{'name': 'Vendor', 'branches': [{'name': 'Software', 'branches': [{'name': 'Benchmark Programming Tool', 'branches': [{'name': '<=1.2.71', 'product': {'name': 'Benchmark Programming Tool <=1.2.71', 'product_id': 'CSAFPID-51001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2022-22521', 'cwe': {'id': 'CWE-269', 'name': 'Improper Privilege Management'}, 'notes': [{'text': 'In Miele Benchmark Programming Tool with versions Prior to 1.2.71, executable files manipulated by attackers are unknowingly executed with users privileges. An attacker with low privileges may trick a user with administrative privileges to execute these binaries as admin.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2022-22521', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.3, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H', 'temporalScore': 7.3, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.3, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': 'As a further risk-minimizing measure, the write permissions of the installation folder C:\\\\Miele_Service\\\\ Miele Benchmark Programming Tool can be adjusted so that an exchange of files is only possible with administrative permissions. This is also possible without reinstalling or updating the tool. The procedure for adjusting the permissions depends on the Microsoft Windows operating system environment used and in most cases requires administrative rights.', 'category': 'workaround', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'known_affected': ['CSAFPID-51001']}}]}
9426b792612cc09157866ff4126ef0db467b2fc40a17301c5f9740eed2a11ab0
2026-05-29 08:30:32.860956+03:00
2026-05-29 08:30:32.860956+03:00
csaf_mieleciekg.ndjson
90442495c9ec810e36355fe0f1c1ee81be471cea5be44f6e6bbcde962e98ade6
{'document': {'lang': 'en-GB', 'notes': [{'text': 'Up until October 5th, 2022 the ease2pay API used by Miele\'s "AppWash" MobileApp was vulnerable to an authorization bypass. A low privileged, remote attacker would have been able to gain read and partial write access to other users data by modifying a small part of a HTTP request sent to the API. Reading or changing the password of another user was not possible, thus no impact to Availability.', 'title': 'Summary', 'category': 'summary'}, {'text': 'The evaluation of the log files by ease2pay did not show any sign of actual exploitation of the vulnerability, extraction of data or misuse.', 'title': 'Impact', 'category': 'description'}, {'text': 'The ease2pay cloud service used by appWash was fixed on 05.10.2022. The tokens used for session authentication were changed to a secure state of the art solution. All affected tokens have been invalidated and new tokens were issued.\nTherefore, no actions have to be taken by the users.', 'title': 'Remediation', 'category': 'description'}], 'title': 'Miele: Vulnerability in ease2pay cloud service used by appWash', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2022-052', 'status': 'final', 'aliases': ['VDE-2022-052'], 'version': '1', 'generator': {'date': '2025-05-05T12:10:12.123Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.24'}}, 'revision_history': [{'date': '2022-11-21T09:00:00.000Z', 'number': '1', 'summary': 'Initial revision.'}], 'current_release_date': '2022-11-21T09:00:00.000Z', 'initial_release_date': '2022-11-21T09:00:00.000Z'}, 'publisher': {'name': 'Miele & Cie KG', 'category': 'vendor', 'namespace': 'https://www.miele.com', 'contact_details': 'psirt@miele.com'}, 'references': [{'url': 'https://certvde.com/en/advisories/VDE-2022-052/', 'summary': 'VDE-2022-052: Miele: Vulnerability in ease2pay cloud service used by appWash - HTML', 'category': 'self'}, {'url': 'https://miele.csaf-tp.certvde.com/.well-known/csaf/white/2022/vde-2022-052.json', 'summary': 'VDE-2022-052: Miele: Vulnerability in ease2pay cloud service used by appWash - CSAF', 'category': 'self'}, {'url': 'https://www.miele.com', 'summary': 'Vendor PSIRT', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/miele/', 'summary': 'CERT@VDE Security Advisories for Miele & Cie KG', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}, {'summary': 'reporting', 'organization': 'Bishoy Roufael'}]}, 'product_tree': {'branches': [{'name': 'Miele', 'branches': [{'name': 'Software', 'branches': [{'name': 'appWash by Miele', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'appWash by Miele vers:all/*', 'product_id': 'CSAFPID-51001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2022-3589', 'cwe': {'id': 'CWE-639', 'name': 'Authorization Bypass Through User-Controlled Key'}, 'notes': [{'text': 'An API Endpoint used by Miele\'s "AppWash" MobileApp in all versions was vulnerable to an authorization bypass. A low privileged, remote attacker would have been able to gain read and partial write access to other users data by modifying a small part of a HTTP request sent to the API. Reading or changing the password of another user was not possible, thus no impact to Availability.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2022-3589', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.1, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N', 'temporalScore': 8.1, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'NONE', 'environmentalScore': 8.1, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': 'The ease2pay cloud service used by appWash was fixed on 05.10.2022. The tokens used for session authentication were changed to a secure state of the art solution. All affected tokens have been invalidated and new tokens were issued.\nTherefore, no actions have to be taken by the users.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'known_affected': ['CSAFPID-51001']}}]}
315fb31061cd1e44236dd7c9ca0d5750e131638c62b393991149b03b799a4263
2026-05-29 08:30:32.860956+03:00
2026-05-29 08:30:32.860956+03:00
csaf_lenzese.ndjson
fc09287574ba18388377cb3423725156397a88f3456c8edbc5e684ea5b071539
{'document': {'lang': 'en-US', 'notes': [{'text': 'The affected products contain a CODESYS Control runtime system in version V2. They are therefore affected by the\nvulnerability described in CODESYS Advisory 2021-06. It provides a communication server for the communication with clients like the CODESYS Development System.\n\nThe 9400 servo inverters is only affected if the communication Path via the inserted EtherNet Module E94AYCEN on slot MXI1 or MXI2 is used. If the Module E94AYCEN is used, the following Versions are affected.\n\nProduct Identification: E94xSHxxx (Single Drive, High Line)\nProduct Identification: E94xMHxxx (Multi Drive, High Line)\n\nRemark: If the product identification of your 9400 product does not fit to the above mentioned identification, please contact Lenze at Security.de@Lenze.com.\n\nThe Versions P (power supply module) and R (regenerative power supply module) are not affected. Furthermore, the Variant P (PLC) and the Variant S (StateLine) are not affected. The communication paths via the diagnostic interface X6, the system bus (CAN) X1 or the field buses (other than the named Ethernet module) that can be plugged into the module slots MXI1 or MXI2 are not affected.\n\nThe focus is therefore on 9400 servo inverters with the product-identification E94x{S/M}{H}... with a plugged in Ethernet module E94AYCEN... in module slot MXI1 or MXI2 and communication with the Engineer-Tools via exactly this channel.\n\nIn addition to the standard tool Engineer, there is also a special Version of the PLC Designer (Version 0.x). The communication path to the PLC Designer is not considered with the planned update and the vulnerabilities here remain even after the update. Here, the customer must provide a secure Environment, see Mitigation.', 'title': 'Summary', 'category': 'summary'}, {'text': 'A crafted request may cause a heap-based, a stack-based buffer overflow or a buffer over-read in the affected products, resulting in a denial-of-service condition or being utilized for remote code execution.\n\nThe crafted requests are only processed on the products, if no online password is configured on the products or if the attacker has previously successfully authenticated himself at the affected products.', 'title': 'Impact', 'category': 'description'}, {'text': 'As part of a security strategy, Lenze SE recommends the following general defense measures to reduce the risk of exploits:\n\n- Only use the products in a protected and controlled environment to minimize network impact and to ensure that they are inaccessible from outside.\n- Use firewalls to protect the automation system network and to separate it from other networks.\n\n\nRemark: One Measure should be to Block port 1200 via the firewall and open this port for authenticated access only.\n\n- Use Virtual Private Networks (VPN) tunnels when remote access is required.\n- Use IDS (Intrusion Detection Systems) where possible to detect anomalies in the network.\n- Activate and use user administration and password functions.\n- Use encrypted communication links.\nRestrict access to both the development tools and their projects and the products of the automation system by physical means, operating system functions, etc.\n- Protect the development tool by using the latest virus detection solutions.', 'title': 'Mitigation', 'category': 'description'}, {'text': 'The affected products\n\n- Embedded Line EL 1800-9800\n- Command Station CS 5800-9800\n- Control Cabinet PC 2800\n- EL100 PLC\n\nare at the end of life and are no longer available. A further development or adaption of the\nproducts is no longer planned and no longer possible from the process of discontinuation.\n\nThe affected product\n\n- 9400 servo inverters\n\nin the constellation described above will be revised in the next product release. An update is\nplanned for Q2 2022.', 'title': 'Remediation', 'category': 'description'}], 'title': 'Lenze: Multiple Vulnerabilities in CODESYS Control V2 communication', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2021-048', 'status': 'final', 'aliases': ['VDE-2021-048'], 'version': '1', 'generator': {'date': '2025-03-24T12:03:41.535Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.21'}}, 'revision_history': [{'date': '2021-10-04T12:33:00.000Z', 'number': '1', 'summary': 'Initial revision.'}], 'current_release_date': '2021-10-04T12:33:00.000Z', 'initial_release_date': '2021-10-04T12:33:00.000Z'}, 'publisher': {'name': 'Lenze SE', 'category': 'vendor', 'namespace': 'https://www.lenze.com', 'contact_details': 'psirt@lenze.com'}, 'references': [{'url': 'https://certvde.com/de/advisories/vendor/lenze/', 'summary': 'Lenze advisory overview at CERT@VDE', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/VDE-2021-048', 'summary': 'VDE-2021-048: Lenze: Multiple Vulnerabilities in CODESYS Control V2 communication - HTML', 'category': 'self'}, {'url': 'https://lenze.csaf-tp.certvde.com/.well-known/csaf/white/2021/vde-2021-048.json', 'summary': 'VDE-2021-048: Lenze: Multiple Vulnerabilities in CODESYS Control V2 communication - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}, {'names': ['Sergey Fedonin', 'Denis Goryushev', 'Anton Dorfman'], 'summary': 'discovered and reported', 'organization': 'Positive Technologies'}, {'names': ['Yossi Reuven'], 'summary': 'discovered and reported', 'organization': 'SCADAfence'}]}, 'product_tree': {'branches': [{'name': 'Weidmueller', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'Command Station CS 5800-9800', 'product': {'name': 'Command Station CS 5800-9800', 'product_id': 'CSAFPID-11001'}, 'category': 'product_name'}, {'name': 'Control Cabinet PC 2800', 'product': {'name': 'Control Cabinet PC 2800', 'product_id': 'CSAFPID-11002'}, 'category': 'product_name'}, {'name': 'EL100 PLC', 'product': {'name': 'EL100 PLC', 'product_id': 'CSAFPID-11003'}, 'category': 'product_name'}, {'name': 'Embedded Line EL 1800-9800', 'product': {'name': 'Embedded Line EL 1800-9800', 'product_id': 'CSAFPID-11004'}, 'category': 'product_name'}, {'name': 'EtherNet Module E94AYCEN on slot MXI1 or MXI2 in 9400 servo inverters', 'product': {'name': 'EtherNet Module E94AYCEN on slot MXI1 or MXI2 in 9400 servo inverters', 'product_id': 'CSAFPID-11005', 'product_identification_helper': {'model_numbers': ['E94xSHxxx']}}, 'category': 'product_name'}, {'name': 'EtherNet Module E94AYCEN on slot MXI1 or MXI2 in 9400 servo inverters', 'product': {'name': 'EtherNet Module E94AYCEN on slot MXI1 or MXI2 in 9400 servo inverters', 'product_id': 'CSAFPID-11006', 'product_identification_helper': {'model_numbers': ['E94xMHxxx']}}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': '<=V15.02.04', 'product': {'name': 'Firmware <=V15.02.04', 'product_id': 'CSAFPID-21001'}, 'category': 'product_version_range'}, {'name': 'vers:all/*', 'product': {'name': 'Firmware vers:all/*', 'product_id': 'CSAFPID-21002'}, 'category': 'product_version_range'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware vers:all/* installed on Command Station CS 5800-9800', 'product_id': 'CSAFPID-31001'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware vers:all/* installed on Control Cabinet PC 2800', 'product_id': 'CSAFPID-31002'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11002'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware vers:all/* installed on EL100 PLC', 'product_id': 'CSAFPID-31003'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11003'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware vers:all/* installed on Embedded Line EL 1800-9800', 'product_id': 'CSAFPID-31004'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11004'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=V15.02.04 installed on EtherNet Module E94AYCEN on slot MXI1 or MXI2 in 9400 servo inverters', 'product_id': 'CSAFPID-31005'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11005'}], 'product_groups': [{'summary': 'Affected Products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}]}, 'vulnerabilities': [{'cve': 'CVE-2021-30188', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'CODESYS V2 runtime system SP before 2.4.7.55 has a Stack-based Buffer Overflow.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2021-30188', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}], 'remediations': [{'details': 'As part of a security strategy, Lenze SE recommends the following general defense measures to reduce the risk of exploits:\n\n- Only use the products in a protected and controlled environment to minimize network impact and to ensure that they are inaccessible from outside.\n- Use firewalls to protect the automation system network and to separate it from other networks.\n\n\nRemark: One Measure should be to Block port 1200 via the firewall and open this port for authenticated access only.\n\n- Use Virtual Private Networks (VPN) tunnels when remote access is required.\n- Use IDS (Intrusion Detection Systems) where possible to detect anomalies in the network.\n- Activate and use user administration and password functions.\n- Use encrypted communication links.\nRestrict access to both the development tools and their projects and the products of the automation system by physical means, operating system functions, etc.\n- Protect the development tool by using the latest virus detection solutions.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'The affected products\n\n- Embedded Line EL 1800-9800\n- Command Station CS 5800-9800\n- Control Cabinet PC 2800\n- EL100 PLC\n\nare at the end of life and are no longer available. A further development or adaption of the\nproducts is no longer planned and no longer possible from the process of discontinuation.\n\nThe affected product\n\n- 9400 servo inverters\n\nin the constellation described above will be revised in the next product release. An update is\nplanned for Q2 2022.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}}, {'cve': 'CVE-2021-30195', 'cwe': {'id': 'CWE-125', 'name': 'Out-of-bounds Read'}, 'notes': [{'text': 'CODESYS V2 runtime system before 2.4.7.55 has Improper Input Validation.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2021-30188', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}], 'remediations': [{'details': 'As part of a security strategy, Lenze SE recommends the following general defense measures to reduce the risk of exploits:\n\n- Only use the products in a protected and controlled environment to minimize network impact and to ensure that they are inaccessible from outside.\n- Use firewalls to protect the automation system network and to separate it from other networks.\n\n\nRemark: One Measure should be to Block port 1200 via the firewall and open this port for authenticated access only.\n\n- Use Virtual Private Networks (VPN) tunnels when remote access is required.\n- Use IDS (Intrusion Detection Systems) where possible to detect anomalies in the network.\n- Activate and use user administration and password functions.\n- Use encrypted communication links.\nRestrict access to both the development tools and their projects and the products of the automation system by physical means, operating system functions, etc.\n- Protect the development tool by using the latest virus detection solutions.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'The affected products\n\n- Embedded Line EL 1800-9800\n- Command Station CS 5800-9800\n- Control Cabinet PC 2800\n- EL100 PLC\n\nare at the end of life and are no longer available. A further development or adaption of the\nproducts is no longer planned and no longer possible from the process of discontinuation.\n\nThe affected product\n\n- 9400 servo inverters\n\nin the constellation described above will be revised in the next product release. An update is\nplanned for Q2 2022.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}}, {'cve': 'CVE-2021-30186', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'CODESYS V2 runtime system SP before 2.4.7.55 has a Heap-based Buffer Overflow.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2021-30186', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}], 'remediations': [{'details': 'As part of a security strategy, Lenze SE recommends the following general defense measures to reduce the risk of exploits:\n\n- Only use the products in a protected and controlled environment to minimize network impact and to ensure that they are inaccessible from outside.\n- Use firewalls to protect the automation system network and to separate it from other networks.\n\n\nRemark: One Measure should be to Block port 1200 via the firewall and open this port for authenticated access only.\n\n- Use Virtual Private Networks (VPN) tunnels when remote access is required.\n- Use IDS (Intrusion Detection Systems) where possible to detect anomalies in the network.\n- Activate and use user administration and password functions.\n- Use encrypted communication links.\nRestrict access to both the development tools and their projects and the products of the automation system by physical means, operating system functions, etc.\n- Protect the development tool by using the latest virus detection solutions.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'The affected products\n\n- Embedded Line EL 1800-9800\n- Command Station CS 5800-9800\n- Control Cabinet PC 2800\n- EL100 PLC\n\nare at the end of life and are no longer available. A further development or adaption of the\nproducts is no longer planned and no longer possible from the process of discontinuation.\n\nThe affected product\n\n- 9400 servo inverters\n\nin the constellation described above will be revised in the next product release. An update is\nplanned for Q2 2022.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}}]}
1b00384dd4405f7fbde8f94a932c4891db90e7983fef131984d126261f47993d
2026-05-29 08:30:33.318940+03:00
2026-05-29 08:30:33.318940+03:00
csaf_lenzese.ndjson
efe94a110f4bb16a0498698f714d24eb5a64569bee52161231424b047e2ed10c
{'document': {'lang': 'en-GB', 'notes': [{'text': 'The machine controller of the cabinet series include an OPC-UA server which uses an user management to authenticate clients via anonymous or user/password authentication. If the user/password authentication is selected, password verification is skipped upon second login. As a result, cases occur in which users can establish communication without correct authentication. This vulnerability is not located in the OPC-UA protocol or server, but in the interface to the products firmware.\n\nThis Security Advisory is only relevant for the following use cases:\n\n• the user management has been activated on the machine controller (is deactivated by default)\n\n• the OPC-UA Server is used\n\n• Data are transferred via a symbol configuration (is not available by default)', 'title': 'Summary', 'category': 'summary'}, {'text': 'The exploitation of the missing critical step in authentication may result in unauthorized use of the OPC-UA interface.', 'title': 'Impact', 'category': 'description'}, {'text': 'As part of a security strategy, Lenze SE recommends the following general defense measures to reduce the risk of exploits:\n\n• Only use the products in a protected and controlled environment to minimize network impact and to ensure that they are inaccessible from outside.\n\n• Use external firewalls to protect the automation system network and to separate it from other networks. Remark: One Measure should be to block port 4840 via the external firewall and open this port for authenticated access only.\n\n• Use Virtual Private Networks (VPN) tunnels when remote access is required.\n\n• Use IDS (Intrusion Detection Systems) where possible to detect anomalies in the network.\n\n• Activate and use user administration and password functions.\n\n• Use encrypted communication links.\n\n• Restrict access to both the development tools and their projects and the products of the automation system by physical means, operating system functions, etc.\n\n• Protect the development tool by using the latest virus detection solutions.\n\n• Use of certificate-based communication via the message security modes Sign or Sign&Encrypt and trust of the corresponding client certificates on the machine controller by the OPC-UA server. This can reduce the risk of exploiting this vulnerability.', 'title': 'Mitigation', 'category': 'description'}, {'text': 'Install version V01.08.01.3021, which solves the identified security vulnerability.', 'title': 'Remediation', 'category': 'description'}], 'title': 'Lenze: Vulnerability in the OPC-UA authentification connection in the firmware', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2022-030', 'status': 'final', 'aliases': ['VDE-2022-030'], 'version': '1', 'generator': {'date': '2025-04-23T18:36:11.196Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.23'}}, 'revision_history': [{'date': '2022-07-11T10:00:00.000Z', 'number': '1', 'summary': 'Initial revision.'}], 'current_release_date': '2022-07-11T10:00:00.000Z', 'initial_release_date': '2022-07-11T10:00:00.000Z'}, 'publisher': {'name': 'Lenze SE', 'category': 'vendor', 'namespace': 'https://www.lenze.com', 'contact_details': 'psirt@lenze.com'}, 'references': [{'url': 'https://certvde.com/en/advisories/VDE-2022-030/', 'summary': 'VDE-2022-030: Lenze: Vulnerability in the OPC-UA authentification connection in the firmware - HTML', 'category': 'self'}, {'url': 'https://lenze.csaf-tp.certvde.com/.well-known/csaf/white/2022/vde-2022-030.json', 'summary': 'VDE-2022-030: Lenze: Vulnerability in the OPC-UA authentification connection in the firmware - CSAF', 'category': 'self'}, {'url': 'https://www.lenze.com', 'summary': 'Vendor PSIRT', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/lenze/', 'summary': 'CERT@VDE Security Advisories for Lenze SE', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}]}, 'product_tree': {'branches': [{'name': 'Lenze', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'cabinet c520', 'product': {'name': 'cabinet c520', 'product_id': 'CSAFPID-11001'}, 'category': 'product_name'}, {'name': 'cabinet c550', 'product': {'name': 'cabinet c550', 'product_id': 'CSAFPID-11002'}, 'category': 'product_name'}, {'name': 'cabinet c750', 'product': {'name': 'cabinet c750', 'product_id': 'CSAFPID-11003'}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': 'V01.07.00.2757<V01.08.01.3021', 'product': {'name': 'Firmware V01.07.00.2757<V01.08.01.3021', 'product_id': 'CSAFPID-21001'}, 'category': 'product_version_range'}, {'name': 'V01.08.01.3021', 'product': {'name': 'Firmware V01.08.01.3021', 'product_id': 'CSAFPID-22001'}, 'category': 'product_version'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware V01.07.00.2757<V01.08.01.3021 installed on cabinet c520', 'product_id': 'CSAFPID-31001'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware V01.07.00.2757<V01.08.01.3021 installed on cabinet c550', 'product_id': 'CSAFPID-31002'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11002'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware V01.07.00.2757<V01.08.01.3021 installed on cabinet c750', 'product_id': 'CSAFPID-31003'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11003'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware V01.08.01.3021 installed on cabinet c520', 'product_id': 'CSAFPID-32001'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware V01.08.01.3021 installed on cabinet c550', 'product_id': 'CSAFPID-32002'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11002'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware V01.08.01.3021 installed on cabinet c750', 'product_id': 'CSAFPID-32003'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11003'}], 'product_groups': [{'summary': 'Affected products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003']}, {'summary': 'Fixed products.', 'group_id': 'CSAFGID-0002', 'product_ids': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003']}]}, 'vulnerabilities': [{'cve': 'CVE-2022-2302', 'cwe': {'id': 'CWE-287', 'name': 'Improper Authentication'}, 'notes': [{'text': 'Multiple Lenze products of the cabinet series skip the password verification upon second login. After a user has been logged on to the device once, a remote attacker can get full access without knowledge of the password.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2022-2302', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003']}], 'remediations': [{'details': 'As part of a security strategy, Lenze SE recommends the following general defense measures to reduce the risk of exploits:\n\n• Only use the products in a protected and controlled environment to minimize network impact and to ensure that they are inaccessible from outside.\n\n• Use external firewalls to protect the automation system network and to separate it from other networks. Remark: One Measure should be to block port 4840 via the external firewall and open this port for authenticated access only.\n\n• Use Virtual Private Networks (VPN) tunnels when remote access is required.\n\n• Use IDS (Intrusion Detection Systems) where possible to detect anomalies in the network.\n\n• Activate and use user administration and password functions.\n\n• Use encrypted communication links.\n\n• Restrict access to both the development tools and their projects and the products of the automation system by physical means, operating system functions, etc.\n\n• Protect the development tool by using the latest virus detection solutions.\n\n• Use of certificate-based communication via the message security modes Sign or Sign&Encrypt and trust of the corresponding client certificates on the machine controller by the OPC-UA server. This can reduce the risk of exploiting this vulnerability.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Install version V01.08.01.3021, which solves the identified security vulnerability.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003']}}]}
6db258a2ecd1997b17f1e95405fafb26c710e9dbbf6e4ddf98a84867dd8e2635
2026-05-29 08:30:33.318940+03:00
2026-05-29 08:30:33.318940+03:00
csaf_lenzese.ndjson
7795f75e81815b6822ea488be4ce15f88ada05be6965a7450846f9183f29a4d1
{'document': {'lang': 'en-GB', 'notes': [{'text': 'The following tools:\n* VisiWinNET Smart\n* VisiWinNET Professional\n* EASY UI Designer \ncreate a directory with insufficient permissions, allowing a low-level user the ability to add and modify certain files that hold SYSTEM privileges, which could lead to privilege escalation.', 'title': 'Summary', 'category': 'summary'}, {'text': 'The vulnerability allows a low-level user to escalate privileges to SYSTEM, which could lead to full system compromise.', 'title': 'Impact', 'category': 'description'}, {'text': 'Only use this tool in a protected and controlled environment to minimize network impact and to ensure that the tool is inaccessable from outside. In addition, the use of firewalls is recommended to reduce the attack surface, specially to the internet and the internal business network.', 'title': 'Mitigation', 'category': 'description'}, {'text': 'Lenze has released version 1.6.1 of the EASY UI Designer tool, which fixes the identified security vulnerability. The other two tools are no longer recommended for new applications and are being prepared for discontinuation.', 'title': 'Remediation', 'category': 'description'}], 'title': 'Lenze: Install Directory with insufficient permissions', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2024-053', 'status': 'final', 'aliases': ['VDE-2024-053'], 'version': '3', 'generator': {'date': '2025-03-19T15:02:53.134Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.21'}}, 'revision_history': [{'date': '2024-08-21T07:00:00.000Z', 'number': '1', 'summary': 'Initial revision.'}, {'date': '2024-11-06T11:27:01.000Z', 'number': '2', 'summary': 'Fix: correct certvde domain, added self-reference'}, {'date': '2025-03-13T11:30:00.000Z', 'number': '3', 'summary': 'Fix: product version'}], 'current_release_date': '2025-03-13T11:30:00.000Z', 'initial_release_date': '2024-09-03T08:00:00.000Z'}, 'publisher': {'name': 'Lenze SE', 'category': 'vendor', 'namespace': 'https://www.lenze.com', 'contact_details': 'psirt@lenze.com'}, 'references': [{'url': 'https://certvde.com/en/advisories/vendor/lenze/', 'summary': 'CERT@VDE Security Advisories for Lenze SE', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/VDE-2024-053', 'summary': 'VDE-2024-053: Lenze: Install Directory with insufficient permissions - HTML', 'category': 'self'}, {'url': 'https://lenze.csaf-tp.certvde.com/.well-known/csaf/white/2024/vde-2024-053.json', 'summary': 'VDE-2024-053: Lenze: Install Directory with insufficient permissions - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}, {'urls': ['https://www.lenze.com/en-us'], 'summary': 'reporting', 'organization': 'Lenze SE'}]}, 'product_tree': {'branches': [{'name': 'Lenze', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'EASY UI Designer', 'product': {'name': 'Lenze EASY UI Designer', 'product_id': 'CSAFPID-11001'}, 'category': 'product_name'}, {'name': 'VisiWinNET Smart', 'product': {'name': 'Lenze VisiWinNET Smart', 'product_id': 'CSAFPID-11002'}, 'category': 'product_name'}, {'name': 'VisiWinNET Professional', 'product': {'name': 'Lenze VisiWinNET Professional', 'product_id': 'CSAFPID-11003'}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'Firmware vers:all/*', 'product_id': 'CSAFPID-21001'}, 'category': 'product_version_range'}, {'name': '<1.6.0', 'product': {'name': 'Firmware <1.6.0', 'product_id': 'CSAFPID-21002'}, 'category': 'product_version_range'}, {'name': '1.6.1', 'product': {'name': 'Firmware 1.6.1', 'product_id': 'CSAFPID-22001'}, 'category': 'product_version'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware <1.6.0 installed on Lenze EASY UI Designer', 'product_id': 'CSAFPID-31001'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware vers:all/* installed on Lenze VisiWinNET Smart', 'product_id': 'CSAFPID-31002'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11002'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware vers:all/* installed on Lenze VisiWinNET Professional', 'product_id': 'CSAFPID-31003'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11003'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 1.6.1 installed on Lenze EASY UI Designer', 'product_id': 'CSAFPID-32001'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11001'}], 'product_groups': [{'summary': 'Affected products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003']}]}, 'vulnerabilities': [{'cve': 'CVE-2023-31468', 'cwe': {'id': 'CWE-276', 'name': 'Incorrect Default Permissions'}, 'notes': [{'text': 'An issue was discovered in Inosoft VisiWin 7 through 2022-2.1 (Runtime RT7.3 RC3 20221209.5). The "%PROGRAMFILES(X86)%\\INOSOFT GmbH" folder has weak permissions for Everyone, allowing an attacker to insert a Trojan horse file that runs as SYSTEM. 2024-1 is a fixed version.', 'title': 'Vulnerability Description', 'audience': 'all', 'category': 'description'}], 'title': 'CVE-2023-31468', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 7.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.8, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003']}], 'remediations': [{'details': 'Only use this tool in a protected and controlled environment to minimize network impact and to ensure that the tool is inaccessable from outside. In addition, the use of firewalls is recommended to reduce the attack surface, specially to the internet and the internal business network.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Lenze has released version 1.6.1 of the EASY UI Designer tool, which fixes the identified security vulnerability. The other two tools are no longer recommended for new applications and are being prepared for discontinuation.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003']}}]}
e3eac8bdb895cb515eeef168f42e09dfb194374933b2cc813861874050722dd0
2026-05-29 08:30:33.318940+03:00
2026-05-29 08:30:33.318940+03:00
csaf_lenzese.ndjson
45126d8bc788768b422c6dfa6931cc9d8fdd010faf231bd8f5057cce6fa2a9e1
{'document': {'lang': 'en-GB', 'notes': [{'text': 'The Lenze VPN client is vulnerable to a Local Privilege Escalation to root/SYSTEM by executing a configuration file which can be controlled by a non-privileged user. This occurs through a race condition exploit, where an attacker can overwrite the temporary OpenVPN configuration file located in a world-writable directory. By injecting malicious commands into the configuration file prior to its execution by the VPN client, an attacker can trigger arbitrary code execution with root/system privileges when a VPN connection is initiated. The vulnerability has been remediated in the version 1.4.4 of the Lenze VPN client.\nDue to some further developments and completion of the functional scope, it is recommended to update the firmware of the x500 IoT Gateway devices immediately, regardless of the current security vulnerability in the VPN client.', 'title': 'Summary', 'category': 'summary'}, {'text': 'The cyber security documentation currently describes some of the implemented functions and is thus intended to provide clarity in the functions described here.', 'title': 'General Recommendations', 'category': 'general'}, {'text': 'Lenze SE assumes no liability whatsoever for any kind of losses or consequential losses that occur by the distribution and/or use of this document . All information published in this document is provided on good faith by Lenze SE. Insofar as permissible by law, however, none of this information shall establish any guarantee, commitment or liability on the part of Lenze SE. Lenze SE reserves the right to change or update this document at any time.', 'title': 'Disclamer', 'category': 'legal_disclaimer'}, {'text': 'This vulnerability allows local non-privileged users to escalate their privileges to root or SYSTEM by exploiting a race condition in the Lenze VPN Client. Successful exploitation could lead to full system compromise, enabling attackers to execute arbitrary code with elevated privileges.', 'title': 'Impact', 'category': 'description'}, {'text': 'Obtain the updated VPN software (version >= 1.4.4) from https://cloud.lenze.digital/fleet-manager/tools and run the installer on a windows and macOS system or run the following\ncommands in an linux system: \ntar -xzf vpn_client_x64.tar.gz \ncd vpn_client_x64 \nsudo ./install', 'title': 'Remediation', 'category': 'description'}], 'title': 'Lenze: VPN Client Privilege Escalation in combination with Lenze x500 IoT Gateway', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2025-042', 'status': 'final', 'aliases': ['VDE-2025-042'], 'version': '1', 'generator': {'date': '2025-05-23T08:15:39.225Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.25'}}, 'revision_history': [{'date': '2025-05-27T09:00:00.000Z', 'number': '1', 'summary': 'Initial version'}], 'current_release_date': '2025-05-27T09:00:00.000Z', 'initial_release_date': '2025-05-27T09:00:00.000Z'}, 'publisher': {'name': 'Lenze SE', 'category': 'vendor', 'namespace': 'https://www.lenze.com', 'contact_details': 'psirt@lenze.com'}, 'references': [{'url': 'https://www.lenze.com/en-de/services/cyber-security', 'summary': 'Lenze SE Product Security Incident Response Team (PSIRT)', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/lenze/', 'summary': 'CERT@VDE Security Advisories for Lenze', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/VDE-2025-042/', 'summary': 'VDE-2025-042: Lenze: VPN Client Privilege Escalation in combination with Lenze x500 IoT Gateway - HTML', 'category': 'self'}, {'url': 'https://lenze.csaf-tp.certvde.com/.well-known/csaf/white/2025/vde-2025-042.json', 'summary': 'VDE-2025-042: Lenze: VPN Client Privilege Escalation in combination with Lenze x500 IoT Gateway - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}], 'aggregate_severity': {'text': 'High', 'namespace': 'https://www.first.org/cvss/calculator/3.1'}}, 'product_tree': {'branches': [{'name': 'Lenze', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'x500', 'branches': [{'name': 'x510', 'product': {'name': 'x510', 'product_id': 'CSAFPID-11001'}, 'category': 'product_name'}, {'name': 'x520', 'product': {'name': 'x520', 'product_id': 'CSAFPID-11002'}, 'category': 'product_name'}, {'name': 'x530', 'product': {'name': 'x530', 'product_id': 'CSAFPID-11003'}, 'category': 'product_name'}, {'name': 'x540', 'product': {'name': 'x540', 'product_id': 'CSAFPID-11004'}, 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': 'x510', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'Firmware x510 vers:all/*', 'product_id': 'CSAFPID-21001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'x520', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'Firmware x520 vers:all/*', 'product_id': 'CSAFPID-21002'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'x530', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'Firmware x530 vers:all/*', 'product_id': 'CSAFPID-21003'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'x540', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'Firmware x540 vers:all/*', 'product_id': 'CSAFPID-21004'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Software', 'branches': [{'name': 'Lenze VPN Client', 'branches': [{'name': '<1.4.4', 'product': {'name': 'Lenze VPN Client <1.4.4', 'product_id': 'CSAFPID-51001'}, 'category': 'product_version_range'}, {'name': '1.4.4', 'product': {'name': 'Lenze VPN Client 1.4.4', 'product_id': 'CSAFPID-52001'}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware x510 vers:all/* installed on x510', 'product_id': 'CSAFPID-31001'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'external_component_of', 'full_product_name': {'name': 'Lenze VPN Client <1.4.4 external component of Firmware x510 vers:all/* installed on x510', 'product_id': 'CSAFPID-31002'}, 'product_reference': 'CSAFPID-51001', 'relates_to_product_reference': 'CSAFPID-31001'}, {'category': 'external_component_of', 'full_product_name': {'name': 'Lenze VPN Client 1.4.4 external component of Firmware x510 vers:all/* installed on x510', 'product_id': 'CSAFPID-32001'}, 'product_reference': 'CSAFPID-52001', 'relates_to_product_reference': 'CSAFPID-31001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware x520 vers:all/* installed on x520', 'product_id': 'CSAFPID-31003'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11002'}, {'category': 'external_component_of', 'full_product_name': {'name': 'Lenze VPN Client <1.4.4 external component of Firmware x520 vers:all/* installed on x520', 'product_id': 'CSAFPID-31004'}, 'product_reference': 'CSAFPID-51001', 'relates_to_product_reference': 'CSAFPID-31003'}, {'category': 'external_component_of', 'full_product_name': {'name': 'Lenze VPN Client 1.4.4 external component of Firmware x520 vers:all/* installed on x520', 'product_id': 'CSAFPID-32002'}, 'product_reference': 'CSAFPID-52001', 'relates_to_product_reference': 'CSAFPID-31003'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware x530 vers:all/* installed on x530', 'product_id': 'CSAFPID-31005'}, 'product_reference': 'CSAFPID-21003', 'relates_to_product_reference': 'CSAFPID-11003'}, {'category': 'external_component_of', 'full_product_name': {'name': 'Lenze VPN Client <1.4.4 external component of Firmware x530 vers:all/* installed on x530', 'product_id': 'CSAFPID-31006'}, 'product_reference': 'CSAFPID-51001', 'relates_to_product_reference': 'CSAFPID-31005'}, {'category': 'external_component_of', 'full_product_name': {'name': 'Lenze VPN Client 1.4.4 external component of Firmware x530 vers:all/* installed on x530', 'product_id': 'CSAFPID-32003'}, 'product_reference': 'CSAFPID-52001', 'relates_to_product_reference': 'CSAFPID-31005'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware x540 vers:all/* installed on x540', 'product_id': 'CSAFPID-31007'}, 'product_reference': 'CSAFPID-21004', 'relates_to_product_reference': 'CSAFPID-11004'}, {'category': 'external_component_of', 'full_product_name': {'name': 'Lenze VPN Client <1.4.4 external component of Firmware x540 vers:all/* installed on x540', 'product_id': 'CSAFPID-31008'}, 'product_reference': 'CSAFPID-51001', 'relates_to_product_reference': 'CSAFPID-31007'}, {'category': 'external_component_of', 'full_product_name': {'name': 'Lenze VPN Client 1.4.4 external component of Firmware x540 vers:all/* installed on x540', 'product_id': 'CSAFPID-32004'}, 'product_reference': 'CSAFPID-52001', 'relates_to_product_reference': 'CSAFPID-31007'}], 'product_groups': [{'summary': 'Affected products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-31002', 'CSAFPID-31004', 'CSAFPID-31006', 'CSAFPID-31008']}, {'summary': 'Fixed products.', 'group_id': 'CSAFGID-0002', 'product_ids': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-32004']}]}, 'vulnerabilities': [{'cve': 'CVE-2025-26168', 'cwe': {'id': 'CWE-732', 'name': 'Incorrect Permission Assignment for Critical Resource'}, 'notes': [{'text': 'IXON VPN Client before 1.4.4 on Linux and macOS allows Local Privilege Escalation to root because there is code execution from a configuration file that can be controlled by a low-privileged user. There is a race condition in which a temporary configuration file, in a world-writable directory, can be overwritten.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2025-26168', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 8.1, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-31002', 'CSAFPID-31004', 'CSAFPID-31006', 'CSAFPID-31008']}], 'remediations': [{'details': 'Obtain the updated VPN software (version >= 1.4.4) from https://cloud.lenze.digital/fleet-manager/tools and run the installer on a windows and macOS system or run the following\ncommands in an linux system: \ntar -xzf vpn_client_x64.tar.gz \ncd vpn_client_x64 \nsudo ./install', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31002', 'CSAFPID-31004', 'CSAFPID-31006', 'CSAFPID-31008']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-32004'], 'known_affected': ['CSAFPID-31002', 'CSAFPID-31004', 'CSAFPID-31006', 'CSAFPID-31008']}}, {'cve': 'CVE-2025-26169', 'cwe': {'id': 'CWE-732', 'name': 'Incorrect Permission Assignment for Critical Resource'}, 'notes': [{'text': 'IXON VPN Client before 1.4.4 on Windows allows Local Privilege Escalation to SYSTEM because there is code execution from a configuration file that can be controlled by a low-privileged user. There is a race condition in which a temporary configuration file, in a world-writable directory, can be overwritten.', 'title': 'Description', 'category': 'description'}], 'title': 'CVE-2025-26169', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 8.1, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-31002', 'CSAFPID-31004', 'CSAFPID-31006', 'CSAFPID-31008']}], 'remediations': [{'details': 'Obtain the updated VPN software (version >= 1.4.4) from https://cloud.lenze.digital/fleet-manager/tools and run the installer on a windows and macOS system or run the following\ncommands in an linux system: \ntar -xzf vpn_client_x64.tar.gz \ncd vpn_client_x64 \nsudo ./install', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31002', 'CSAFPID-31004', 'CSAFPID-31006', 'CSAFPID-31008']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-32004'], 'known_affected': ['CSAFPID-31002', 'CSAFPID-31004', 'CSAFPID-31006', 'CSAFPID-31008']}}]}
a8c34715ebe5b888254bea51db22d35434333069b36b6a031c99402750e44189
2026-05-29 08:30:33.318940+03:00
2026-05-29 08:30:33.318940+03:00
csaf_lenzese.ndjson
0e9a3f863aa58f52125d94abc5e1cb73791e7abde8c24977140b24c5dd7d2247
{'document': {'lang': 'en-GB', 'notes': [{'text': 'A security vulnerability was discovered in the PLC Designer V4 in the version 4.0.0 where the programmer of a Controller can set a password for the connected device. Here it is possible in an interface of the PLC Designer V4 for the programmer to enter a password for the Device. There is a special constellation where the password entered appears in plain text. Only the display in the tool is affected and not the management of the password on the device. This vulnerability of PLC Designer V4 only occurs in combination with the devices c430 controller, c520 controller and c550 controller and not in combination with other devices, as this functionality is only used here. It is generally recommended that all users update to 4.0.1, but especially all users who operate PLC Designer V4 in combination with the controllers mentioned.', 'title': 'Summary', 'category': 'summary'}, {'text': 'The cyber security documentation currently describes some of the implemented functions and is thus intended to provide clarity in the functions described here. ', 'title': 'General Recommendations', 'category': 'general'}, {'text': 'Lenze SE assumes no liability whatsoever for any kind of losses or consequential losses that occur by the distribution and/or use of this document . All information published in this document is provided on good faith by Lenze SE. Insofar as permissible by law, however, none of this information shall establish any guarantee, commitment or liability on the part of Lenze SE. Lenze SE reserves the right to change or update this document at any time.', 'title': 'Disclamer', 'category': 'legal_disclaimer'}, {'text': 'This vulnerability may lead to unintended exposure of passwords in plain text within the PLC Designer V4 interface, potentially allowing unauthorized individuals with access to the engineering workstation to view sensitive credentials. The issue is limited to versions 4.0.0 used with c430, c520, and c550 controllers, and does not affect password handling on the device itself.', 'title': 'Impact', 'category': 'description'}, {'text': 'The PLC Designer V4 tool is designed and developed for use in closed and protected security zones. Lenze therefore strongly recommends that this tool is only used in familiar areas. As this security vulnerability relates to a plain text display of an entered password and not to the password method saved afterwards, it is recommended as mitigation to protect the viewing area of the tool from strangers when entering it in order to prevent the shoulder surfing attack method.', 'title': 'Mitigation', 'category': 'description'}, {'text': 'This vulnerability has been fixed in the new version. All users are strongly recommended to use the new version 4.0.1.', 'title': 'Remediation', 'category': 'description'}], 'title': 'Lenze: PLC Designer V4 with insecure storage of sensitive information', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2025-043', 'status': 'final', 'aliases': ['VDE-2025-043'], 'version': '1', 'generator': {'date': '2025-06-23T08:21:40.731Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.27'}}, 'revision_history': [{'date': '2025-06-25T10:00:00.000Z', 'number': '1', 'summary': 'Initial Version'}], 'current_release_date': '2025-06-25T10:00:00.000Z', 'initial_release_date': '2025-06-25T10:00:00.000Z'}, 'publisher': {'name': 'Lenze SE', 'category': 'vendor', 'namespace': 'https://www.lenze.com', 'contact_details': 'psirt@lenze.com'}, 'references': [{'url': 'https://www.lenze.com/en-de/services/cyber-security', 'summary': 'Lenze SE Product Security Incident Response Team (PSIRT)', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/lenze/', 'summary': 'https://www.lenze.com/en-de/services/cyber-security', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/VDE-2025-043/', 'summary': 'VDE-2025-043: Lenze: PLC Designer V4 with insecure storage of sensitive information - HTML', 'category': 'self'}, {'url': 'https://lenze.csaf-tp.certvde.com/.well-known/csaf/white/2025/vde-2025-043.json', 'summary': 'VDE-2025-043: Lenze: PLC Designer V4 with insecure storage of sensitive information - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}], 'aggregate_severity': {'text': 'Medium', 'namespace': 'https://www.first.org/cvss/calculator/3.1'}}, 'product_tree': {'branches': [{'name': 'Lenze', 'branches': [{'name': 'Software', 'branches': [{'name': 'PLC Designer V4', 'branches': [{'name': '4.0.0', 'product': {'name': 'PLC Designer V4 4.0.0', 'product_id': 'CSAFPID-51001'}, 'category': 'product_version'}, {'name': '4.0.1', 'product': {'name': 'PLC Designer V4 4.0.1', 'product_id': 'CSAFPID-52001'}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-41647', 'cwe': {'id': 'CWE-312', 'name': 'Cleartext Storage of Sensitive Information'}, 'notes': [{'text': 'A local, low-privileged attacker can learn the password of the connected controller in PLC Designer V4 due to an incorrect implementation that results in the password being displayed in plain text under special conditions.', 'title': 'Description', 'category': 'description'}], 'title': 'CVE-2025-41647', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': 'This vulnerability has been fixed in the new version. All users are strongly recommended to use the new version 4.0.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}, {'details': 'The PLC Designer V4 tool is designed and developed for use in closed and protected security zones. Lenze therefore strongly recommends that this tool is only used in familiar areas. As this security vulnerability relates to a plain text display of an entered password and not to the password method saved afterwards, it is recommended as mitigation to protect the viewing area of the tool from strangers when entering it in order to prevent the shoulder surfing attack method.', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}]}
3bd8ab57b3be091d5ff056ae6c132e0aa5e66003b778ee936858192cc0e49a73
2026-05-29 08:30:33.318940+03:00
2026-05-29 08:30:33.318940+03:00
csaf_sauterag.ndjson
b41dd11399647dca821988436aa052bc36cda0186f3ac200febf7c5f2d3227ed
{'document': {'lang': 'en-US', 'notes': [{'text': 'Vulnerabilities have been discovered in the embedded firmware of SAUTER modulo 6 devices. These vulnerabilities affect the embedded web server as well as the interface to the SAUTER CASE Suite tools.', 'title': 'Summary', 'category': 'summary'}, {'text': 'Update to firmware version 3.2.0. or newer. This will require CASE Suite Version 5.2 SR5 or newer. Contact your local SAUTER representative for support.', 'title': 'Remediation', 'category': 'description'}, {'text': 'The vulnerabilities in the modulo 6 devices allow privilege escalation, remote exploitation, and compromise of device integrity, availability and confidentiality. ', 'title': 'Impact', 'category': 'description'}], 'title': 'Sauter: Multiple vulnerabilities in SAUTER modulo 6 ', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2025-060', 'status': 'final', 'aliases': ['VDE-2025-060'], 'version': '1.1.0', 'generator': {'date': '2025-10-27T09:37:27.479Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.35'}}, 'revision_history': [{'date': '2025-10-21T10:00:00.000Z', 'number': '1.0.0', 'summary': 'Initial revision'}, {'date': '2025-10-27T11:00:00.000Z', 'number': '1.1.0', 'summary': 'Correction: modu524 and modu525 not affected by CVE-2025-41723'}], 'current_release_date': '2025-10-27T11:00:00.000Z', 'initial_release_date': '2025-10-21T10:00:00.000Z'}, 'publisher': {'name': 'Sauter AG', 'category': 'vendor', 'namespace': 'https://www.sauter-controls.com', 'contact_details': 'psirt@sauter-bc.com'}, 'references': [{'url': 'https://certvde.com/de/advisories/vendor/sauter/', 'summary': 'Sauter advisory overview at CERT@VDE', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/VDE-2025-060', 'summary': 'VDE-2025-060: Sauter: Multiple vulnerabilities in SAUTER modulo 6 - HTML', 'category': 'self'}, {'url': 'https://sauter.csaf-tp.certvde.com/.well-known/csaf/white/2025/vde-2025-060.json', 'summary': 'VDE-2025-060: Sauter: Multiple vulnerabilities in SAUTER modulo 6 - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://www.ar.admin.ch/cyberdefencecampus'], 'names': ['Damian Pfammatter', 'Daniel Hulliger'], 'summary': 'SAUTER thanks the Cyber-Defence Campus of ARMASUISSE S+T for organizing the hackathon and for reporting the vulnerabilities.', 'organization': 'Cyber-Defence Campus armasuisse S+T'}, {'summary': 'coordination', 'organization': 'CERT@VDE'}], 'aggregate_severity': {'text': 'High', 'namespace': 'https://www.first.org/cvss/v3.1/specification-document#Qualitative-Severity-Rating-Scale'}}, 'product_tree': {'branches': [{'name': 'Fr. SAUTER AG', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'modulo 6 devices', 'branches': [{'name': 'modu680-AS', 'product': {'name': 'modulo 6 devices modu680-AS', 'product_id': 'CSAFPID-11001'}, 'category': 'product_name'}, {'name': 'modu660-AS', 'product': {'name': 'modulo 6 devices modu660-AS', 'product_id': 'CSAFPID-11002'}, 'category': 'product_name'}, {'name': 'modu612-LC', 'product': {'name': 'modulo 6 devices modu612-LC', 'product_id': 'CSAFPID-11003'}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'EY-modulo 5', 'branches': [{'name': 'modu 5', 'branches': [{'name': 'modu524', 'product': {'name': 'EY-modulo 5 modu 5 modu524', 'product_id': 'CSAFPID-11004'}, 'category': 'product_name'}, {'name': 'modu525', 'product': {'name': 'EY-modulo 5 modu 5 modu525', 'product_id': 'CSAFPID-11005'}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'ecos 5', 'branches': [{'name': 'ecos504/505', 'product': {'name': 'EY-modulo 5 ecos 5 ecos504/505', 'product_id': 'CSAFPID-11006'}, 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'product_family'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': 'modulo 6 embedded software', 'branches': [{'name': 'v3.2.0', 'product': {'name': 'Firmware modulo 6 embedded software v3.2.0', 'product_id': 'CSAFPID-22001'}, 'category': 'product_version'}, {'name': '<v3.2.0', 'product': {'name': 'Firmware modulo 6 embedded software <v3.2.0', 'product_id': 'CSAFPID-21001'}, 'category': 'product_version_range'}], 'category': 'product_family'}, {'name': 'EY-modulo 5 embedded software', 'branches': [{'name': 'v6.0', 'product': {'name': 'Firmware EY-modulo 5 embedded software v6.0', 'product_id': 'CSAFPID-22002'}, 'category': 'product_version'}, {'name': '<v6.0', 'product': {'name': 'Firmware EY-modulo 5 embedded software <v6.0', 'product_id': 'CSAFPID-21002'}, 'category': 'product_version_range'}], 'category': 'product_family'}], 'category': 'product_family'}, {'name': 'Software', 'branches': [{'name': 'CASE Suite', 'branches': [{'name': '<v5.2 SR5', 'product': {'name': 'Software CASE Suite <v5.2 SR5', 'product_id': 'CSAFPID-51001'}, 'category': 'product_version_range'}, {'name': 'v5.2 SR5', 'product': {'name': 'Software CASE Suite v5.2 SR5', 'product_id': 'CSAFPID-52001'}, 'category': 'product_version'}], 'category': 'product_family'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware modulo 6 embedded software v3.2.0 installed on modulo 6 devices modu680-AS', 'product_id': 'CSAFPID-32001'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware modulo 6 embedded software v3.2.0 installed on modulo 6 devices modu660-AS', 'product_id': 'CSAFPID-32002'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11002'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware modulo 6 embedded software v3.2.0 installed on modulo 6 devices modu612-LC', 'product_id': 'CSAFPID-32003'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11003'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware modulo 6 embedded software <v3.2.0 installed on modulo 6 devices modu680-AS', 'product_id': 'CSAFPID-31001'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware modulo 6 embedded software <v3.2.0 installed on modulo 6 devices modu660-AS', 'product_id': 'CSAFPID-31002'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11002'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware modulo 6 embedded software <v3.2.0 installed on modulo 6 devices modu612-LC', 'product_id': 'CSAFPID-31003'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11003'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware EY-modulo 5 embedded software v6.0 installed on EY-modulo 5 ecos 5 ecos504/505', 'product_id': 'CSAFPID-32006'}, 'product_reference': 'CSAFPID-22002', 'relates_to_product_reference': 'CSAFPID-11006'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware EY-modulo 5 embedded software <v6.0 installed on EY-modulo 5 modu 5 modu524', 'product_id': 'CSAFPID-31004'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11004'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware EY-modulo 5 embedded software <v6.0 installed on EY-modulo 5 modu 5 modu525', 'product_id': 'CSAFPID-31005'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11005'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware EY-modulo 5 embedded software <v6.0 installed on EY-modulo 5 ecos 5 ecos504/505', 'product_id': 'CSAFPID-31006'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11006'}, {'category': 'installed_with', 'full_product_name': {'name': 'Firmware modulo 6 embedded software <v3.2.0 installed on modulo 6 devices modu680-AS installed with Software CASE Suite <v5.2 SR5', 'product_id': 'CSAFPID-31101'}, 'product_reference': 'CSAFPID-31001', 'relates_to_product_reference': 'CSAFPID-51001'}, {'category': 'installed_with', 'full_product_name': {'name': 'Firmware modulo 6 embedded software v3.2.0 installed on modulo 6 devices modu680-AS installed with Software CASE Suite v5.2 SR5', 'product_id': 'CSAFPID-32201'}, 'product_reference': 'CSAFPID-32001', 'relates_to_product_reference': 'CSAFPID-52001'}, {'category': 'installed_with', 'full_product_name': {'name': 'Firmware modulo 6 embedded software v3.2.0 installed on modulo 6 devices modu660-AS installed with Software CASE Suite v5.2 SR5', 'product_id': 'CSAFPID-32202'}, 'product_reference': 'CSAFPID-32002', 'relates_to_product_reference': 'CSAFPID-52001'}, {'category': 'installed_with', 'full_product_name': {'name': 'Firmware modulo 6 embedded software v3.2.0 installed on modulo 6 devices modu612-LC installed with Software CASE Suite v5.2 SR5', 'product_id': 'CSAFPID-32203'}, 'product_reference': 'CSAFPID-32003', 'relates_to_product_reference': 'CSAFPID-52001'}, {'category': 'installed_with', 'full_product_name': {'name': 'Firmware EY-modulo 5 embedded software v6.0 installed on EY-modulo 5 ecos 5 ecos504/505 installed with Software CASE Suite v5.2 SR5', 'product_id': 'CSAFPID-32204'}, 'product_reference': 'CSAFPID-32006', 'relates_to_product_reference': 'CSAFPID-52001'}, {'category': 'installed_with', 'full_product_name': {'name': 'Firmware modulo 6 embedded software v3.2.0 installed with Software CASE Suite v5.2 SR5', 'product_id': 'CSAFPID-0005'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-52001'}], 'product_groups': [{'summary': 'affected products', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006']}, {'summary': 'fixed products', 'group_id': 'CSAFGID-0002', 'product_ids': ['CSAFPID-32201', 'CSAFPID-32202', 'CSAFPID-32203', 'CSAFPID-32204']}]}, 'vulnerabilities': [{'cve': 'CVE-2025-41719', 'cwe': {'id': 'CWE-1286', 'name': 'Improper Validation of Syntactic Correctness of Input'}, 'notes': [{'text': 'A low privileged remote attacker can corrupt the webserver users storage on the device by setting a sequence of unsupported characters which leads to deletion of all previously configured users and the creation of the default Administrator with a known default password.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'Sauter: Improper Validation of user-controlled data', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 8.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 8.8, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003']}], 'remediations': [{'details': 'Install modulo 6 embedded software version 3.2.0 on modulo 6 devices', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001'], 'entitlements': ['Contact your SAUTER representative to update to the embedded firmware version fixing the vulnerability', 'Requires upgrade to CASE Suite v5.2SR5'], 'restart_required': {'details': 'Update requires device restart.', 'category': 'vulnerable_component'}}, {'details': 'Upgrade to CASE Suite v5.2 SR5', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}, {'details': 'Protect access to device and network according to best practices and state of the art means', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}], 'discovery_date': '2025-02-07T11:00:00.000Z', 'product_status': {'fixed': ['CSAFPID-32201', 'CSAFPID-32202', 'CSAFPID-32203'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003'], 'known_not_affected': ['CSAFPID-11004', 'CSAFPID-11005', 'CSAFPID-11006']}, 'acknowledgments': [{'names': ['Damian Pfammatter', 'Daniel Hulliger'], 'summary': 'The Cyber-Defence Campus armasuisse S+T reported the vulnerability to Fr. SAUTER AG', 'organization': 'Cyber-Defence Campus armasuisse S+T'}]}, {'cve': 'CVE-2025-41720', 'cwe': {'id': 'CWE-646', 'name': 'Reliance on File Name or Extension of Externally-Supplied File'}, 'notes': [{'text': 'A low privileged remote attacker can upload arbitrary data masked as a png file to the affected device using the webserver API because only the file extension is verified.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'Sauter: Arbitrary File Upload', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 4.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N', 'temporalScore': 4.3, 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 4.3, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003']}], 'remediations': [{'details': 'Install modulo 6 embedded software version 3.2.0 on modulo 6 devices', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001'], 'entitlements': ['Requires upgrade to CASE Suite v5.2SR5'], 'restart_required': {'details': 'Update requires device restart', 'category': 'vulnerable_component'}}, {'details': 'Upgrade to CASE Suite v5.2 SR5', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}, {'details': 'Protect access to device and network according to best practices and state of the art means', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32201', 'CSAFPID-32202', 'CSAFPID-32203'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003'], 'known_not_affected': ['CSAFPID-11004', 'CSAFPID-11005', 'CSAFPID-11006']}, 'acknowledgments': [{'names': ['Damian Pfammatter', 'Daniel Hulliger'], 'summary': 'The Cyber-Defence Campus armasuisse S+T reported the vulnerability to Fr. SAUTER AG', 'organization': 'Cyber-Defence Campus armasuisse S+T'}]}, {'cve': 'CVE-2025-41721', 'cwe': {'id': 'CWE-77', 'name': "Improper Neutralization of Special Elements used in a Command ('Command Injection')"}, 'notes': [{'text': 'A high privileged remote attacker can influence the parameters passed to the openssl command due to improper neutralization of special elements when adding a password protected self-signed certificate.', 'title': 'Vulnerability Description', 'category': 'description'}, {'text': 'This Vulnerability can be combined with CVE-2025-41720 resulting in full file system access via reverse shell.\nCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H - 7.2 ', 'title': 'Vulnerability Characterisation', 'category': 'details'}], 'title': 'Sauter: Command Injection', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 2.7, 'attackVector': 'NETWORK', 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N', 'temporalScore': 2.7, 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'LOW', 'availabilityImpact': 'NONE', 'environmentalScore': 2.7, 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'LOW'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003']}], 'remediations': [{'details': 'Install modulo 6 embedded software version 3.2.0 on modulo 6 devices', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001'], 'entitlements': ['Requires upgrade to CASE Suite v5.2SR5'], 'restart_required': {'details': 'Update requires device restart', 'category': 'vulnerable_component'}}, {'details': 'Upgrade to CASE Suite v5.2 SR5', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}, {'details': 'Protect access to device and network according to best practices and state of the art means', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32201', 'CSAFPID-32202', 'CSAFPID-32203'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003'], 'known_not_affected': ['CSAFPID-11004', 'CSAFPID-11005', 'CSAFPID-11006']}, 'acknowledgments': [{'names': ['Damian Pfammatter', 'Daniel Hulliger'], 'summary': 'The Cyber-Defence Campus armasuisse S+T reported the vulnerability to Fr. SAUTER AG', 'organization': 'Cyber-Defence Campus armasuisse S+T'}]}, {'cve': 'CVE-2025-41722', 'cwe': {'id': 'CWE-798', 'name': 'Use of Hard-coded Credentials'}, 'notes': [{'text': 'The wsc server uses a hard-coded certificate to check the authenticity of SOAP messages. An unauthenticated remote attacker can extract private keys from the Software of the affected devices.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'Sauter: Hard-coded Authentication Credentials', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'NONE', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006']}], 'remediations': [{'details': 'Install modulo 6 embedded software version 3.2.0 on modulo 6 devices', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001'], 'entitlements': ['Requires upgrade to CASE Suite v5.2SR5'], 'restart_required': {'details': 'Update requires device restart', 'category': 'vulnerable_component'}}, {'details': 'Install EY-modulo 5 embedded software v6.0 on supported EY-modulo 5 devices', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001'], 'restart_required': {'details': 'Update requires device restart', 'category': 'vulnerable_component'}}, {'details': 'Upgrade to CASE Suite v5.2 SR5', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}, {'details': 'Protect access to device and network according to best practices and state of the art means', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32201', 'CSAFPID-32202', 'CSAFPID-32203', 'CSAFPID-32204'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006']}, 'acknowledgments': [{'names': ['Damian Pfammatter', 'Daniel Hulliger'], 'summary': 'The Cyber-Defence Campus armasuisse S+T reported the vulnerability to Fr. SAUTER AG', 'organization': 'Cyber-Defence Campus armasuisse S+T'}]}, {'cve': 'CVE-2025-41723', 'cwe': {'id': 'CWE-35', 'name': "Path Traversal: '.../...//'"}, 'notes': [{'text': 'The importFile SOAP method is vulnerable to a directory traversal attack. An unauthenticated remote attacker bypass the path restriction and upload files to arbitrary locations.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'Sauter: Directory Traversal in importFile SOAP Method', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006']}], 'remediations': [{'details': 'Install modulo 6 embedded software version 3.2.0 on modulo 6 devices', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001'], 'entitlements': ['Requires upgrade to CASE Suite v5.2SR5'], 'restart_required': {'details': 'Update requires device restart', 'category': 'vulnerable_component'}}, {'details': 'Install EY-modulo 5 embedded software v6.0 on supported EY-modulo 5 devices', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001'], 'entitlements': ['Requires upgrade to CASE Suite v5.2SR5'], 'restart_required': {'details': 'Update requires device restart', 'category': 'vulnerable_component'}}, {'details': 'Upgrade to CASE Suite v5.2 SR5', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}, {'details': 'Protect access to device and network according to best practices and state of the art means', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32201', 'CSAFPID-32202', 'CSAFPID-32203', 'CSAFPID-32204'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31006'], 'known_not_affected': ['CSAFPID-11004', 'CSAFPID-11005']}, 'acknowledgments': [{'names': ['Damian Pfammatter', 'Daniel Hulliger'], 'summary': 'The Cyber-Defence Campus armasuisse S+T reported the vulnerability to Fr. SAUTER AG', 'organization': 'Cyber-Defence Campus armasuisse S+T'}]}, {'cve': 'CVE-2025-41724', 'cwe': {'id': 'CWE-239', 'name': 'Failure to Handle Incomplete Element'}, 'notes': [{'text': 'An unauthenticated remote attacker can crash the wscserver by sending incomplete SOAP requests. The wscserver process will not be restarted by a watchdog and a device reboot is necessary to make it work again.\n', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'Sauter: Crash via Incomplete SOAP Request', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006']}], 'remediations': [{'details': 'Install modulo 6 embedded software version 3.2.0 on modulo 6 devices', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001'], 'entitlements': ['Requires upgrade to CASE Suite v5.2SR5'], 'restart_required': {'details': 'Update requires device restart', 'category': 'vulnerable_component'}}, {'details': 'Install EY-modulo 5 embedded software v6.0 on supported EY-modulo 5 devices', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001'], 'entitlements': ['Requires upgrade to CASE Suite v5.2SR5'], 'restart_required': {'details': 'Update requires device restart', 'category': 'vulnerable_component'}}, {'details': 'Upgrade to CASE Suite v5.2 SR5', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}, {'details': 'Protect access to device and network according to best practices and state of the art means', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32201', 'CSAFPID-32202', 'CSAFPID-32203', 'CSAFPID-32204'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006']}, 'acknowledgments': [{'names': ['Damian Pfammatter', 'Daniel Hulliger'], 'summary': 'The Cyber-Defence Campus armasuisse S+T reported the vulnerability to Fr. SAUTER AG', 'organization': 'Cyber-Defence Campus armasuisse S+T'}]}]}
2bc9125ba0592ecced133b7109e27e3a16aa4a97c68a6612affc7e23de70bc0c
2026-05-29 08:30:33.709690+03:00
2026-05-29 08:30:33.709690+03:00
csaf_swarcotrafficsystemsgmbh.ndjson
62cab7bc18440cbfd87c8255702c585e48a99e959dfea6a6fe2c433722879df7
{'document': {'lang': 'en-GB', 'notes': [{'text': 'An open port used for debugging grants root access to the device without access control via network.', 'title': 'Summary', 'category': 'summary'}, {'text': 'A malicious user could use this vulnerability to get access to the device and disturb operations with connected devices.', 'title': 'Impact', 'category': 'description'}, {'text': 'SWARCO TRAFFIC SYSTEMS released a patch to fix the vulnerability and close the port. Please contact your SWARCO TRAFFIC SYSTEMS contact person for further information.', 'title': 'Remediation', 'category': 'description'}], 'title': 'SWARCO: Critical Vulnerability in CPU LS4000', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2020-016', 'status': 'final', 'aliases': ['VDE-2020-016'], 'version': '1', 'generator': {'date': '2025-01-15T13:47:43.142Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.16'}}, 'revision_history': [{'date': '2020-05-28T13:00:00.000Z', 'number': '1', 'summary': 'Initial revision.'}], 'current_release_date': '2020-05-28T13:00:00.000Z', 'initial_release_date': '2020-05-28T13:00:00.000Z'}, 'publisher': {'name': 'SWARCO TRAFFIC SYSTEMS GmbH', 'category': 'vendor', 'namespace': 'https://www.swarco.de', 'contact_details': 'security-meldungen@swarco.de'}, 'references': [{'url': 'https://certvde.com/en/advisories/vendor/swarco/', 'summary': 'CERT@VDE Security Advisories for SWARCO', 'category': 'external'}, {'url': 'https://certvde.com/de/advisories/VDE-2020-016/', 'summary': 'VDE-2020-016: SWARCO: Critical Vulnerability in CPU LS4000 - HTML', 'category': 'self'}, {'url': 'https://swarco.csaf-tp.certvde.com/.well-known/csaf/white/2020/vde-2020-016.json', 'summary': 'VDE-2020-016: SWARCO: Critical Vulnerability in CPU LS4000 - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}, {'names': ['Martin Aman'], 'summary': 'reported', 'organization': 'ProtectEM'}]}, 'product_tree': {'branches': [{'name': 'SWARCO', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'CPU LS4000', 'product': {'name': 'SWARCO Hardware CPU LS4000', 'product_id': 'CSAFPID-11002'}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': 'G4*', 'product': {'name': 'Firmware G4*', 'product_id': 'CSAFPID-21001'}, 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware G4* installed on SWARCO Hardware CPU LS4000', 'product_id': 'CSAFPID-31003'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11002'}]}, 'vulnerabilities': [{'cve': 'CVE-2020-12493', 'cwe': {'id': 'CWE-284', 'name': 'Improper Access Control'}, 'notes': [{'text': 'An open port used for debugging in SWARCOs CPU LS4000 Series with versions starting with G4... grants root access to the device without access control via network. A malicious user could use this vulnerability to get access to the device and disturb operations with connected devices.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2020-12493', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 10, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H', 'temporalScore': 10, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 10, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31003']}], 'remediations': [{'details': 'SWARCO TRAFFIC SYSTEMS released a patch to fix the vulnerability and close the port. Please contact your SWARCO TRAFFIC SYSTEMS contact person for further information.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31003']}], 'product_status': {'known_affected': ['CSAFPID-31003']}}]}
b45c72bf21a68d6c0f4166a7bd0a98e37cb612577e4e079a8631c85cbbb80a4b
2026-05-29 08:30:34.109251+03:00
2026-05-29 08:30:34.109251+03:00
csaf_smasolartechnologyag.ndjson
a32793f496677975a736c76032fb0987e30cc1d268b9abc9d38cd09ee2b91b03
{'document': {'lang': 'en-GB', 'notes': [{'text': 'A security researcher discovered a Cross Site Request Forgery (CSRF, XSRF) vulnerability in SMA Cluster Controller. The affected products are out of support (End-of-Life 2018-06-30).', 'title': 'Summary', 'category': 'summary'}, {'text': "The vulnerability could allow an attacker to send a malicious link to an authenticated user to perform actions with the user's permissions on the affected device.", 'title': 'Impact', 'category': 'description'}, {'text': 'If you can not replace your Cluster Controller by a suitable up-to-date product then isolate the affected network segment by blocking all incoming network traffic. Especially never configure your network to allow a port forwarding to SMA Cluster Controller. Avoid accessing Internet resources while logged in to the Cluster Controller.', 'title': 'Mitigation', 'category': 'description'}, {'text': 'Replace out-of-support Cluster Controller by a suitable up-to-date product. Please note technical information on the switchover to be found at https://www.sma-sunny.com/en/how-to-replace-old-data-logger/', 'title': 'Remediation', 'category': 'description'}], 'title': 'SMA: Cluster Controller CSRF vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2024-020', 'status': 'final', 'aliases': ['VDE-2024-020'], 'version': '2', 'generator': {'date': '2025-01-23T10:31:46.978Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.17'}}, 'revision_history': [{'date': '2025-01-20T11:00:00.000Z', 'number': '1', 'summary': 'Initial revision.'}, {'date': '2025-02-12T16:48:47.000Z', 'number': '2', 'summary': 'Fix: corrected self-reference'}], 'current_release_date': '2025-02-12T16:48:47.000Z', 'initial_release_date': '2025-01-27T13:00:00.000Z'}, 'publisher': {'name': 'SMA Solar Technology AG', 'category': 'vendor', 'namespace': 'https://sma.de', 'contact_details': 'information-security@sma.de'}, 'references': [{'url': 'https://www.sma.de/en/cybersecurity/product-security', 'summary': 'SMA PSIRT', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/sma/', 'summary': 'CERT@VDE Security Advisories for SMA', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/VDE-2024-020', 'summary': 'VDE-2024-020: SMA: Cluster Controller CSRF vulnerability - HTML', 'category': 'self'}, {'url': 'https://sma.csaf-tp.certvde.com/.well-known/csaf/white/2025/vde-2024-020.json', 'summary': 'VDE-2024-020: SMA: Cluster Controller CSRF vulnerability - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}, {'urls': ['https://www.incibe.es'], 'summary': 'reporting', 'organization': 'INCIBE'}]}, 'product_tree': {'branches': [{'name': 'SMA Solar Technology AG', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'SMA Cluster Controller', 'product': {'name': 'SMA Cluster Controller', 'product_id': 'CSAFPID-11900'}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'Firmware vers:all/* ', 'product_id': 'CSAFPID-21900'}, 'category': 'product_version_range'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'All firmware installed on SMA Cluster Controller', 'product_id': 'CSAFPID-32900'}, 'product_reference': 'CSAFPID-21900', 'relates_to_product_reference': 'CSAFPID-11900'}]}, 'vulnerabilities': [{'cve': 'CVE-2024-1889', 'cwe': {'id': 'CWE-352', 'name': 'Cross-Site Request Forgery (CSRF)'}, 'notes': [{'text': 'Cross-Site Request Forgery vulnerability in SMA Cluster Controller, affecting firmware version 01.05.01.R and earlier. This vulnerability could allow an attacker to send a malicious link to an authenticated user to perform actions with these user permissions on the affected device.', 'title': 'Vulnerability Description', 'audience': 'all', 'category': 'description'}], 'title': 'CVE-2024-1889', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'temporalScore': 8.8, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 8.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-32900']}], 'release_date': '2024-02-26T11:00:00.000Z', 'remediations': [{'date': '2025-01-20T11:00:00.000Z', 'details': 'Replace out-of-support Cluster Controller by a suitable up-to-date product. Please note technical information on the switchover to be found at https://www.sma-sunny.com/en/how-to-replace-old-data-logger/', 'category': 'mitigation', 'product_ids': ['CSAFPID-32900']}], 'product_status': {'known_affected': ['CSAFPID-32900']}}]}
7b0ff122b022fef6d8a38a1a71b9cd2cafb4a6a045c46d70f1a01db9c172d827
2026-05-29 08:30:34.565004+03:00
2026-05-29 08:30:34.565004+03:00
csaf_smasolartechnologyag.ndjson
52bf9ca52b12d0f18faf87857de6bb3d1aca1caefd0cf9da5efd79d0d4417be5
{'document': {'lang': 'en-GB', 'notes': [{'text': 'A security researcher discovered that in the affected products an authenticated (administration privileges) SQL injection has been found on the administration panel allowing access to a database. The database that can be accessed is a log database in which measurement data are stored for a graphical representation. ', 'title': 'Summary', 'category': 'summary'}, {'text': 'An authenticated user can access (read/write) an internal SQL database with measurement data that are used only for a graphical representation in UI.', 'title': 'Impact', 'category': 'description'}, {'text': 'If you can not update your system to the latest version and you assume a manipulation of this database, you can download the raw data as a csv file.', 'title': 'Mitigation', 'category': 'description'}, {'text': 'Update Firmware to at least version 10.01.18.R', 'title': 'Remediation', 'category': 'description'}], 'title': 'SMA: SQL injection in Sunny Central UP', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2024-074', 'status': 'final', 'aliases': ['VDE-2024-074'], 'version': '3', 'generator': {'date': '2024-11-29T08:19:08.281Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.15'}}, 'revision_history': [{'date': '2024-11-27T09:00:00.000Z', 'number': '1', 'summary': 'Initial revision.'}, {'date': '2024-11-29T08:00:00.000Z', 'number': '2', 'summary': 'fixed URL in CSAF reference, removed draft'}, {'date': '2025-05-14T12:28:19.000Z', 'number': '3', 'summary': 'Fix: version space'}], 'current_release_date': '2025-05-14T12:28:19.000Z', 'initial_release_date': '2024-11-27T09:00:00.000Z'}, 'publisher': {'name': 'SMA Solar Technology AG', 'category': 'vendor', 'namespace': 'https://sma.de', 'contact_details': 'information-security@sma.de'}, 'references': [{'url': 'https://www.sma.de/cybersicherheit/produktsicherheit', 'summary': 'SMA PSIRT', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/sma/', 'summary': 'CERT@VDE Security Advisories for SMA', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/VDE-2024-074', 'summary': 'VDE-2024-074: SMA: SQL injection in Sunny Central UP - HTML', 'category': 'self'}, {'url': 'https://sma.csaf-tp.certvde.com/.well-known/csaf/white/2024/vde-2024-074.json', 'summary': 'VDE-2024-074: SMA: SQL injection in Sunny Central UP - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}, {'urls': ['https://www.synacktiv.com'], 'names': ['Pierre Martin'], 'summary': 'reporting', 'organization': 'Synacktiv'}]}, 'product_tree': {'branches': [{'name': 'SMA Solar Technology AG', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'Sunny Central UP', 'branches': [{'name': 'SC 4000 UP', 'product': {'name': 'SC 4000 UP', 'product_id': 'CSAFPID-11001', 'product_identification_helper': {'model_numbers': ['SC 4000 UP']}}, 'category': 'product_name'}, {'name': 'SC 4200 UP', 'product': {'name': 'SC 4200 UP', 'product_id': 'CSAFPID-11002', 'product_identification_helper': {'model_numbers': ['SC 4200 UP']}}, 'category': 'product_name'}, {'name': 'SC 4400 UP', 'product': {'name': 'SC 4400 UP', 'product_id': 'CSAFPID-11003', 'product_identification_helper': {'model_numbers': ['SC 4400 UP']}}, 'category': 'product_name'}, {'name': 'SC 4600 UP', 'product': {'name': 'SC 4600 UP', 'product_id': 'CSAFPID-11004', 'product_identification_helper': {'model_numbers': ['SC 4600 UP']}}, 'category': 'product_name'}, {'name': 'SC 2660 UP', 'product': {'name': 'SC 2660 UP', 'product_id': 'CSAFPID-11005', 'product_identification_helper': {'model_numbers': ['SC 2660 UP']}}, 'category': 'product_name'}, {'name': 'SC 2800 UP', 'product': {'name': 'SC 2800 UP', 'product_id': 'CSAFPID-11006', 'product_identification_helper': {'model_numbers': ['SC 2800 UP']}}, 'category': 'product_name'}, {'name': 'SC 2930 UP', 'product': {'name': 'SC 2930 UP', 'product_id': 'CSAFPID-11007', 'product_identification_helper': {'model_numbers': ['SC 2930 UP']}}, 'category': 'product_name'}, {'name': 'SC 3060 UP', 'product': {'name': 'SC 3060 UP', 'product_id': 'CSAFPID-11008', 'product_identification_helper': {'model_numbers': ['SC 3060 UP']}}, 'category': 'product_name'}, {'name': 'SC 4400 UP-JP', 'product': {'name': 'SC 4400 UP-JP', 'product_id': 'CSAFPID-11009', 'product_identification_helper': {'model_numbers': ['SC 4400 UP-JP']}}, 'category': 'product_name'}, {'name': 'SC 2660 UP-US', 'product': {'name': 'SC 2660 UP-US', 'product_id': 'CSAFPID-11010', 'product_identification_helper': {'model_numbers': ['SC 2660 UP-US']}}, 'category': 'product_name'}, {'name': 'SC 2800 UP-US', 'product': {'name': 'SC 2800 UP-US', 'product_id': 'CSAFPID-11011', 'product_identification_helper': {'model_numbers': ['SC 2800 UP-US']}}, 'category': 'product_name'}, {'name': 'SC 2930 UP-US', 'product': {'name': 'SC 2930 UP-US', 'product_id': 'CSAFPID-11012', 'product_identification_helper': {'model_numbers': ['SC 2930 UP-US']}}, 'category': 'product_name'}, {'name': 'SC 3060 UP-US', 'product': {'name': 'SC 3060 UP-US', 'product_id': 'CSAFPID-11013', 'product_identification_helper': {'model_numbers': ['SC 3060 UP-US']}}, 'category': 'product_name'}, {'name': 'SC 2750 UP-US', 'product': {'name': 'SC 2750 UP-US', 'product_id': 'CSAFPID-11014', 'product_identification_helper': {'model_numbers': ['SC 2750 UP-US']}}, 'category': 'product_name'}, {'name': 'SC 4000 UP-US', 'product': {'name': 'SC 4000 UP-US', 'product_id': 'CSAFPID-11015', 'product_identification_helper': {'model_numbers': ['SC 4000 UP-US']}}, 'category': 'product_name'}, {'name': 'SC 4200 UP-US', 'product': {'name': 'SC 4200 UP-US', 'product_id': 'CSAFPID-11016', 'product_identification_helper': {'model_numbers': ['SC 4200 UP-US']}}, 'category': 'product_name'}, {'name': 'SC 4400 UP-US', 'product': {'name': 'SC 4400 UP-US', 'product_id': 'CSAFPID-11017', 'product_identification_helper': {'model_numbers': ['SC 4400 UP-US']}}, 'category': 'product_name'}, {'name': 'SC 4600 UP-US', 'product': {'name': 'SC 4600 UP-US', 'product_id': 'CSAFPID-11018', 'product_identification_helper': {'model_numbers': ['SC 4600 UP-US']}}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Sunny Central ', 'branches': [{'name': 'SC 1760-US', 'product': {'name': 'SC 1760-US', 'product_id': 'CSAFPID-11101', 'product_identification_helper': {'model_numbers': ['SC 1760-US']}}, 'category': 'product_name'}, {'name': 'SC 1850-US', 'product': {'name': 'SC 1850-US', 'product_id': 'CSAFPID-11102', 'product_identification_helper': {'model_numbers': ['SC 1850-US']}}, 'category': 'product_name'}, {'name': 'SC 2000-US', 'product': {'name': 'SC 2000-US', 'product_id': 'CSAFPID-11103', 'product_identification_helper': {'model_numbers': ['SC 2000-US']}}, 'category': 'product_name'}, {'name': 'SC 2200-US', 'product': {'name': 'SC 2200-US', 'product_id': 'CSAFPID-11104', 'product_identification_helper': {'model_numbers': ['SC 2200-US']}}, 'category': 'product_name'}, {'name': 'SC 2000 EV-US', 'product': {'name': 'SC 2000 EV-US', 'product_id': 'CSAFPID-11105', 'product_identification_helper': {'model_numbers': ['SC 2000 EV-US']}}, 'category': 'product_name'}, {'name': 'SC 2500 EV-US', 'product': {'name': 'SC 2500 EV-US', 'product_id': 'CSAFPID-11106', 'product_identification_helper': {'model_numbers': ['SC 2500 EV-US']}}, 'category': 'product_name'}, {'name': 'SC 2750 EV-US', 'product': {'name': 'SC 2750 EV-US', 'product_id': 'CSAFPID-11107', 'product_identification_helper': {'model_numbers': ['SC 2750 EV-US']}}, 'category': 'product_name'}, {'name': 'SC-2200-10', 'product': {'name': 'SC-2200-10', 'product_id': 'CSAFPID-11108', 'product_identification_helper': {'model_numbers': ['SC-2200-10']}}, 'category': 'product_name'}, {'name': 'SC-2475-10', 'product': {'name': 'SC-2475-10', 'product_id': 'CSAFPID-11109', 'product_identification_helper': {'model_numbers': ['SC-2475-10']}}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Sunny Central Storage UP', 'branches': [{'name': 'SCS 3450 UP', 'product': {'name': 'SCS 3450 UP', 'product_id': 'CSAFPID-11201', 'product_identification_helper': {'model_numbers': ['SCS 3450 UP']}}, 'category': 'product_name'}, {'name': 'SCS 3600 UP', 'product': {'name': 'SCS 3600 UP', 'product_id': 'CSAFPID-11202', 'product_identification_helper': {'model_numbers': ['SCS 3600 UP']}}, 'category': 'product_name'}, {'name': 'SCS 3800 UP', 'product': {'name': 'SCS 3800 UP', 'product_id': 'CSAFPID-11203', 'product_identification_helper': {'model_numbers': ['SCS 3800 UP']}}, 'category': 'product_name'}, {'name': 'SCS 3950 UP', 'product': {'name': 'SCS 3950 UP', 'product_id': 'CSAFPID-11204', 'product_identification_helper': {'model_numbers': ['SCS 3950 UP']}}, 'category': 'product_name'}, {'name': 'SCS 3450 UP-US', 'product': {'name': 'SCS 3450 UP-US', 'product_id': 'CSAFPID-11205', 'product_identification_helper': {'model_numbers': ['SCS 3450 UP-US']}}, 'category': 'product_name'}, {'name': 'SCS 3600 UP-US', 'product': {'name': 'SCS 3600 UP-US', 'product_id': 'CSAFPID-11206', 'product_identification_helper': {'model_numbers': ['SCS 3600 UP-US']}}, 'category': 'product_name'}, {'name': 'SCS 3800 UP-US', 'product': {'name': 'SCS 3800 UP-US', 'product_id': 'CSAFPID-11207', 'product_identification_helper': {'model_numbers': ['SCS 3800 UP-US']}}, 'category': 'product_name'}, {'name': 'SCS 3950 UP-US', 'product': {'name': 'SCS 3950 UP-US', 'product_id': 'CSAFPID-11208', 'product_identification_helper': {'model_numbers': ['SCS 3950 UP-US']}}, 'category': 'product_name'}, {'name': 'SCS 2300 UP-XT', 'product': {'name': 'SCS 2300 UP-XT', 'product_id': 'CSAFPID-11209', 'product_identification_helper': {'model_numbers': ['SCS 2300 UP-XT']}}, 'category': 'product_name'}, {'name': 'SCS 2400 UP-XT', 'product': {'name': 'SCS 2400 UP-XT', 'product_id': 'CSAFPID-11210', 'product_identification_helper': {'model_numbers': ['SCS 2400 UP-XT']}}, 'category': 'product_name'}, {'name': 'SCS 2530 UP-XT', 'product': {'name': 'SCS 2530 UP-XT', 'product_id': 'CSAFPID-11211', 'product_identification_helper': {'model_numbers': ['SCS 2530 UP-XT']}}, 'category': 'product_name'}, {'name': 'SCS 2630 UP-XT', 'product': {'name': 'SCS 2630 UP-XT', 'product_id': 'CSAFPID-11212', 'product_identification_helper': {'model_numbers': ['SCS 2630 UP-XT']}}, 'category': 'product_name'}, {'name': 'SCS 3450 UP-XT', 'product': {'name': 'SCS 3450 UP-XT', 'product_id': 'CSAFPID-11213', 'product_identification_helper': {'model_numbers': ['SCS 3450 UP-XT']}}, 'category': 'product_name'}, {'name': 'SCS 3600 UP-XT', 'product': {'name': 'SCS 3600 UP-XT', 'product_id': 'CSAFPID-11214', 'product_identification_helper': {'model_numbers': ['SCS 3600 UP-XT']}}, 'category': 'product_name'}, {'name': 'SCS 3800 UP-XT', 'product': {'name': 'SCS 3800 UP-XT', 'product_id': 'CSAFPID-11215', 'product_identification_helper': {'model_numbers': ['SCS 3800 UP-XT']}}, 'category': 'product_name'}, {'name': 'SCS 3950 UP-XT', 'product': {'name': 'SCS 3950 UP-XT', 'product_id': 'CSAFPID-11216', 'product_identification_helper': {'model_numbers': ['SCS 3950 UP-XT']}}, 'category': 'product_name'}, {'name': 'SCS 3450 UP-XT-JP', 'product': {'name': 'SCS 3450 UP-XT-JP', 'product_id': 'CSAFPID-11217', 'product_identification_helper': {'model_numbers': ['SCS 3450 UP-XT-JP']}}, 'category': 'product_name'}, {'name': 'SCS 2300 UP-XT-US', 'product': {'name': 'SCS 2300 UP-XT-US', 'product_id': 'CSAFPID-11218', 'product_identification_helper': {'model_numbers': ['SCS 2300 UP-XT-US']}}, 'category': 'product_name'}, {'name': 'SCS 2400 UP-XT-US', 'product': {'name': 'SCS 2400 UP-XT-US', 'product_id': 'CSAFPID-11219', 'product_identification_helper': {'model_numbers': ['SCS 2400 UP-XT-US']}}, 'category': 'product_name'}, {'name': 'SCS 2530 UP-XT-US', 'product': {'name': 'SCS 2530 UP-XT-US', 'product_id': 'CSAFPID-11220', 'product_identification_helper': {'model_numbers': ['SCS 2530 UP-XT-US']}}, 'category': 'product_name'}, {'name': 'SCS 2630 UP-XT-US', 'product': {'name': 'SCS 2630 UP-XT-US', 'product_id': 'CSAFPID-11221', 'product_identification_helper': {'model_numbers': ['SCS 2630 UP-XT-US']}}, 'category': 'product_name'}, {'name': 'SCS 3450 UP-XT-US', 'product': {'name': 'SCS 3450 UP-XT-US', 'product_id': 'CSAFPID-11222', 'product_identification_helper': {'model_numbers': ['SCS 3450 UP-XT-US']}}, 'category': 'product_name'}, {'name': 'SCS 3600 UP-XT-US', 'product': {'name': 'SCS 3600 UP-XT-US', 'product_id': 'CSAFPID-11223', 'product_identification_helper': {'model_numbers': ['SCS 3600 UP-XT-US']}}, 'category': 'product_name'}, {'name': 'SCS 3800 UP-XT-US', 'product': {'name': 'SCS 3800 UP-XT-US', 'product_id': 'CSAFPID-11224', 'product_identification_helper': {'model_numbers': ['SCS 3800 UP-XT-US']}}, 'category': 'product_name'}, {'name': 'SCS 3950 UP-XT-US', 'product': {'name': 'SCS 3950 UP-XT-US', 'product_id': 'CSAFPID-11225', 'product_identification_helper': {'model_numbers': ['SCS 3950 UP-XT-US']}}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Sunny Central Storage', 'branches': [{'name': 'SCS-1900-10', 'product': {'name': 'SCS-1900-10', 'product_id': 'CSAFPID-11301', 'product_identification_helper': {'model_numbers': ['SCS-1900-10']}}, 'category': 'product_name'}, {'name': 'SCS-2200-10', 'product': {'name': 'SCS-2200-10', 'product_id': 'CSAFPID-11302', 'product_identification_helper': {'model_numbers': ['SCS-2200-10']}}, 'category': 'product_name'}, {'name': 'SCS-2475-10', 'product': {'name': 'SCS-2475-10', 'product_id': 'CSAFPID-11303', 'product_identification_helper': {'model_numbers': ['SCS-2475-10']}}, 'category': 'product_name'}, {'name': 'SCS-2900-10', 'product': {'name': 'SCS-2900-10', 'product_id': 'CSAFPID-11304', 'product_identification_helper': {'model_numbers': ['SCS-2900-10']}}, 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': '<10.01.18.R', 'product': {'name': 'Firmware <10.01.18.R', 'product_id': 'CSAFPID-21001'}, 'category': 'product_version_range'}, {'name': '10.01.18.R', 'product': {'name': 'Firmware 10.01.18.R', 'product_id': 'CSAFPID-22001'}, 'category': 'product_version'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SC 4000 UP', 'product_id': 'CSAFPID-31001'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SC 4200 UP', 'product_id': 'CSAFPID-31002'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11002'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SC 4400 UP', 'product_id': 'CSAFPID-31003'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11003'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SC 4600 UP', 'product_id': 'CSAFPID-31004'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11004'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SC 2660 UP', 'product_id': 'CSAFPID-31005'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11005'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SC 2800 UP', 'product_id': 'CSAFPID-31006'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11006'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SC 2930 UP', 'product_id': 'CSAFPID-31007'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11007'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SC 3060 UP', 'product_id': 'CSAFPID-31008'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11008'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SC 4400 UP-JP', 'product_id': 'CSAFPID-31009'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11009'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SC 2660 UP-US', 'product_id': 'CSAFPID-31010'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11010'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SC 2800 UP-US', 'product_id': 'CSAFPID-31011'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11011'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SC 2930 UP-US', 'product_id': 'CSAFPID-31012'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11012'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SC 3060 UP-US', 'product_id': 'CSAFPID-31013'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11013'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SC 2750 UP-US', 'product_id': 'CSAFPID-31014'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11014'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SC 4000 UP-US', 'product_id': 'CSAFPID-31015'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11015'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SC 4200 UP-US', 'product_id': 'CSAFPID-31016'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11016'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SC 4400 UP-US', 'product_id': 'CSAFPID-31017'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11017'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SC 4600 UP-US', 'product_id': 'CSAFPID-31018'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11018'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SC 1760-US', 'product_id': 'CSAFPID-31101'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11101'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SC 1850-US', 'product_id': 'CSAFPID-31102'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11102'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SC 2000-US', 'product_id': 'CSAFPID-31103'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11103'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SC 2200-US', 'product_id': 'CSAFPID-31104'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11104'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SC 2000 EV-US', 'product_id': 'CSAFPID-31105'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11105'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SC 2500 EV-US', 'product_id': 'CSAFPID-31106'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11106'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SC 2750 EV-US', 'product_id': 'CSAFPID-31107'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11107'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SC-2200-10', 'product_id': 'CSAFPID-31108'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11108'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SC-2475-10', 'product_id': 'CSAFPID-31109'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11109'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SCS 3450 UP', 'product_id': 'CSAFPID-31201'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11201'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SCS 3600 UP', 'product_id': 'CSAFPID-31202'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11202'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SCS 3800 UP', 'product_id': 'CSAFPID-31203'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11203'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SCS 3950 UP', 'product_id': 'CSAFPID-31204'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11204'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SCS 3450 UP-US', 'product_id': 'CSAFPID-31205'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11205'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SCS 3600 UP-US', 'product_id': 'CSAFPID-31206'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11206'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SCS 3800 UP-US', 'product_id': 'CSAFPID-31207'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11207'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SCS 3950 UP-US', 'product_id': 'CSAFPID-31208'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11208'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SCS 2300 UP-XT', 'product_id': 'CSAFPID-31209'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11209'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SCS 2400 UP-XT', 'product_id': 'CSAFPID-31210'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11210'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SCS 2530 UP-XT', 'product_id': 'CSAFPID-31211'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11211'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SCS 2630 UP-XT', 'product_id': 'CSAFPID-31212'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11212'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SCS 3450 UP-XT', 'product_id': 'CSAFPID-31213'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11213'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SCS 3600 UP-XT', 'product_id': 'CSAFPID-31214'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11214'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SCS 3800 UP-XT', 'product_id': 'CSAFPID-31215'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11215'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SCS 3950 UP-XT', 'product_id': 'CSAFPID-31216'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11216'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SCS 3450 UP-XT-JP', 'product_id': 'CSAFPID-31217'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11217'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SCS 2300 UP-XT-US', 'product_id': 'CSAFPID-31218'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11218'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SCS 2400 UP-XT-US', 'product_id': 'CSAFPID-31219'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11219'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SCS 2530 UP-XT-US', 'product_id': 'CSAFPID-31220'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11220'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SCS 2630 UP-XT-US', 'product_id': 'CSAFPID-31221'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11221'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SCS 3450 UP-XT-US', 'product_id': 'CSAFPID-31222'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11222'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SCS 3600 UP-XT-US', 'product_id': 'CSAFPID-31223'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11223'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SCS 3800 UP-XT-US', 'product_id': 'CSAFPID-31224'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11224'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SCS 3950 UP-XT-US', 'product_id': 'CSAFPID-31225'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11225'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SCS-1900-10', 'product_id': 'CSAFPID-31301'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11301'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SCS-2200-10', 'product_id': 'CSAFPID-31302'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11302'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SCS-2475-10', 'product_id': 'CSAFPID-31303'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11303'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <10.01.18.R installed on SCS-2900-10', 'product_id': 'CSAFPID-31304'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11304'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SC 4000 UP', 'product_id': 'CSAFPID-32001'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SC 4200 UP', 'product_id': 'CSAFPID-32002'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11002'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SC 4400 UP', 'product_id': 'CSAFPID-32003'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11003'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SC 4600 UP', 'product_id': 'CSAFPID-32004'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11004'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SC 2660 UP', 'product_id': 'CSAFPID-32005'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11005'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SC 2800 UP', 'product_id': 'CSAFPID-32006'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11006'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SC 2930 UP', 'product_id': 'CSAFPID-32007'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11007'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SC 3060 UP', 'product_id': 'CSAFPID-32008'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11008'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SC 4400 UP-JP', 'product_id': 'CSAFPID-32009'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11009'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SC 2660 UP-US', 'product_id': 'CSAFPID-32010'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11010'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SC 2800 UP-US', 'product_id': 'CSAFPID-32011'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11011'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SC 2930 UP-US', 'product_id': 'CSAFPID-32012'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11012'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SC 3060 UP-US', 'product_id': 'CSAFPID-32013'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11013'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SC 2750 UP-US', 'product_id': 'CSAFPID-32014'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11014'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SC 4000 UP-US', 'product_id': 'CSAFPID-32015'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11015'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SC 4200 UP-US', 'product_id': 'CSAFPID-32016'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11016'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SC 4400 UP-US', 'product_id': 'CSAFPID-32017'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11017'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SC 4600 UP-US', 'product_id': 'CSAFPID-32018'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11018'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SC 1760-US', 'product_id': 'CSAFPID-32101'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11101'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SC 1850-US', 'product_id': 'CSAFPID-32102'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11102'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SC 2000-US', 'product_id': 'CSAFPID-32103'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11103'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SC 2200-US', 'product_id': 'CSAFPID-32104'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11104'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SC 2000 EV-US', 'product_id': 'CSAFPID-32105'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11105'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SC 2500 EV-US', 'product_id': 'CSAFPID-32106'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11106'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SC 2750 EV-US', 'product_id': 'CSAFPID-32107'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11107'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SC-2200-10', 'product_id': 'CSAFPID-32108'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11108'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SC-2475-10', 'product_id': 'CSAFPID-32109'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11109'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SCS 3450 UP', 'product_id': 'CSAFPID-32201'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11201'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SCS 3600 UP', 'product_id': 'CSAFPID-32202'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11202'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SCS 3800 UP', 'product_id': 'CSAFPID-32203'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11203'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SCS 3950 UP', 'product_id': 'CSAFPID-32204'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11204'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SCS 3450 UP-US', 'product_id': 'CSAFPID-32205'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11205'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SCS 3600 UP-US', 'product_id': 'CSAFPID-32206'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11206'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SCS 3800 UP-US', 'product_id': 'CSAFPID-32207'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11207'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SCS 3950 UP-US', 'product_id': 'CSAFPID-32208'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11208'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SCS 2300 UP-XT', 'product_id': 'CSAFPID-32209'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11209'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SCS 2400 UP-XT', 'product_id': 'CSAFPID-32210'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11210'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SCS 2530 UP-XT', 'product_id': 'CSAFPID-32211'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11211'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SCS 2630 UP-XT', 'product_id': 'CSAFPID-32212'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11212'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SCS 3450 UP-XT', 'product_id': 'CSAFPID-32213'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11213'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SCS 3600 UP-XT', 'product_id': 'CSAFPID-32214'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11214'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SCS 3800 UP-XT', 'product_id': 'CSAFPID-32215'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11215'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SCS 3950 UP-XT', 'product_id': 'CSAFPID-32216'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11216'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SCS 3450 UP-XT-JP', 'product_id': 'CSAFPID-32217'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11217'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SCS 2300 UP-XT-US', 'product_id': 'CSAFPID-32218'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11218'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SCS 2400 UP-XT-US', 'product_id': 'CSAFPID-32219'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11219'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SCS 2530 UP-XT-US', 'product_id': 'CSAFPID-32220'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11220'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SCS 2630 UP-XT-US', 'product_id': 'CSAFPID-32221'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11221'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SCS 3450 UP-XT-US', 'product_id': 'CSAFPID-32222'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11222'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SCS 3600 UP-XT-US', 'product_id': 'CSAFPID-32223'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11223'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SCS 3800 UP-XT-US', 'product_id': 'CSAFPID-32224'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11224'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SCS 3950 UP-XT-US', 'product_id': 'CSAFPID-32225'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11225'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SCS-1900-10', 'product_id': 'CSAFPID-32301'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11301'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SCS-2200-10', 'product_id': 'CSAFPID-32302'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11302'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SCS-2475-10', 'product_id': 'CSAFPID-32303'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11303'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 10.01.18.R installed on SCS-2900-10', 'product_id': 'CSAFPID-32304'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11304'}], 'product_groups': [{'summary': 'Affected products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007', 'CSAFPID-31008', 'CSAFPID-31009', 'CSAFPID-31010', 'CSAFPID-31011', 'CSAFPID-31012', 'CSAFPID-31013', 'CSAFPID-31014', 'CSAFPID-31015', 'CSAFPID-31016', 'CSAFPID-31017', 'CSAFPID-31018', 'CSAFPID-31101', 'CSAFPID-31102', 'CSAFPID-31103', 'CSAFPID-31104', 'CSAFPID-31105', 'CSAFPID-31106', 'CSAFPID-31107', 'CSAFPID-31108', 'CSAFPID-31109', 'CSAFPID-31201', 'CSAFPID-31202', 'CSAFPID-31203', 'CSAFPID-31204', 'CSAFPID-31205', 'CSAFPID-31206', 'CSAFPID-31207', 'CSAFPID-31208', 'CSAFPID-31209', 'CSAFPID-31210', 'CSAFPID-31211', 'CSAFPID-31212', 'CSAFPID-31213', 'CSAFPID-31214', 'CSAFPID-31215', 'CSAFPID-31216', 'CSAFPID-31217', 'CSAFPID-31218', 'CSAFPID-31219', 'CSAFPID-31220', 'CSAFPID-31221', 'CSAFPID-31222', 'CSAFPID-31223', 'CSAFPID-31224', 'CSAFPID-31225', 'CSAFPID-31301', 'CSAFPID-31302', 'CSAFPID-31303', 'CSAFPID-31304']}, {'summary': 'Fixed products.', 'group_id': 'CSAFGID-0002', 'product_ids': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-32004', 'CSAFPID-32005', 'CSAFPID-32006', 'CSAFPID-32007', 'CSAFPID-32008', 'CSAFPID-32009', 'CSAFPID-32010', 'CSAFPID-32011', 'CSAFPID-32012', 'CSAFPID-32013', 'CSAFPID-32014', 'CSAFPID-32015', 'CSAFPID-32016', 'CSAFPID-32017', 'CSAFPID-32018', 'CSAFPID-32101', 'CSAFPID-32102', 'CSAFPID-32103', 'CSAFPID-32104', 'CSAFPID-32105', 'CSAFPID-32106', 'CSAFPID-32107', 'CSAFPID-32108', 'CSAFPID-32109', 'CSAFPID-32201', 'CSAFPID-32202', 'CSAFPID-32203', 'CSAFPID-32204', 'CSAFPID-32205', 'CSAFPID-32206', 'CSAFPID-32207', 'CSAFPID-32208', 'CSAFPID-32209', 'CSAFPID-32210', 'CSAFPID-32211', 'CSAFPID-32212', 'CSAFPID-32213', 'CSAFPID-32214', 'CSAFPID-32215', 'CSAFPID-32216', 'CSAFPID-32217', 'CSAFPID-32218', 'CSAFPID-32219', 'CSAFPID-32220', 'CSAFPID-32221', 'CSAFPID-32222', 'CSAFPID-32223', 'CSAFPID-32224', 'CSAFPID-32225', 'CSAFPID-32301', 'CSAFPID-32302', 'CSAFPID-32303', 'CSAFPID-32304']}]}, 'vulnerabilities': [{'cve': 'CVE-2024-11025', 'cwe': {'id': 'CWE-89', 'name': "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')"}, 'notes': [{'text': 'An authenticated attacker with low privileges may use a SQL Injection vulnerability in the affected products administration panel to gain read and write access to a specific log file of the device.', 'title': 'Vulnerability Description', 'audience': 'all', 'category': 'description'}], 'title': 'CVE-2024-11025', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.4, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N', 'temporalScore': 5.4, 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 5.4, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'LOW', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007', 'CSAFPID-31008', 'CSAFPID-31009', 'CSAFPID-31010', 'CSAFPID-31011', 'CSAFPID-31012', 'CSAFPID-31013', 'CSAFPID-31014', 'CSAFPID-31015', 'CSAFPID-31016', 'CSAFPID-31017', 'CSAFPID-31018', 'CSAFPID-31101', 'CSAFPID-31102', 'CSAFPID-31103', 'CSAFPID-31104', 'CSAFPID-31105', 'CSAFPID-31106', 'CSAFPID-31107', 'CSAFPID-31108', 'CSAFPID-31109', 'CSAFPID-31201', 'CSAFPID-31202', 'CSAFPID-31203', 'CSAFPID-31204', 'CSAFPID-31205', 'CSAFPID-31206', 'CSAFPID-31207', 'CSAFPID-31208', 'CSAFPID-31209', 'CSAFPID-31210', 'CSAFPID-31211', 'CSAFPID-31212', 'CSAFPID-31213', 'CSAFPID-31214', 'CSAFPID-31215', 'CSAFPID-31216', 'CSAFPID-31217', 'CSAFPID-31218', 'CSAFPID-31219', 'CSAFPID-31220', 'CSAFPID-31221', 'CSAFPID-31222', 'CSAFPID-31223', 'CSAFPID-31224', 'CSAFPID-31225', 'CSAFPID-31301', 'CSAFPID-31302', 'CSAFPID-31303', 'CSAFPID-31304']}], 'remediations': [{'details': 'Update Firmware to version 10.01.18.R', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}, {'details': 'If you can not update your system to the latest version and you assume a manipulation of this database, you can download the raw data as a csv file.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-32004', 'CSAFPID-32005', 'CSAFPID-32006', 'CSAFPID-32007', 'CSAFPID-32008', 'CSAFPID-32009', 'CSAFPID-32010', 'CSAFPID-32011', 'CSAFPID-32012', 'CSAFPID-32013', 'CSAFPID-32014', 'CSAFPID-32015', 'CSAFPID-32016', 'CSAFPID-32017', 'CSAFPID-32018', 'CSAFPID-32101', 'CSAFPID-32102', 'CSAFPID-32103', 'CSAFPID-32104', 'CSAFPID-32105', 'CSAFPID-32106', 'CSAFPID-32107', 'CSAFPID-32108', 'CSAFPID-32109', 'CSAFPID-32201', 'CSAFPID-32202', 'CSAFPID-32203', 'CSAFPID-32204', 'CSAFPID-32205', 'CSAFPID-32206', 'CSAFPID-32207', 'CSAFPID-32208', 'CSAFPID-32209', 'CSAFPID-32210', 'CSAFPID-32211', 'CSAFPID-32212', 'CSAFPID-32213', 'CSAFPID-32214', 'CSAFPID-32215', 'CSAFPID-32216', 'CSAFPID-32217', 'CSAFPID-32218', 'CSAFPID-32219', 'CSAFPID-32220', 'CSAFPID-32221', 'CSAFPID-32222', 'CSAFPID-32223', 'CSAFPID-32224', 'CSAFPID-32225', 'CSAFPID-32301', 'CSAFPID-32302', 'CSAFPID-32303', 'CSAFPID-32304'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007', 'CSAFPID-31008', 'CSAFPID-31009', 'CSAFPID-31010', 'CSAFPID-31011', 'CSAFPID-31012', 'CSAFPID-31013', 'CSAFPID-31014', 'CSAFPID-31015', 'CSAFPID-31016', 'CSAFPID-31017', 'CSAFPID-31018', 'CSAFPID-31101', 'CSAFPID-31102', 'CSAFPID-31103', 'CSAFPID-31104', 'CSAFPID-31105', 'CSAFPID-31106', 'CSAFPID-31107', 'CSAFPID-31108', 'CSAFPID-31109', 'CSAFPID-31201', 'CSAFPID-31202', 'CSAFPID-31203', 'CSAFPID-31204', 'CSAFPID-31205', 'CSAFPID-31206', 'CSAFPID-31207', 'CSAFPID-31208', 'CSAFPID-31209', 'CSAFPID-31210', 'CSAFPID-31211', 'CSAFPID-31212', 'CSAFPID-31213', 'CSAFPID-31214', 'CSAFPID-31215', 'CSAFPID-31216', 'CSAFPID-31217', 'CSAFPID-31218', 'CSAFPID-31219', 'CSAFPID-31220', 'CSAFPID-31221', 'CSAFPID-31222', 'CSAFPID-31223', 'CSAFPID-31224', 'CSAFPID-31225', 'CSAFPID-31301', 'CSAFPID-31302', 'CSAFPID-31303', 'CSAFPID-31304']}}]}
f05baf02ea611fef2c042551e6956949124bd4b0e92e69406fcb92e23679d19e
2026-05-29 08:30:34.565004+03:00
2026-05-29 08:30:34.565004+03:00
csaf_smasolartechnologyag.ndjson
896b278b4f14fe5b3503b84e4f896b421e93b1b13cbb64be886ceab7124da375
{'document': {'lang': 'en-GB', 'notes': [{'text': 'A security researcher discovered that in the affected products a clickjacking vulnerability in the web frontend exists. An attacker could lure the user to click on a malicious website which seems to be the WebUI of the affected product. The affected products are out of support (End-of-Life 2015-12-31).', 'title': 'Summary', 'category': 'summary'}, {'text': 'A user can be tricked into unwanted actions on other systems while he expects to click on the Webbox WebUI.', 'title': 'Impact', 'category': 'description'}, {'text': 'If you can not replace your Webbox by a suitable up-to-date product then isolate the affected network segment by blocking all incoming network traffic. Especially never configure your network to allow a port forwarding to SMA Webbox.', 'title': 'Mitigation', 'category': 'description'}, {'text': 'Replace out-of-support Sunny Webbox / Sunny Webbox with Bluetooth to a suitable up-to-date product. Please note technical information on the switchover to be found at https://www.sma-sunny.com/en/how-to-replace-old-data-logger/', 'title': 'Remediation', 'category': 'description'}], 'title': 'SMA: Sunny Webbox clickjacking vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2024-075', 'status': 'final', 'aliases': ['VDE-2024-075'], 'version': '2.0.1', 'generator': {'date': '2025-06-17T05:54:59.215Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.26'}}, 'revision_history': [{'date': '2025-01-20T11:00:00.000Z', 'number': '1.0.0', 'summary': 'Initial revision.'}, {'date': '2025-02-12T16:48:47.000Z', 'number': '2.0.0', 'summary': 'Fix: corrected self-reference'}, {'date': '2025-06-17T06:00:00.000Z', 'number': '2.0.1', 'summary': "fixed typo: Got 'vers:all/* ', expected 'vers:all/*', switched to semver versioning scheme"}], 'current_release_date': '2025-06-17T06:00:00.000Z', 'initial_release_date': '2025-01-27T13:00:00.000Z'}, 'publisher': {'name': 'SMA Solar Technology AG', 'category': 'vendor', 'namespace': 'https://sma.de', 'contact_details': 'information-security@sma.de'}, 'references': [{'url': 'https://www.sma.de/en/cybersecurity/product-security', 'summary': 'SMA PSIRT', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/sma/', 'summary': 'CERT@VDE Security Advisories for SMA', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/VDE-2024-075', 'summary': 'VDE-2024-075: SMA: Sunny Webbox clickjacking vulnerability - HTML', 'category': 'self'}, {'url': 'https://sma.csaf-tp.certvde.com/.well-known/csaf/white/2025/vde-2024-075.json', 'summary': 'VDE-2024-075: SMA: Sunny Webbox clickjacking vulnerability - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}, {'urls': ['https://www.incibe.es'], 'summary': 'reporting', 'organization': 'INCIBE'}]}, 'product_tree': {'branches': [{'name': 'SMA Solar Technology AG', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'Sunny Webbox', 'branches': [{'name': 'SMA Sunny Webbox', 'product': {'name': 'SMA Sunny Webbox', 'product_id': 'CSAFPID-11900'}, 'category': 'product_name'}, {'name': 'SMA Sunny Webbox with Bluetooth', 'product': {'name': 'SMA Sunny Webbox with Bluetooth', 'product_id': 'CSAFPID-11901'}, 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': 'vers:all/* ', 'product': {'name': 'SMA Sunny Webbox Firmware all', 'product_id': 'CSAFPID-21900'}, 'category': 'product_version_range'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'All firmware installed on SMA Sunny Webbox', 'product_id': 'CSAFPID-32900'}, 'product_reference': 'CSAFPID-21900', 'relates_to_product_reference': 'CSAFPID-11900'}, {'category': 'installed_on', 'full_product_name': {'name': 'All firmware installed on SMA Sunny Webbox with Bluetooth', 'product_id': 'CSAFPID-32901'}, 'product_reference': 'CSAFPID-21900', 'relates_to_product_reference': 'CSAFPID-11901'}], 'product_groups': [{'summary': 'Affected products, End of Life', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-11900', 'CSAFPID-11901']}]}, 'vulnerabilities': [{'cve': 'CVE-2024-1890', 'cwe': {'id': 'CWE-1021', 'name': 'Improper Restriction of Rendered UI Layers or Frames'}, 'notes': [{'text': 'Vulnerability whereby an attacker could send a malicious link to an authenticated operator, which could allow remote attackers to perform a clickjacking attack on Sunny WebBox firmware version 1.6.1 and earlier.', 'title': 'Vulnerability Description', 'audience': 'all', 'category': 'description'}], 'title': 'CVE-2024-1890', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.4, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:L', 'temporalScore': 6.4, 'integrityImpact': 'LOW', 'userInteraction': 'REQUIRED', 'attackComplexity': 'HIGH', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'LOW', 'environmentalScore': 6.4, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-11900', 'CSAFPID-11901']}], 'release_date': '2024-02-26T11:00:00.000Z', 'remediations': [{'date': '2025-01-20T11:00:00.000Z', 'details': 'Replace out-of-support Sunny Webbox / Sunny Webbox with Bluetooth to a suitable up-to-date product. Please note technical information on the switchover to be found at https://www.sma-sunny.com/en/how-to-replace-old-data-logger/', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-11900', 'CSAFPID-11901']}}]}
2e7787314b550d41234a962f149629f46257fed2e76184421d93f1165f4abaf4
2026-05-29 08:30:34.565004+03:00
2026-05-29 08:30:34.565004+03:00
csaf_smasolartechnologyag.ndjson
4286bf52f573316a08e1c0c2fbae9c2f29783a4545714fe66da5726e09a7d14e
{'document': {'lang': 'en-GB', 'notes': [{'text': '[CERT@VDE CSAF Template](https://github.com/CERTVDE/CSAF-Template) © 2024 by [CERT@VDE](https://certvde.com) is licensed under [CC BY-NC 4.0](https://creativecommons.org/licenses/by-nc/4.0/?ref=chooser-v1) \n\nThis document note may only be removed in order to create a CSAF advisory based on this template.', 'title': 'LICENSE', 'audience': 'csaf creator', 'category': 'other'}, {'text': 'A security researcher discovered a privilege escalation vulnerability in the demo system area of the SMA Classic Portal, www.sunnyportal.com.\nOnly systems of other users have been affected who unintendedly and illicitly had added their non-demo systems to the demo system area.', 'title': 'Summary', 'category': 'summary'}, {'text': 'An unauthenticated attacker could get access to systems within the demo-system area. Limited to the demo-systems provided there the attacker could change parameters and configuration data. No indicators of compromise have been identified.', 'title': 'Impact', 'category': 'description'}, {'text': 'No action required. The vulnerability was closed in the portal backend on Feb 20th, 2025. A workaround mitigating the impact was implemented on Jan 20th, 2025 immediately after reporting of the issue.', 'title': 'Remediation', 'category': 'description'}, {'text': 'Sunny Portal is an online portal for SMA customers to monitor their PV Systems', 'title': 'Product Description', 'category': 'description'}], 'title': 'SMA: Sunny Portal demo system privilege escalation', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2025-010', 'status': 'final', 'aliases': ['VDE-2025-010'], 'version': '2', 'generator': {'date': '2025-05-08T09:09:24.633Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.24'}}, 'revision_history': [{'date': '2025-05-13T11:00:00.000Z', 'number': '1', 'summary': 'Initial revision.'}, {'date': '2025-05-14T13:00:14.000Z', 'number': '2', 'summary': 'Fix: added distribution'}], 'current_release_date': '2025-05-14T13:00:14.000Z', 'initial_release_date': '2025-05-13T11:00:00.000Z'}, 'publisher': {'name': 'SMA Solar Technology AG', 'category': 'vendor', 'namespace': 'https://sma.de', 'contact_details': 'information-security@sma.de'}, 'references': [{'url': 'https://www.sma.de/en/cybersecurity/product-security', 'summary': 'SMA PSIRT', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/sma/', 'summary': 'CERT@VDE Security Advisories for SMA', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/VDE-2025-010', 'summary': 'VDE-2025-010: SMA: Sunny Portal demo system privilege escalation - HTML', 'category': 'self'}, {'url': 'https://sma.csaf-tp.certvde.com/.well-known/csaf/white/2025/vde-2025-010.json', 'summary': 'VDE-2025-010: SMA: Sunny Portal demo system privilege escalation - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}, {'summary': 'reporting', 'organization': 'Jannik Zimmer'}]}, 'product_tree': {'branches': [{'name': 'SMA Solar Technology AG', 'branches': [{'name': 'Software', 'branches': [{'name': 'www.sunnyportal.com', 'branches': [{'name': '<20.02.2025', 'product': {'name': 'www.sunnyportal.com <20.02.2025', 'product_id': 'CSAFPID-51001'}, 'category': 'product_version_range'}, {'name': '20.02.2025', 'product': {'name': 'Software www.sunnyportal.com 20.02.2025', 'product_id': 'CSAFPID-52001'}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-41645', 'cwe': {'id': 'CWE-669', 'name': 'Incorrect Resource Transfer Between Spheres'}, 'notes': [{'text': 'An unauthenticated remote attacker could use a demo account of the portal to hijack devices that were created in that account by mistake.', 'title': 'Vulnerability Description', 'audience': 'all', 'category': 'description'}], 'title': 'CVE-2025-41645', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 8.6, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N', 'temporalScore': 8.6, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'NONE', 'environmentalScore': 8.6, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': 'SMA has fixed the vulnerability on the web service. No customer action required.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-52001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}]}
8973f898fbf8ae683143c03413d05b8e0dfd0e89bc8bf3013335a9aa3f33e51b
2026-05-29 08:30:34.565004+03:00
2026-05-29 08:30:34.565004+03:00
csaf_smasolartechnologyag.ndjson
1b7e567d9bce2a208352c517c1c42838c24168c0dde12cfbd361faeb64bb273c
{'document': {'lang': 'en-GB', 'notes': [{'text': '[CERT@VDE CSAF Template](https://github.com/CERTVDE/CSAF-Template) © 2024 by [CERT@VDE](https://certvde.com) is licensed under [CC BY-NC 4.0](https://creativecommons.org/licenses/by-nc/4.0/?ref=chooser-v1) \n\nThis document note may only be removed in order to create a CSAF advisory based on this template.', 'title': 'LICENSE', 'audience': 'csaf creator', 'category': 'other'}, {'text': 'A security researcher discovered a critical Remote Code Execution vulnerability in sunnyportal.com.\nAn attacker could upload code instead of an image and remotely execute this code.', 'title': 'Summary', 'category': 'summary'}, {'text': 'An unauthenticated attacker could upload code instead of an image in the demo section of the portal and can remotely execute this code.', 'title': 'Impact', 'category': 'description'}, {'text': 'No action required. The vulnerability was closed in the portal on December, 19, 2024.', 'title': 'Remediation', 'category': 'description'}, {'text': 'Sunny Portal is an online portal for SMA customers to monitor their PV Systems', 'title': 'Product Description', 'category': 'description'}], 'title': 'SMA: Sunny Portal Remote Code Execution', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2025-012', 'status': 'final', 'aliases': ['VDE-2025-012'], 'version': '4', 'generator': {'date': '2025-02-28T13:40:20.075Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.18'}}, 'revision_history': [{'date': '2025-02-26T11:00:00.000Z', 'number': '1', 'summary': 'Initial revision.'}, {'date': '2025-02-28T14:00:00.000Z', 'number': '2', 'summary': 'Update: Changed Date in Remediation'}, {'date': '2025-04-10T13:00:00.000Z', 'number': '3', 'summary': 'fixed document status, csaf reference URL'}, {'date': '2025-05-22T13:03:10.000Z', 'number': '4', 'summary': 'Fix: added distribution, quotation mark'}], 'current_release_date': '2025-05-22T13:03:10.000Z', 'initial_release_date': '2025-02-26T11:00:00.000Z'}, 'publisher': {'name': 'SMA Solar Technology AG', 'category': 'vendor', 'namespace': 'https://sma.de', 'contact_details': 'information-security@sma.de'}, 'references': [{'url': 'https://www.sma.de/en/cybersecurity/product-security', 'summary': 'SMA PSIRT', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/sma/', 'summary': 'CERT@VDE Security Advisories for SMA', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/VDE-2025-012', 'summary': 'VDE-2025-012: SMA: Sunny Portal Remote Code Execution - HTML', 'category': 'self'}, {'url': 'https://sma.csaf-tp.certvde.com/.well-known/csaf/white/2025/vde-2025-012.json', 'summary': 'VDE-2025-012: SMA: Sunny Portal Remote Code Execution - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}, {'urls': ['https://www.forescout.com'], 'names': ['Francesco La Spina'], 'summary': 'reporting', 'organization': 'Forescout Technologies Inc. '}]}, 'product_tree': {'branches': [{'name': 'SMA Solar Technology AG', 'branches': [{'name': 'Software', 'branches': [{'name': 'www.sunnyportal.com', 'branches': [{'name': '<19.12.2024', 'product': {'name': 'www.sunnyportal.com <19.12.2024', 'product_id': 'CSAFPID-51001'}, 'category': 'product_version_range'}, {'name': '19.12.2024', 'product': {'name': 'Software www.sunnyportal.com 19.12.2024', 'product_id': 'CSAFPID-52001'}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-0731', 'cwe': {'id': 'CWE-434', 'name': 'Unrestricted Upload of File with Dangerous Type'}, 'notes': [{'text': "An unauthenticated remote attacker can upload a '.aspx' file instead of a PV system picture through the demo account. The code can only be executed in the security context of the user.\n", 'title': 'Vulnerability Description', 'audience': 'all', 'category': 'description'}], 'title': 'CVE-2025-0731', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L', 'temporalScore': 6.5, 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'LOW', 'environmentalScore': 6.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'date': '2024-12-19T11:00:00.000Z', 'details': 'SMA has fixed the vulnerability on the web service. No customer action required.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-52001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}]}
143310925fe4ce2e9ce3e9e9dd96ef51972a8676cacff25382331de5c447b1f8
2026-05-29 08:30:34.565004+03:00
2026-05-29 08:30:34.565004+03:00
csaf_smasolartechnologyag.ndjson
bb41f785dfde7aac37a158c53bb8336aeeb99b445b460607da4bdf5923465c88
{'document': {'lang': 'en-GB', 'notes': [{'text': '[CERT@VDE CSAF Template](https://github.com/CERTVDE/CSAF-Template) © 2024 by [CERT@VDE](https://certvde.com) is licensed under [CC BY-NC 4.0](https://creativecommons.org/licenses/by-nc/4.0/?ref=chooser-v1) \n\nThis document note may only be removed in order to create a CSAF advisory based on this template.', 'title': 'LICENSE', 'audience': 'csaf creator', 'category': 'other'}, {'text': 'A security researcher discovered a data disclosure vulnerability in Sunny Portal powered by ennexOS, ennexos.sunnyportal.com.\nA regularly authenticated user can receive the name of an other registered Sunny Portal user by entering the email address of this registered user.', 'title': 'Summary', 'category': 'summary'}, {'text': 'A regularly authenticated user of Sunny Portal could receive name and surname of other registered users.', 'title': 'Impact', 'category': 'description'}, {'text': 'No action required. The vulnerability was closed in the Sunny Portal powered by ennexOS on August, 15th 2025.', 'title': 'Remediation', 'category': 'description'}, {'text': 'Sunny Portal powered by ennexOS is an online portal for SMA customers to monitor their PV Systems', 'title': 'Product Description', 'category': 'description'}], 'title': 'SMA: Sunny Portal limited disclosure of personal data of registered users to an authenticated user', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2025-050', 'status': 'final', 'aliases': ['VDE-2025-050'], 'version': '1', 'generator': {'date': '2025-07-28T08:00:30.061Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.26'}}, 'revision_history': [{'date': '2025-08-19T10:00:00.000Z', 'number': '1', 'summary': 'Initial revision.'}], 'current_release_date': '2025-08-19T10:00:00.000Z', 'initial_release_date': '2025-08-19T10:00:00.000Z'}, 'publisher': {'name': 'SMA Solar Technology AG', 'category': 'vendor', 'namespace': 'https://sma.de', 'contact_details': 'information-security@sma.de'}, 'references': [{'url': 'https://www.sma.de/en/cybersecurity/product-security', 'summary': 'SMA PSIRT', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/sma/', 'summary': 'CERT@VDE Security Advisories for SMA', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/VDE-2025-050', 'summary': 'VDE-2025-050: SMA: Sunny Portal limited disclosure of personal data of registered users to an authenticated user - HTML', 'category': 'self'}, {'url': 'https://sma.csaf-tp.certvde.com/.well-known/csaf/white/2025/vde-2025-050.json', 'summary': 'VDE-2025-050: SMA: Sunny Portal limited disclosure of personal data of registered users to an authenticated user - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}, {'summary': 'Reporting', 'organization': 'Jannik Zimmer'}], 'aggregate_severity': {'text': 'Medium', 'namespace': 'https://www.first.org/cvss/v3.1/specification-document#Qualitative-Severity-Rating-Scale'}}, 'product_tree': {'branches': [{'name': 'SMA Solar Technology AG', 'branches': [{'name': 'Software', 'branches': [{'name': 'ennexos.sunnyportal.com', 'branches': [{'name': '<15.08.2025', 'product': {'name': 'ennexos.sunnyportal.com <15.08.2025', 'product_id': 'CSAFPID-51001'}, 'category': 'product_version_range'}, {'name': '15.08.2025', 'product': {'name': 'Software ennexos.sunnyportal.com 15.08.2025', 'product_id': 'CSAFPID-52001'}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-41685', 'cwe': {'id': 'CWE-359', 'name': 'Exposure of Private Personal Information to an Unauthorized Actor'}, 'notes': [{'text': "A low-privileged remote attacker can obtain the username of another registered Sunny Portal user by entering that user's email address.", 'title': 'Vulnerability Description', 'audience': 'all', 'category': 'description'}], 'title': 'CVE-2025-41685', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N', 'temporalScore': 6.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 6.5, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'date': '2025-08-15T10:00:00.000Z', 'details': 'SMA has fixed the vulnerability on the Sunny Portal powered by ennexOS. No customer action required.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-52001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}]}
b249c894b4138fc762ca8219f9d560eb4cb33a1452afdfa367aa050b762bc0f1
2026-05-29 08:30:34.565004+03:00
2026-05-29 08:30:34.565004+03:00
csaf_smasolartechnologyag.ndjson
dd17721486d41a672edb421a7fceaa5012d7a3b0d4b86d9441541d36ee74067d
{'document': {'lang': 'en-GB', 'notes': [{'text': 'A security researcher discovered a Directory Traversal vulnerability in Sunny Boy 3, which allows remote attackers to access sensitive information. \nThe vulnerability is already fixed since January 2021 with version 3.10.27.R. ', 'title': 'Summary', 'category': 'summary'}, {'text': 'An authenticated user can access files and directories outside the intended web root.', 'title': 'Impact', 'category': 'description'}, {'text': 'Update Firmware to at least version 3.10.27.R.', 'title': 'Remediation', 'category': 'description'}], 'title': 'SMA: Directory Traversal in Sunny Boy', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2025-066', 'status': 'final', 'aliases': ['VDE-2025-066'], 'version': '1.0.0', 'generator': {'date': '2025-08-21T09:10:39.333Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.33'}}, 'revision_history': [{'date': '2025-08-27T08:00:00.000Z', 'number': '1.0.0', 'summary': 'Initial revision.'}], 'current_release_date': '2025-08-27T08:00:00.000Z', 'initial_release_date': '2025-08-27T08:00:00.000Z'}, 'publisher': {'name': 'SMA Solar Technology AG', 'category': 'vendor', 'namespace': 'https://sma.de', 'contact_details': 'information-security@sma.de'}, 'references': [{'url': 'https://www.sma.de/cybersicherheit/produktsicherheit', 'summary': 'SMA PSIRT', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/sma/', 'summary': 'CERT@VDE Security Advisories for SMA', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/VDE-2025-066', 'summary': 'VDE-2025-066: SMA: Directory Traversal in Sunny Boy - HTML', 'category': 'self'}, {'url': 'https://sma.csaf-tp.certvde.com/.well-known/csaf/white/2025/vde-2025-066.json', 'summary': 'VDE-2025-066: SMA: Directory Traversal in Sunny Boy - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}, {'names': ['Ahmed Alroky'], 'summary': 'reporting', 'organization': ' KOIN Network'}]}, 'product_tree': {'branches': [{'name': 'SMA Solar Technology AG', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'Sony Boy', 'branches': [{'name': 'Sunny Boy 3.0', 'product': {'name': 'Sunny Boy 3.0', 'product_id': 'CSAFPID-11001', 'product_identification_helper': {'model_numbers': ['SB3.0-1AV-41']}}, 'category': 'product_name'}, {'name': 'Sunny Boy 3.6', 'product': {'name': 'Sunny Boy 3.6', 'product_id': 'CSAFPID-11002', 'product_identification_helper': {'model_numbers': ['SB3.6-1AV-41']}}, 'category': 'product_name'}, {'name': 'Sunny Boy 4.0', 'product': {'name': 'Sunny Boy 4.0', 'product_id': 'CSAFPID-11003', 'product_identification_helper': {'model_numbers': ['SB4.0-1AV-41']}}, 'category': 'product_name'}, {'name': 'Sunny Boy 5.0', 'product': {'name': 'Sunny Boy 5.0', 'product_id': 'CSAFPID-11004', 'product_identification_helper': {'model_numbers': ['SB5.0-1AV-41']}}, 'category': 'product_name'}, {'name': 'Sunny Boy 6.0', 'product': {'name': 'Sunny Boy 6.0', 'product_id': 'CSAFPID-11005', 'product_identification_helper': {'model_numbers': ['SB6.0-1AV-41']}}, 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': '<3.10.27.R', 'product': {'name': 'Firmware <3.10.27.R', 'product_id': 'CSAFPID-21001'}, 'category': 'product_version_range'}, {'name': '3.10.27.R', 'product': {'name': 'Firmware 3.10.27.R', 'product_id': 'CSAFPID-22001'}, 'category': 'product_version'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware <3.10.27.R installed on Sunny Boy 3.0', 'product_id': 'CSAFPID-31001'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <3.10.27.R installed on Sunny Boy 3.6', 'product_id': 'CSAFPID-31002'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11002'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <3.10.27.R installed on Sunny Boy 4.0', 'product_id': 'CSAFPID-31003'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11003'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <3.10.27.R installed on Sunny Boy 5.0', 'product_id': 'CSAFPID-31004'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11004'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <3.10.27.R installed on Sunny Boy 6.0', 'product_id': 'CSAFPID-31005'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11005'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 3.10.27.R installed on Sunny Boy 3.0', 'product_id': 'CSAFPID-32001'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 3.10.27.R installed on Sunny Boy 3.6', 'product_id': 'CSAFPID-32002'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11002'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 3.10.27.R installed on Sunny Boy 4.0', 'product_id': 'CSAFPID-32003'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11003'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 3.10.27.R installed on Sunny Boy 5.0', 'product_id': 'CSAFPID-32004'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11004'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 3.10.27.R installed on Sunny Boy 6.0', 'product_id': 'CSAFPID-32005'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11005'}], 'product_groups': [{'summary': 'Affected products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}, {'summary': 'Fixed products.', 'group_id': 'CSAFGID-0002', 'product_ids': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-32004', 'CSAFPID-32005']}]}, 'vulnerabilities': [{'cve': 'CVE-2021-4459', 'cwe': {'id': 'CWE-23', 'name': 'Relative Path Traversal'}, 'notes': [{'text': 'An authorized remote attacker can access files and directories outside the intended web root, potentially exposing sensitive system information of the affected Sunny Boy devices. ', 'title': 'Vulnerability Description', 'audience': 'all', 'category': 'description'}], 'title': 'CVE-2021-4459', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N', 'temporalScore': 6.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 6.5, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}], 'remediations': [{'details': 'Update Firmware to version 3.10.27.R or newer.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-32004', 'CSAFPID-32005'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}}]}
ff32c3690660359847a215b443c1437587be05e89c14aefb26cdf9677bc533b3
2026-05-29 08:30:34.565004+03:00
2026-05-29 08:30:34.565004+03:00
csaf_trustsource.ndjson
18ba55cd6984afea66652b78113c7138342c43f5e2aa5b33a547c0af3cf96f42
{'document': {'notes': [{'text': 'Detailed list of project vulnerabilities', 'title': 'Author comment', 'category': 'summary'}], 'title': 'Project CSAF document', 'category': 'csaf_vex', 'tracking': {'id': 'tssa-2025-00001', 'status': 'final', 'version': '1', 'generator': {'date': '2025-10-06T11:54:52.856Z', 'engine': {'name': 'TrustSource-CSAF', 'version': '1.0.0'}}, 'revision_history': [{'date': '2025-10-06T11:54:52.856Z', 'number': '1', 'summary': 'Initial version.'}], 'current_release_date': '2025-10-06T11:54:52.856Z', 'initial_release_date': '2025-10-06T11:54:52.856Z'}, 'publisher': {'name': 'TrustSource Product and Service Security', 'category': 'vendor', 'namespace': 'https://app.trustsource.io/'}, 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}}, 'product_tree': {'branches': [{'name': 'EACG Operations Solutions GmbH', 'branches': [{'name': 'JavaTools', 'branches': [{'name': '0.4.0', 'product': {'name': 'ecs-java-client', 'product_id': 'U2FsdGVkX1/PvkRLmbU707SrI0ySwi7noULP/t0B93/l'}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2023-25761', 'cwe': {'id': 'CWE-79', 'name': 'CWE-79'}, 'notes': [{'text': 'Jenkins JUnit Plugin 1166.va_436e268e972 and earlier does not escape test case class names in JavaScript expressions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control test case class names in the JUnit resources processed by the plugin.', 'title': 'CVE description', 'category': 'description'}], 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 5.4, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N', 'integrityImpact': 'LOW', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'LOW'}, 'products': ['U2FsdGVkX1/PvkRLmbU707SrI0ySwi7noULP/t0B93/l']}], 'references': [{'url': 'http://www.openwall.com/lists/oss-security/2023/02/15/4', 'summary': 'Mailing List - Third Party Advisory', 'category': 'external'}, {'url': 'https://www.jenkins.io/security/advisory/2023-02-15/#SECURITY-3032', 'summary': 'Vendor Advisory', 'category': 'external'}, {'url': 'http://www.openwall.com/lists/oss-security/2023/02/15/4', 'summary': 'Mailing List - Third Party Advisory', 'category': 'external'}, {'url': 'https://www.jenkins.io/security/advisory/2023-02-15/#SECURITY-3032', 'summary': 'Vendor Advisory', 'category': 'external'}], 'product_status': {'under_investigation': ['U2FsdGVkX1/PvkRLmbU707SrI0ySwi7noULP/t0B93/l']}}, {'cve': 'CVE-2022-45380', 'cwe': {'id': 'CWE-79', 'name': 'CWE-79'}, 'notes': [{'text': 'Jenkins JUnit Plugin 1159.v0b_396e1e07dd and earlier converts HTTP(S) URLs in test report output to clickable links in an unsafe manner, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.', 'title': 'CVE description', 'category': 'description'}], 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 5.4, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N', 'integrityImpact': 'LOW', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'LOW'}, 'products': ['U2FsdGVkX1/PvkRLmbU707SrI0ySwi7noULP/t0B93/l']}], 'references': [{'url': 'http://www.openwall.com/lists/oss-security/2022/11/15/4', 'summary': 'Mailing List', 'category': 'external'}, {'url': 'https://www.jenkins.io/security/advisory/2022-11-15/#SECURITY-2888', 'summary': 'Vendor Advisory', 'category': 'external'}, {'url': 'http://www.openwall.com/lists/oss-security/2022/11/15/4', 'summary': 'Mailing List', 'category': 'external'}, {'url': 'https://www.jenkins.io/security/advisory/2022-11-15/#SECURITY-2888', 'summary': 'Vendor Advisory', 'category': 'external'}], 'product_status': {'under_investigation': ['U2FsdGVkX1/PvkRLmbU707SrI0ySwi7noULP/t0B93/l']}}, {'cve': 'CVE-2023-0482', 'cwe': {'id': 'CWE-378', 'name': 'CWE-378'}, 'notes': [{'text': 'In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes which creates temp files with insecure permissions that could be read by a local user.', 'title': 'CVE description', 'category': 'description'}], 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['U2FsdGVkX1/PvkRLmbU707SrI0ySwi7noULP/t0B93/l']}], 'references': [{'url': 'https://github.com/resteasy/resteasy/pull/3409/commits/807d7456f2137cde8ef7c316707211bf4e542d56', 'summary': 'Patch', 'category': 'external'}, {'url': 'https://security.netapp.com/advisory/ntap-20230427-0001/', 'summary': 'Third Party Advisory', 'category': 'external'}, {'url': 'https://github.com/resteasy/resteasy/pull/3409/commits/807d7456f2137cde8ef7c316707211bf4e542d56', 'summary': 'Patch', 'category': 'external'}, {'url': 'https://security.netapp.com/advisory/ntap-20230427-0001/', 'summary': 'Third Party Advisory', 'category': 'external'}], 'product_status': {'under_investigation': ['U2FsdGVkX1/PvkRLmbU707SrI0ySwi7noULP/t0B93/l']}}]}
13b31e68b89fefe00ecbbb5baf5271c410dd04062e569bcde886923f34a38815
2026-05-29 08:30:34.965997+03:00
2026-05-29 08:30:34.965997+03:00
csaf_beckhoffautomationgmbhcokg.ndjson
1a83451b3d35456137959ea0a27d8dba577a1d12410f4c2964ed3418747b118b
{'document': {'lang': 'en-GB', 'notes': [{'text': 'In case TwinCAT is configured to use the Profinet driver, a denial of service of the controller could be reached by sending special packets to the device.', 'title': 'Summary', 'category': 'summary'}, {'text': 'TwinCAT includes a Profinet driver, which could be configured in the engineering environment to use Profinet connections to the controller.\n\nIn case this is configured and the controller is started, a specially crafted Profinet DCP packet could be sent to the TwinCAT device, which will lead to a denial of service of the device.\n\nOperation can be resumed by restarting the device.', 'title': 'Impact', 'category': 'description'}, {'text': 'Profinet could be blocked in perimeter firewall to block PROFINET DCP packets from untrusted networks to the device.\n\nBeckhoff will provide updates for the mentioned TwinCAT Versions.', 'title': 'Remediation', 'category': 'description'}], 'title': 'Beckhoff: TwinCAT Denial-of-Service in Profinet driver', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2019-019', 'status': 'final', 'aliases': ['VDE-2019-019'], 'version': '4', 'generator': {'date': '2025-04-11T07:14:12.685Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.23'}}, 'revision_history': [{'date': '2019-10-09T10:00:00.000Z', 'number': '1', 'summary': 'Initial revision.'}, {'date': '2024-11-06T11:27:01.000Z', 'number': '2', 'summary': 'Fix: correct certvde domain, added self-reference'}, {'date': '2025-04-11T07:00:00.000Z', 'number': '3', 'summary': 'Fix: version range'}, {'date': '2025-05-14T13:00:14.000Z', 'number': '4', 'summary': 'Fix: added distribution'}], 'current_release_date': '2025-05-14T13:00:14.000Z', 'initial_release_date': '2019-10-09T10:00:00.000Z'}, 'publisher': {'name': 'Beckhoff Automation GmbH & Co. KG', 'category': 'vendor', 'namespace': 'https://www.beckhoff.com', 'contact_details': 'product-securityincident@beckhoff.com'}, 'references': [{'url': 'https://certvde.com/en/advisories/vendor/beckhoff/', 'summary': 'CERT@VDE Security Advisories for Beckhoff', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/VDE-2019-019', 'summary': 'VDE-2019-019: Beckhoff: TwinCAT Denial-of-Service in Profinet driver - HTML', 'category': 'self'}, {'url': 'https://beckhoff.csaf-tp.certvde.com/.well-known/csaf/white/2019/vde-2019-019.json', 'summary': 'VDE-2019-019: Beckhoff: TwinCAT Denial-of-Service in Profinet driver - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}, {'names': ['Andreas Galauner'], 'summary': 'coordination', 'organization': 'Rapid7'}]}, 'product_tree': {'branches': [{'name': 'Beckhoff', 'branches': [{'name': 'Software', 'branches': [{'name': 'TwinCAT', 'branches': [{'name': '<=2304', 'product': {'name': 'TwinCAT <=2304', 'product_id': 'CSAFPID-11001'}, 'category': 'product_version_range'}, {'name': '<=4204.0', 'product': {'name': 'TwinCAT <=4204.0', 'product_id': 'CSAFPID-11002'}, 'category': 'product_version_range'}, {'name': '2305', 'product': {'name': 'TwinCAT 2305', 'product_id': 'CSAFPID-12001'}, 'category': 'product_version'}, {'name': '4204.1', 'product': {'name': 'TwinCAT 4204.1', 'product_id': 'CSAFPID-12002'}, 'category': 'product_version'}], 'category': 'product_family'}], 'category': 'product_family'}], 'category': 'vendor'}], 'product_groups': [{'summary': 'Affected products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-11001', 'CSAFPID-11002']}, {'summary': 'Fixed products.', 'group_id': 'CSAFGID-0002', 'product_ids': ['CSAFPID-12001', 'CSAFPID-12002']}]}, 'vulnerabilities': [{'cve': 'CVE-2019-5637', 'cwe': {'id': 'CWE-369', 'name': 'Divide By Zero'}, 'notes': [{'text': 'When Beckhoff TwinCAT is configured to use the Profinet driver, a denial of service of the controller could be reached by sending a malformed UDP packet to the device. This issue affects TwinCAT 2 version 2304 (and prior) and TwinCAT 3.1 version 4204.0 (and prior).', 'title': 'Vulnerability Description', 'audience': 'all', 'category': 'description'}], 'title': 'CVE-2019-5637', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-11001', 'CSAFPID-11002']}], 'remediations': [{'details': 'Profinet could be blocked in perimeter firewall to block PROFINET DCP packets from untrusted networks to the device.\n\nBeckhoff will provide updates for the mentioned TwinCAT Versions.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001'], 'entitlements': ['Please contact your support representative for this particular firmware package and update the corresponding product.']}], 'product_status': {'fixed': ['CSAFPID-12001', 'CSAFPID-12002'], 'known_affected': ['CSAFPID-11001', 'CSAFPID-11002']}}]}
987fe4330a2f9eb82cca82930c3cf518ace743c7da63e353d525f290c948b41c
2026-05-29 08:30:35.455889+03:00
2026-05-29 08:30:35.455889+03:00
csaf_beckhoffautomationgmbhcokg.ndjson
9e06db7d3712ca6952f0a391ee663ac8696398562ae93b59cdfa803e478c7040
{'document': {'lang': 'en-GB', 'notes': [{'text': "The coupler's function could be inhibited by an attack.", 'title': 'Summary', 'category': 'summary'}, {'text': "The coupler's function could be inhibited by a denial of service attack. The coupler will not recover after the attack has stopped.\nA reboot of the device recovers the operation.", 'title': 'Impact', 'category': 'description'}, {'text': 'Beckhoff will not change this behaviour.\nCustomers should configure a perimeter firewall to block traffic from untrusted networks to the device.', 'title': 'Mitigation', 'category': 'description'}], 'title': 'Beckhoff: BK9000 couplers - Denial of service inhibits function', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2020-005', 'status': 'final', 'aliases': ['VDE-2020-005'], 'version': '4', 'generator': {'date': '2025-04-11T07:19:30.715Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.23'}}, 'revision_history': [{'date': '2020-03-10T13:17:00.000Z', 'number': '1', 'summary': 'Initial revision.'}, {'date': '2025-01-16T10:00:00.000Z', 'number': '2', 'summary': 'Fix: list of branches, typo in references url'}, {'date': '2025-04-11T07:00:00.000Z', 'number': '3', 'summary': 'Fix: version range'}, {'date': '2025-05-22T13:03:10.000Z', 'number': '4', 'summary': 'Fix: quotation mark'}], 'current_release_date': '2025-05-22T13:03:10.000Z', 'initial_release_date': '2020-03-10T13:17:00.000Z'}, 'publisher': {'name': 'Beckhoff Automation GmbH & Co. KG', 'category': 'vendor', 'namespace': 'https://www.beckhoff.com', 'contact_details': 'product-securityincident@beckhoff.com'}, 'references': [{'url': 'https://certvde.com/en/advisories/vendor/beckhoffautomation/', 'summary': 'CERT@VDE Security Advisories for Beckhoff Automation', 'category': 'external'}, {'url': 'https://certvde.com/de/advisories/vde-2020-005/', 'summary': 'VDE-2020-005: Beckhoff: BK9000 couplers - Denial of service inhibits function - HTML', 'category': 'self'}, {'url': 'https://beckhoff.csaf-tp.certvde.com/.well-known/csaf/white/2020/vde-2020-005.json', 'summary': 'VDE-2020-005: Beckhoff: BK9000 couplers - Denial of service inhibits function - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}, {'names': ['Martin Menschner'], 'summary': 'support and efforts within coordinated\ndisclousure.', 'organization': 'Rhebo GmbH'}]}, 'product_tree': {'branches': [{'name': 'Beckhoff Automation', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'BK9000', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'BK9000 vers:all/*', 'product_id': 'CSAFPID-11001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2020-9464', 'cwe': {'id': 'CWE-400', 'name': 'Uncontrolled Resource Consumption'}, 'notes': [{'text': "A Denial-of-Service vulnerability exists in BECKHOFF Ethernet TCP/IP Bus Coupler BK9000. After an attack has occurred, the device's functionality can be restored by rebooting.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2020-9464', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-11001']}], 'remediations': [{'details': 'Beckhoff will not change this behaviour.\nCustomers should configure a perimeter firewall to block traffic from untrusted networks to the device.', 'category': 'mitigation', 'product_ids': ['CSAFPID-11001']}], 'product_status': {'known_affected': ['CSAFPID-11001']}}]}
79185f5abc9470409bad3ae5284ace69963980437b0ed08f313a15139250ee1c
2026-05-29 08:30:35.455889+03:00
2026-05-29 08:30:35.455889+03:00
csaf_beckhoffautomationgmbhcokg.ndjson
bd11e2b69ff0029ed89f5db420c4b9403371c87e908e65a8a09de6e30e984a13
{'document': {'lang': 'en-GB', 'notes': [{'text': "Beckhoff's TwinCAT RT network driver for Intel 8254x and 8255x is providing EtherCAT functionality. The driver implements real-time features. Except for Ethernet frames sent from real-time functionality, all other Ethernet frames sent through the driver are not padded if their payload is less than the minimum Ethernet frame size. Instead, arbitrary memory content is transmitted within in the padding bytes of the frame. Most likely this memory contains slices from previously transmitted or received frames.", 'title': 'Summary', 'category': 'summary'}, {'text': 'By this method, memory content is disclosed, however, an attacker can hardly control which memory content is affected. For example, the disclosure can be provoked with small sized ICMP echo requests sent to the device.', 'title': 'Impact', 'category': 'description'}, {'text': 'Beckhoff offers software patches for TwinCAT 3.1 and TwinCAT 2.11 on request. These patches will be included in the the next regular releases to the affected software versions.', 'title': 'Remediation', 'category': 'description'}, {'text': 'If no real-time communication from TwinCAT is required on the Ethernet interface, then users can alternatively re-configure them to use the Intel ® driver, which is shipped with Beckhoff images.\n\nCustomers should configure a perimeter firewall to block traffic from untrusted networks to the device, especially regarding ICMP and other small ethernet frames.', 'title': 'Mitigation', 'category': 'description'}], 'title': 'Beckhoff: EtherLeak in TwinCAT RT network driver', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2020-019', 'status': 'final', 'aliases': ['VDE-2020-019'], 'version': '4', 'generator': {'date': '2025-04-11T07:22:18.684Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.23'}}, 'revision_history': [{'date': '2020-06-16T08:31:00.000Z', 'number': '1', 'summary': 'Initial revision.'}, {'date': '2024-11-06T11:27:01.000Z', 'number': '2', 'summary': 'Fix: added self-reference'}, {'date': '2025-04-11T07:00:00.000Z', 'number': '3', 'summary': 'Fix: version range'}, {'date': '2025-05-22T13:03:10.000Z', 'number': '4', 'summary': 'Fix: added distribution, quotation mark'}], 'current_release_date': '2025-05-22T13:03:10.000Z', 'initial_release_date': '2020-06-16T08:31:00.000Z'}, 'publisher': {'name': 'Beckhoff Automation GmbH & Co. KG', 'category': 'vendor', 'namespace': 'https://www.beckhoff.com', 'contact_details': 'product-securityincident@beckhoff.com'}, 'references': [{'url': 'https://certvde.com/en/advisories/vendor/beckhoff/', 'summary': 'CERT@VDE Security Advisories for Beckhoff Automation GmbH & Co. KG', 'category': 'external'}, {'url': 'https://certvde.com/de/advisories/VDE-2020-019/', 'summary': 'VDE-2020-019: Beckhoff: EtherLeak in TwinCAT RT network driver - HTML', 'category': 'self'}, {'url': 'https://beckhoff.csaf-tp.certvde.com/.well-known/csaf/white/2020/vde-2020-019.json', 'summary': 'VDE-2020-019: Beckhoff: EtherLeak in TwinCAT RT network driver - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'summary': 'coordination', 'organization': 'CERT@VDE'}]}, 'product_tree': {'branches': [{'name': 'Beckhoff', 'branches': [{'name': 'Software', 'branches': [{'name': 'TwinCAT Driver for Intel 8254x', 'branches': [{'name': 'TwinCAT 2.11 2350', 'branches': [{'name': '<=2.11.0.2120', 'product': {'name': 'TwinCAT Driver for Intel 8254x TwinCAT 2.11 2350 <=2.11.0.2120', 'product_id': 'CSAFPID-51001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'TwinCAT 3.1 4022', 'branches': [{'name': '<=3.1.0.3512', 'product': {'name': 'TwinCAT Driver for Intel 8254x TwinCAT 3.1 4022 <=3.1.0.3512', 'product_id': 'CSAFPID-51002'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'TwinCAT 3.1 4024', 'branches': [{'name': '<=3.1.0.3603', 'product': {'name': 'TwinCAT Driver for Intel 8254x TwinCAT 3.1 4024 <=3.1.0.3603', 'product_id': 'CSAFPID-51003'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'TwinCAT Driver for Intel 8255x', 'branches': [{'name': 'TwinCAT 2.11 2350', 'branches': [{'name': '<=2.11.0.2117', 'product': {'name': 'TwinCAT Driver for Intel 8255x TwinCAT 2.11 2350 <=2.11.0.2117', 'product_id': 'CSAFPID-51004'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'TwinCAT 3.1 402', 'branches': [{'name': '<=3.1.0.3600', 'product': {'name': 'TwinCAT Driver for Intel 8255x TwinCAT 3.1 402 <=3.1.0.3600', 'product_id': 'CSAFPID-51005'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'TwinCAT 3.1 4024', 'branches': [{'name': '<=3.1.0.3500', 'product': {'name': 'TwinCAT Driver for Intel 8255x TwinCAT 3.1 4024 <=3.1.0.3500', 'product_id': 'CSAFPID-51006'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2020-12494', 'cwe': {'id': 'CWE-200', 'name': 'Exposure of Sensitive Information to an Unauthorized Actor'}, 'notes': [{'text': "Beckhoff's TwinCAT RT network driver for Intel 8254x and 8255x is providing EtherCAT functionality. The driver implements real-time features. Except for Ethernet frames sent from real-time functionality, all other Ethernet frames sent through the driver are not padded if their payload is less than the minimum Ethernet frame size. Instead, arbitrary memory content is transmitted within in the padding bytes of the frame. Most likely this memory contains slices from previously transmitted or received frames. By this method, memory content is disclosed, however, an attacker can hardly control which memory content is affected. For example, the disclosure can be provoked with small sized ICMP echo requests sent to the device.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2020-12494', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N', 'temporalScore': 5.3, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 5.3, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003', 'CSAFPID-51004', 'CSAFPID-51005', 'CSAFPID-51006']}], 'remediations': [{'details': 'Beckhoff offers software patches for TwinCAT 3.1 and TwinCAT 2.11 on request. These patches will be included in the the next regular releases to the affected software versions. The advisory will be updated upon availability.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003', 'CSAFPID-51004', 'CSAFPID-51005', 'CSAFPID-51006']}, {'details': 'If no real-time communication from TwinCAT is required on the Ethernet interface, then users can alternatively re-configure them to use the Intel ® driver, which is shipped with Beckhoff images.\n\nCustomers should configure a perimeter firewall to block traffic from untrusted networks to the device, especially regarding ICMP and other small ethernet frames.', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003', 'CSAFPID-51004', 'CSAFPID-51005', 'CSAFPID-51006']}], 'product_status': {'known_affected': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003', 'CSAFPID-51004', 'CSAFPID-51005', 'CSAFPID-51006']}}]}
050850bb13f30d6739ab2f42707b5da4aec23b097f260a72bbdc64dc2d7a9ded
2026-05-29 08:30:35.455889+03:00
2026-05-29 08:30:35.455889+03:00
csaf_beckhoffautomationgmbhcokg.ndjson
093a408063833dd79bf503046e05ac7519f217e2426f5e6a0daf95b86be1a73b
{'document': {'lang': 'en-GB', 'notes': [{'text': 'The default installation path and its permissions for the TwinCAT runtime allow a local user to replace or modify executables other users of the same system might execute. The issue does not apply for installations underneath C:\\Program Files.', 'title': 'Summary', 'category': 'summary'}, {'text': "The default installation path of the TwinCAT software is underneath C:\\TwinCAT. If the directory does not exist it and further subdirectories are created with permissions which allow every local user to modify the content. The default installation registers TcSysUI.exe for automatic execution upon log in of a user. If a less privileged user has a local account he or she can replace TcSysUI.exe. It will be executed automatically by another user during login. This is also true for users with administrative access. Consequently, a less privileged user can trick a higher privileged user into executing code he or she modified this way. By default Beckhoff's IPCs are shipped with TwinCAT software installed this way and with just a single local user configured. Thus the vulnerability exists if further less privileged users have been added.", 'title': 'Impact', 'category': 'description'}, {'text': "Please consider the solution described with the next section (title 'Solution') for new installations only and installations for which it is acceptable to reinstall TwinCAT.\n\nFor existing installations a script is provided for download at the following link:\nhttps://download.beckhoff.com/download/Document/product-security/Advisories/advisory-2020-003/cve-2020-12510.zip external link\n\nIt changes the permissions of a directory of an already installed TwinCAT 3.1 installation. More precisely, it reads the current permissions of 'C:\\Program Files' and copies them to the directory '3.1\\System' underneath the installation path of TwinCAT (default 'C:\\TwinCAT\\3.1\\System').\n\nThe procedure to use that script is as follows:\n\n1. Download the script, unzip it, and copy it to the IPC.\n2. On the IPC log in as administrator and open a PowerShell (Windows-Key + R + 'PowerShell').\n3. At the PowerShell enter the following command to temporarily allow the execution of scripts: set-executionpolicy -ExecutionPolicy Unrestricted -Scope Process (The effect of this is limited to the life-time of the current shell window because of '-Scope Process'.)\n4. Then change to the path to where you downloaded the script and execute it: .\\cve-2020-12510.ps1 The expected output is 'Copied the permissions from C:\\Program Files to \\3.1\\System'.\n5. Close the PowerShell and log out from the IPC as needed.\nIt is safe to apply the script several times. It is safe to run it during full operation of TwinCAT XAR 3.1. There is no need to reboot the IPC afterwards.\n\nThere is no need to periodically run the script. Future updates of TwinCAT 3.1 will either not touch the permissions which are set by the script or apply more appropriate ones.\n\nTo apply the procedure to a set of IPCs you can prepare a USB stick with the content of the ZIP file 'cve-2020- 12510.zip' (see download URL above). Then the procedure for each IPC is:\n\n1. Log in as administrator on the IPC.\n2. Open the USB stick with the File Explorer (formerly known as Windows Explorer).\n3. Double click on the file 'run-cve-2020-12510.bat'. (This simply invokes the PowerShell to execute the script already described above.)", 'title': 'Mitigation', 'category': 'description'}, {'text': "Please consider the mitigation described with the section above for existing installations for operation.\n\nPlease consider to choose 'C:\\Program Files\\TwinCAT' during installation of TwinCAT 3.1. If you have installed it already then please uninstall and re-install it with the changed path. Please use the custom installation for this. That will automatically protect the binaries such that they can only be modified by an administrator.\n\nPlease mind that already installed projects underneath C:\\TwinCAT need to be moved. It is recommended to perform a backup of the complete device before such action. For security reasons, please remove the former content of C:\\TwinCAT at the end of this sequence. This will also prevent confusion.\n\nUpdate A (25.11.2020): Split into Mitigation and Solution", 'title': 'Remediation', 'category': 'description'}], 'title': 'Beckhoff: Privilege Escalation through TwinCat System Tray (TcSysUI.exe)', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2020-037', 'status': 'final', 'aliases': ['VDE-2020-037'], 'version': '3', 'generator': {'date': '2025-03-20T10:25:06.803Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.21'}}, 'revision_history': [{'date': '2020-11-19T13:41:00.000Z', 'number': '1', 'summary': 'Initial revision.'}, {'date': '2021-11-11T07:28:00.000Z', 'number': '2', 'summary': 'Update A'}, {'date': '2025-05-22T13:03:10.000Z', 'number': '3', 'summary': 'Fix: added distribution, quotation mark'}], 'current_release_date': '2025-05-22T13:03:10.000Z', 'initial_release_date': '2020-11-19T13:41:00.000Z'}, 'publisher': {'name': 'Beckhoff Automation GmbH & Co. KG', 'category': 'vendor', 'namespace': 'https://www.beckhoff.com', 'contact_details': 'product-securityincident@beckhoff.com'}, 'references': [{'url': 'https://certvde.com/en/advisories/vendor/beckhoff/', 'summary': 'CERT@VDE Security Advisories for Beckhoff Automation GmbH & Co. KG', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/VDE-2020-037/', 'summary': 'VDE-2020-037: Beckhoff: Privilege Escalation through TwinCat System Tray (TcSysUI.exe) - HTML', 'category': 'self'}, {'url': 'https://beckhoff.csaf-tp.certvde.com/.well-known/csaf/white/2020/vde-2020-037.json', 'summary': 'VDE-2020-037: Beckhoff: Privilege Escalation through TwinCat System Tray (TcSysUI.exe) - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'summary': 'coordination', 'organization': 'CERT@VDE'}, {'summary': 'reported', 'organization': 'Ayushman Dutta'}]}, 'product_tree': {'branches': [{'name': 'Beckhoff', 'branches': [{'name': 'Software', 'branches': [{'name': 'TwinCAT XAR with default installation path', 'branches': [{'name': '3.1', 'product': {'name': 'TwinCAT XAR with default installation path 3.1', 'product_id': 'CSAFPID-51001'}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2020-12510', 'cwe': {'id': 'CWE-276', 'name': 'Incorrect Default Permissions'}, 'notes': [{'text': "The default installation path of the TwinCAT XAR 3.1 software in all versions is underneath C:\\TwinCAT. If the directory does not exist it and further subdirectories are created with permissions which allow every local user to modify the content. The default installation registers TcSysUI.exe for automatic execution upon log in of a user. If a less privileged user has a local account he or she can replace TcSysUI.exe. It will be executed automatically by another user during login. This is also true for users with administrative access. Consequently, a less privileged user can trick a higher privileged user into executing code he or she modified this way. By default Beckhoff's IPCs are shipped with TwinCAT software installed this way and with just a single local user configured. Thus the vulnerability exists if further less privileged users have been added.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2020-12510', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.3, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H', 'temporalScore': 7.3, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.3, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': "Please consider the solution described with the next section (title 'Solution') for new installations only and installations for which it is acceptable to reinstall TwinCAT.\n\nFor existing installations a script is provided for download at the following link:\nhttps://download.beckhoff.com/download/Document/product-security/Advisories/advisory-2020-003/cve-2020-12510.zip external link\n\nIt changes the permissions of a directory of an already installed TwinCAT 3.1 installation. More precisely, it reads the current permissions of 'C:\\Program Files' and copies them to the directory '3.1\\System' underneath the installation path of TwinCAT (default 'C:\\TwinCAT\\3.1\\System').\n\nThe procedure to use that script is as follows:\n\n1. Download the script, unzip it, and copy it to the IPC.\n2. On the IPC log in as administrator and open a PowerShell (Windows-Key + R + 'PowerShell').\n3. At the PowerShell enter the following command to temporarily allow the execution of scripts: set-executionpolicy -ExecutionPolicy Unrestricted -Scope Process (The effect of this is limited to the life-time of the current shell window because of '-Scope Process'.)\n4. Then change to the path to where you downloaded the script and execute it: .\\cve-2020-12510.ps1 The expected output is 'Copied the permissions from C:\\Program Files to \\3.1\\System'.\n5. Close the PowerShell and log out from the IPC as needed.\nIt is safe to apply the script several times. It is safe to run it during full operation of TwinCAT XAR 3.1. There is no need to reboot the IPC afterwards.\n\nThere is no need to periodically run the script. Future updates of TwinCAT 3.1 will either not touch the permissions which are set by the script or apply more appropriate ones.\n\nTo apply the procedure to a set of IPCs you can prepare a USB stick with the content of the ZIP file 'cve-2020- 12510.zip' (see download URL above). Then the procedure for each IPC is:\n\n1. Log in as administrator on the IPC.\n2. Open the USB stick with the File Explorer (formerly known as Windows Explorer).\n3. Double click on the file 'run-cve-2020-12510.bat'. (This simply invokes the PowerShell to execute the script already described above.)", 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': "Please consider the mitigation described with the section above for existing installations for operation.\n\nPlease consider to choose 'C:\\Program Files\\TwinCAT' during installation of TwinCAT 3.1. If you have installed it already then please uninstall and re-install it with the changed path. Please use the custom installation for this. That will automatically protect the binaries such that they can only be modified by an administrator.\n\nPlease mind that already installed projects underneath C:\\TwinCAT need to be moved. It is recommended to perform a backup of the complete device before such action. For security reasons, please remove the former content of C:\\TwinCAT at the end of this sequence. This will also prevent confusion.\n\nUpdate A (25.11.2020): Split into Mitigation and Solution", 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'known_affected': ['CSAFPID-51001']}}]}
acf045579e83dfa89ad2178d43ac96fc4fe1f0b7340ebed1e66b7ec3a50dc296
2026-05-29 08:30:35.455889+03:00
2026-05-29 08:30:35.455889+03:00
csaf_beckhoffautomationgmbhcokg.ndjson
29debe5a93c9506f5c45627cdb233be3fc50020a54f6868b41db1ca19d421068
{'document': {'lang': 'en-GB', 'notes': [{'text': 'Some TwinCAT OPC UA Server and IPC Diagnostics UA Server versions from Beckhoff Automation GmbH & Co. KG are vulnerable to denial of service attacks. The attacker needs to send several specifically crafted requests to the running OPC UA server. After some of these requests the OPC UA server is no longer responsive to any client. This is without effect to the real-time functionality of IPCs.\n\nUPDATE A - 11.05.2021\n\nPlease note that some hardware products from Beckhoff are shipped with a TwinCAT OPC UA Server pre-installed. In some cases the server is enabled by default.\n\nIPC Diagnostics UA Server (contained in Beckhoff\'s Windows images)\n\nserver versions up to and including 3.1.0.1 are affected\nPlease note that IPC products from Beckhoff are shipped with an IPC Diagnostics UA Server pre-installed. In all cases the server is disabled by default.\nThe version numbers named above always refer to the version number which is accessible via OPC UA at the server via the standard OPC UA node /Objects/Server/ServerStatus/BuildInfo/SoftwareVersion and on Windows also as the file property "File version" of the file TcOpcUaServer.exe for TwinCAT OPC UA Server respectively the file DevMgrSvr-UA.exe for IPC Diagnostics UA Server.\n\nUPDATE A - 11.05.2021\n\nPlease note that IPC products from Beckhoff are shipped with an IPC Diagnostics UA Server pre-installed. While on Windows CE it is disabled by default all other Windows images have it enabled by default.', 'title': 'Summary', 'category': 'summary'}, {'text': 'An attacker who can establish a TCP connection to one of the affected OPC UA servers can send a series of specifically crafted data packets to it. By repeating this several times this will provoke a stack overflow at the OPC UA server which then stops and does not recover until restarted by an administrator.\n\nSince TCP connections are routable there attacker may perform the exploit from remote if there is no firewall set up which limits the access to the TCP which the OPC UA server is listening on. The attacker does not need to have a local account at the device or OPC UA server nor it any authentication required for the attack.\n\nPlease note: The availability impact within the CVSS vector has been rated low because the TwinCAT OPC UA Server and IPC Diagnostics UA Server are seen as less-essential functional parts of an Industrial PC (IPC) image, not as its core functionality. The critical functionality of the IPC is its real-time runtime. The TwinCAT OPC UA Server is a communication interface. The IPC Diagnostics UA Server is for the hardware diagnostics functionality of the IPC. The main function of the IPC remains unaffected during the attack.', 'title': 'Impact', 'category': 'description'}, {'text': 'Consider disabling the IPC Diagnostics Server by stopping and disabling the corresponding Windows service or service. For example this can be achieved with the following PowerShell commands:\n\nStop-Service -Force -Name DevMgrSvr-UA\nSet-Service -Name DevMgrSvr-UA -StartupType Disabled\n\nAlternatively consider limiting access to the TCP port the OPC UA server is listening on. This can happen with a dedicated firewall appliance which sits in front of an affected device. Alternatively at the device the Windows firewall can be configured to limit access to the TCP port. Further guidance is provided within the "Security Guide IPC" from Beckhoff which is accessible at https://www.beckhoff.com/secguide', 'title': 'Mitigation', 'category': 'description'}, {'text': 'For devices running Windows but not Windows CE or TwinCAT/BSD please get a recent version of the OPC UA servers through the conventional ways and update your system.\n\nFor devices running Windows CE please request a recent image via Beckhoff\'s support and apply it to your device.\n\nFor the product CX8091 please use firmware version "CX8091_CE600_LF_v356f_TC211R3_B2306_v2" or later which can be downloaded at\n\nhttps://download.beckhoff.com/download/software/embPC-Control/CX80x0/CX8091/OPC-update\n\nPlease note that the updated OPC UA server leaves less RAM available to your application on the CX8091.', 'title': 'Remediation', 'category': 'description'}], 'title': 'Beckhoff: DoS-Vulnerability for TwinCAT OPC UA Server and IPC Diagnostics UA Server', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2020-051', 'status': 'final', 'aliases': ['VDE-2020-051'], 'version': '1.1.0', 'generator': {'date': '2025-06-12T08:11:49.312Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.27'}}, 'revision_history': [{'date': '2021-04-27T08:08:00.000Z', 'number': '1.0.0', 'summary': 'Initial revision.'}, {'date': '2021-05-11T10:00:00.000Z', 'number': '1.1.0', 'summary': 'UPDATE A'}], 'current_release_date': '2021-05-11T10:00:00.000Z', 'initial_release_date': '2021-04-27T08:08:00.000Z'}, 'publisher': {'name': 'Beckhoff Automation GmbH & Co. KG', 'category': 'vendor', 'namespace': 'https://www.beckhoff.com', 'contact_details': 'product-securityincident@beckhoff.com'}, 'references': [{'url': 'https://certvde.com/en/advisories/VDE-2020-051/', 'summary': 'VDE-2020-051: Beckhoff: DoS-Vulnerability for TwinCAT OPC UA Server and IPC Diagnostics UA Server - HTML', 'category': 'self'}, {'url': 'https://beckhoff.csaf-tp.certvde.com/.well-known/csaf/white/2021/vde-2020-051.json', 'summary': 'VDE-2020-051: Beckhoff: DoS-Vulnerability for TwinCAT OPC UA Server and IPC Diagnostics UA Server - CSAF', 'category': 'self'}, {'url': 'https://www.beckhoff.com', 'summary': 'Vendor PSIRT', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/beckhoff/', 'summary': 'CERT@VDE Security Advisories for Beckhoff Automation GmbH & Co. KG', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}, {'summary': 'reporting', 'organization': 'Industrial Control Security Laboratory of QI-ANXIN Technology Group Inc.'}]}, 'product_tree': {'branches': [{'name': 'Vendor', 'branches': [{'name': 'Software', 'branches': [{'name': 'IPC Diagnostics UA Server', 'branches': [{'name': '<=3.1.0.1', 'product': {'name': 'IPC Diagnostics UA Server <=3.1.0.1', 'product_id': 'CSAFPID-51001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'TwinCAT OPC UA Server', 'branches': [{'name': '<=2.3.0.12', 'product': {'name': 'TwinCAT OPC UA Server <=2.3.0.12', 'product_id': 'CSAFPID-51002'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}], 'product_groups': [{'summary': 'Affected products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-51001', 'CSAFPID-51002']}]}, 'vulnerabilities': [{'cve': 'CVE-2020-12526', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'TwinCAT OPC UA Server in versions up to 2.3.0.12 and IPC Diagnostics UA Server in versions up to 3.1.0.1 from Beckhoff Automation GmbH & Co. KG are vulnerable to denial of service attacks. The attacker needs to send several specifically crafted requests to the running OPC UA server. After some of these requests the OPC UA server is no longer responsive to any client. This is without effect to the real-time functionality of IPCs.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2020-12526', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L', 'temporalScore': 5.3, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'LOW', 'environmentalScore': 5.3, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001', 'CSAFPID-51002']}], 'remediations': [{'details': 'Consider disabling the IPC Diagnostics Server by stopping and disabling the corresponding Windows service or service. For example this can be achieved with the following PowerShell commands:\n\nStop-Service -Force -Name DevMgrSvr-UA\nSet-Service -Name DevMgrSvr-UA -StartupType Disabled\n\nAlternatively consider limiting access to the TCP port the OPC UA server is listening on. This can happen with a dedicated firewall appliance which sits in front of an affected device. Alternatively at the device the Windows firewall can be configured to limit access to the TCP port. Further guidance is provided within the "Security Guide IPC" from Beckhoff which is accessible at https://www.beckhoff.com/secguide', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'For devices running Windows but not Windows CE or TwinCAT/BSD please get a recent version of the OPC UA servers through the conventional ways and update your system.\n\nFor devices running Windows CE please request a recent image via Beckhoff\'s support and apply it to your device.\n\nFor the product CX8091 please use firmware version "CX8091_CE600_LF_v356f_TC211R3_B2306_v2" or later which can be downloaded at\n\nhttps://download.beckhoff.com/download/software/embPC-Control/CX80x0/CX8091/OPC-update\n\nPlease note that the updated OPC UA server leaves less RAM available to your application on the CX8091.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-51001', 'CSAFPID-51002']}}]}
c25ecaafd7ea52667fac7d06894427cdcdf72ffd114c7ae9de4d53b7e7c03412
2026-05-29 08:30:35.455889+03:00
2026-05-29 08:30:35.455889+03:00
csaf_beckhoffautomationgmbhcokg.ndjson
17d4bf8a29ec52d1296d38b660220195d20cef61db8a1e3bae9e2596b836b4f2
{'document': {'lang': 'en-GB', 'notes': [{'text': 'The affected products can act as OPC UA client or server and are vulnerable to two different kind of attacks via\nthe OPC UA protocol. For both cases the attacker can send packets via the OPC UA protocol without the need to\nauthenticate and\n\n1. provoke a stack overflow resulting in denial of service of the product or\n2. make the product disclose information to the attacker without authorization.', 'title': 'Summary', 'category': 'summary'}, {'text': "For both kinds of attacks the attacker needs to use a specifically crafted OPC UA client when attacking an OPC UA server respectively needs to use a specifically crafted OPC UA server when attacking an OPC UA client. For attacking a server the attacker needs to be able to establish a TCP connection to that server. For attacking a client the attacker needs to be able to make the client connect to the attacker's server. For all cases it is sufficient if after the establishment of the TCP connection the attacker lets the specifically crafted application (client or server) respond with a sequence of specifically crafted network packets. No authentication is required by the attacker.\n\nFor the first kind of attack the specifically crafted network packets cause a stack overflow as consequence of an uncontrolled recursion when the attacked application (client or server) processes them. With the components of the product described above, this attack results in a denial of service because the components become unavailable and need to be restarted manually after the attack.\n\nFor the second kind of attack the specifically crafted network packets cause the attacked application to resolve XML entities which allows the inclusion of contents from files on disk as far as they are accessible to the attacked application. Further processing of XML entities allow the resulting XML content to be posted to an HTTP server of the attackers choice. This allows the disclosure of file content from the computer the attacked application is running on even though the attacker is not required to authenticate nor to have access to these files.\n\nThe second attack is possible only if an outdated version of a .NET Framework from Microsoft is used. For more information like vulnerable and fixed versions of the .NET Framework, please see CVE-2015-6096 external link.\n\nSince TCP connections are routable the attacker may perform all these kinds of exploits from remote if there is no firewall set up which limits the access for example to the TCP ports which the OPC UA application is using. The attacker does not need to have a local account at the device or OPC UA server nor is any authentication required for the attack.", 'title': 'Impact', 'category': 'description'}, {'text': "Consider limiting access to the network communication ports of affected server products. Also consider limiting where the affected client products are allowed to connect to. For example, this can be achived with Windows' built-in firewall by incoming rules for servers and outgoing rules for clients. Consider to minimize the ability of an attacker to hijack communication establishment from a client to a server. For example this can be achieved with the help of zones and conduits: Try to keep servers and clients within the same network zone and prevent intrusion into that zone. Try to enclose communication establishment within conduits like VPN channels (where one conduit can serve for many OPC UA connections) and prevent attackers from intruding into such channels. Consider updating the .NET Framework.", 'title': 'Mitigation', 'category': 'description'}, {'text': 'Update to a recent version of the affected product and update the .NET Framework.', 'title': 'Remediation', 'category': 'description'}], 'title': 'Beckhoff: Stack Overflow and XXE vulnerability in various OPC UA products', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2021-008', 'status': 'final', 'aliases': ['VDE-2021-008'], 'version': '4', 'generator': {'date': '2025-04-11T07:25:35.560Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.23'}}, 'revision_history': [{'date': '2021-05-19T09:04:00.000Z', 'number': '1', 'summary': 'Initial revision.'}, {'date': '2025-01-16T11:40:00.000Z', 'number': '2', 'summary': 'Fix: list of branches, references '}, {'date': '2025-04-11T07:00:00.000Z', 'number': '3', 'summary': 'Fix: version range'}, {'date': '2025-05-22T13:03:10.000Z', 'number': '4', 'summary': 'Fix: quotation mark'}], 'current_release_date': '2025-05-22T13:03:10.000Z', 'initial_release_date': '2024-10-21T08:00:00.000Z'}, 'publisher': {'name': 'Beckhoff Automation GmbH & Co. KG', 'category': 'vendor', 'namespace': 'https://www.beckhoff.com', 'contact_details': 'product-securityincident@beckhoff.com'}, 'references': [{'url': 'https://certvde.com/de/advisories/vendor/beckhoff/', 'summary': 'CERT@VDE Security Advisories for Beckhoff', 'category': 'external'}, {'url': 'https://certvde.com/de/advisories/vde-2021-008/', 'summary': 'VDE-2021-008: Beckhoff: Stack Overflow and XXE vulnerability in various OPC UA products - HTML', 'category': 'self'}, {'url': 'https://beckhoff.csaf-tp.certvde.com/.well-known/csaf/white/2024/vde-2021-008.json', 'summary': 'VDE-2021-008: Beckhoff: Stack Overflow and XXE vulnerability in various OPC UA products - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}]}, 'product_tree': {'branches': [{'name': 'Beckhoff', 'branches': [{'name': 'Software', 'branches': [{'name': 'TwinCAT OPC UA Client System Manager Extension included in TF6100', 'branches': [{'name': '<4.3.46.0', 'product': {'name': 'TwinCAT OPC UA Client System Manager Extension included in TF6100 <4.3.46.0', 'product_id': 'CSAFPID-51001'}, 'category': 'product_version_range'}, {'name': '4.3.46.0', 'product': {'name': 'TwinCAT OPC UA Client System Manager Extension included in TF6100 4.3.46.0', 'product_id': 'CSAFPID-52001'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'TwinCAT OPC UA Configurator (Standalone) included in TF6100', 'branches': [{'name': '<4.3.46.0', 'product': {'name': 'TwinCAT OPC UA Configurator (Standalone) included in TF6100 <4.3.46.0', 'product_id': 'CSAFPID-51002'}, 'category': 'product_version_range'}, {'name': '4.3.46.0', 'product': {'name': 'TwinCAT OPC UA Configurator (Standalone) included in TF6100 4.3.46.0', 'product_id': 'CSAFPID-52002'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'TwinCAT OPC UA Configurator (Standalone) included in TS6100', 'branches': [{'name': '<4.3.46.0', 'product': {'name': 'TwinCAT OPC UA Configurator (Standalone) included in TS6100 <4.3.46.0', 'product_id': 'CSAFPID-51003'}, 'category': 'product_version_range'}, {'name': '4.3.46.0', 'product': {'name': 'TwinCAT OPC UA Configurator (Standalone) included in TS6100 4.3.46.0', 'product_id': 'CSAFPID-52003'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'TwinCAT OPC UA Configurator (Visual Studio) included in TF6100', 'branches': [{'name': '<4.3.46.0', 'product': {'name': 'TwinCAT OPC UA Configurator (Visual Studio) included in TF6100 <4.3.46.0', 'product_id': 'CSAFPID-51004'}, 'category': 'product_version_range'}, {'name': '4.3.46.0', 'product': {'name': 'TwinCAT OPC UA Configurator (Visual Studio) included in TF6100 4.3.46.0', 'product_id': 'CSAFPID-52004'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'TwinCAT OPC UA Sample Client included in TF6100', 'branches': [{'name': '<4.3.46.0', 'product': {'name': 'TwinCAT OPC UA Sample Client included in TF6100 <4.3.46.0', 'product_id': 'CSAFPID-51005'}, 'category': 'product_version_range'}, {'name': '4.3.46.0', 'product': {'name': 'TwinCAT OPC UA Sample Client included in TF6100 4.3.46.0', 'product_id': 'CSAFPID-52005'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'TwinCAT OPC UA Sample Client included in TS6100', 'branches': [{'name': '<4.3.46.0', 'product': {'name': 'TwinCAT OPC UA Sample Client included in TS6100 <4.3.46.0', 'product_id': 'CSAFPID-51006'}, 'category': 'product_version_range'}, {'name': '4.3.46.0', 'product': {'name': 'TwinCAT OPC UA Sample Client included in TS6100 4.3.46.0', 'product_id': 'CSAFPID-52006'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'TwinCAT Scope Server in TF3300', 'branches': [{'name': '<3.4.3144.11', 'product': {'name': 'TwinCAT Scope Server in TF3300 <3.4.3144.11', 'product_id': 'CSAFPID-51007'}, 'category': 'product_version_range'}, {'name': ' 3.4.3144.11', 'product': {'name': 'TwinCAT Scope Server in TF3300 3.4.3144.11', 'product_id': 'CSAFPID-52007'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'TwinCAT Target Browser OPC UA Extension included in TF3300', 'branches': [{'name': '<3.4.3144.11', 'product': {'name': 'TwinCAT Target Browser OPC UA Extension included in TF3300 <3.4.3144.11', 'product_id': 'CSAFPID-51008'}, 'category': 'product_version_range'}, {'name': ' 3.4.3144.11', 'product': {'name': 'TwinCAT Target Browser OPC UA Extension included in TF3300 3.4.3144.11', 'product_id': 'CSAFPID-52008'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'TwinCAT Target Browser OPC UA Extension included in TF6100', 'branches': [{'name': '<4.3.46.0', 'product': {'name': 'TwinCAT Target Browser OPC UA Extension included in TF6100 <4.3.46.0', 'product_id': 'CSAFPID-51009'}, 'category': 'product_version_range'}, {'name': '4.3.46.0', 'product': {'name': 'TwinCAT Target Browser OPC UA Extension included in TF6100 4.3.46.0', 'product_id': 'CSAFPID-52009'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'TwinCAT Target Browser OPC UA Extension included in TF6720', 'branches': [{'name': '<1.1.68.0', 'product': {'name': 'TwinCAT Target Browser OPC UA Extension included in TF6720 <1.1.68.0', 'product_id': 'CSAFPID-510010'}, 'category': 'product_version_range'}, {'name': '1.1.68.0', 'product': {'name': 'TwinCAT Target Browser OPC UA Extension included in TF6720 1.1.68.0', 'product_id': 'CSAFPID-52010'}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}], 'product_groups': [{'summary': 'Affected products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003', 'CSAFPID-51004', 'CSAFPID-51005', 'CSAFPID-51006', 'CSAFPID-51007', 'CSAFPID-51008', 'CSAFPID-51009', 'CSAFPID-510010']}, {'summary': 'Fixed Products.', 'group_id': 'CSAFGID-0002', 'product_ids': ['CSAFPID-52001', 'CSAFPID-52002', 'CSAFPID-52003', 'CSAFPID-52004', 'CSAFPID-52005', 'CSAFPID-52006', 'CSAFPID-52007', 'CSAFPID-52008', 'CSAFPID-52009', 'CSAFPID-52010']}]}, 'vulnerabilities': [{'cve': 'CVE-2021-27432', 'cwe': {'id': 'CWE-674', 'name': 'Uncontrolled Recursion'}, 'notes': [{'text': 'OPC Foundation UA .NET Standard versions prior to 1.4.365.48 and OPC UA .NET Legacy are vulnerable to an uncontrolled recursion, which may allow an attacker to trigger a stack overflow.', 'title': 'Vulnerability Description', 'audience': 'all', 'category': 'description'}], 'title': 'CVE-2021-27432', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003', 'CSAFPID-51004', 'CSAFPID-51005', 'CSAFPID-51006', 'CSAFPID-51007', 'CSAFPID-51008', 'CSAFPID-51009', 'CSAFPID-510010']}], 'remediations': [{'details': "Consider limiting access to the network communication ports of affected server products. Also consider limiting where the affected client products are allowed to connect to. For example, this can be achived with Windows' built-in firewall by incoming rules for servers and outgoing rules for clients. Consider to minimize the ability of an attacker to hijack communication establishment from a client to a server. For example this can be achieved with the help of zones and conduits: Try to keep servers and clients within the same network zone and prevent intrusion into that zone. Try to enclose communication establishment within conduits like VPN channels (where one conduit can serve for many OPC UA connections) and prevent attackers from intruding into such channels. Consider updating the .NET Framework.", 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Update to a recent version of the affected product and update the .NET Framework.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-52001', 'CSAFPID-52002', 'CSAFPID-52003', 'CSAFPID-52004', 'CSAFPID-52005', 'CSAFPID-52006', 'CSAFPID-52007', 'CSAFPID-52008', 'CSAFPID-52009', 'CSAFPID-52010'], 'known_affected': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003', 'CSAFPID-51004', 'CSAFPID-51005', 'CSAFPID-51006', 'CSAFPID-51007', 'CSAFPID-51008', 'CSAFPID-51009', 'CSAFPID-510010']}}, {'cve': 'CVE-2021-27434', 'cwe': {'id': 'CWE-200', 'name': 'Exposure of Sensitive Information to an Unauthorized Actor'}, 'notes': [{'text': 'The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could\nlead to unauthenticated remote code execution and full system compromise.\nusers should be able to use the API. The vulnerability allows an unauthenticated attacker to read and set several device\nparameters that can lead to full compromise of the device.', 'title': 'Vulnerability Description', 'audience': 'all', 'category': 'description'}], 'title': 'CVE-2021-27434', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'NONE', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003', 'CSAFPID-51004', 'CSAFPID-51005', 'CSAFPID-51006', 'CSAFPID-51007', 'CSAFPID-51008', 'CSAFPID-51009', 'CSAFPID-510010']}], 'remediations': [{'details': "Consider limiting access to the network communication ports of affected server products. Also consider limiting where the affected client products are allowed to connect to. For example, this can be achived with Windows' built-in firewall by incoming rules for servers and outgoing rules for clients. Consider to minimize the ability of an attacker to hijack communication establishment from a client to a server. For example this can be achieved with the help of zones and conduits: Try to keep servers and clients within the same network zone and prevent intrusion into that zone. Try to enclose communication establishment within conduits like VPN channels (where one conduit can serve for many OPC UA connections) and prevent attackers from intruding into such channels. Consider updating the .NET Framework.", 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Update to a recent version of the affected product and update the .NET Framework.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-52001', 'CSAFPID-52002', 'CSAFPID-52003', 'CSAFPID-52004', 'CSAFPID-52005', 'CSAFPID-52006', 'CSAFPID-52007', 'CSAFPID-52008', 'CSAFPID-52009', 'CSAFPID-52010'], 'known_affected': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003', 'CSAFPID-51004', 'CSAFPID-51005', 'CSAFPID-51006', 'CSAFPID-51007', 'CSAFPID-51008', 'CSAFPID-51009', 'CSAFPID-510010']}}]}
21527657d9a646f30d015683027325ab07ca3f8d7d546af05434b14c287573f3
2026-05-29 08:30:35.455889+03:00
2026-05-29 08:30:35.455889+03:00
csaf_beckhoffautomationgmbhcokg.ndjson
458788af7cabead39ce118b8c7d4ccbf3b6c83d2d8cd12142f9e3742383e7815
{'document': {'lang': 'en-GB', 'notes': [{'text': 'Through specific nodes of the server configuration interface of the TwinCAT OPC UA Server administrators are able to remotely create and delete any files on the system which the server is running on, though this access should have been restricted to specific directories. In case that configuration interface is combined with not recommended settings to allow anonymous access via the TwinCAT OPC UA Server then this kind of file access is even possible for any unauthenticated user from remote.', 'title': 'Summary', 'category': 'summary'}, {'text': 'The OPC UA server called \'TcOpcUaServer\' provides specific nodes within a specifc namespace which allow to configure features of that OPC UA server. By accessing some of these nodes an OPC UA client can create and delete configuration files for these features on behalf of the administrator of the \'TcOpcUaServer\'. For these files dedicated directories are used on the file system of the computer where the \'TcOpcUaServer\' is running. Affected versions were missing specific sanity checks for the file names used and an attacker could add relative paths to the file names to create and delete files outside of the dedicated directories.\n\nThe specific nodes reside within the OPC UA namespace which is identified by the following namespace URI:\n\nhttp://beckhoff.com/TwinCAT/TF6100/Server/Configuration\nWith the default configuration the dedicated directories are the following on the system partition of the system where \'TcOpcUAServer\' is running:\n\nTwinCAT\\Functions\\TF6100-OPC-UA\\Server\\res\nTwinCAT\\Functions\\TF6100-OPC-UA\\Server\\xmlnodesets\nTwinCAT\\Functions\\TF6100-OPC-UA\\Server\\symbolfiles\nPlease note that the default installation of the \'TcOpcUAServer\' does allow anonymous access even to the administrative nodes within the namespace described above. However, Beckhoff recommends to restrict access with the help of the various security features of the \'TcOpcUaServer\' as described with "Configuring security settings - Beckhoff Information System external link" . This is why operating the \'TcOpcUAServer\' with allowing anonymous access to the administrative nodes is not considered the intended use here.', 'title': 'Impact', 'category': 'description'}, {'text': "Consider restricting access to the nodes of the 'TcOpcUAServer' with the methods described by https://infosys.beckhoff.com/content/1033/tcopcuaserver/5930038411-1.html such that the administrative interface can only be accessed by administrative users of well known OPC UA clients.", 'title': 'Mitigation', 'category': 'description'}, {'text': 'Please update to a recent version of the affected product.', 'title': 'Remediation', 'category': 'description'}], 'title': 'Beckhoff: Relative path traversal vulnerability through TwinCAT OPC UA Server', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2021-051', 'status': 'final', 'aliases': ['VDE-2021-051'], 'version': '2', 'generator': {'date': '2025-03-12T10:03:53.568Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.18'}}, 'revision_history': [{'date': '2021-11-04T07:00:00.000Z', 'number': '1', 'summary': 'initial revision'}, {'date': '2025-05-22T13:03:10.000Z', 'number': '2', 'summary': 'Fix: added distribution, quotation mark'}], 'current_release_date': '2025-05-22T13:03:10.000Z', 'initial_release_date': '2021-11-04T07:00:00.000Z'}, 'publisher': {'name': 'Beckhoff Automation GmbH & Co. KG', 'category': 'vendor', 'namespace': 'https://www.beckhoff.com', 'contact_details': 'product-securityincident@beckhoff.com'}, 'references': [{'url': 'https://infosys.beckhoff.com/index.php?content=../content/1031/ipc_security/976057355.html&id=', 'summary': 'Beckhoff Automation GmbH & Co. KG', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/Beckhoff/', 'summary': 'CERT@VDE Security Advisories', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/VDE-2021-051/', 'summary': 'VDE-2021-051: Beckhoff: Relative path traversal vulnerability through TwinCAT OPC UA Server - HTML', 'category': 'self'}, {'url': 'https://beckhoff.csaf-tp.certvde.com/.well-known/csaf/white/2021/vde-2021-051.json', 'summary': 'VDE-2021-051: Beckhoff: Relative path traversal vulnerability through TwinCAT OPC UA Server - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERTVDE'}]}, 'product_tree': {'branches': [{'name': 'Beckhoff Automation GmbH & Co. KG', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'TwinCAT OPC UA Server in TF6100 < 4.3.48.0', 'product': {'name': 'TwinCAT OPC UA Server in TF6100 < 4.3.48.0', 'product_id': 'CSAFPID-11001'}, 'category': 'product_name'}, {'name': 'TwinCAT OPC UA Server in TS6100 < 4.3.48.0', 'product': {'name': 'TwinCAT OPC UA Server in TS6100 < 4.3.48.0', 'product_id': 'CSAFPID-11002'}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': '<3.2.0.194', 'product': {'name': 'Firmware <3.2.0.194', 'product_id': 'CSAFPID-21001'}, 'category': 'product_version_range'}, {'name': '3.2.0.194', 'product': {'name': 'Firmware 3.2.0.194', 'product_id': 'CSAFPID-22001'}, 'category': 'product_version'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware <3.2.0.194 installed on TwinCAT OPC UA Server in TF6100 < 4.3.48.0', 'product_id': 'CSAFPID-31001'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 3.2.0.194 installed on TwinCAT OPC UA Server in TF6100 < 4.3.48.0', 'product_id': 'CSAFPID-32001'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <3.2.0.194 installed on TwinCAT OPC UA Server in TS6100 < 4.3.48.0', 'product_id': 'CSAFPID-31002'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11002'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 3.2.0.194 installed on TwinCAT OPC UA Server in TS6100 < 4.3.48.0', 'product_id': 'CSAFPID-32002'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11002'}], 'product_groups': [{'summary': 'affected products', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-31001', 'CSAFPID-31002']}, {'summary': 'fixed products', 'group_id': 'CSAFGID-0002', 'product_ids': ['CSAFPID-32001', 'CSAFPID-32002']}]}, 'vulnerabilities': [{'cve': 'CVE-2021-34594', 'cwe': {'id': 'CWE-23', 'name': 'Relative Path Traversal'}, 'notes': [{'text': 'TwinCAT OPC UA Server in TF6100 and TS6100 in product versions before 4.3.48.0 or with TcOpcUaServer versions below 3.2.0.194 are prone to a relative path traversal that allow administrators to create or delete any files on the system.', 'category': 'summary'}], 'title': 'CVE-2021-34594', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H', 'temporalScore': 6.5, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'HIGH', 'environmentalScore': 6.5, 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002']}], 'remediations': [{'details': "Consider restricting access to the nodes of the 'TcOpcUAServer' with the methods described by https://infosys.beckhoff.com/content/1033/tcopcuaserver/5930038411-1.html such that the administrative interface can only be accessed by administrative users of well known OPC UA clients.", 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Please update to a recent version of the affected product.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002']}}]}
a82b68985e3646d1764aa9ac0f5e0fd1207f26d2c841986ed775b9871ae22841
2026-05-29 08:30:35.455889+03:00
2026-05-29 08:30:35.455889+03:00
csaf_beckhoffautomationgmbhcokg.ndjson
7a6c5c94491d967cf10cc452c71b282781cbbd8995ef6322f866d835c8a4b986
{'document': {'lang': 'en-GB', 'notes': [{'text': 'By tricking clients of the mentioned products into contacting malicious OPC UA servers and thereby acting as OPC UA clients, a crash of the component can be provoked.', 'title': 'Summary', 'category': 'summary'}, {'text': 'The mentioned products can be used as clients which contact an OPC UA server. If such connection is made with SecurityMode=None for the connection then the client can receive a malformed message during the conversation which provokes a null pointer dereference within the OPC UA stack of the product. The product crashes then by memory access violation. Though this is uncommon and not recommended, such connections with SecurityMode=None may even be used by OPC UA Servers, for example if they act as client to register at a Discovery Server.', 'title': 'Impact', 'category': 'description'}, {'text': "Have your applications configured to use other than SecurityMode=None for all OPC UA connections. Avoid that these connect to an unknown OPC UA server with SecurityMode=None. In particular, avoid that your applications connect to servers which they discover via mDNS, a Local Discovery Server (LDS), an untrusted Global Discovery Server (GDS) or even trusted GDS using SecurityMode=none. Especially in the latter case an adversary might be able to apply the 'man in the middle' pattern to attack the connection and inject a bad message which triggers the vulnerability.", 'title': 'Mitigation', 'category': 'description'}, {'text': 'Please update to a recent version of the affected product.', 'title': 'Remediation', 'category': 'description'}], 'title': 'BECKHOFF: Null Pointer Dereference vulnerability in products with OPC UA technology', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2022-003', 'status': 'final', 'aliases': ['VDE-2022-003'], 'version': '2', 'generator': {'date': '2025-05-08T11:17:51.310Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.25'}}, 'revision_history': [{'date': '2022-03-01T12:34:00.000Z', 'number': '1', 'summary': 'Initial revision.'}, {'date': '2025-06-05T13:28:13.000Z', 'number': '2', 'summary': 'Fix: quotation mark'}], 'current_release_date': '2025-06-05T13:28:13.000Z', 'initial_release_date': '2022-03-01T12:34:00.000Z'}, 'publisher': {'name': 'Beckhoff Automation GmbH & Co. KG', 'category': 'vendor', 'namespace': 'https://www.beckhoff.com', 'contact_details': 'product-securityincident@beckhoff.com'}, 'references': [{'url': 'https://certvde.com/en/advisories/VDE-2022-003/', 'summary': 'VDE-2022-003: BECKHOFF: Null Pointer Dereference vulnerability in products with OPC UA technology - HTML', 'category': 'self'}, {'url': 'https://beckhoff.csaf-tp.certvde.com/.well-known/csaf/white/2022/vde-2022-003.json', 'summary': 'VDE-2022-003: BECKHOFF: Null Pointer Dereference vulnerability in products with OPC UA technology - CSAF', 'category': 'self'}, {'url': 'https://www.beckhoff.com', 'summary': 'Vendor PSIRT', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/beckhoff/', 'summary': 'CERT@VDE Security Advisories for Beckhoff Automation GmbH & Co. KG', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}, {'summary': 'reporting', 'organization': 'OPC Foundation'}, {'summary': 'reporting', 'organization': 'Unified Automation'}]}, 'product_tree': {'branches': [{'name': 'BECKHOFF', 'branches': [{'name': 'Software', 'branches': [{'name': 'EK9160 (TcOpcUaServer)', 'branches': [{'name': '<3.2.0.239', 'product': {'name': 'EK9160 (TcOpcUaServer) <3.2.0.239', 'product_id': 'CSAFPID-51001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'IPC Diagnostic UA Server on windows images (MDP UA Server)', 'branches': [{'name': '<3.1.0.8', 'product': {'name': 'IPC Diagnostic UA Server on windows images (MDP UA Server) <3.1.0.8', 'product_id': 'CSAFPID-51002'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'TF2110 (Setup)', 'branches': [{'name': '<1.12.754.0', 'product': {'name': 'TF2110 (Setup) <1.12.754.0', 'product_id': 'CSAFPID-51003'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'TF6100-OPC-UA-Client (TcOpcUaClient)', 'branches': [{'name': '<2.2.9.1', 'product': {'name': 'TF6100-OPC-UA-Client (TcOpcUaClient) <2.2.9.1', 'product_id': 'CSAFPID-51004'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'TF6100-OPC-UA-Gateway (TcOpcUaGateway)', 'branches': [{'name': '<1.5.8.454', 'product': {'name': 'TF6100-OPC-UA-Gateway (TcOpcUaGateway) <1.5.8.454', 'product_id': 'CSAFPID-51005'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'TF6100-OPC-UA-Server (TcOpcUaServer)', 'branches': [{'name': '<3.2.0.240', 'product': {'name': 'TF6100-OPC-UA-Server (TcOpcUaServer) <3.2.0.240', 'product_id': 'CSAFPID-51006'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'TS6100-0030-OPC-UA (TcOpcUaClient)', 'branches': [{'name': '<2.2.9.1', 'product': {'name': 'TS6100-0030-OPC-UA (TcOpcUaClient) <2.2.9.1', 'product_id': 'CSAFPID-51007'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'TS6100-0030-OPC-UA (TcOpcUaGateway)', 'branches': [{'name': '<1.5.8.454', 'product': {'name': 'TS6100-0030-OPC-UA (TcOpcUaGateway) <1.5.8.454', 'product_id': 'CSAFPID-51008'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'TS6100-0030-OPC-UA (TcOpcUaServer)', 'branches': [{'name': '<3.2.0.240', 'product': {'name': 'TS6100-0030-OPC-UA (TcOpcUaServer) <3.2.0.240', 'product_id': 'CSAFPID-51009'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'TS6100-OPC-UA (TcOpcUaClient)', 'branches': [{'name': '<2.2.9.1', 'product': {'name': 'TS6100-OPC-UA (TcOpcUaClient) <2.2.9.1', 'product_id': 'CSAFPID-510010'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'TS6100-OPC-UA (TcOpcUaGateway)', 'branches': [{'name': '<1.5.8.454', 'product': {'name': 'TS6100-OPC-UA (TcOpcUaGateway) <1.5.8.454', 'product_id': 'CSAFPID-510011'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'TS6100-OPC-UA (TcOpcUaServer)', 'branches': [{'name': '<3.2.0.240', 'product': {'name': 'TS6100-OPC-UA (TcOpcUaServer) <3.2.0.240', 'product_id': 'CSAFPID-510012'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}], 'product_groups': [{'summary': 'Affected products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003', 'CSAFPID-51004', 'CSAFPID-51005', 'CSAFPID-51006', 'CSAFPID-51007', 'CSAFPID-51008', 'CSAFPID-51009', 'CSAFPID-510010', 'CSAFPID-510011', 'CSAFPID-510012']}]}, 'vulnerabilities': [{'cve': 'CVE-2021-45117', 'cwe': {'id': 'CWE-476', 'name': 'NULL Pointer Dereference'}, 'notes': [{'text': 'The OPC autogenerated ANSI C stack stubs (in the NodeSets) do not handle all error cases. This can lead to a NULL pointer dereference.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2021-45117', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'temporalScore': 6.5, 'integrityImpact': 'NONE', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'HIGH', 'environmentalScore': 6.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003', 'CSAFPID-51004', 'CSAFPID-51005', 'CSAFPID-51006', 'CSAFPID-51007', 'CSAFPID-51008', 'CSAFPID-51009', 'CSAFPID-510010', 'CSAFPID-510011', 'CSAFPID-510012']}], 'remediations': [{'details': "Have your applications configured to use other than SecurityMode=None for all OPC UA connections. Avoid that these connect to an unknown OPC UA server with SecurityMode=None. In particular, avoid that your applications connect to servers which they discover via mDNS, a Local Discovery Server (LDS), an untrusted Global Discovery Server (GDS) or even trusted GDS using SecurityMode=none. Especially in the latter case an adversary might be able to apply the 'man in the middle' pattern to attack the connection and inject a bad message which triggers the vulnerability.", 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Please update to a recent version of the affected product.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003', 'CSAFPID-51004', 'CSAFPID-51005', 'CSAFPID-51006', 'CSAFPID-51007', 'CSAFPID-51008', 'CSAFPID-51009', 'CSAFPID-510010', 'CSAFPID-510011', 'CSAFPID-510012']}}]}
5b12f8da054dcce013d39049cfa2ade3a533b70a0d703ce237890790d1672917
2026-05-29 08:30:35.455889+03:00
2026-05-29 08:30:35.455889+03:00
csaf_beckhoffautomationgmbhcokg.ndjson
6c3240fd40a0c5bf1358637b36db7e8289276af618a5ab30a78190d282210da9
{'document': {'lang': 'en-GB', 'notes': [{'text': 'With TwinCAT/BSD based products the HTTPS request to the Authelia login page accepts user-controlled input that specifies a link to an external site.', 'title': 'Summary', 'category': 'summary'}, {'text': "By default TwinCAT/BSD based products have Authelia installed and configured to perform the user authentication for web applications hosted on a target. This installation and configuration is provided with the package named 'authelia-bhf'. With the affected versions of the package Authelia is configured to accept user-controlled input via URL parameter that specifies a link which can then be a link to an arbitrary external site.\n\nPlease note: The sources for the package 'authelia-bhf' are a fork from the original Open Source Software called 'Authelia'. The vulnerability was exclusively introduced with that fork and has been removed there. It never became part of 'Authelia'.", 'title': 'Impact', 'category': 'description'}, {'text': 'Use firewall or web-proxy technology at your network perimeter which allow internal clients to access only trusted external sites directly.', 'title': 'Mitigation', 'category': 'description'}, {'text': 'Please update to a recent version of the affected product.', 'title': 'Remediation', 'category': 'description'}], 'title': 'Beckhoff: Open redirect in TwinCAT/BSD package authelia-bhf', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2023-067', 'status': 'final', 'aliases': ['VDE-2023-067'], 'version': '2', 'generator': {'date': '2025-04-10T15:03:49.421Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.23'}}, 'revision_history': [{'date': '2023-12-13T08:00:00.000Z', 'number': '1', 'summary': 'initial revision'}, {'date': '2025-05-22T13:03:10.000Z', 'number': '2', 'summary': 'Fix: added distribution, quotation mark'}], 'current_release_date': '2025-05-22T13:03:10.000Z', 'initial_release_date': '2023-12-13T08:00:00.000Z'}, 'publisher': {'name': 'Beckhoff Automation GmbH & Co. KG', 'category': 'vendor', 'namespace': 'https://www.beckhoff.com', 'contact_details': 'product-securityincident@beckhoff.com'}, 'references': [{'url': 'https://certvde.com/de/advisories/VDE-2023-067/', 'summary': 'VDE-2023-067: Beckhoff: Open redirect in TwinCAT/BSD package authelia-bhf - HTML', 'category': 'self'}, {'url': 'https://certvde.com/en/advisories/vendor/beckhoff/', 'summary': 'CERT@VDE Security Advisories for Beckhoff Automation GmbH & Co. KG', 'category': 'external'}, {'url': 'https://beckhoff.csaf-tp.certvde.com/.well-known/csaf/white/2023/vde-2023-067.json', 'summary': 'VDE-2023-067: Beckhoff: Open redirect in TwinCAT/BSD package authelia-bhf - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERTVDE'}, {'urls': ['https://www.siemens-energy.com'], 'names': ['Benedikt Kühne'], 'summary': 'reporting', 'organization': 'Siemens Energy'}]}, 'product_tree': {'branches': [{'name': 'Beckhoff Automation GmbH & Co. KG', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'authelia-bhf included in TwinCAT/BSD', 'product': {'name': 'authelia-bhf included in TwinCAT/BSD', 'product_id': 'CSAFPID-11001'}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': '<4.37.5', 'product': {'name': 'Firmware <4.37.5', 'product_id': 'CSAFPID-21001'}, 'category': 'product_version_range'}, {'name': '4.37.5', 'product': {'name': 'Firmware 4.37.5', 'product_id': 'CSAFPID-22001'}, 'category': 'product_version'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware <4.37.5 installed on authelia-bhf included in TwinCAT/BSD', 'product_id': 'CSAFPID-31001'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 4.37.5 installed on authelia-bhf included in TwinCAT/BSD', 'product_id': 'CSAFPID-32001'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11001'}]}, 'vulnerabilities': [{'cve': 'CVE-2023-6545', 'cwe': {'id': 'CWE-601', 'name': "URL Redirection to Untrusted Site ('Open Redirect')"}, 'notes': [{'text': 'The package authelia-bhf included in Beckhoffs TwinCAT/BSD is prone to an open redirect that allows a remote unprivileged attacker to redirect a user to another site. This may have limited impact to integrity and does solely affect anthelia-bhf the Beckhoff fork of authelia.', 'category': 'summary'}], 'title': 'CVE-2023-6545', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 4.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N', 'temporalScore': 4.3, 'integrityImpact': 'LOW', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 4.3, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-31001']}], 'remediations': [{'details': 'Use firewall or web-proxy technology at your network perimeter which allow internal clients to access only trusted external sites directly.', 'category': 'mitigation', 'product_ids': ['CSAFPID-31001']}, {'details': 'Please update to a recent version of the affected product.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31001']}], 'product_status': {'fixed': ['CSAFPID-32001'], 'known_affected': ['CSAFPID-31001']}}]}
dfc73aa4b110ee29464bf8edc089485d6ce8ad699f13a010426853b9c99eda5b
2026-05-29 08:30:35.455889+03:00
2026-05-29 08:30:35.455889+03:00
csaf_beckhoffautomationgmbhcokg.ndjson
9df94a657d1359280cef1bcb625cb3be1c4aab5ae43b9209086ef5daa045630f
{'document': {'lang': 'en-US', 'notes': [{'text': 'By default, TwinCAT/BSD-based products have a device-specific web interface for web-based management (WBM) enabled, developed by Beckhoff and known as Beckhoff Device Manager UI. It can be accessed remotely or locally. When accessed locally, the authentication mechanism for the web interface can be bypassed by any local user, regardless of their permissions, and they can act with administrative access rights via this mechanism.', 'title': 'Summary', 'category': 'summary'}, {'text': 'A local, low privileged attacker could bypass the authentication mechanism for the web interface and act as an administrator.', 'title': 'Impact', 'category': 'description'}, {'text': 'Avoid the existence of user accounts with login permission on the target other than administrator access. By default, TwinCAT/BSD has preconfigured user accounts with lower privileges, but none of them have a password, which results in them being denied login access. Avoid running third-party applications on the target that have not been properly audited, regardless of the user they are running as.', 'title': 'Mitigation', 'category': 'description'}, {'text': 'Please update to a recent version of the affected product. In general, Beckhoff recommends updating the entire TwinCAT/BSD operating system to a current version rather than individual packages. Information on updating existing TwinCAT/BSD installations is available in [here:](https://infosys.beckhoff.com/content/1033/twincat_bsd/11780818443.html?id=4222392218353411614). There you will also find information on how to determine the operating system version via the command line. This is also visible via the Beckhoff Device Manager UI. Please note that when updating from the TwinCAT/BSD major version 12, two consecutive upgrades are required.', 'title': 'Remediation', 'category': 'description'}, {'text': 'Beckhoff Automation welcomes responsibly coordinated reports of vulnerabilities and Beckhoff will collaborate with reporting parties to fix vulnerabilities or mitigate threats.', 'title': 'Reporting vulnerabilities', 'category': 'general'}, {'text': 'Beckhoff is not responsible for any side effects negatively affecting the real-time capabilities of your TwinCAT control application possibly caused by updates. Beckhoff offers updated images with qualified performance for Beckhoff hardware from time to time. TwinCAT System Manager offers tools which can be of assistance to verify real-time performance after update. A backup should be created every time before installing an update. Only administrators or IT experts should perform the backup and update procedure.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}], 'title': 'Beckhoff: Local authentication bypass in IPC-Diagnostics package included in TwinCAT/BSD operating system', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2024-045', 'status': 'final', 'aliases': ['VDE-2024-045'], 'version': '5', 'generator': {'date': '2025-04-11T07:28:12.790Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.23'}}, 'revision_history': [{'date': '2024-08-13T07:00:00.000Z', 'number': '1', 'summary': 'initial revision', 'legacy_version': '1.0'}, {'date': '2024-11-06T11:27:01.000Z', 'number': '2', 'summary': 'Fix: correct certvde domain, added self-reference'}, {'date': '2025-01-16T10:50:00.000Z', 'number': '3', 'summary': 'Fix: list of branches, references url'}, {'date': '2025-04-11T07:00:00.000Z', 'number': '4', 'summary': 'Fix: version range'}, {'date': '2025-05-22T13:03:10.000Z', 'number': '5', 'summary': 'Fix: quotation mark'}], 'current_release_date': '2025-05-22T13:03:10.000Z', 'initial_release_date': '2024-08-27T08:00:00.000Z'}, 'publisher': {'name': 'Beckhoff Automation GmbH & Co. KG', 'category': 'vendor', 'namespace': 'https://www.beckhoff.com', 'contact_details': 'product-securityincident@beckhoff.com'}, 'references': [{'url': 'https://download.beckhoff.com/download/Document/product-security/Advisories/advisory-2024-001.pdf', 'summary': "Beckhoff Security Advisory 2024-001: Local authentication bypass in TwinCAT/BSD package 'IPC-Diagnostics' - PDF version", 'category': 'self'}, {'url': 'https://www.beckhoff.com/secinfo', 'summary': 'Additional information about the latest IPC security advisories is provided here:', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vde-2024-045', 'summary': 'VDE-2024-045: Beckhoff: Local authentication bypass in IPC-Diagnostics package included in TwinCAT/BSD operating system - HTML', 'category': 'self'}, {'url': 'https://certvde.com/en/advisories/vendor/beckhoff/', 'summary': 'CERT@VDE Security Advisories for Beckhoff Automation GmbH & Co. KG', 'category': 'external'}, {'url': 'https://infosys.beckhoff.com/content/1033/twincat_bsd/11780818443.html?id=4222392218353411614', 'summary': 'Detailed information on updating the TwinCAT/BSD operating system', 'category': 'external'}, {'url': 'https://beckhoff.csaf-tp.certvde.com/.well-known/csaf/white/2024/vde-2024-045.json', 'summary': 'VDE-2024-045: Beckhoff: Local authentication bypass in IPC-Diagnostics package included in TwinCAT/BSD operating system - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/v1/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}, {'urls': ['https://www.nozominetworks.com'], 'names': ['Andrea Palanca'], 'summary': 'Reported by', 'organization': 'Nozomi Networks'}]}, 'product_tree': {'branches': [{'name': 'Beckhoff', 'branches': [{'name': 'Software', 'branches': [{'name': 'IPC Diagnostics package', 'branches': [{'name': '<2.0.0.1', 'product': {'name': 'IPC Diagnostics package <2.0.0.1', 'product_id': 'CSAFPID-51001'}, 'category': 'product_version_range'}, {'name': '2.0.0.1', 'product': {'name': 'IPC Diagnostics package 2.0.0.1', 'product_id': 'CSAFPID-52001'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'TwinCAT/BSD', 'branches': [{'name': '<14.1.2.0_153968', 'product': {'name': 'TwinCAT/BSD <14.1.2.0_153968', 'product_id': 'CSAFPID-51002'}, 'category': 'product_version_range'}, {'name': '14.1.2.0_153968', 'product': {'name': 'TwinCAT/BSD 14.1.2.0_153968', 'product_id': 'CSAFPID-52002'}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}], 'product_groups': [{'summary': 'Affected products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-51001', 'CSAFPID-51002']}, {'summary': 'Fixed products.', 'group_id': 'CSAFGID-0002', 'product_ids': ['CSAFPID-52001', 'CSAFPID-52002']}]}, 'vulnerabilities': [{'cve': 'CVE-2024-41173', 'cwe': {'id': 'CWE-288', 'name': 'Authentication Bypass Using an Alternate Path or Channel'}, 'notes': [{'text': 'The IPC-Diagnostics package included in TwinCAT/BSD is vulnerable to a local authentication bypass by a low privileged attacker.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2024-41173', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 7.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.8, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001', 'CSAFPID-51002']}], 'release_date': '2024-08-13T07:00:00.000Z', 'remediations': [{'date': '2024-08-13T07:00:00.000Z', 'details': 'Avoid the existence of user accounts with login permission on the target other than administrator access. By default, TwinCAT/BSD has preconfigured user accounts with lower privileges, but none of them have a password, which results in them being denied login access. Avoid running third-party applications on the target that have not been properly audited, regardless of the user they are running as.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Please update to a recent version of the affected product.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-52001', 'CSAFPID-52002'], 'known_affected': ['CSAFPID-51001', 'CSAFPID-51002']}, 'acknowledgments': [{'urls': ['https://www.nozominetworks.com'], 'names': ['Andrea Palanca'], 'summary': 'Nozomi Networks reported the vulnerability to Beckhoff', 'organization': 'Nozomi Networks'}]}]}
a4ef9e4192e88078b15e2ca948ea402335c289ab5323c3f77b8cf1e7c407657d
2026-05-29 08:30:35.455889+03:00
2026-05-29 08:30:35.455889+03:00
csaf_beckhoffautomationgmbhcokg.ndjson
b3d74c00dff7b71a64ca569ae65b040fbb0cb2688b26b0e7ae1a8be20263469b
{'document': {'lang': 'en-GB', 'notes': [{'text': 'By default, TwinCAT/BSD-based products have a device-specific web interface for web-based management (WBM) enabled, developed by Beckhoff and known as Beckhoff Device Manager UI. It can be accessed remotely or locally. When accessed locally, the user can bypass input validation by entering specially crafted inputs into the user interface for certain pages, which then allows local commands to be executed with administrative privileges.', 'title': 'Summary', 'category': 'summary'}, {'text': 'A local, low privileged attacker could bypass input validation by entering specially crafted inputs into\nthe user interface for certain pages, which then allows local commands to be executed with administrative\nprivileges.', 'title': 'Impact', 'category': 'description'}, {'text': 'Avoid the existence of user accounts with login permission on the target other than administrator access. By default, TwinCAT/BSD has preconfigured user accounts with lower privileges, but none of them have a password, which results in them being denied login access. Avoid running third-party applications on the target that have not been properly audited, regardless of the user they are running as.', 'title': 'Mitigation', 'category': 'description'}, {'text': 'Please update to a recent version of the affected product. In general, Beckhoff recommends updating the entire TwinCAT/BSD operating system to a current version rather than individual packages. Information on updating existing TwinCAT/BSD installations is available in [here:](https://infosys.beckhoff.com/content/1033/twincat_bsd/11780818443.html?id=4222392218353411614). There you will also find information on how to determine the operating system version via the command line. This is also visible via the Beckhoff Device Manager UI. Please note that when updating from the TwinCAT/BSD major version 12, two consecutive upgrades are required.', 'title': 'Remediation', 'category': 'description'}, {'text': 'Beckhoff Automation welcomes responsibly coordinated reports of vulnerabilities and Beckhoff will collaborate with reporting parties to fix vulnerabilities or mitigate threats.', 'title': 'Reporting vulnerabilities', 'category': 'general'}, {'text': 'Beckhoff is not responsible for any side effects negatively affecting the real-time capabilities of your TwinCAT control application possibly caused by updates. Beckhoff offers updated images with qualified performance for Beckhoff hardware from time to time. TwinCAT System Manager offers tools which can be of assistance to verify real-time performance after update. A backup should be created every time before installing an update. Only administrators or IT experts should perform the backup and update procedure.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}], 'title': 'Beckhoff: Improper neutralization of input in IPC-Diagnostics-www package included in TwinCAT/BSD operating system', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2024-048', 'status': 'final', 'aliases': ['VDE-2024-048'], 'version': '5', 'generator': {'date': '2025-04-11T07:30:24.655Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.23'}}, 'revision_history': [{'date': '2024-08-13T07:00:00.000Z', 'number': '1', 'summary': 'initial revision'}, {'date': '2024-11-06T11:27:01.000Z', 'number': '2', 'summary': 'Fix: correct certvde domain, added self-reference'}, {'date': '2025-01-16T10:20:00.000Z', 'number': '3', 'summary': 'Fix: list of branches'}, {'date': '2025-04-11T07:00:00.000Z', 'number': '4', 'summary': 'Fix: version range'}, {'date': '2025-05-22T13:03:10.000Z', 'number': '5', 'summary': 'Fix: quotation mark'}], 'current_release_date': '2025-05-22T13:03:10.000Z', 'initial_release_date': '2024-08-27T08:00:00.000Z'}, 'publisher': {'name': 'Beckhoff Automation GmbH & Co. KG', 'category': 'vendor', 'namespace': 'https://www.beckhoff.com', 'contact_details': 'product-securityincident@beckhoff.com'}, 'references': [{'url': 'https://download.beckhoff.com/download/Document/product-security/Advisories/advisory-2024-002.pdf', 'summary': "Beckhoff Security Advisory 2024-002: Improper neutralization of input in TwinCAT/BSD package 'IPC-Diagnostics-www' - PDF version", 'category': 'self'}, {'url': 'https://www.beckhoff.com/secinfo', 'summary': 'Additional information about the latest IPC security advisories is provided here:', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vde-2024-048', 'summary': 'VDE-2024-048: Beckhoff: Improper neutralization of input in IPC-Diagnostics-www package included in TwinCAT/BSD operating system - HTML', 'category': 'self'}, {'url': 'https://certvde.com/en/advisories/vendor/beckhoff/', 'summary': 'CERT@VDE Security Advisories for Beckhoff Automation GmbH & Co. KG', 'category': 'external'}, {'url': 'https://infosys.beckhoff.com/content/1033/twincat_bsd/11780818443.html?id=4222392218353411614', 'summary': 'Detailed information on updating the TwinCAT/BSD operating system', 'category': 'external'}, {'url': 'https://beckhoff.csaf-tp.certvde.com/.well-known/csaf/white/2024/vde-2024-048.json', 'summary': 'VDE-2024-048: Beckhoff: Improper neutralization of input in IPC-Diagnostics-www package included in TwinCAT/BSD operating system - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/v1/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}, {'urls': ['https://www.nozominetworks.com'], 'names': ['Andrea Palanca'], 'summary': 'Reported by', 'organization': 'Nozomi Networks'}]}, 'product_tree': {'branches': [{'name': 'Beckhoff', 'branches': [{'name': 'Software', 'branches': [{'name': 'IPC-Diagnostics-www package', 'branches': [{'name': '<2.1.1.0', 'product': {'name': 'IPC-Diagnostics-www package <2.1.1.0', 'product_id': 'CSAFPID-51001'}, 'category': 'product_version_range'}, {'name': '2.1.1.0', 'product': {'name': 'IPC-Diagnostics-www package 2.1.1.0', 'product_id': 'CSAFPID-52001'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'TwinCAT/BSD', 'branches': [{'name': '<14.1.2.0_153968', 'product': {'name': 'TwinCAT/BSD <14.1.2.0_153968', 'product_id': 'CSAFPID-51002'}, 'category': 'product_version_range'}, {'name': '14.1.2.0_153968', 'product': {'name': 'TwinCAT/BSD 14.1.2.0_153968', 'product_id': 'CSAFPID-52002'}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}], 'product_groups': [{'summary': 'Affected products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-51001', 'CSAFPID-51002']}, {'summary': 'Fixed products.', 'group_id': 'CSAFGID-0002', 'product_ids': ['CSAFPID-52001', 'CSAFPID-52002']}]}, 'vulnerabilities': [{'cve': 'CVE-2024-41174', 'cwe': {'id': 'CWE-79', 'name': "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"}, 'notes': [{'text': 'The IPC-Diagnostics-www package in TwinCAT/BSD is susceptible to improper input neutralization by a low-privileged local attacker.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2024-41174', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.3, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H', 'temporalScore': 7.3, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.3, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001', 'CSAFPID-51002']}], 'release_date': '2024-08-13T07:00:00.000Z', 'remediations': [{'date': '2024-08-13T07:00:00.000Z', 'details': 'Avoid the existence of user accounts with login permission on the target other than administrator access. By default, TwinCAT/BSD has preconfigured user accounts with lower privileges, but none of them have a password, which results in them being denied login access. Avoid running third-party applications on the target that have not been properly audited, regardless of the user they are running as.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Please update to a recent version of the affected product.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-52001', 'CSAFPID-52002'], 'known_affected': ['CSAFPID-51001', 'CSAFPID-51002']}, 'acknowledgments': [{'urls': ['https://www.nozominetworks.com'], 'names': ['Andrea Palanca'], 'summary': 'Nozomi Networks reported the vulnerability to Beckhoff', 'organization': 'Nozomi Networks'}]}]}
bcc7d69c78cc406727d866e2f7e0afb1129c1bfc39158649321472c853ce1964
2026-05-29 08:30:35.455889+03:00
2026-05-29 08:30:35.455889+03:00
csaf_beckhoffautomationgmbhcokg.ndjson
787736cea68cbf51a22ffb0d6347594d107c43874bbf07bc216372f3f973c744
{'document': {'lang': 'en-GB', 'notes': [{'text': "By default, TwinCAT/BSD-based products have a device-specific web interface for web-based management\n(WBM) enabled, developed by Beckhoff and known as Beckhoff Device Manager UI. It can be accessed remotely\nor locally. When accessed locally, a user can post specifically crafted input which then lets the process\n'MDPWebServer' consume a maximum of CPU cycles and Random Access Memory (RAM).", 'title': 'Summary', 'category': 'summary'}, {'text': 'A local, low privileged attacker could cause a denial-of-service.', 'title': 'Impact', 'category': 'description'}, {'text': 'Avoid the existence of user accounts with login permission on the target other than administrator access. By default, TwinCAT/BSD has preconfigured user accounts with lower privileges, but none of them have a password, which results in them being denied login access. Avoid running third-party applications on the target that have not been properly audited, regardless of the user they are running as.', 'title': 'Mitigation', 'category': 'description'}, {'text': 'Please update to a recent version of the affected product. In general, Beckhoff recommends updating the entire TwinCAT/BSD operating system to a current version rather than individual packages. Information on updating existing TwinCAT/BSD installations is available in [here:](https://infosys.beckhoff.com/content/1033/twincat_bsd/11780818443.html?id=4222392218353411614). There you will also find information on how to determine the operating system version via the command line. This is also visible via the Beckhoff Device Manager UI. Please note that when updating from the TwinCAT/BSD major version 12, two consecutive upgrades are required.', 'title': 'Remediation', 'category': 'description'}, {'text': 'Beckhoff Automation welcomes responsibly coordinated reports of vulnerabilities and Beckhoff will collaborate with reporting parties to fix vulnerabilities or mitigate threats.', 'title': 'Reporting vulnerabilities', 'category': 'general'}, {'text': 'Beckhoff is not responsible for any side effects negatively affecting the real-time capabilities of your TwinCAT control application possibly caused by updates. Beckhoff offers updated images with qualified performance for Beckhoff hardware from time to time. TwinCAT System Manager offers tools which can be of assistance to verify real-time performance after update. A backup should be created every time before installing an update. Only administrators or IT experts should perform the backup and update procedure.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}], 'title': 'Beckhoff: Denial-of-Service vulnerability in the IPC-Diagnostics package included in TwinCAT/BSD operating system', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2024-049', 'status': 'final', 'aliases': ['VDE-2024-049'], 'version': '5', 'generator': {'date': '2025-04-11T07:32:28.088Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.23'}}, 'revision_history': [{'date': '2024-08-13T07:00:00.000Z', 'number': '1', 'summary': 'initial revision'}, {'date': '2024-11-06T11:27:01.000Z', 'number': '2', 'summary': 'Fix: correct certvde domain, added self-reference'}, {'date': '2025-01-16T10:40:00.000Z', 'number': '3', 'summary': 'Fix: list of branches, references url'}, {'date': '2025-04-11T07:00:00.000Z', 'number': '4', 'summary': 'Fix: version range'}, {'date': '2025-05-22T13:03:10.000Z', 'number': '5', 'summary': 'Fix: quotation mark'}], 'current_release_date': '2025-05-22T13:03:10.000Z', 'initial_release_date': '2024-08-27T08:00:00.000Z'}, 'publisher': {'name': 'Beckhoff Automation GmbH & Co. KG', 'category': 'vendor', 'namespace': 'https://www.beckhoff.com', 'contact_details': 'product-securityincident@beckhoff.com'}, 'references': [{'url': 'https://download.beckhoff.com/download/Document/product-security/Advisories/advisory-2024-003.pdf', 'summary': "Beckhoff Security Advisory 2024-003: Local Denial of Service issue in TwinCAT/BSD package 'IPC-Diagnostics' - PDF version", 'category': 'self'}, {'url': 'https://www.beckhoff.com/secinfo', 'summary': 'Additional information about the latest IPC security advisories is provided here:', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/beckhoff/', 'summary': 'CERT@VDE Security Advisories for Beckhoff Automation GmbH & Co. KG', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vde-2024-049', 'summary': 'VDE-2024-049: Beckhoff: Denial-of-Service vulnerability in the IPC-Diagnostics package included in TwinCAT/BSD operating system - HTML', 'category': 'self'}, {'url': 'https://infosys.beckhoff.com/content/1033/twincat_bsd/11780818443.html?id=4222392218353411614', 'summary': 'Detailed information on updating the TwinCAT/BSD operating system', 'category': 'external'}, {'url': 'https://beckhoff.csaf-tp.certvde.com/.well-known/csaf/white/2024/vde-2024-049.json', 'summary': 'VDE-2024-049: Beckhoff: Denial-of-Service vulnerability in the IPC-Diagnostics package included in TwinCAT/BSD operating system - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/v1/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}, {'urls': ['https://www.nozominetworks.com'], 'names': ['Andrea Palanca'], 'summary': 'Reported by', 'organization': 'Nozomi Networks'}]}, 'product_tree': {'branches': [{'name': 'Beckhoff', 'branches': [{'name': 'Software', 'branches': [{'name': 'IPC Diagnostics package', 'branches': [{'name': '<2.0.0.1', 'product': {'name': 'IPC Diagnostics package <2.0.0.1', 'product_id': 'CSAFPID-51001'}, 'category': 'product_version_range'}, {'name': '2.0.0.1', 'product': {'name': 'IPC Diagnostics package 2.0.0.1', 'product_id': 'CSAFPID-52001'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'TwinCAT/BSD', 'branches': [{'name': '<14.1.2.0_153968', 'product': {'name': 'TwinCAT/BSD <14.1.2.0_153968', 'product_id': 'CSAFPID-51002'}, 'category': 'product_version_range'}, {'name': '14.1.2.0_153968', 'product': {'name': 'TwinCAT/BSD 14.1.2.0_153968', 'product_id': 'CSAFPID-52002'}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}], 'product_groups': [{'summary': 'Affected products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-51001', 'CSAFPID-51002']}, {'summary': 'Fixed products.', 'group_id': 'CSAFGID-0002', 'product_ids': ['CSAFPID-52001', 'CSAFPID-52002']}]}, 'vulnerabilities': [{'cve': 'CVE-2024-41175', 'cwe': {'id': 'CWE-770', 'name': 'Allocation of Resources Without Limits or Throttling'}, 'notes': [{'text': 'The IPC-Diagnostics package included in TwinCAT/BSD is vulnerable to a local denial-of-service attack by a low privileged attacker.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2024-41175', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 5.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'HIGH', 'environmentalScore': 5.5, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001', 'CSAFPID-51002']}], 'release_date': '2024-08-13T07:00:00.000Z', 'remediations': [{'date': '2024-08-13T07:00:00.000Z', 'details': 'Avoid the existence of user accounts with login permission on the target other than administrator access. By default, TwinCAT/BSD has preconfigured user accounts with lower privileges, but none of them have a password, which results in them being denied login access. Avoid running third-party applications on the target that have not been properly audited, regardless of the user they are running as.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Please update to a recent version of the affected product.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-52001', 'CSAFPID-52002'], 'known_affected': ['CSAFPID-51001', 'CSAFPID-51002']}, 'acknowledgments': [{'urls': ['https://www.nozominetworks.com'], 'names': ['Andrea Palanca'], 'summary': 'Nozomi Networks reported the vulnerability to Beckhoff', 'organization': 'Nozomi Networks'}]}]}
c33d47b2f45f765876c9634ca3c9c6243c7c5ef3b7aa2be84774aba7372458f3
2026-05-29 08:30:35.455889+03:00
2026-05-29 08:30:35.455889+03:00
csaf_beckhoffautomationgmbhcokg.ndjson
b1c2e5a38fb2604955b6c628b925a4c391228bdcfb80ec13ba995fb881d5c993
{'document': {'lang': 'en-GB', 'notes': [{'text': "By default, TwinCAT/BSD-based products have a device-specific web interface for web-based management (WBM) enabled, developed by Beckhoff and known as Beckhoff Device Manager UI. It can be accessed remotely or locally. When accessed locally, a user can post specifically crafted input which then causes a buffer overflow on stack which in turn lets the process 'MDPService' crash such that the web interface becomes unavailable until next restart or even execute code in the context of user 'root'. ", 'title': 'Summary', 'category': 'summary'}, {'text': "A local attacker could cause a denial-of-service or execute code in the context of user 'root' via a crafted HTTP request.", 'title': 'Impact', 'category': 'description'}, {'text': 'Avoid the existence of user accounts with login permission on the target other than administrator access. By default, TwinCAT/BSD has preconfigured user accounts with lower privileges, but none of them have a password, which results in them being denied login access. Avoid running third-party applications on the target that have not been properly audited, regardless of the user they are running as.', 'title': 'Mitigation', 'category': 'description'}, {'text': 'Please update to a recent version of the affected product. In general, Beckhoff recommends updating the entire TwinCAT/BSD operating system to a current version rather than individual packages. Information on updating existing TwinCAT/BSD installations is available in [here:](https://infosys.beckhoff.com/content/1033/twincat_bsd/11780818443.html?id=4222392218353411614). There you will also find information on how to determine the operating system version via the command line. This is also visible via the Beckhoff Device Manager UI. Please note that when updating from the TwinCAT/BSD major version 12, two consecutive upgrades are required.', 'title': 'Remediation', 'category': 'description'}, {'text': 'Beckhoff Automation welcomes responsibly coordinated reports of vulnerabilities and Beckhoff will collaborate with reporting parties to fix vulnerabilities or mitigate threats.', 'title': 'Reporting vulnerabilities', 'category': 'general'}, {'text': 'Beckhoff is not responsible for any side effects negatively affecting the real-time capabilities of your TwinCAT control application possibly caused by updates. Beckhoff offers updated images with qualified performance for Beckhoff hardware from time to time. TwinCAT System Manager offers tools which can be of assistance to verify real-time performance after update. A backup should be created every time before installing an update. Only administrators or IT experts should perform the backup and update procedure.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}], 'title': 'Beckhoff: Denial-of-Service vulnerability in the MDP package included in TwinCAT/BSD operating system', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2024-050', 'status': 'final', 'aliases': ['VDE-2024-050'], 'version': '5', 'generator': {'date': '2025-04-11T07:34:22.615Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.23'}}, 'revision_history': [{'date': '2024-08-13T07:00:00.000Z', 'number': '1', 'summary': 'initial revision'}, {'date': '2024-11-06T11:27:01.000Z', 'number': '2', 'summary': 'Fix: correct certvde domain, added self-reference'}, {'date': '2025-01-16T09:45:00.000Z', 'number': '3', 'summary': 'Fix: list of branches, typo in reference url'}, {'date': '2025-04-11T07:00:00.000Z', 'number': '4', 'summary': 'Fix: version range'}, {'date': '2025-05-22T13:03:10.000Z', 'number': '5', 'summary': 'Fix: quotation mark'}], 'current_release_date': '2025-05-22T13:03:10.000Z', 'initial_release_date': '2024-08-27T08:00:00.000Z'}, 'publisher': {'name': 'Beckhoff Automation GmbH & Co. KG', 'category': 'vendor', 'namespace': 'https://www.beckhoff.com', 'contact_details': 'product-securityincident@beckhoff.com'}, 'references': [{'url': 'https://download.beckhoff.com/download/Document/product-security/Advisories/advisory-2024-004.pdf', 'summary': "Beckhoff Security Advisory 2024-004: Local Denial of Service issue in TwinCAT/BSD package 'MDP' - PDF version", 'category': 'self'}, {'url': 'https://www.beckhoff.com/secinfo', 'summary': 'Additional information about the latest IPC security advisories is provided here:', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/beckhoff/', 'summary': 'CERT@VDE Security Advisories for Beckhoff Automation GmbH & Co. KG', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vde-2024-050', 'summary': 'VDE-2024-050: Beckhoff: Denial-of-Service vulnerability in the MDP package included in TwinCAT/BSD operating system - HTML', 'category': 'self'}, {'url': 'https://infosys.beckhoff.com/content/1033/twincat_bsd/11780818443.html?id=4222392218353411614', 'summary': 'Detailed information on updating the TwinCAT/BSD operating system', 'category': 'external'}, {'url': 'https://beckhoff.csaf-tp.certvde.com/.well-known/csaf/white/2024/vde-2024-050.json', 'summary': 'VDE-2024-050: Beckhoff: Denial-of-Service vulnerability in the MDP package included in TwinCAT/BSD operating system - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/v1/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}, {'urls': ['https://www.nozominetworks.com'], 'names': ['Andrea Palanca'], 'summary': 'Reported by', 'organization': 'Nozomi Networks'}]}, 'product_tree': {'branches': [{'name': 'Beckhoff', 'branches': [{'name': 'Software', 'branches': [{'name': 'MDP package version', 'branches': [{'name': '<1.2.7.0', 'product': {'name': 'MDP package <1.2.7.0', 'product_id': 'CSAFPID-51001'}, 'category': 'product_version_range'}, {'name': '1.2.7.0', 'product': {'name': 'MDP package 1.2.7.0', 'product_id': 'CSAFPID-52001'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'TwinCAT/BSD', 'branches': [{'name': '<14.1.2.0_153968', 'product': {'name': 'TwinCAT/BSD <14.1.2.0_153968', 'product_id': 'CSAFPID-51002'}, 'category': 'product_version_range'}, {'name': '14.1.2.0_153968', 'product': {'name': 'TwinCAT/BSD 14.1.2.0_153968', 'product_id': 'CSAFPID-52002'}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}], 'product_groups': [{'summary': 'Affected products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-51001', 'CSAFPID-51002']}, {'summary': 'Fixed products.', 'group_id': 'CSAFGID-0002', 'product_ids': ['CSAFPID-52001', 'CSAFPID-52002']}]}, 'vulnerabilities': [{'cve': 'CVE-2024-41176', 'cwe': {'id': 'CWE-121', 'name': 'Stack-based Buffer Overflow'}, 'notes': [{'text': "The MPD package included in TwinCAT/BSD allows an authenticated, low-privileged local\nattacker to induce a Denial-of-Service (DoS) condition on the daemon and execute code in\nthe context of user 'root' via a crafted HTTP request.", 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2024-41176', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L', 'temporalScore': 6.5, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'LOW', 'environmentalScore': 6.5, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001', 'CSAFPID-51002']}], 'release_date': '2024-08-13T07:00:00.000Z', 'remediations': [{'details': 'Avoid the existence of user accounts with login permission on the target other than administrator access. By default, TwinCAT/BSD has preconfigured user accounts with lower privileges, but none of them have a password, which results in them being denied login access. Avoid running third-party applications on the target that have not been properly audited, regardless of the user they are running as.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Please update to a recent version of the affected product.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-52001', 'CSAFPID-52002'], 'known_affected': ['CSAFPID-51001', 'CSAFPID-51002']}, 'acknowledgments': [{'urls': ['https://www.nozominetworks.com'], 'names': ['Andrea Palanca'], 'summary': 'Nozomi Networks reported the vulnerability to Beckhoff', 'organization': 'Nozomi Networks'}]}]}
54dbad5a1fb3186ac6829291a3e66a6962dbfa539a8cf54e78243e2f92efec2e
2026-05-29 08:30:35.455889+03:00
2026-05-29 08:30:35.455889+03:00
csaf_beckhoffautomationgmbhcokg.ndjson
b05a3df9273a6edba125a20d4b430e75cca439560c4c4afdd15fe195ab64574e
{'document': {'lang': 'en-US', 'notes': [{'text': "Beckhoff's TwinCAT 3.1 Build 4026 software is modularized and is installed with different packages depending on user requirements. These packages are selected and installed using either the command line utility tcpkg or the corresponding graphical user interface called TwinCAT Package Manager. Both use the same configuration that specifies where to load packages from. These locations are called feeds, have preconfigured default settings and can be customized by administrative users, for example to add another local mirror of a package server. When using the TwinCAT Package Manager on a PC, a user with administrative access rights can locally set a specially crafted URL for a feed that causes the TwinCAT Package Manager to execute arbitrary operating system commands.", 'title': 'Summary', 'category': 'summary'}, {'text': 'A local user with administrative access rights can enter specialy crafted values for settings at the user interface (UI) of the TwinCAT Package Manager which then causes arbitrary OS commands to be executed.', 'title': 'Impact', 'category': 'description'}, {'text': 'Administrative users shall always act thoroughly and inspect the values which they enter.', 'title': 'Mitigation', 'category': 'description'}, {'text': 'Please update to a recent version of the affected product.', 'title': 'Remediation', 'category': 'description'}, {'text': 'Beckhoff Automation welcomes responsibly coordinated reports of vulnerabilities and Beckhoff will collaborate with reporting parties to fix vulnerabilities or mitigate threats.', 'title': 'Reporting vulnerabilities', 'category': 'general'}, {'text': 'Beckhoff is not responsible for any side effects negatively affecting the real-time capabilities of your TwinCAT control application possibly caused by updates. Beckhoff offers updated images with qualified performance for Beckhoff hardware from time to time. TwinCAT System Manager offers tools which can be of assistance to verify real-time performance after update. A backup should be created every time before installing an update. Only administrators or IT experts should perform the backup and update procedure.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}], 'title': 'Beckhoff: Local command injection via TwinCAT Package Manager', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2024-064', 'status': 'final', 'aliases': ['VDE-2024-064'], 'version': '3', 'generator': {'date': '2025-04-11T07:36:54.283Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.23'}}, 'revision_history': [{'date': '2024-10-31T11:00:00.000Z', 'number': '1', 'summary': 'initial revision'}, {'date': '2025-01-16T10:30:00.000Z', 'number': '2', 'summary': 'Fix: list of branches, references'}, {'date': '2025-04-11T07:00:00.000Z', 'number': '3', 'summary': 'Fix: version range'}], 'current_release_date': '2025-04-11T07:00:00.000Z', 'initial_release_date': '2024-10-31T11:00:00.000Z'}, 'publisher': {'name': 'Beckhoff Automation GmbH & Co. KG', 'category': 'vendor', 'namespace': 'https://www.beckhoff.com', 'contact_details': 'product-securityincident@beckhoff.com'}, 'references': [{'url': 'https://download.beckhoff.com/download/Document/product-security/Advisories/advisory-2024-005.pdf', 'summary': 'Beckhoff Security Advisory 2024-005: Local command injection via TwinCAT Package Manager - PDF', 'category': 'self'}, {'url': 'https://www.beckhoff.com/secinfo', 'summary': 'Additional information about the latest IPC security advisories is provided here:', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/beckhoff/', 'summary': 'CERT@VDE Security Advisories for Beckhoff Automation GmbH & Co. KG', 'category': 'external'}, {'url': 'https://beckhoff.csaf-tp.certvde.com/.well-known/csaf/white/2024/vde-2024-064.json', 'summary': 'VDE-2024-064: Beckhoff: Local command injection via TwinCAT Package Manager - CSAF', 'category': 'self'}, {'url': 'https://certvde.com/en/advisories/vde-2024-064', 'summary': 'VDE-2024-064: Beckhoff: Local command injection via TwinCAT Package Manager - HTML', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/v1/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}, {'names': ['elcazator'], 'summary': 'Reporting', 'organization': 'ELEX FEIGONG RESEARCH INSTITUTE of Elex CyberSecurity, Inc.'}]}, 'product_tree': {'branches': [{'name': 'Beckhoff', 'branches': [{'name': 'Software', 'branches': [{'name': 'TwinCAT Package Manager', 'branches': [{'name': '<1.0.603.0', 'product': {'name': 'TwinCAT Package Manager <1.0.603.0', 'product_id': 'CSAFPID-51001'}, 'category': 'product_version_range'}, {'name': '1.0.603.0', 'product': {'name': 'TwinCAT Package Manager 1.0.603.0', 'product_id': 'CSAFPID-52001'}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2024-8934', 'cwe': {'id': 'CWE-78', 'name': "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"}, 'notes': [{'text': 'A local user with administrative access rights can enter specialy crafted values for settings at the user interface (UI) of the TwinCAT Package Manager which then causes arbitrary OS commands to be executed.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2024-8934', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H', 'temporalScore': 6.5, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'HIGH', 'environmentalScore': 6.5, 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001']}], 'release_date': '2024-09-27T07:00:00.000Z', 'remediations': [{'date': '2024-09-27T07:00:00.000Z', 'details': 'Administrative users shall always act thoroughly and inspect the values which they enter.', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Please update TwinCAT Package Manager to 1.0.603.0', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}, 'acknowledgments': [{'names': ['Elcazator'], 'summary': 'Elcazator reported the vulnerability to Beckhoff', 'organization': 'ELEX FEIGONG RESEARCH INSTITUTE of Elex CyberSecurity, Inc.'}]}]}
4e3307b1ee8850f3c67d6a5619d6956deb9edeb0c7d1a6cbd39bacb1e14255dc
2026-05-29 08:30:35.455889+03:00
2026-05-29 08:30:35.455889+03:00
csaf_beckhoffautomationgmbhcokg.ndjson
59fffdb228b551f5bd8a3d8e645ecd3b20e29d1e798f4238b35b18dd76117eec
{'document': {'lang': 'en-US', 'notes': [{'text': 'Beckhoff\'s TwinCAT 3 Engineering software is intented to craft automation projects consisting of a set of files which are stored locally as files underneath an individual folder or in a packed file. The TwinCAT 3 Engineering stores user settings and preferences among the non packed local files which are relevant to continue former work on the project conventienly. TwinCAT 3 Engineering stores such settings in files which are called "Solution User Options (.suo) File". When such settings are manipulated or crafted by an adversary in a specific way then TwinCAT 3 Engineering executes arbitrary commands as determined by these settings when the user uses TwinCAT 3 Engineering to open the project. These arbitrary commands are executed in the user context. \n\nPlease note that solution user option files should not be checked in to source code control. This is also a best practice when working with source code projects and solutions. For example, see https://learn.microsoft.com/en-us/visualstudio/extensibility/internals/solution-user-options-dot-suo-file and https://infosys.beckhoff.com/content/1033/tc3_sourcecontrol/14604066827.html. \n\nThe vulnerability is similar to older vulnerabilities that were addressed in the CODESYS Development System V3 product from CODESYS GmbH with CVE-2021-21864, CVE-2021-21865, CVE-2021-21866, CVE-2021-21867, CVE-2021-21868, CVE-2021-21869, and the associated Advisory 2021-13 from CODESYS GmbH.', 'title': 'Summary', 'category': 'summary'}, {'text': 'An attacker with access to local files can trick a local user into executing arbitrary commands by opening a deliberately manipulated project file with an affected engineering tool. These arbitrary commands are executed in the user context. When older affected versions of the engineering tool are installed then the deliberate manipulation of the project file can cause that these are used to open it.\n\n\nPlease note that TwinCAT 3 Engineering offers the "Remote Manager" feature (see https://infosys.beckhoff.com/content/1033/tc3_remote_manager/index.html?id=1584127271344589360) which means that older versions of TwinCAT 3 Engineering can stay installed in parallel to more recent versions. TwinCAT projects can be "pinned" to be edited with a fixed version, see https://infosys.beckhoff.com/content/1033/tc3_remote_manager/3154642571.html. If such a pinned project is opened while a more recent version of TwinCAT 3 Engineering is installed and at the same time the matching older version of TwinCAT 3 Engineering is still installed then the project is automatically passed from the more recent version to the matching older version and edited with that older version where that older version is vulnerable.', 'title': 'Impact', 'category': 'description'}, {'text': 'Developers shall care for opening projects from trusted sources only. This is a best practice when working with source code and the main content of a project which is crafted with TwinCAT 3 Engineering is source code which is to be compiled to activate it on a target. \n\nSolution user option files should not be checked in to source code control. This is also a best practice when working with source code projects and solutions. For example, see https://learn.microsoft.com/en-us/visualstudio/extensibility/internals/solution-user-options-dot-suo-file and https://infosys.beckhoff.com/content/1033/tc3_sourcecontrol/14604066827.html. \n\nAvoid pinning of projects to exact versions of TwinCAT 3 Engineering, see https://infosys.beckhoff.com/content/1033/tc3_remote_manager/index.html?id=1584127271344589360 and https://infosys.beckhoff.com/content/1033/tc3_remote_manager/3154642571.html. Always open projects with the most recent version of TwinCAT 3.', 'title': 'General Recommendation', 'category': 'description'}, {'text': 'Please update to a recent version of the affected product and uninstall older versions of TwinCAT 3 Engineering. Make sure that older versions of TwinCAT 3 Engineering do not occur as "Remote Manager" versions, see https://infosys.beckhoff.com/content/1033/tc3_remote_manager/index.html?id=1584127271344589360. Remove the "pinning" from your projects to older versions of TwinCAT 3 Engineering, if present, see https://infosys.beckhoff.com/content/1033/tc3_remote_manager/3154642571.html.', 'title': 'Remediation', 'category': 'description'}, {'text': 'Beckhoff Automation welcomes responsibly coordinated reports of vulnerabilities and Beckhoff will collaborate with reporting parties to fix vulnerabilities or mitigate threats.', 'title': 'Reporting vulnerabilities', 'category': 'general'}, {'text': 'Beckhoff is not responsible for any side effects negatively affecting the real-time capabilities of your TwinCAT control application possibly caused by updates. Beckhoff offers updated images with qualified performance for Beckhoff hardware from time to time. TwinCAT System Manager offers tools which can be of assistance to verify real-time performance after update. A backup should be created every time before installing an update. Only administrators or IT experts should perform the backup and update procedure.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}], 'title': 'Beckhoff: Deserialization of untrusted data by TwinCAT 3 Engineering', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2025-075', 'status': 'final', 'aliases': ['VDE-2025-075'], 'version': '1', 'generator': {'date': '2025-08-28T07:42:39.284Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.32'}}, 'revision_history': [{'date': '2025-09-09T10:00:00.000Z', 'number': '1', 'summary': 'initial revision'}], 'current_release_date': '2025-09-09T10:00:00.000Z', 'initial_release_date': '2025-09-09T10:00:00.000Z'}, 'publisher': {'name': 'Beckhoff Automation GmbH & Co. KG', 'category': 'vendor', 'namespace': 'https://www.beckhoff.com', 'contact_details': 'product-securityincident@beckhoff.com'}, 'references': [{'url': 'https://download.beckhoff.com/download/Document/product-security/Advisories/advisory-2025-001.pdf', 'summary': 'Beckhoff Security Advisory 2025-001: Deserialization of untrusted data by TwinCAT 3 Engineering - PDF version', 'category': 'self'}, {'url': 'https://www.beckhoff.com/secinfo', 'summary': 'Additional information about the latest security advisories is provided here:', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/beckhoff/', 'summary': 'CERT@VDE Security Advisories for Beckhoff Automation GmbH & Co. KG', 'category': 'external'}, {'url': 'https://beckhoff.csaf-tp.certvde.com/.well-known/csaf/white/2025/vde-2025-075.json', 'summary': 'VDE-2025-075: Beckhoff: Deserialization of untrusted data by TwinCAT 3 Engineering - CSAF', 'category': 'self'}, {'url': 'https://certvde.com/en/advisories/VDE-2025-075', 'summary': 'VDE-2025-075: Beckhoff: Deserialization of untrusted data by TwinCAT 3 Engineering - HTML', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/v1/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}, {'names': ['Peter Cheng'], 'summary': 'Reported by', 'organization': 'ELEX FEIGONG RESEARCH INSTITUTE of Elex CyberSecurity, Inc.'}]}, 'product_tree': {'branches': [{'name': 'Beckhoff', 'branches': [{'name': 'Software', 'branches': [{'name': 'TE1000 | TwinCAT 3 Enineering', 'branches': [{'name': '<3.1.4024.67', 'product': {'name': 'TE1000 | TwinCAT 3 Enineering <3.1.4024.67', 'product_id': 'CSAFPID-51001'}, 'category': 'product_version_range'}, {'name': '3.1.4024.67', 'product': {'name': 'TE1000 | TwinCAT 3 Enineering 3.1.4024.67', 'product_id': 'CSAFPID-52001'}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-41701', 'cwe': {'id': 'CWE-502', 'name': 'Deserialization of Untrusted Data'}, 'notes': [{'text': 'An unauthenticated attacker can trick a local user into executing arbitrary commands by opening a deliberately manipulated project file with an affected engineering tool. These arbitrary commands are executed in the user context.', 'title': 'Description', 'category': 'description'}], 'title': 'CVE-2025-41701', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'temporalScore': 7.8, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': 'Please update to a recent version of the affected product and uninstall older versions of TwinCAT 3 Engineering. Make sure that older versions of TwinCAT 3 Engineering do not occur as "Remote Manager" versions, see https://infosys.beckhoff.com/content/1033/tc3_remote_manager/index.html?id=1584127271344589360. Remove the "pinning" from your projects to older versions of TwinCAT 3 Engineering, if present, see https://infosys.beckhoff.com/content/1033/tc3_remote_manager/3154642571.html.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}, 'acknowledgments': [{'names': ['Peter Cheng'], 'summary': 'Peter Cheng reported the vulnerability to Beckhoff', 'organization': 'ELEX FEIGONG RESEARCH INSTITUTE of Elex CyberSecurity, Inc.'}]}]}
4964c46738966be649cdfb87aff12799d1e6449ff6817a3b05e09cc4064c4539
2026-05-29 08:30:35.455889+03:00
2026-05-29 08:30:35.455889+03:00
csaf_beckhoffautomationgmbhcokg.ndjson
64d223861ecd907c5fcd3c79e0b7e7a1a0c3141af9fc821af8337c8dc5ffdf1f
{'document': {'lang': 'en-US', 'notes': [{'text': 'The vulnerability CVE-2025-41726 (NN-2025-0074) allows an authenticated remote user to execute arbitrary commands on the device. This can be exploited over the web UI or via API. In one case the execution of the arbitrary command happens within a privileged process.\n\nThe vulnerability CVE-2025-41727 (NN-2025-0075) allows a local user with low privileges on the device to bypass the authentication mechanism of the UI and send commands to a privileged process which it executes on behalf of that user but with higher privileges. This way the local user can escalate privileges.\n\nThe vulnerability CVE-2025-41728 (NN-2025-0076) allows an authenticated remote user to cause an out-of-bounds read operation within a specific service process which runs on the device. The read operation might copy sensitive information from the memory of the specific service into a response message which is then provided to the user but the user cannot choose which information is disclosed.', 'title': 'Summary', 'category': 'summary'}, {'text': 'CVE-2025-41726: On a Beckhoff IPC or CX device an authenticated user can execute arbitrary code by sending specially crafted calls to the web service of the Beckhoff Device Manager or locally via an API and can cause integer overflows which then can lead to arbitrary code execution within privileged processes.\n\nCVE-2025-41727: On a Beckhoff IPC or CX device a local user can bypass the authentication of the Beckhoff Device Manager user interface, allowing them to perform privileged operations and gain administrator access.\n\nCVE-2025-41728: On a Beckhoff IPC or CX device, an authenticated user may be able to disclose confidential information from the memory of a privileged process by sending specially crafted calls to the Beckhoff Device Manager web service that cause an out-of-bounds read operation and thereby potentially copy confidential information into a response.', 'title': 'Impact', 'category': 'description'}, {'text': 'Beckhoff IPC and CX devices are intended for industrial use within operational technology (OT). For the Beckhoff Device Manager user interface network access is to be restricted to trustworthy personal. Additionally, it is advisable to restrict local access to trustworthy personal.\n\nWhen not needed, the Beckhoff Device Manager user interface can be disabled for remote access or even be uninstalled. In example, for disabling remote access the OS firewall can be used to forbid the access to the network port or the web server process can be stopped permanently.', 'title': 'General Recommendation', 'category': 'description'}, {'text': "Please update to a recent version of the affected components (see below) or update the complete operating system image. Operating system images are available on request from Beckhoff's service (service@beckhoff.com). The setup / installer for Windows 10 and 11 are available on request from Beckhoff's service also.\n\n| Product | Fixed Version |\n|----------------------------------|---------------|\n| Beckhoff.Device.Manager.XAR tcpkg package | 2.5.3 |\n| Beckhoff IPC Diagnostics software for Windows | 2.5.3 |\n| MDP.dll library library for Windows CE 6.0 and Embedded Compact 7 on x86 | 1.7.0.0 |\n| MDP software package for TwinCAT/BSD | 1.7.0.0 |\n| mdp-bhf software package Beckhoff RT Linux(R) | 0.0.5-1 |\n| MDP.dll library library for Windows CE 6.0 and Embedded Compact 7 on ARM32 | 1.7.0.0 |", 'title': 'Remediation', 'category': 'description'}, {'text': 'Beckhoff Automation welcomes responsibly coordinated reports of vulnerabilities and Beckhoff will collaborate with reporting parties to fix vulnerabilities or mitigate threats.', 'title': 'Reporting vulnerabilities', 'category': 'general'}, {'text': 'Beckhoff is not responsible for any side effects negatively affecting the real-time capabilities of your TwinCAT control application possibly caused by updates. Beckhoff offers updated images with qualified performance for Beckhoff hardware from time to time. TwinCAT System Manager offers tools which can be of assistance to verify real-time performance after update. A backup should be created every time before installing an update. Only administrators or IT experts should perform the backup and update procedure.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}, {'text': 'Beckhoff IPC and CX devices are shipped with the Beckhoff Device Manager user interface (UI) installed when they are ordered with an operating system. This Device Manager user interface can be accessed from the network or by a local user. Either way the user must authenticate before access and have administrative access rights assigned on the device to use the UI. The Beckhoff Device Manager user interface is intended as UI for administrators to configure the device including the creation and maintenance of user accounts and their access rights.', 'title': 'Product description', 'category': 'details'}], 'title': 'Beckhoff: Privilege escalation and information leak via Beckhoff Device Manager', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2025-092', 'status': 'final', 'aliases': ['VDE-2025-092'], 'version': '1.0.1', 'generator': {'date': '2026-01-27T11:30:02.659Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.42'}}, 'revision_history': [{'date': '2026-01-20T10:00:00.000Z', 'number': '1.0.0', 'summary': 'Initial revision'}, {'date': '2026-01-27T11:00:00.000Z', 'number': '1.0.1', 'summary': 'fixed date'}], 'current_release_date': '2026-01-27T11:00:00.000Z', 'initial_release_date': '2026-01-27T11:00:00.000Z'}, 'publisher': {'name': 'Beckhoff Automation GmbH & Co. KG', 'category': 'vendor', 'namespace': 'https://www.beckhoff.com', 'contact_details': 'product-securityincident@beckhoff.com'}, 'references': [{'url': 'https://download.beckhoff.com/download/Document/product-security/Advisories/advisory-2025-003.pdf', 'summary': 'Beckhoff Security Advisory 2025-003: Privilege escalation and information leak via Beckhoff Device Manager - PDF version', 'category': 'self'}, {'url': 'https://www.beckhoff.com/secinfo', 'summary': 'Additional information about the latest security advisories is provided here:', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/beckhoff/', 'summary': 'CERT@VDE Security Advisories for Beckhoff Automation GmbH & Co. KG', 'category': 'external'}, {'url': 'https://beckhoff.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2025-092.json', 'summary': 'VDE-2025-092: Beckhoff: Privilege escalation and information leak via Beckhoff Device Manager - CSAF', 'category': 'self'}, {'url': 'https://certvde.com/en/advisories/VDE-2025-092', 'summary': 'VDE-2025-092: Beckhoff: Privilege escalation and information leak via Beckhoff Device Manager - HTML', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/v1/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}, {'urls': ['https://www.nozominetworks.com'], 'names': ['Diego Giubertoni'], 'summary': 'Reported by', 'organization': 'Nozomi Networks'}]}, 'product_tree': {'branches': [{'name': 'Beckhoff', 'branches': [{'name': 'Software', 'branches': [{'name': 'Beckhoff.Device.Manager.XAR', 'branches': [{'name': 'vers:semver/<2.5.3', 'product': {'name': 'Beckhoff.Device.Manager.XAR tcpkg package <2.5.3', 'product_id': 'CSAFPID-51001', 'product_identification_helper': {'purl': 'pkg:tcpkg/beckhoff/Beckhoff.Device.Manager.XAR?vers=%3C2.5.3'}}, 'category': 'product_version_range'}, {'name': '2.5.3', 'product': {'name': 'Beckhoff.Device.Manager.XAR tcpkg package 2.5.3', 'product_id': 'CSAFPID-52001', 'product_identification_helper': {'purl': 'pkg:tcpkg/beckhoff/Beckhoff.Device.Manager.XAR@2.5.3'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Beckhoff IPC Diagnosticssoftware for Windows', 'branches': [{'name': '2.4.5', 'product': {'name': 'Beckhoff IPC Diagnostics softwarefor Windows 2.4.5', 'product_id': 'CSAFPID-51011', 'product_identification_helper': {'cpe': 'cpe:2.3:a:beckhoff:ipc_diagnostics_package:2.4.5:*:*:*:*:Windows:*:*'}}, 'category': 'product_version'}, {'name': '2.5.3', 'product': {'name': 'Beckhoff IPC Diagnostics software for Windows 2.5.3', 'product_id': 'CSAFPID-52011', 'product_identification_helper': {'cpe': 'cpe:2.3:a:beckhoff:ipc_diagnostics_package:2.5.3:*:*:*:*:Windows:*:*'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'MDP.dll library for Windows CE 6.0 and Embedded Compact 7', 'branches': [{'name': 'x86', 'branches': [{'name': '1.2.4.0', 'product': {'name': 'MDP.dll library library for Windows CE 6.0 and Embedded Compact on x86 7 1.2.4.0', 'product_id': 'CSAFPID-51021', 'product_identification_helper': {'cpe': 'cpe:2.3:a:beckhoff:MDP.dll:1.2.4.0:*:*:*:*:*:x86:*', 'hashes': [{'filename': 'MDP.dll', 'file_hashes': [{'value': 'ab1476181b38e981da0fe3603799531369f97538c8491455e9f0b7f506e6341a', 'algorithm': 'sha256'}]}]}}, 'category': 'product_version'}, {'name': '1.7.0.0', 'product': {'name': 'MDP.dll library library for Windows CE 6.0 and Embedded Compact 7 on x86 1.7.0.0', 'product_id': 'CSAFPID-52021', 'product_identification_helper': {'cpe': 'cpe:2.3:a:beckhoff:MDP.dll:1.7.0.0:*:*:*:*:*:x86:*', 'hashes': [{'filename': 'MDP.dll', 'file_hashes': [{'value': 'f9b7846531207d14aeca1fde18876076affc860be680d2947bba22501601e654', 'algorithm': 'sha256'}]}]}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'arm32', 'branches': [{'name': '1.2.4.0', 'product': {'name': 'MDP.dll library library for Windows CE 6.0 and Embedded Compact on ARM32 7 1.2.4.0', 'product_id': 'CSAFPID-51051', 'product_identification_helper': {'cpe': 'cpe:2.3:a:beckhoff:MDP.dll:1.2.4.0:*:*:*:*:*:arm32:*', 'hashes': [{'filename': 'MDP.dll', 'file_hashes': [{'value': '19d466138f34b861b5dea35e9f7dc152dfa07659cd96061add04b60bd7463aec', 'algorithm': 'sha256'}]}]}}, 'category': 'product_version'}, {'name': '1.7.0.0', 'product': {'name': 'MDP.dll library library for Windows CE 6.0 and Embedded Compact 7 on ARM32 1.7.0.0', 'product_id': 'CSAFPID-52051', 'product_identification_helper': {'cpe': 'cpe:2.3:a:beckhoff:MDP.dll:1.7.0.0:*:*:*:*:*:arm32:*', 'hashes': [{'filename': 'MDP.dll', 'file_hashes': [{'value': '454f53f7972ef8fdb57e45ffc0861612a1853f75264e86dedb78cbc36854457b', 'algorithm': 'sha256'}]}]}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'product_name'}, {'name': 'MDP software package for TwinCAT/BSD', 'branches': [{'name': 'vers:generic/<1.7.0.0', 'product': {'name': 'MDP software package for TwinCAT/BSD <1.7.0.0', 'product_id': 'CSAFPID-51031', 'product_identification_helper': {'purl': 'pkg:bsd/beckhoff/MDP?vers=%3C1.7.0.0'}}, 'category': 'product_version_range'}, {'name': '1.2.7.0', 'product': {'name': 'MDP software package for TwinCAT/BSD 1.7.0.0', 'product_id': 'CSAFPID-52031', 'product_identification_helper': {'purl': 'pkg:bsd/beckhoff/MDP@1.7.0.0'}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'MDP for Beckhoff RT Linux(R)', 'branches': [{'name': 'vers:generic/<0.0.5-1', 'product': {'name': 'mdp-bhf software package Beckhoff RT Linux(R) <0.0.5-1', 'product_id': 'CSAFPID-51041', 'product_identification_helper': {'purl': 'pkg:deb/beckhoff/mdp-bhf?vers=%3C0.0.5-1'}}, 'category': 'product_version_range'}, {'name': '0.0.5-1', 'product': {'name': 'mdp-bhf software package Beckhoff RT Linux(R) 0.0.5-1', 'product_id': 'CSAFPID-52041', 'product_identification_helper': {'purl': 'pkg:deb/beckhoff/mdp-bhf@0.0.5-1'}}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}], 'product_groups': [{'summary': 'Affected products', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-51001', 'CSAFPID-51031', 'CSAFPID-51041']}, {'summary': 'Fixed products', 'group_id': 'CSAFGID-0002', 'product_ids': ['CSAFPID-52001', 'CSAFPID-52011', 'CSAFPID-52021', 'CSAFPID-52031', 'CSAFPID-52041', 'CSAFPID-52051']}, {'summary': 'Last affected products', 'group_id': 'CSAFGID-0003', 'product_ids': ['CSAFPID-51011', 'CSAFPID-51021', 'CSAFPID-51051']}]}, 'vulnerabilities': [{'cve': 'CVE-2025-41726', 'cwe': {'id': 'CWE-190', 'name': 'Integer Overflow or Wraparound'}, 'notes': [{'text': 'A low privileged remote attacker can execute arbitrary code by sending specially crafted calls to the web service of the Device Manager or locally via an API and can cause integer overflows which then may lead to arbitrary code execution within privileged processes.', 'title': 'CVE Description', 'category': 'description'}], 'title': 'CVE-2025-41726', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 8.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 8.8, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001', 'CSAFPID-51011', 'CSAFPID-51021', 'CSAFPID-51031', 'CSAFPID-51041', 'CSAFPID-51051']}], 'remediations': [{'details': "Please update to a recent version of the affected components or update the complete operating system image. Operating system images are available on request from Beckhoff's service (service@beckhoff.com). The setup / installer for Windows 10 and 11 are available on request from Beckhoff's service also.", 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001', 'CSAFGID-0003']}], 'product_status': {'fixed': ['CSAFPID-52001', 'CSAFPID-52011', 'CSAFPID-52021', 'CSAFPID-52031', 'CSAFPID-52041', 'CSAFPID-52051'], 'last_affected': ['CSAFPID-51011', 'CSAFPID-51021', 'CSAFPID-51051'], 'known_affected': ['CSAFPID-51001', 'CSAFPID-51031', 'CSAFPID-51041']}, 'acknowledgments': [{'names': ['Diego Giubertoni'], 'summary': 'Diego Giubertoni reported the vulnerability to Beckhoff', 'organization': 'Nozomi Networks'}]}, {'cve': 'CVE-2025-41727', 'cwe': {'id': 'CWE-420', 'name': 'Unprotected Alternate Channel'}, 'notes': [{'text': 'A local low privileged attacker can bypass the authentication of the Device Manager user interface, allowing them to perform privileged operations and gain administrator access.', 'title': 'CVE Description', 'category': 'description'}], 'title': 'CVE-2025-41727', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 7.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.8, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001', 'CSAFPID-51011', 'CSAFPID-51021', 'CSAFPID-51031', 'CSAFPID-51041', 'CSAFPID-51051']}], 'remediations': [{'details': "Please update to a recent version of the affected components or update the complete operating system image. Operating system images are available on request from Beckhoff's service (service@beckhoff.com). The setup / installer for Windows 10 and 11 are available on request from Beckhoff's service also.", 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001', 'CSAFGID-0003']}], 'product_status': {'fixed': ['CSAFPID-52001', 'CSAFPID-52011', 'CSAFPID-52021', 'CSAFPID-52031', 'CSAFPID-52041', 'CSAFPID-52051'], 'last_affected': ['CSAFPID-51011', 'CSAFPID-51021', 'CSAFPID-51051'], 'known_affected': ['CSAFPID-51001', 'CSAFPID-51031', 'CSAFPID-51041']}, 'acknowledgments': [{'names': ['Diego Giubertoni'], 'summary': 'Diego Giubertoni reported the vulnerability to Beckhoff', 'organization': 'Nozomi Networks'}]}, {'cve': 'CVE-2025-41728', 'cwe': {'id': 'CWE-125', 'name': 'Out-of-bounds Read'}, 'notes': [{'text': 'A low privileged remote attacker may be able to disclose confidential information from the memory of a privileged process by sending specially crafted calls to the Device Manager web service that cause an out-of-bounds read operation under certain circumstances due to ASLR and thereby potentially copy confidential information into a response.', 'title': 'CVE Description', 'category': 'description'}], 'title': 'CVE-2025-41728', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N', 'temporalScore': 5.3, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 5.3, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001', 'CSAFPID-51011', 'CSAFPID-51021', 'CSAFPID-51031', 'CSAFPID-51041', 'CSAFPID-51051']}], 'remediations': [{'details': "Please update to a recent version of the affected components or update the complete operating system image. Operating system images are available on request from Beckhoff's service (service@beckhoff.com). The setup / installer for Windows 10 and 11 are available on request from Beckhoff's service also.", 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001', 'CSAFGID-0003']}], 'product_status': {'fixed': ['CSAFPID-52001', 'CSAFPID-52011', 'CSAFPID-52021', 'CSAFPID-52031', 'CSAFPID-52041', 'CSAFPID-52051'], 'last_affected': ['CSAFPID-51011', 'CSAFPID-51021', 'CSAFPID-51051'], 'known_affected': ['CSAFPID-51001', 'CSAFPID-51031', 'CSAFPID-51041']}, 'acknowledgments': [{'names': ['Diego Giubertoni'], 'summary': 'Diego Giubertoni reported the vulnerability to Beckhoff', 'organization': 'Nozomi Networks'}]}]}
f92185bc6f7dc1dc81b5fff0af77afeeb08ed617157daf2f4ecf44f616c72962
2026-05-29 08:30:35.455889+03:00
2026-05-29 08:30:35.455889+03:00
csaf_beckhoffautomationgmbhcokg.ndjson
7ead3e781cb127c519d79e1428e1625edf553af076096bfb250db1c84f3ee7cf
{'document': {'lang': 'en-US', 'notes': [{'text': 'An optional package of the TwinCAT 3 XAR installs the TwinCAT 3 HMI Server on a device. It provides a server configuration page which can be accessed by administrative users only. When such an administrator accesses the server configuration page it is possible to upload arbitrary content into the CUSTOM_CSS field which is then persisted on the device and later returned and rendered with each login and error page.\nPlease note that administrators have the access rights to modify any content on the HMI server, for example, via the server configuration page. Therefore, administrators would have to act maliciously to exploit this vulnerability.', 'title': 'Summary', 'category': 'summary'}, {'text': 'On an instance of TwinCAT 3 HMI Server running on a device an authenticated administrator can inject arbitrary content into the custom CSS field which is persisted on the device and later returned via the login page and error page.', 'title': 'Impact', 'category': 'description'}, {'text': 'Administrators must exercise due diligence when configuring the TwinCAT 3 HMI server via the server configuration page. Administrators must be selected from trustworthy personnel.', 'title': 'General Recommendation', 'category': 'description'}, {'text': 'Please update to a recent version of the affected components.', 'title': 'Remediation', 'category': 'description'}, {'text': 'Beckhoff Automation welcomes responsibly coordinated reports of vulnerabilities and Beckhoff will collaborate with reporting parties to fix vulnerabilities or mitigate threats.', 'title': 'Reporting vulnerabilities', 'category': 'general'}, {'text': 'Beckhoff is not responsible for any side effects negatively affecting the real-time capabilities of your TwinCAT control application possibly caused by updates. Beckhoff offers updated images with qualified performance for Beckhoff hardware from time to time. TwinCAT System Manager offers tools which can be of assistance to verify real-time performance after update. A backup should be created every time before installing an update. Only administrators or IT experts should perform the backup and update procedure.', 'title': 'Disclaimer', 'category': 'legal_disclaimer'}], 'title': 'Beckhoff: XSS Vulnerability in TwinCAT 3 HMI Server', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2025-106', 'status': 'final', 'aliases': ['VDE-2025-106'], 'version': '1.0.1', 'generator': {'date': '2026-02-12T08:54:19.787Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.42'}}, 'revision_history': [{'date': '2025-12-10T10:00:00.000Z', 'number': '1.0.0', 'summary': 'Initial revision'}, {'date': '2026-02-12T09:00:00.000Z', 'number': '1.0.1', 'summary': 'A typo was corrected in the CVE description.'}], 'current_release_date': '2026-02-12T09:00:00.000Z', 'initial_release_date': '2026-01-26T10:00:00.000Z'}, 'publisher': {'name': 'Beckhoff Automation GmbH & Co. KG', 'category': 'vendor', 'namespace': 'https://www.beckhoff.com', 'contact_details': 'product-securityincident@beckhoff.com'}, 'references': [{'url': 'https://download.beckhoff.com/download/Document/product-security/Advisories/advisory-2025-002.pdf', 'summary': 'Beckhoff Security Advisory 2025-002: XSS Vulnerability in TwinCAT 3 HMI Server - PDF version', 'category': 'self'}, {'url': 'https://www.beckhoff.com/secinfo', 'summary': 'Additional information about the latest security advisories is provided here:', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/beckhoff/', 'summary': 'CERT@VDE Security Advisories for Beckhoff Automation GmbH & Co. KG', 'category': 'external'}, {'url': 'https://beckhoff.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2025-106.json', 'summary': 'VDE-2025-106: Beckhoff: XSS Vulnerability in TwinCAT 3 HMI Server - CSAF', 'category': 'self'}, {'url': 'https://certvde.com/en/advisories/VDE-2025-106', 'summary': 'VDE-2025-106: Beckhoff: XSS Vulnerability in TwinCAT 3 HMI Server - HTML', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/v1/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}, {'urls': ['https://www.jbnu.ac.kr/'], 'names': ['Roby Firnando Yusuf'], 'summary': 'Reported by', 'organization': 'Jeonbuk National University'}]}, 'product_tree': {'branches': [{'name': 'Beckhoff', 'branches': [{'name': 'Software', 'branches': [{'name': 'TwinCAT.HMI.Server', 'branches': [{'name': 'vers:npm/<14.4.267', 'product': {'name': 'TwinCAT.HMI.Server tcpkg package <14.4.267', 'product_id': 'CSAFPID-51001', 'product_identification_helper': {'purl': 'pkg:tcpkg/beckhoff/TwinCAT.HMI.Server?vers=%3C14.4.267'}}, 'category': 'product_version_range'}, {'name': 'vers:npm/14.4.267', 'product': {'name': 'TwinCAT.HMI.Server tcpkg package 14.4.267', 'product_id': 'CSAFPID-52001', 'product_identification_helper': {'purl': 'pkg:tcpkg/beckhoff/TwinCAT.HMI.Server@14.4.267', 'hashes': [{'filename': 'twincat.hmi.server.14.4.267.nupkg', 'file_hashes': [{'value': 'd62b79b11e2ec822514b5b75fc7733e274b7efc722a3d099e10c4e1184dcf849', 'algorithm': 'sha256'}]}]}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'TF2000-HMI-Server', 'branches': [{'name': 'vers:bsd/<14.4.267', 'product': {'name': 'TF2000-HMI-Server OS software package for TwinCAT/BSD <14.4.267', 'product_id': 'CSAFPID-51011', 'product_identification_helper': {'purl': 'pkg:bsd/beckhoff/TF2000-HMI-Server?vers=%3C14.4.267'}}, 'category': 'product_version_range'}, {'name': '14.4.267', 'product': {'name': 'TF2000-HMI-Server OS software package for TwinCAT/BSD 14.4.267', 'product_id': 'CSAFPID-52011', 'product_identification_helper': {'purl': 'pkg:bsd/beckhoff/TF2000-HMI-Server@14.4.267', 'hashes': [{'filename': 'TF2000-HMI-Server-14.4.267.0.pkg', 'file_hashes': [{'value': 'b1bde82c12d72c509edf40908f9f752a49de1274f712aebf0612f2f1bb870413', 'algorithm': 'sha256'}]}]}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'tf2000-hmi-server', 'branches': [{'name': 'arm64', 'branches': [{'name': 'vers:deb/<14.4.267', 'product': {'name': 'tf2000-hmi-server OS software package for Beckhoff RT Linux(R) on ARM64 <14.4.267', 'product_id': 'CSAFPID-51021', 'product_identification_helper': {'purl': 'pkg:deb/beckhoff/tf2000-hmi-server@14.4.267?arch=arm64&vers=%3C14.4.267'}}, 'category': 'product_version_range'}, {'name': '14.4.267', 'product': {'name': 'tf2000-hmi-server OS software package for Beckhoff RT Linux(R) on ARM64 14.4.267', 'product_id': 'CSAFPID-52021', 'product_identification_helper': {'purl': 'pkg:deb/beckhoff/tf2000-hmi-server@14.4.267?arch=arm64', 'hashes': [{'filename': 'tf2000-hmi-server-14.4.267.0_arm64.deb', 'file_hashes': [{'value': '0c8612f70c9f0cdcd8ae36b77622130d633db7a3203e1365e5be5210c131a795', 'algorithm': 'sha256'}]}]}}, 'category': 'product_version'}], 'category': 'architecture'}, {'name': 'amd64', 'branches': [{'name': 'vers:deb/<14.4.267', 'product': {'name': 'tf2000-hmi-server for Beckhoff RT Linux(R) on AMD64 <14.4.267', 'product_id': 'CSAFPID-51031', 'product_identification_helper': {'purl': 'pkg:deb/beckhoff/tf2000-hmi-server@14.4.267?arch=amd64&vers=%3C14.4.267'}}, 'category': 'product_version_range'}, {'name': '14.4.267', 'product': {'name': 'tf2000-hmi-server for Beckhoff RT Linux(R) on AMD64 14.4.267', 'product_id': 'CSAFPID-52031', 'product_identification_helper': {'purl': 'pkg:deb/beckhoff/tf2000-hmi-server@14.4.267?arch=amd64', 'hashes': [{'filename': 'tf2000-hmi-server-14.4.267.0_amd64.deb', 'file_hashes': [{'value': 'cb9fbc60ed97dffa9f71542b49a95d607c09e241210a69e83d8643e475d4256e', 'algorithm': 'sha256'}]}]}}, 'category': 'product_version'}], 'category': 'architecture'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}], 'product_groups': [{'summary': 'Affected products', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-51001', 'CSAFPID-51011', 'CSAFPID-51021', 'CSAFPID-51031']}, {'summary': 'Fixed products', 'group_id': 'CSAFGID-0002', 'product_ids': ['CSAFPID-52001', 'CSAFPID-52011', 'CSAFPID-52021', 'CSAFPID-52031']}]}, 'vulnerabilities': [{'cve': 'CVE-2025-41768', 'cwe': {'id': 'CWE-79', 'name': "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"}, 'notes': [{'text': "An high privileged remote attacker can inject arbitrary content into the custom CSS field on the affected devices due to improper neutralization of input during web page generation ('Cross-site Scripting').\n\n", 'title': 'CVE Description', 'category': 'description'}], 'title': 'CVE-2025-41768', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 5.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N', 'temporalScore': 5.5, 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 5.5, 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'LOW', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001', 'CSAFPID-51011', 'CSAFPID-51021', 'CSAFPID-51031']}], 'remediations': [{'details': 'Please update to a recent version of the affected components.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-52001', 'CSAFPID-52011', 'CSAFPID-52021', 'CSAFPID-52031'], 'known_affected': ['CSAFPID-51001', 'CSAFPID-51011', 'CSAFPID-51021', 'CSAFPID-51031']}, 'acknowledgments': [{'names': ['Roby Firnando Yusuf'], 'summary': 'Roby Firnando Yusuf reported the vulnerability to Beckhoff', 'organization': 'Jeonbuk National University'}]}]}
1da3709818b0effc476478fc7ef3bf5bfd36306c1ac27a8688c0f3b4cb531b9d
2026-05-29 08:30:35.455889+03:00
2026-05-29 08:30:35.455889+03:00
csaf_vartastoragegmbh.ndjson
a9fc83636e98340c46373bead3c42dcbfb0077eec67401d8de3a6149fc1ab6dd
{'document': {'lang': 'en-GB', 'notes': [{'text': 'VARTA energy storage systems have a web user interface via which users and installers can access live data measurements and configure the system to their needs. It has been discovered that the corresponding credentials are hard-coded within the frontend and thus potentially exploitable.', 'title': 'Summary', 'category': 'summary'}, {'text': 'The vulnerability allows unauthorized read and write access to the web backend. This allows reading and writing of parameters that are not intended for this purpose (e.g. connectivity settings, grid parameters). This can impact the operational availability and integrity. The safety of the battery storage device is not affected because safety relevant parameters are not accessible via the web backend.', 'title': 'Impact', 'category': 'description'}, {'text': 'General countermeasures: Restrict HTTP traffic to the energy storage system by using an inbound firewall or other measures on the network level.', 'title': 'Mitigation', 'category': 'description'}, {'text': 'A fixed version will be rolled out OTA as soon as it is available. Rollout for VARTA element backup will start end of Q1/2023 followed by Element S4.', 'title': 'Remediation', 'category': 'description'}], 'title': 'VARTA: Multiple devices prone to hard-coded credentials', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2022-061', 'status': 'final', 'aliases': ['VDE-2022-061'], 'version': '1', 'generator': {'date': '2025-05-05T11:39:30.191Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.24'}}, 'revision_history': [{'date': '2023-03-15T09:00:00.000Z', 'number': '1', 'summary': 'Initial revision.'}], 'current_release_date': '2023-03-15T09:00:00.000Z', 'initial_release_date': '2023-03-15T09:00:00.000Z'}, 'publisher': {'name': 'VARTA Storage GmbH', 'category': 'vendor', 'namespace': 'https://varta-storage.com', 'contact_details': 'info@varta-storage.com'}, 'references': [{'url': 'https://certvde.com/en/advisories/VDE-2022-061/', 'summary': 'VDE-2022-061: VARTA: Multiple devices prone to hard-coded credentials - HTML', 'category': 'self'}, {'url': 'https://varta-storage.csaf-tp.certvde.com/.well-known/csaf/white/2023/vde-2022-061.json', 'summary': 'VDE-2022-061: VARTA: Multiple devices prone to hard-coded credentials - CSAF', 'category': 'self'}, {'url': 'https://varta-storage.com', 'summary': 'VARTA PSIRT', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/varta-storage/', 'summary': 'CERT@VDE Security Advisories for VARTA Storage GmbH', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}, {'summary': 'reporting', 'organization': 'Andreas Dolp'}]}, 'product_tree': {'branches': [{'name': 'VARTA', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'Element backup', 'product': {'name': 'Element backup', 'product_id': 'CSAFPID-11001', 'product_identification_helper': {'model_numbers': ['2709858310 - 90']}}, 'category': 'product_name'}, {'name': 'Element S1', 'product': {'name': 'Element S1', 'product_id': 'CSAFPID-11002', 'product_identification_helper': {'model_numbers': ['2700852201 - 52']}}, 'category': 'product_name'}, {'name': 'Element S2', 'product': {'name': 'Element S2', 'product_id': 'CSAFPID-11003', 'product_identification_helper': {'model_numbers': ['2700852301 - 53', '2700852401 - 53']}}, 'category': 'product_name'}, {'name': 'Element S3', 'product': {'name': 'Element S3', 'product_id': 'CSAFPID-11004', 'product_identification_helper': {'model_numbers': ['2709852201 - 53']}}, 'category': 'product_name'}, {'name': 'Element S4', 'product': {'name': 'Element S4', 'product_id': 'CSAFPID-11005', 'product_identification_helper': {'model_numbers': ['2709858202 - 13']}}, 'category': 'product_name'}, {'name': 'One L/XL', 'product': {'name': 'One L/XL', 'product_id': 'CSAFPID-11006', 'product_identification_helper': {'model_numbers': ['2703852201']}}, 'category': 'product_name'}, {'name': 'Pulse (not pulse neo)', 'product': {'name': 'Pulse (not pulse neo)', 'product_id': 'CSAFPID-11007', 'product_identification_helper': {'model_numbers': ['2707852201']}}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': '<F21000400', 'product': {'name': 'Firmware < F21000400', 'product_id': 'CSAFPID-21001'}, 'category': 'product_version_range'}, {'name': '<2e.3.8.0', 'product': {'name': 'Firmware < 2e.3.8.0', 'product_id': 'CSAFPID-21002'}, 'category': 'product_version_range'}, {'name': '<2e.4.4.0', 'product': {'name': 'Firmware < 2e.4.4.0', 'product_id': 'CSAFPID-21003'}, 'category': 'product_version_range'}, {'name': '<D21010400', 'product': {'name': 'Firmware < D21010400', 'product_id': 'CSAFPID-21004'}, 'category': 'product_version_range'}, {'name': '<C21010800', 'product': {'name': 'Firmware < C21010800', 'product_id': 'CSAFPID-21005'}, 'category': 'product_version_range'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware < F21000400 installed on Element backup', 'product_id': 'CSAFPID-31001'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware < 2e.3.8.0 installed on Element S1', 'product_id': 'CSAFPID-31002'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11002'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware < 2e.3.8.0 installed on Element S2', 'product_id': 'CSAFPID-31003'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11003'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware < 2e.3.8.0 installed on Element S3', 'product_id': 'CSAFPID-31004'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11004'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware < 2e.3.8.0 installed on Element S4', 'product_id': 'CSAFPID-31005'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11005'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware < 2e.4.4.0 installed on One L/XL', 'product_id': 'CSAFPID-31006'}, 'product_reference': 'CSAFPID-21003', 'relates_to_product_reference': 'CSAFPID-11006'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware < D21010400 installed on Pulse (not pulse neo)', 'product_id': 'CSAFPID-31007'}, 'product_reference': 'CSAFPID-21004', 'relates_to_product_reference': 'CSAFPID-11007'}], 'product_groups': [{'summary': 'Affected products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007']}]}, 'vulnerabilities': [{'cve': 'CVE-2022-22512', 'cwe': {'id': 'CWE-798', 'name': 'Use of Hard-coded Credentials'}, 'notes': [{'text': 'Hard-coded credentials in Web-UI of multiple VARTA Storage products in multiple versions allows an unauthorized attacker to gain administrative access to the Web-UI via network.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2022-22512', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007']}], 'remediations': [{'details': 'General countermeasures: Restrict HTTP traffic to the energy storage system by using an inbound firewall or other measures on the network level.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'A fixed version will be rolled out OTA as soon as it is available. Rollout for VARTA element backup will start end of Q1/2023 followed by Element S4.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007']}}]}
bdc0444786833be9093035aa516e318d3eea5b9c895b2668e7cd1fce35cb985d
2026-05-29 08:30:35.951160+03:00
2026-05-29 08:30:35.951160+03:00
csaf_pilzgmbhcokg.ndjson
e2bff402f20c77f767e2503b1d5e02c8c43d35e31e0889059b19ff9c9e83710f
{'document': {'lang': 'en-GB', 'notes': [{'text': 'PiCtory, a web application to configure the Pilz industrial PC IndustrialPI, has three vulnerabilities with varying degrees of severity. The first two are of critical severity and can lead to a bypass of authentication and a cross-site-scripting attack. The third vulnerability with medium severity puts PiCtory at a risk of a reflected cross-site-scripting attack.', 'title': 'Summary', 'category': 'summary'}, {'text': 'An unauthenticated attacker can change the configuration of the PiCtory project. This can lead to unwanted behavior or a Denial of Service.', 'title': 'Impact', 'category': 'description'}, {'text': "Update the PiCtory package to version 2.12 via the 'apt' package manager. Use 'sudo apt update && sudo apt upgrade -y' to pull and install all available updates for the IndustrialPI. To check the version of the pictory package, use 'dpkg -l | grep pictory'.; Limit network access to the IndustrialPI by using a firewall or similar measures.; ", 'title': 'Remediation', 'category': 'description'}], 'title': 'Pilz: Authentication Bypass and Cross-Site-Scripting in PiCtory', 'category': 'csaf_security_advisory', 'tracking': {'id': 'PPSA-2025-001', 'status': 'final', 'aliases': ['VDE-2025-046', 'PPSA-2025-001'], 'version': '1', 'generator': {'date': '2025-06-24T10:07:02.640Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.26'}}, 'revision_history': [{'date': '2025-06-30T10:00:00.000Z', 'number': '1', 'summary': 'Initial Version'}], 'current_release_date': '2025-06-30T10:00:00.000Z', 'initial_release_date': '2025-06-30T10:00:00.000Z'}, 'publisher': {'name': 'Pilz GmbH & Co. KG', 'category': 'vendor', 'namespace': 'https://www.pilz.com', 'contact_details': 'security@pilz.com'}, 'references': [{'url': 'https://www.pilz.com/security', 'summary': 'For further security-related issues in Pilz products please contact the Pilz Product Security Incident Response Team (PSIRT)', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/pilz/', 'summary': 'CERT@VDE Security Advisories for Pilz GmbH & Co. KG', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/PPSA-2025-001/', 'summary': 'PPSA-2025-001: Pilz: Authentication Bypass and Cross-Site-Scripting in PiCtory - HTML', 'category': 'self'}, {'url': 'https://pilz.csaf-tp.certvde.com/.well-known/csaf/white/2025/ppsa-2025-001.json', 'summary': 'PPSA-2025-001: Pilz: Authentication Bypass and Cross-Site-Scripting in PiCtory - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}], 'aggregate_severity': {'text': 'Critical', 'namespace': 'https://www.first.org/cvss/v3.1/specification-document#Qualitative-Severity-Rating-Scale'}}, 'product_tree': {'branches': [{'name': 'Pilz', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'IndustrialPI 4', 'product': {'name': 'Pilz Hardware IndustrialPI 4', 'product_id': 'CSAFPID-11000', 'product_identification_helper': {'model_numbers': ['A1000002', 'A1000003']}}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': 'Bullseye', 'branches': [{'name': '<=2024-08', 'product': {'name': 'Pilz Firmware Bullseye <=2024-08', 'product_id': 'CSAFPID-21000'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Software', 'branches': [{'name': 'PiCtory', 'branches': [{'name': '<2.12', 'product': {'name': 'Pilz Software PiCtory <2.12', 'product_id': 'CSAFPID-51000'}, 'category': 'product_version_range'}, {'name': '2.12', 'product': {'name': 'Pilz Software PiCtory 2.12', 'product_id': 'CSAFPID-52000'}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Pilz Firmware Bullseye <=2024-08 installed on Pilz Hardware IndustrialPI 4', 'product_id': 'CSAFPID-31000'}, 'product_reference': 'CSAFPID-21000', 'relates_to_product_reference': 'CSAFPID-11000'}, {'category': 'installed_on', 'full_product_name': {'name': 'Pilz Software PiCtory <2.12 installed on (Pilz Firmware Bullseye <=2024-08 installed on Pilz Hardware IndustrialPI 4)', 'product_id': 'CSAFPID-31001'}, 'product_reference': 'CSAFPID-51000', 'relates_to_product_reference': 'CSAFPID-31000'}, {'category': 'installed_on', 'full_product_name': {'name': 'Pilz Software PiCtory 2.12 installed on (Pilz Firmware Bullseye <=2024-08 installed on Pilz Hardware IndustrialPI 4)', 'product_id': 'CSAFPID-32000'}, 'product_reference': 'CSAFPID-52000', 'relates_to_product_reference': 'CSAFPID-31000'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-32011', 'cwe': {'id': 'CWE-305', 'name': 'Authentication Bypass by Primary Weakness'}, 'notes': [{'text': 'KUNBUS PiCtory versions 2.5.0 through 2.11.1 have an authentication bypass vulnerability where a remote attacker can bypass authentication to get access due to a path traversal.', 'title': 'Summary', 'category': 'description'}], 'title': 'CVE-2025-32011', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'modifiedScope': 'UNCHANGED', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'modifiedAttackVector': 'NETWORK', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL', 'modifiedIntegrityImpact': 'HIGH', 'modifiedUserInteraction': 'NONE', 'modifiedAttackComplexity': 'LOW', 'modifiedAvailabilityImpact': 'HIGH', 'modifiedPrivilegesRequired': 'NONE', 'modifiedConfidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-31001']}], 'remediations': [{'details': "Update the PiCtory package to version 2.12 via the 'apt' package manager. Use 'sudo apt update && sudo apt upgrade -y' to pull and install all available updates for the IndustrialPI. To check the version of the pictory package, use 'dpkg -l | grep pictory'.", 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31001']}, {'details': 'Limit network access to the IndustrialPI by using a firewall or similar measures.', 'category': 'mitigation', 'product_ids': ['CSAFPID-31001']}], 'product_status': {'fixed': ['CSAFPID-32000'], 'known_affected': ['CSAFPID-31001']}}, {'cve': 'CVE-2025-35996', 'cwe': {'id': 'CWE-97', 'name': 'Improper Neutralization of Server-Side Includes (SSI) Within a Web Page'}, 'notes': [{'text': 'KUNBUS PiCtory version 2.11.1 and earlier are vulnerable when an authenticated remote attacker crafts a special filename that can be stored by API endpoints. That filename is later transmitted to the client in order to show a list of configuration files. Due to a missing escape or sanitization, the filename could be executed as HTML script tag resulting in a cross-site-scripting attack.', 'title': 'Summary', 'category': 'description'}], 'title': 'CVE-2025-35996', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 9, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H', 'modifiedScope': 'CHANGED', 'temporalScore': 9, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.1, 'privilegesRequired': 'LOW', 'modifiedAttackVector': 'NETWORK', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL', 'modifiedIntegrityImpact': 'HIGH', 'modifiedUserInteraction': 'REQUIRED', 'modifiedAttackComplexity': 'LOW', 'modifiedAvailabilityImpact': 'HIGH', 'modifiedPrivilegesRequired': 'LOW', 'modifiedConfidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-31001']}], 'remediations': [{'details': "Update the PiCtory package to version 2.12 via the 'apt' package manager. Use 'sudo apt update && sudo apt upgrade -y' to pull and install all available updates for the IndustrialPI. To check the version of the pictory package, use 'dpkg -l | grep pictory'.", 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31001']}, {'details': 'Limit network access to the IndustrialPI by using a firewall or similar measures.', 'category': 'mitigation', 'product_ids': ['CSAFPID-31001']}], 'product_status': {'fixed': ['CSAFPID-32000'], 'known_affected': ['CSAFPID-31001']}}, {'cve': 'CVE-2025-36558', 'cwe': {'id': 'CWE-97', 'name': 'Improper Neutralization of Server-Side Includes (SSI) Within a Web Page'}, 'notes': [{'text': 'KUNBUS PiCtory version 2.11.1 and earlier are vulnerable to a cross-site-scripting attack via the sso_token used for authentication. If an attacker provides the user with a PiCtory URL containing an HTML script as an sso_token, that script will reply to the user and be executed.', 'title': 'Summary', 'category': 'description'}], 'title': 'CVE-2025-36558', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 6.1, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N', 'modifiedScope': 'CHANGED', 'temporalScore': 6.1, 'integrityImpact': 'LOW', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 6.1, 'privilegesRequired': 'NONE', 'modifiedAttackVector': 'NETWORK', 'confidentialityImpact': 'LOW', 'environmentalSeverity': 'MEDIUM', 'modifiedIntegrityImpact': 'LOW', 'modifiedUserInteraction': 'REQUIRED', 'modifiedAttackComplexity': 'LOW', 'modifiedAvailabilityImpact': 'NONE', 'modifiedPrivilegesRequired': 'NONE', 'modifiedConfidentialityImpact': 'LOW'}, 'products': ['CSAFPID-31001']}], 'remediations': [{'details': "Update the PiCtory package to version 2.12 via the 'apt' package manager. Use 'sudo apt update && sudo apt upgrade -y' to pull and install all available updates for the IndustrialPI. To check the version of the pictory package, use 'dpkg -l | grep pictory'.", 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31001']}, {'details': 'Limit network access to the IndustrialPI by using a firewall or similar measures.', 'category': 'mitigation', 'product_ids': ['CSAFPID-31001']}], 'product_status': {'fixed': ['CSAFPID-32000'], 'known_affected': ['CSAFPID-31001']}}]}
fecb4f2174b129a510f0165dacdefb45baeca340979043bbe5ebe0302d74cb32
2026-05-29 08:30:36.474121+03:00
2026-05-29 08:30:36.474121+03:00
csaf_pilzgmbhcokg.ndjson
467b72d58e5444c7abbff7f325e6800141dfdeb55a3d2bc7a5976345f53de576
{'document': {'lang': 'en-GB', 'notes': [{'text': 'Authentication is not configured by default for the Node-RED server on the Pilz industrial PC IndustrialPI. An unauthenticated remote attacker has full access to the Node-RED server and can run arbitrary operating system commands on the underlying operating system with privileged rights.', 'title': 'Summary', 'category': 'summary'}, {'text': 'The attacker can not only view but create and alter flows in Node-RED. Flows can contain code blocks where commands are executed on the IndustrialPI itself. An attacker can use these code blocks to run any command as a privileged user on the IndustrialPI.', 'title': 'Impact', 'category': 'description'}, {'text': 'Consult our PDF with remediations which you can find under [https://www.pilz.com/search#currentPage=1&SEARCH=Security%20Advis.%20IndustrialPI%20Remediat.](https://www.pilz.com/search#currentPage=1&SEARCH=Security%20Advis.%20IndustrialPI%20Remediat.). In order to activate the authentication as described in the PDF, you have to have the Node-RED service enabled via the web application.', 'title': 'Remediation', 'category': 'description'}, {'text': 'Limit network access to the IndustrialPI by using a firewall or similar measures.', 'title': 'Mitigation', 'category': 'description'}], 'title': 'Pilz: Missing Authentication in Node-RED integration', 'category': 'csaf_security_advisory', 'tracking': {'id': 'PPSA-2025-002', 'status': 'final', 'aliases': ['VDE-2025-045', 'PPSA-2025-002'], 'version': '1.0.0', 'generator': {'date': '2025-06-26T09:07:18.730Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.26'}}, 'revision_history': [{'date': '2025-07-01T10:00:00.000Z', 'number': '1.0.0', 'summary': 'Initial Version'}], 'current_release_date': '2025-07-01T10:00:00.000Z', 'initial_release_date': '2025-07-01T10:00:00.000Z'}, 'publisher': {'name': 'Pilz GmbH & Co. KG', 'category': 'vendor', 'namespace': 'https://www.pilz.com', 'contact_details': 'security@pilz.com'}, 'references': [{'url': 'https://www.pilz.com/security', 'summary': 'For further security-related issues in Pilz products please contact the Pilz Product Security Incident Response Team (PSIRT)', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/pilz/', 'summary': 'CERT@VDE Security Advisories for Pilz GmbH & Co. KG', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/PPSA-2025-002/', 'summary': 'PPSA-2025-002: Pilz: Missing Authentication in Node-RED integration - HTML', 'category': 'self'}, {'url': 'https://pilz.csaf-tp.certvde.com/.well-known/csaf/white/2025/ppsa-2025-002.json', 'summary': 'PPSA-2025-002: Pilz: Missing Authentication in Node-RED integration - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}]}, 'product_tree': {'branches': [{'name': 'Pilz', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'IndustrialPI 4', 'product': {'name': 'IndustrialPI 4', 'product_id': 'CSAFPID-11000', 'product_identification_helper': {'model_numbers': ['A1000002', 'A1000003']}}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': 'Bullseye', 'branches': [{'name': '<=2024-08', 'product': {'name': 'Firmware Bullseye <=2024-08', 'product_id': 'CSAFPID-21000'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware Bullseye <=2024-08 installed on IndustrialPI 4', 'product_id': 'CSAFPID-31000'}, 'product_reference': 'CSAFPID-21000', 'relates_to_product_reference': 'CSAFPID-11000'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-41656', 'cwe': {'id': 'CWE-306', 'name': 'Missing Authentication for Critical Function'}, 'notes': [{'text': 'An unauthenticated remote attacker can run arbitrary commands on the affected devices with high privileges because the authentication for the Node_RED server is not configured by default. \n', 'title': 'Summary', 'category': 'description'}], 'title': 'CVE-2025-41656', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 10, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H', 'temporalScore': 10, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 10, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31000']}], 'remediations': [{'details': 'Consult our PDF with remediations which you can find under [www.pilz.com/downloads](https://www.pilz.com/search#currentPage=1&SEARCH=Security%20Advis.%20IndustrialPI%20Remediat.). In order to activate the authentication as described in the PDF, you have to have the Node-RED service enabled via the web application.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31000']}, {'details': 'Limit network access to the IndustrialPI by using a firewall or similar measures.', 'category': 'mitigation', 'product_ids': ['CSAFPID-31000']}], 'product_status': {'known_affected': ['CSAFPID-31000']}}]}
20811319be9ba297e6a9a485f46b8327dd774d715c6ad64974dda35f4cd7ec81
2026-05-29 08:30:36.474121+03:00
2026-05-29 08:30:36.474121+03:00
csaf_pilzgmbhcokg.ndjson
4bee9e32f156a9c6e6de1b0b1d2fe81eb9647b80314db10cb5b98f4a594ee14b
{'document': {'lang': 'en-GB', 'notes': [{'text': 'The Pilz industrial PC IndustrialPI webstatus application is vulnerable to an authentication bypass.', 'title': 'Summary', 'category': 'summary'}, {'text': 'An attacker can bypass the login to the web application making it possible to access and maliciously change all available settings of the IndustrialPI.', 'title': 'Impact', 'category': 'description'}, {'text': "Update the webstatus package to version 2.4.6 via the 'apt' package manager. Use 'sudo apt update && sudo apt upgrade -y' to pull and install all available updates for the IndustrialPI. To check the version of the webstatus package, use 'dpkg -l | grep revpi-webstatus'.; Limit network access to the IndustrialPI by using a firewall or similar measures.; ", 'title': 'Remediation', 'category': 'description'}], 'title': 'Pilz: Authentication Bypass in IndustrialPI Webstatus', 'category': 'csaf_security_advisory', 'tracking': {'id': 'PPSA-2025-003', 'status': 'final', 'aliases': ['VDE-2025-039', 'PPSA-2025-003'], 'version': '1.0.0', 'generator': {'date': '2025-06-27T08:29:49.019Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.26'}}, 'revision_history': [{'date': '2025-07-01T10:00:00.000Z', 'number': '1.0.0', 'summary': 'Initial Version'}], 'current_release_date': '2025-07-01T10:00:00.000Z', 'initial_release_date': '2025-07-01T10:00:00.000Z'}, 'publisher': {'name': 'Pilz GmbH & Co. KG', 'category': 'vendor', 'namespace': 'https://www.pilz.com', 'contact_details': 'security@pilz.com'}, 'references': [{'url': 'https://www.pilz.com/security', 'summary': 'For further security-related issues in Pilz products please contact the Pilz Product Security Incident Response Team (PSIRT)', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/pilz/', 'summary': 'CERT@VDE Security Advisories for Pilz GmbH & Co. KG', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/PPSA-2025-003/', 'summary': 'PPSA-2025-003: Pilz: Authentication Bypass in IndustrialPI Webstatus - HTML', 'category': 'self'}, {'url': 'https://pilz.csaf-tp.certvde.com/.well-known/csaf/white/2025/ppsa-2025-003.json', 'summary': 'PPSA-2025-003: Pilz: Authentication Bypass in IndustrialPI Webstatus - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}]}, 'product_tree': {'branches': [{'name': 'Pilz', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'IndustrialPI 4', 'product': {'name': 'IndustrialPI 4', 'product_id': 'CSAFPID-11000', 'product_identification_helper': {'model_numbers': ['A1000002', 'A1000003']}}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': 'Bullseye', 'branches': [{'name': '<=2024-08', 'product': {'name': 'Firmware Bullseye <=2024-08', 'product_id': 'CSAFPID-21000'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Software', 'branches': [{'name': 'IndustrialPI webstatus', 'branches': [{'name': '<2.4.6', 'product': {'name': 'IndustrialPI webstatus <2.4.6', 'product_id': 'CSAFPID-51000'}, 'category': 'product_version_range'}, {'name': '2.4.6', 'product': {'name': 'IndustrialPI webstatus 2.4.6', 'product_id': 'CSAFPID-52000'}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware Bullseye <=2024-08 installed on IndustrialPI 4', 'product_id': 'CSAFPID-31000'}, 'product_reference': 'CSAFPID-21000', 'relates_to_product_reference': 'CSAFPID-11000'}, {'category': 'installed_on', 'full_product_name': {'name': 'IndustrialPI webstatus <2.4.6 installed on Firmware Bullseye <=2024-08 installed on IndustrialPI 4', 'product_id': 'CSAFPID-31001'}, 'product_reference': 'CSAFPID-51000', 'relates_to_product_reference': 'CSAFPID-31000'}, {'category': 'installed_on', 'full_product_name': {'name': 'IndustrialPI webstatus 2.4.6 installed on Firmware Bullseye <=2024-08 installed on IndustrialPI 4', 'product_id': 'CSAFPID-32000'}, 'product_reference': 'CSAFPID-52000', 'relates_to_product_reference': 'CSAFPID-31000'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-41648', 'cwe': {'id': 'CWE-704', 'name': 'Incorrect Type Conversion or Cast'}, 'notes': [{'text': 'An unauthenticated remote attacker can bypass the login to the web application of the affected devices making it possible to access and change all available settings of the IndustrialPI.', 'title': 'Summary', 'category': 'description'}], 'title': 'CVE-2025-41648', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001']}], 'remediations': [{'details': "Update the webstatus package to version 2.4.6 via the 'apt' package manager. Use 'sudo apt update && sudo apt upgrade -y' to pull and install all available updates for the IndustrialPI. To check the version of the webstatus package, use 'dpkg -l | grep revpi-webstatus'.", 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31001']}, {'details': 'Limit network access to the IndustrialPI by using a firewall or similar measures.', 'category': 'mitigation', 'product_ids': ['CSAFPID-31001']}], 'product_status': {'fixed': ['CSAFPID-32000'], 'known_affected': ['CSAFPID-31001']}}]}
cbede2a0756d9f8b30c8982cda57ed80c30e6e19c069aa54e17fd5ffd901c35f
2026-05-29 08:30:36.474121+03:00
2026-05-29 08:30:36.474121+03:00
csaf_pilzgmbhcokg.ndjson
c588a2929927589314405a28e57904a5123e8e82400568ea9baa2176a22ebc80
{'document': {'lang': 'en-GB', 'notes': [{'text': 'The PASvisu Runtime is affected by a vulnerability in a third-party component which can be exploited by a malicious web request.', 'title': 'Summary', 'category': 'summary'}, {'text': 'A successful attack leads to a loss of availability of the affected Pilz products. For the products to be operational again, a manual restart is required.', 'title': 'Impact', 'category': 'description'}, {'text': 'Limit network access to PASvisu server by using a firewall, a host-based firewall or similar measures.', 'title': 'Mitigation', 'category': 'description'}, {'text': "- PASvisu: Please visit the Pilz website (https://www.pilz.com/en-INT/search) and install the new version 'PASvisu 1.15.1' on to your device.\n\n- PMIv7xxe: Please visit the Pilz website (https://www.pilz.com/en-INT/search) and install the new firmware image 'Firmware PMI v70Xe (visu 1.15.1) 03.01.00' on to your device.\n\n- PMIv8xx: Please visit the Pilz website (https://www.pilz.com/en-INT/search) and download 'Firmware PMI v8 Assistant (visu 1.15.1) 2.2.2' in order to install the new verison of the firmware on to your device. ; ", 'title': 'Remediation', 'category': 'description'}], 'title': 'Pilz: Vulnerability affecting PASvisu Runtime', 'category': 'csaf_security_advisory', 'tracking': {'id': 'PPSA-2025-004', 'status': 'final', 'aliases': ['VDE-2025-093', 'PPSA-2025-004'], 'version': '1.0.0', 'generator': {'date': '2025-10-20T06:32:52.941Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.35'}}, 'revision_history': [{'date': '2025-10-20T10:00:00.000Z', 'number': '1.0.0', 'summary': 'Initial Version'}], 'current_release_date': '2025-10-20T10:00:00.000Z', 'initial_release_date': '2025-10-20T10:00:00.000Z'}, 'publisher': {'name': 'Pilz GmbH & Co. KG', 'category': 'vendor', 'namespace': 'https://www.pilz.com', 'contact_details': 'security@pilz.com'}, 'references': [{'url': 'https://www.pilz.com/security', 'summary': 'For further security-related issues in Pilz products please contact the Pilz Product Security Incident Response Team (PSIRT)', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/pilz/', 'summary': 'CERT@VDE Security Advisories for Pilz GmbH & Co. KG', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/PPSA-2025-004', 'summary': 'PPSA-2025-004: Pilz: Vulnerability affecting PASvisu Runtime - HTML', 'category': 'self'}, {'url': 'https://pilz.csaf-tp.certvde.com/.well-known/csaf/white/2025/ppsa-2025-004.json', 'summary': 'PPSA-2025-004: Pilz: Vulnerability affecting PASvisu Runtime - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}]}, 'product_tree': {'branches': [{'name': 'Pilz', 'branches': [{'name': 'Software', 'branches': [{'name': 'PASvisu', 'branches': [{'name': '<=1.15.0', 'product': {'name': 'PASvisu <=1.15.0', 'product_id': 'CSAFPID-51000'}, 'category': 'product_version_range'}, {'name': '1.15.1', 'product': {'name': 'PASvisu 1.15.1', 'product_id': 'CSAFPID-52000'}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Hardware', 'branches': [{'name': 'PMIv7xxe', 'product': {'name': 'PMIv7xxe', 'product_id': 'CSAFPID-11000', 'product_identification_helper': {'model_numbers': ['266704', '266707']}}, 'category': 'product_name'}, {'name': 'PMIv8xx', 'product': {'name': 'PMIv8xx', 'product_id': 'CSAFPID-12000', 'product_identification_helper': {'model_numbers': ['266807', '266812', '266815']}}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': 'Firmware PMI v70Xe', 'branches': [{'name': '<=03.00.00', 'product': {'name': 'Firmware PMI v70Xe <=03.00.00', 'product_id': 'CSAFPID-21000'}, 'category': 'product_version_range'}, {'name': '03.01.00', 'product': {'name': 'Firmware PMI v70Xe 03.01.00', 'product_id': 'CSAFPID-22000'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Firmware PMI v8', 'branches': [{'name': '<=2.2.1', 'product': {'name': 'Firmware PMI v8 <=2.2.1', 'product_id': 'CSAFPID-21001'}, 'category': 'product_version_range'}, {'name': '2.2.2', 'product': {'name': 'Firmware PMI v8 2.2.2', 'product_id': 'CSAFPID-22001'}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'product_name'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware PMI v70Xe <=03.00.00 installed on PMIv7xxe', 'product_id': 'CSAFPID-31000'}, 'product_reference': 'CSAFPID-21000', 'relates_to_product_reference': 'CSAFPID-11000'}, {'category': 'installed_on', 'full_product_name': {'name': 'PASvisu <=1.15.0 installed on Firmware PMI v70Xe <=03.00.00 installed on PMIv7xxe', 'product_id': 'CSAFPID-31001'}, 'product_reference': 'CSAFPID-51000', 'relates_to_product_reference': 'CSAFPID-31000'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware PMI v70Xe 03.01.00 installed on PMIv7xxe', 'product_id': 'CSAFPID-32000'}, 'product_reference': 'CSAFPID-22000', 'relates_to_product_reference': 'CSAFPID-11000'}, {'category': 'installed_on', 'full_product_name': {'name': 'PASvisu 1.15.1 installed on Firmware PMI v70Xe 03.01.00 installed on PMIv7xxe', 'product_id': 'CSAFPID-32001'}, 'product_reference': 'CSAFPID-52000', 'relates_to_product_reference': 'CSAFPID-32000'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware PMI v8 <=2.2.1 installed on PMIv8xx', 'product_id': 'CSAFPID-31002'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-12000'}, {'category': 'installed_on', 'full_product_name': {'name': 'PASvisu <=1.15.0 installed on Firmware PMI v8 <=2.2.1 installed on PMIv8xx', 'product_id': 'CSAFPID-31003'}, 'product_reference': 'CSAFPID-51000', 'relates_to_product_reference': 'CSAFPID-31002'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware PMI v8 2.2.2 installed on PMIv8xx', 'product_id': 'CSAFPID-32002'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-12000'}, {'category': 'installed_on', 'full_product_name': {'name': 'PASvisu 1.15.1 installed on Firmware PMI v8 2.2.2 installed on PMIv8xx', 'product_id': 'CSAFPID-32003'}, 'product_reference': 'CSAFPID-52000', 'relates_to_product_reference': 'CSAFPID-32002'}], 'product_groups': [{'summary': 'Affected products', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-31001', 'CSAFPID-31003', 'CSAFPID-51000']}, {'summary': 'fixed products', 'group_id': 'CSAFGID-0002', 'product_ids': ['CSAFPID-32001', 'CSAFPID-32003', 'CSAFPID-52000']}]}, 'vulnerabilities': [{'cve': 'CVE-2025-51495', 'cwe': {'id': 'CWE-190', 'name': 'Integer Overflow or Wraparound'}, 'notes': [{'text': 'An integer overflow vulnerability exists in the WebSocket component of Mongoose 7.5 thru 7.17. By sending a specially crafted WebSocket request, an attacker can cause the application to crash. If downstream vendors integrate this component improperly, the issue may lead to a buffer overflow.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2025-51495', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51000', 'CSAFPID-31001', 'CSAFPID-31003']}], 'remediations': [{'details': 'Limit network access to PASvisu server by using a firewall, a host-based firewall or similar measures.', 'category': 'mitigation', 'product_ids': ['CSAFPID-31001', 'CSAFPID-31003', 'CSAFPID-51000']}, {'details': "Please visit the Pilz website (https://www.pilz.com/en-INT/search) and install the new version 'PASvisu 1.15.1' on to your device.", 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51000']}, {'details': "Please visit the Pilz website (https://www.pilz.com/en-INT/search) and install the new firmware image 'Firmware PMI v70Xe (visu 1.15.1) 03.01.00' on to your device.", 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31001']}, {'details': "Please visit the Pilz website (https://www.pilz.com/en-INT/search) and download 'Firmware PMI v8 Assistant (visu 1.15.1) 2.2.2' in order to install the new verison of the firmware on to your device.", 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31003']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32003', 'CSAFPID-52000'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31003', 'CSAFPID-51000']}}]}
50b2a096171152067949576158fb4cb6748417e9dab50212141a963de8f5b70a
2026-05-29 08:30:36.474121+03:00
2026-05-29 08:30:36.474121+03:00
csaf_pilzgmbhcokg.ndjson
0b20a0983cd8fa9c31259eb4d4cb642dfa31a4665b3e76815d64f73409ec2446
{'document': {'lang': 'en-GB', 'notes': [{'text': 'Link to repository: [CERT@VDE CSAF Template](https://github.com/CERTVDE/CSAF-Template) © 2025 by [CERT@VDE](https://certvde.com) is licensed under [CC BY-NC 4.0](https://creativecommons.org/licenses/by-nc/4.0/?ref=chooser-v1) \n\nThis document note may only be removed in order to create a CSAF advisory based on this template.', 'title': 'LICENSE', 'audience': 'csaf creator', 'category': 'other'}, {'text': '**PIT User Authentication Service is part of the operating mode selection and access permission system PITmode.** The PIT User Authentication Service is affected by multiple vulnerabilities in included third-party components.', 'title': 'Summary', 'category': 'summary'}, {'text': 'The attacker can intercept the communication between the PITreader and the PIT User Authentication Service which can lead to disclosure of the PITreader API token. Furthermore the PIT User Authentication Service is vulnerable to a Denial of Service attack.', 'title': 'Impact', 'category': 'description'}, {'text': 'Please visit the Pilz website (https://www.pilz.com/en-INT/search) and install the new version "Software PIT User Auth. Service 1.4.1" on to your device.', 'title': 'Remediation', 'category': 'description'}, {'text': 'Limit network access to the PITreader and PIT User Authentication Service by using a firewall, a host-based firewall or similar measures. ', 'title': 'Mitigation', 'category': 'description'}], 'title': 'Pilz: Multiple Vulnerabilities affecting the PIT User Authentication Service', 'category': 'csaf_security_advisory', 'tracking': {'id': 'PPSA-2026-001', 'status': 'final', 'aliases': ['VDE-2026-006', 'PPSA-2026-001'], 'version': '1.0.1', 'generator': {'date': '2026-02-02T10:01:58.102Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.42'}}, 'revision_history': [{'date': '2026-02-02T08:00:00.000Z', 'number': '1.0.0', 'summary': 'Initial Version'}, {'date': '2026-02-02T10:00:00.000Z', 'number': '1.0.1', 'summary': 'Summary has been updated.'}], 'current_release_date': '2026-02-02T10:00:00.000Z', 'initial_release_date': '2026-02-02T08:00:00.000Z'}, 'publisher': {'name': 'Pilz GmbH & Co. KG', 'category': 'vendor', 'namespace': 'https://www.pilz.com', 'contact_details': 'security@pilz.com'}, 'references': [{'url': 'https://www.pilz.com/security', 'summary': 'For further security-related issues in Pilz products please contact the Pilz Product Security Incident Response Team (PSIRT)', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/pilz/', 'summary': 'CERT@VDE Security Advisories for Pilz GmbH & Co. KG', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/VDE-2026-006/', 'summary': 'PPSA-2026-001: Pilz: Multiple Vulnerabilities affecting the PIT User Authentication Service - HTML', 'category': 'self'}, {'url': 'https://pilz.csaf-tp.certvde.com/.well-known/csaf/white/2026/ppsa-2026-001.json', 'summary': 'PPSA-2026-001: Pilz: Multiple Vulnerabilities affecting the PIT User Authentication Service - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}], 'aggregate_severity': {'text': 'High', 'namespace': 'https://www.first.org/cvss/v3.1/specification-document#Qualitative-Severity-Rating-Scale'}}, 'product_tree': {'branches': [{'name': 'Pilz', 'branches': [{'name': 'Software', 'branches': [{'name': 'PIT User Authentication Service', 'branches': [{'name': 'vers:generic/<1.4.1', 'product': {'name': 'PIT User Authentication Service <1.4.1', 'product_id': 'CSAFPID-51001'}, 'category': 'product_version_range'}, {'name': '1.4.1', 'product': {'name': 'PIT User Authentication Service 1.4.1', 'product_id': 'CSAFPID-52001', 'product_identification_helper': {'cpe': 'cpe:2.3:a:pilz:pit_user_authentication_service_software:1.4.1:*:*:*:*:*:*:*'}}, 'category': 'product_version'}, {'name': '1.4.0', 'product': {'name': 'PIT User Authentication Service 1.4.0', 'product_id': 'CSAFPID-51002', 'product_identification_helper': {'cpe': 'cpe:2.3:a:pilz:pit_user_authentication_service_software:1.4.0:*:*:*:*:*:*:*'}}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-12383', 'cwe': {'id': 'CWE-362', 'name': "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')"}, 'notes': [{'text': 'In Eclipse Jersey versions 2.45, 3.0.16, 3.1.9 a race condition can cause ignoring of critical SSL configurations - such as mutual authentication, custom key/trust stores, and other security settings. This issue may result in SSLHandshakeException under normal circumstances, but under certain conditions, it could lead to unauthorized trust in insecure servers (see PoC)', 'title': 'CVE Description', 'category': 'description'}], 'title': 'Race Condition allows Bypass of Trust Restrictions', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.4, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N', 'modifiedScope': 'UNCHANGED', 'temporalScore': 7.4, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'NONE', 'environmentalScore': 7.4, 'privilegesRequired': 'NONE', 'modifiedAttackVector': 'NETWORK', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH', 'modifiedIntegrityImpact': 'HIGH', 'modifiedUserInteraction': 'NONE', 'modifiedAttackComplexity': 'HIGH', 'modifiedAvailabilityImpact': 'NONE', 'modifiedPrivilegesRequired': 'NONE', 'modifiedConfidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-51001', 'CSAFPID-51002']}], 'remediations': [{'details': 'Limit network access to the PITreader and PIT User Authentication Service by using a firewall, a host-based firewall or similar measures.', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001', 'CSAFPID-51002']}, {'details': "Please visit the Pilz website (https://www.pilz.com/en-INT/search) and install the new version 'Software PIT User Auth. Service 1.4.1' on to your device.", 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001', 'CSAFPID-51002']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001', 'CSAFPID-51002']}}, {'cve': 'CVE-2025-61795', 'cwe': {'id': 'CWE-404', 'name': 'Improper Resource Shutdown or Release'}, 'notes': [{'text': 'Improper Resource Shutdown or Release vulnerability in Apache Tomcat. If an error occurred (including exceeding limits) during the processing of a multipart upload, temporary copies of the uploaded parts written to disc were not cleaned up immediately but left for the garbage collection process to delete. Depending on JVM settings, application memory usage and application load, it was possible that space for the temporary copies of uploaded parts would be filled faster than GC cleared it, leading to a DoS. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.11, from 10.1.0-M1 through 10.1.46, from 9.0.0.M1 through 9.0.109. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.12 or later, 10.1.47 or later or 9.0.110 or later which fixes the issue.', 'title': 'CVE Description', 'category': 'description'}], 'title': 'Apache Tomcat: Delayed cleaning of multi-part upload temporary files may lead to DoS', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H', 'modifiedScope': 'UNCHANGED', 'temporalScore': 5.3, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'HIGH', 'environmentalScore': 5.3, 'privilegesRequired': 'LOW', 'modifiedAttackVector': 'NETWORK', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM', 'modifiedIntegrityImpact': 'NONE', 'modifiedUserInteraction': 'NONE', 'modifiedAttackComplexity': 'HIGH', 'modifiedAvailabilityImpact': 'HIGH', 'modifiedPrivilegesRequired': 'LOW', 'modifiedConfidentialityImpact': 'NONE'}, 'products': ['CSAFPID-51001', 'CSAFPID-51002']}], 'remediations': [{'details': 'Limit network access to the PITreader and PIT User Authentication Service by using a firewall, a host-based firewall or similar measures.', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001', 'CSAFPID-51002']}, {'details': "Please visit the Pilz website (https://www.pilz.com/en-INT/search) and install the new version 'Software PIT User Auth. Service 1.4.1' on to your device.", 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001', 'CSAFPID-51002']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001', 'CSAFPID-51002']}}, {'cve': 'CVE-2025-48988', 'cwe': {'id': 'CWE-770', 'name': 'Allocation of Resources Without Limits or Throttling'}, 'notes': [{'text': 'Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.', 'title': 'CVE Description', 'category': 'description'}], 'title': 'Apache Tomcat: FileUpload large number of parts with headers DoS', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'modifiedScope': 'UNCHANGED', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'modifiedAttackVector': 'NETWORK', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH', 'modifiedIntegrityImpact': 'NONE', 'modifiedUserInteraction': 'NONE', 'modifiedAttackComplexity': 'LOW', 'modifiedAvailabilityImpact': 'HIGH', 'modifiedPrivilegesRequired': 'NONE', 'modifiedConfidentialityImpact': 'NONE'}, 'products': ['CSAFPID-51001', 'CSAFPID-51002']}], 'remediations': [{'details': 'Limit network access to the PITreader and PIT User Authentication Service by using a firewall, a host-based firewall or similar measures.', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001', 'CSAFPID-51002']}, {'details': "Please visit the Pilz website (https://www.pilz.com/en-INT/search) and install the new version 'Software PIT User Auth. Service 1.4.1' on to your device.", 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001', 'CSAFPID-51002']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001', 'CSAFPID-51002']}}, {'cve': 'CVE-2025-31650', 'cwe': {'id': 'CWE-459', 'name': 'Incomplete Cleanup'}, 'notes': [{'text': 'Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority headers resulted in incomplete clean-up of the failed request which created a memory leak. A large number of such requests could trigger an OutOfMemoryException resulting in a denial of service. This issue affects Apache Tomcat: from 9.0.76 through 9.0.102, from 10.1.10 through 10.1.39, from 11.0.0-M2 through 11.0.5. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.90 though 8.5.100. Users are recommended to upgrade to version 9.0.104, 10.1.40 or 11.0.6 which fix the issue.', 'title': 'CVE Description', 'category': 'description'}], 'title': 'Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'modifiedScope': 'UNCHANGED', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'modifiedAttackVector': 'NETWORK', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH', 'modifiedIntegrityImpact': 'NONE', 'modifiedUserInteraction': 'NONE', 'modifiedAttackComplexity': 'LOW', 'modifiedAvailabilityImpact': 'HIGH', 'modifiedPrivilegesRequired': 'NONE', 'modifiedConfidentialityImpact': 'NONE'}, 'products': ['CSAFPID-51001', 'CSAFPID-51002']}], 'remediations': [{'details': 'Limit network access to the PITreader and PIT User Authentication Service by using a firewall, a host-based firewall or similar measures.', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001', 'CSAFPID-51002']}, {'details': "Please visit the Pilz website (https://www.pilz.com/en-INT/search) and install the new version 'Software PIT User Auth. Service 1.4.1' on to your device.", 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001', 'CSAFPID-51002']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001', 'CSAFPID-51002']}}]}
890fa4712052312568e6a9d75c409b6b30bd50ac2f522685b369fabbed831fc4
2026-05-29 08:30:36.474121+03:00
2026-05-29 08:30:36.474121+03:00
csaf_pilzgmbhcokg.ndjson
737113dde237095ecd45f91c6b829be04d9c7a4c2ee575ca63e2f655379ff36e
{'document': {'lang': 'en-GB', 'notes': [{'text': 'Link to repository: [CERT@VDE CSAF Template](https://github.com/CERTVDE/CSAF-Template) © 2025 by [CERT@VDE](https://certvde.com) is licensed under [CC BY-NC 4.0](https://creativecommons.org/licenses/by-nc/4.0/?ref=chooser-v1) \n\nThis document note may only be removed in order to create a CSAF advisory based on this template.', 'title': 'LICENSE', 'audience': 'csaf creator', 'category': 'other'}, {'text': 'The PASvisu Runtime is affected by a vulnerability in a third-party component which can be exploited by malicious web requests.', 'title': 'Summary', 'category': 'summary'}, {'text': 'A successful attack leads to a loss of availability of the affected Pilz products. For the products to be operational again, a manual restart is required.', 'title': 'Impact', 'category': 'description'}, {'text': 'Limit network access to PASvisu server by using a firewall, a host-based firewall or similar measures.; ', 'title': 'Remediation', 'category': 'description'}], 'title': 'Pilz: Vulnerability affecting PASvisu Runtime', 'category': 'csaf_security_advisory', 'tracking': {'id': 'PPSA-2026-002', 'status': 'final', 'aliases': ['VDE-2026-019', 'PPSA-2026-002'], 'version': '1.0.0', 'generator': {'date': '2026-04-23T12:38:13.854Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.44'}}, 'revision_history': [{'date': '2026-04-23T12:00:00.000Z', 'number': '1.0.0', 'summary': 'Initial Version'}], 'current_release_date': '2026-04-23T12:00:00.000Z', 'initial_release_date': '2026-04-23T12:00:00.000Z'}, 'publisher': {'name': 'Pilz GmbH & Co. KG', 'category': 'vendor', 'namespace': 'https://www.pilz.com', 'contact_details': 'security@pilz.com'}, 'references': [{'url': 'https://www.pilz.com/security', 'summary': 'For further security-related issues in Pilz products please contact the Pilz Product Security Incident Response Team (PSIRT)', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/pilz/', 'summary': 'CERT@VDE Security Advisories for Pilz GmbH & Co. KG', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/VDE-2026-019/', 'summary': 'PPSA-2026-002: Pilz: Vulnerability affecting PASvisu Runtime - HTML', 'category': 'self'}, {'url': 'https://pilz.csaf-tp.certvde.com/.well-known/csaf/white/2026/ppsa-2026-002.json', 'summary': 'PPSA-2026-002: Pilz: Vulnerability affecting PASvisu Runtime - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}]}, 'product_tree': {'branches': [{'name': 'Pilz', 'branches': [{'name': 'Software', 'branches': [{'name': 'PASvisu', 'branches': [{'name': '<=1.15.1', 'product': {'name': 'PASvisu <=1.15.1', 'product_id': 'CSAFPID-51000'}, 'category': 'product_version_range'}, {'name': '1.16.0', 'product': {'name': 'PASvisu 1.16.0', 'product_id': 'CSAFPID-52000'}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Hardware', 'branches': [{'name': 'PMIv7xxe', 'product': {'name': 'PMIv7xxe', 'product_id': 'CSAFPID-11000', 'product_identification_helper': {'model_numbers': ['266704', '266707']}}, 'category': 'product_name'}, {'name': 'PMIv8xx', 'product': {'name': 'PMIv8xx', 'product_id': 'CSAFPID-12000', 'product_identification_helper': {'model_numbers': ['266807', '266812', '266815']}}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': 'Firmware PMI v70Xe', 'branches': [{'name': '<=03.01.00', 'product': {'name': 'Firmware PMI v70Xe <=03.01.00', 'product_id': 'CSAFPID-21000'}, 'category': 'product_version_range'}, {'name': '04.00.00', 'product': {'name': 'Firmware PMI v70Xe 04.00.00', 'product_id': 'CSAFPID-22000'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Firmware PMI v8', 'branches': [{'name': '<=2.2.2', 'product': {'name': 'Firmware PMI v8 <=2.2.2', 'product_id': 'CSAFPID-21001'}, 'category': 'product_version_range'}, {'name': '2.3.0', 'product': {'name': 'Firmware PMI v8 2.3.0', 'product_id': 'CSAFPID-22001'}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'product_name'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware PMI v70Xe <=03.01.00 installed on PMIv7xxe', 'product_id': 'CSAFPID-31000'}, 'product_reference': 'CSAFPID-21000', 'relates_to_product_reference': 'CSAFPID-11000'}, {'category': 'installed_on', 'full_product_name': {'name': 'PASvisu <=1.15.1 installed on Firmware PMI v70Xe <=03.01.00 installed on PMIv7xxe', 'product_id': 'CSAFPID-31001'}, 'product_reference': 'CSAFPID-51000', 'relates_to_product_reference': 'CSAFPID-31000'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware PMI v70Xe 04.00.00 installed on PMIv7xxe', 'product_id': 'CSAFPID-32000'}, 'product_reference': 'CSAFPID-22000', 'relates_to_product_reference': 'CSAFPID-11000'}, {'category': 'installed_on', 'full_product_name': {'name': 'PASvisu 1.16.0 installed on Firmware PMI v70Xe 04.00.00 installed on PMIv7xxe', 'product_id': 'CSAFPID-32001'}, 'product_reference': 'CSAFPID-52000', 'relates_to_product_reference': 'CSAFPID-32000'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware PMI v8 <=2.2.2 installed on PMIv8xx', 'product_id': 'CSAFPID-31002'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-12000'}, {'category': 'installed_on', 'full_product_name': {'name': 'PASvisu <=1.15.1 installed on Firmware PMI v8 <=2.2.2 installed on PMIv8xx', 'product_id': 'CSAFPID-31003'}, 'product_reference': 'CSAFPID-51000', 'relates_to_product_reference': 'CSAFPID-31002'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware PMI v8 2.3.0 installed on PMIv8xx', 'product_id': 'CSAFPID-32002'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-12000'}, {'category': 'installed_on', 'full_product_name': {'name': 'PASvisu 1.16.0 installed on Firmware PMI v8 2.3.0 installed on PMIv8xx', 'product_id': 'CSAFPID-32003'}, 'product_reference': 'CSAFPID-52000', 'relates_to_product_reference': 'CSAFPID-32002'}], 'product_groups': [{'summary': 'Affected products', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-31001', 'CSAFPID-31003', 'CSAFPID-51000']}, {'summary': 'fixed products', 'group_id': 'CSAFGID-0002', 'product_ids': ['CSAFPID-32001', 'CSAFPID-32003', 'CSAFPID-52000']}]}, 'vulnerabilities': [{'cve': 'CVE-2018-25193', 'cwe': {'id': 'CWE-1188', 'name': 'Initialization of a Resource with an Insecure Default'}, 'notes': [{'text': 'Mongoose Web Server 6.9 contains a denial of service vulnerability that allows remote attackers to crash the service by establishing multiple socket connections. Attackers can repeatedly create connections to the default port and send malformed data to exhaust server resources and cause service unavailability.', 'title': 'CVE Description', 'category': 'description'}], 'title': 'CVE-2018-25193', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'modifiedScope': 'UNCHANGED', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'modifiedAttackVector': 'NETWORK', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH', 'modifiedIntegrityImpact': 'NONE', 'modifiedUserInteraction': 'NONE', 'modifiedAttackComplexity': 'LOW', 'modifiedAvailabilityImpact': 'HIGH', 'modifiedPrivilegesRequired': 'NONE', 'modifiedConfidentialityImpact': 'NONE'}, 'products': ['CSAFPID-51000', 'CSAFPID-31001', 'CSAFPID-31003']}], 'remediations': [{'details': 'Limit network access to PASvisu server by using a firewall, a host-based firewall or similar measures.', 'category': 'mitigation', 'product_ids': ['CSAFPID-31001', 'CSAFPID-31003', 'CSAFPID-51000']}, {'details': "Please visit the Pilz website (https://www.pilz.com/en-INT/search) and install the new version 'PASvisu 1.16.0' on to your device.", 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51000']}, {'details': "Please visit the Pilz website (https://www.pilz.com/en-INT/search) and install the new firmware image 'Firmware PMI v70Xe (visu 1.16.0) 04.00.00' on to your device.", 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31001']}, {'details': "Please visit the Pilz website (https://www.pilz.com/en-INT/search) and download 'Firmware PMI v8 Assistant (visu 1.16.0) 2.3.0' in order to install the new verison of the firmware on to your device.", 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31003']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32003', 'CSAFPID-52000'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31003', 'CSAFPID-51000']}}]}
966129cb2c0695038969058dc837ef3f97c9558e0dc8f9761a49dd6eb72e32ee
2026-05-29 08:30:36.474121+03:00
2026-05-29 08:30:36.474121+03:00
csaf_pilzgmbhcokg.ndjson
b6af4b87de12873de01ce5cecff70477f69c938019ca8721f0ba75c7ff16ea29
{'document': {'lang': 'en-GB', 'notes': [{'text': 'A number of Pilz software tools use the Software CodeMeter Runtime application from WIBU-SYSTEMS AG to manage licences. This application contains a number of vulnerabilities, which enable an attacker to change and falsify a licence file, prevent normal operation of Code- Meter (Denial-of-Service) and potentially execute arbitrary code.', 'title': 'Summary', 'category': 'summary'}, {'text': 'The stated Pilz products are supplied with the WIBU Software CodeMeter Runtime Software in Ver- sions lower than v6.90, which contain a number of vulnerabilities. One of the vulnerabilities enables further vulnerabilities to be exploited via the network.', 'title': 'Impact', 'category': 'description'}, {'text': "Use the current Version 7.10 of the Software CodeMeter Runtime, available via the manufacturer's website. https://www.wibu.com/de/support/anwendersoftware/anwendersoftware.html \nOnly use the Software CodeMeter Runtime as Client. The software tools named under affected products use the Software CodeMeter Runtime as Client in their default setting.\nPilz also recommends using a local firewall to limit unwanted access to the network ser- vices of the device with Software CodeMeter Runtime installed.", 'title': 'Remediation', 'category': 'description'}], 'title': 'Pilz: Multiple products prone to WIBU-SYSTEMS CodeMeter vulnerabilities', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2020-033', 'status': 'final', 'aliases': ['VDE-2020-033'], 'version': '3', 'generator': {'date': '2024-09-30T11:36:52.290Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.12'}}, 'revision_history': [{'date': '2020-09-10T13:18:00.000Z', 'number': '1', 'summary': 'Initial revision.'}, {'date': '2024-11-06T11:27:01.000Z', 'number': '2', 'summary': 'Fix: correct certvde domain, added self-reference'}, {'date': '2025-05-14T12:28:19.000Z', 'number': '3', 'summary': 'Fix: version space, removed ia, firmware category, added distribution'}], 'current_release_date': '2025-05-14T12:28:19.000Z', 'initial_release_date': '2020-09-10T13:18:00.000Z'}, 'publisher': {'name': 'Pilz GmbH & Co. KG', 'category': 'vendor', 'namespace': 'https://www.pilz.com', 'contact_details': 'security@pilz.com'}, 'references': [{'url': 'https://certvde.com/en/advisories/vendor/pilz', 'summary': 'CERT@VDE Security Advisories for Pilz GmbH & Co. KG', 'category': 'external'}, {'url': 'https://certvde.com/de/advisories/VDE-2020-033/', 'summary': 'VDE-2020-033: Pilz: Multiple products prone to WIBU-SYSTEMS CodeMeter vulnerabilities - HTML', 'category': 'self'}, {'url': 'https://pilz.csaf-tp.certvde.com/.well-known/csaf/white/2020/vde-2020-033.json', 'summary': 'VDE-2020-033: Pilz: Multiple products prone to WIBU-SYSTEMS CodeMeter vulnerabilities - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'names': ['Sharon Brizinov', 'Tal Keren'], 'summary': 'discovered and reported', 'organization': 'Claroty'}, {'summary': 'coordination', 'organization': 'CERT@VDE'}, {'summary': 'coordination', 'organization': 'CISA'}, {'summary': 'coordination', 'organization': 'BSI'}, {'organization': 'WIBU-Systems'}]}, 'product_tree': {'branches': [{'name': 'PILZ', 'branches': [{'name': 'Software', 'branches': [{'name': 'CODESYS DevSys', 'branches': [{'name': '<=V3 3.5.12', 'product': {'name': 'Software CODESYS DevSys <=V3 3.5.12', 'product_id': 'CSAFPID-51001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Live Video Server', 'branches': [{'name': '<=1.1.0', 'product': {'name': 'Software Live Video Server <=1.1.0', 'product_id': 'CSAFPID-51002'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'PAS4000', 'branches': [{'name': '<=1.21.1', 'product': {'name': 'Software PAS4000 <=1.21.1', 'product_id': 'CSAFPID-51003'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'PASloto', 'branches': [{'name': '<=1.1.3', 'product': {'name': 'Software PASloto <=1.1.3', 'product_id': 'CSAFPID-51004'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'PASvisu', 'branches': [{'name': '<=1.9.0', 'product': {'name': 'Software PASvisu <=1.9.0', 'product_id': 'CSAFPID-51005'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'PNOZsigma', 'branches': [{'name': '<=1.3.0', 'product': {'name': 'Software PNOZsigma <=1.3.0', 'product_id': 'CSAFPID-51006'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SafetyEYE', 'branches': [{'name': '3.0.0<=3.0.1', 'product': {'name': 'Software SafetyEYE 3.0.0<=3.0.1', 'product_id': 'CSAFPID-51007'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}, {'name': 'WIBU', 'branches': [{'name': 'Software', 'branches': [{'name': 'CodeMeter Runtime', 'branches': [{'name': '<6.90', 'product': {'name': 'Software CodeMeter Runtime <6.90', 'product_id': 'CSAFPID-51008'}, 'category': 'product_version_range'}, {'name': '7.10', 'product': {'name': 'Software CodeMeter Runtime 7.10', 'product_id': 'CSAFPID-52001'}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'external_component_of', 'full_product_name': {'name': 'Software CodeMeter Runtime <6.90 external component of Software CODESYS DevSys <=V3 3.5.12', 'product_id': 'CSAFPID-31001'}, 'product_reference': 'CSAFPID-51008', 'relates_to_product_reference': 'CSAFPID-51001'}, {'category': 'external_component_of', 'full_product_name': {'name': 'Software CodeMeter Runtime <6.90 external component of Software Live Video Server <=1.1.0', 'product_id': 'CSAFPID-31002'}, 'product_reference': 'CSAFPID-51008', 'relates_to_product_reference': 'CSAFPID-51002'}, {'category': 'external_component_of', 'full_product_name': {'name': 'Software CodeMeter Runtime <6.90 external component of Software PAS4000 <=1.21.1', 'product_id': 'CSAFPID-31003'}, 'product_reference': 'CSAFPID-51008', 'relates_to_product_reference': 'CSAFPID-51003'}, {'category': 'external_component_of', 'full_product_name': {'name': 'Software CodeMeter Runtime <6.90 external component of Software CodeMeter Runtime <6.90', 'product_id': 'CSAFPID-31004'}, 'product_reference': 'CSAFPID-51008', 'relates_to_product_reference': 'CSAFPID-51008'}, {'category': 'external_component_of', 'full_product_name': {'name': 'Software CodeMeter Runtime <6.90 external component of Software PASvisu <=1.9.0', 'product_id': 'CSAFPID-31005'}, 'product_reference': 'CSAFPID-51008', 'relates_to_product_reference': 'CSAFPID-51005'}, {'category': 'external_component_of', 'full_product_name': {'name': 'Software CodeMeter Runtime <6.90 external component of Software PNOZsigma <=1.3.0', 'product_id': 'CSAFPID-31006'}, 'product_reference': 'CSAFPID-51008', 'relates_to_product_reference': 'CSAFPID-51006'}, {'category': 'external_component_of', 'full_product_name': {'name': 'Software CodeMeter Runtime <6.90 external component of Software SafetyEYE 3.0.0<=3.0.1', 'product_id': 'CSAFPID-31007'}, 'product_reference': 'CSAFPID-51008', 'relates_to_product_reference': 'CSAFPID-51007'}, {'category': 'external_component_of', 'full_product_name': {'name': 'Software CodeMeter Runtime 7.10 external component of Software CODESYS DevSys <=V3 3.5.12', 'product_id': 'CSAFPID-32001'}, 'product_reference': 'CSAFPID-52001', 'relates_to_product_reference': 'CSAFPID-51001'}, {'category': 'external_component_of', 'full_product_name': {'name': 'Software CodeMeter Runtime 7.10 external component of Software Live Video Server <=1.1.0', 'product_id': 'CSAFPID-32002'}, 'product_reference': 'CSAFPID-52001', 'relates_to_product_reference': 'CSAFPID-51002'}, {'category': 'external_component_of', 'full_product_name': {'name': 'Software CodeMeter Runtime 7.10 external component of Software PAS4000 <=1.21.1', 'product_id': 'CSAFPID-32003'}, 'product_reference': 'CSAFPID-52001', 'relates_to_product_reference': 'CSAFPID-51003'}, {'category': 'external_component_of', 'full_product_name': {'name': 'Software CodeMeter Runtime 7.10 external component of Software PASloto <=1.1.3', 'product_id': 'CSAFPID-32004'}, 'product_reference': 'CSAFPID-52001', 'relates_to_product_reference': 'CSAFPID-51004'}, {'category': 'external_component_of', 'full_product_name': {'name': 'Software CodeMeter Runtime 7.10 external component of Software PASvisu <=1.9.0', 'product_id': 'CSAFPID-32005'}, 'product_reference': 'CSAFPID-52001', 'relates_to_product_reference': 'CSAFPID-51005'}, {'category': 'external_component_of', 'full_product_name': {'name': 'Software CodeMeter Runtime 7.10 external component of Software PNOZsigma <=1.3.0', 'product_id': 'CSAFPID-32006'}, 'product_reference': 'CSAFPID-52001', 'relates_to_product_reference': 'CSAFPID-51006'}, {'category': 'external_component_of', 'full_product_name': {'name': 'Software CodeMeter Runtime 7.10 external component of Software SafetyEYE 3.0.0<=3.0.1', 'product_id': 'CSAFPID-32007'}, 'product_reference': 'CSAFPID-52001', 'relates_to_product_reference': 'CSAFPID-51007'}], 'product_groups': [{'summary': 'Affected products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007']}, {'summary': 'Fixed products.', 'group_id': 'CSAFGID-0002', 'product_ids': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-32004', 'CSAFPID-32005', 'CSAFPID-32006', 'CSAFPID-32007']}]}, 'vulnerabilities': [{'cve': 'CVE-2020-12499', 'cwe': {'id': 'CWE-805', 'name': 'Buffer Access with Incorrect Length Value'}, 'notes': [{'text': 'Multiple memory corruption vulnerabilities exist in CodeMeter (All versions prior to 7.10) where the packet parser mechanism does not verify length fields. An attacker could send specially crafted packets to exploit these vulnerabilities.', 'title': 'Vulnerability Description', 'audience': 'all', 'category': 'description'}], 'title': 'CVE-2020-12499', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007']}], 'remediations': [{'details': "Use the current Version 7.10 of the Software CodeMeter Runtime, available via the manufacturer's website. https://www.wibu.com/de/support/anwendersoftware/anwendersoftware.html \nOnly use the Software CodeMeter Runtime as Client. The software tools named under affected products use the Software CodeMeter Runtime as Client in their default setting.\nPilz also recommends using a local firewall to limit unwanted access to the network ser- vices of the device with Software CodeMeter Runtime installed.", 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-32004', 'CSAFPID-32005', 'CSAFPID-32006', 'CSAFPID-32007'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007']}}, {'cve': 'CVE-2020-14517', 'cwe': {'id': 'CWE-326', 'name': 'Inadequate Encryption Strength'}, 'notes': [{'text': 'Protocol encryption can be easily broken for CodeMeter (All versions prior to 6.90 are affected, including Version 6.90 or newer only if Software CodeMeter Runtime is running as server) and the server accepts external connections, which may allow an attacker to remotely communicate with the CodeMeter API.', 'title': 'Vulnerability Description', 'audience': 'all', 'category': 'description'}], 'title': 'CVE-2020-14517', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007']}], 'remediations': [{'details': "Use the current Version 7.10 of the Software CodeMeter Runtime, available via the manufacturer's website. https://www.wibu.com/de/support/anwendersoftware/anwendersoftware.html \nOnly use the Software CodeMeter Runtime as Client. The software tools named under affected products use the Software CodeMeter Runtime as Client in their default setting.\nPilz also recommends using a local firewall to limit unwanted access to the network ser- vices of the device with Software CodeMeter Runtime installed.", 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-32004', 'CSAFPID-32005', 'CSAFPID-32006', 'CSAFPID-32007'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007']}}, {'cve': 'CVE-2020-16233', 'cwe': {'id': 'CWE-404', 'name': 'Improper Resource Shutdown or Release'}, 'notes': [{'text': 'An attacker could send a specially crafted packet that could have CodeMeter (All versions prior to 7.10) send back packets containing data from the heap.', 'title': 'Vulnerability Description', 'audience': 'all', 'category': 'description'}], 'title': 'CVE-2020-16233', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'NONE', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007']}], 'remediations': [{'details': "Use the current Version 7.10 of the Software CodeMeter Runtime, available via the manufacturer's website. https://www.wibu.com/de/support/anwendersoftware/anwendersoftware.html \nOnly use the Software CodeMeter Runtime as Client. The software tools named under affected products use the Software CodeMeter Runtime as Client in their default setting.\nPilz also recommends using a local firewall to limit unwanted access to the network ser- vices of the device with Software CodeMeter Runtime installed.", 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-32004', 'CSAFPID-32005', 'CSAFPID-32006', 'CSAFPID-32007'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007']}}, {'cve': 'CVE-2020-14519', 'cwe': {'id': 'CWE-346', 'name': 'Origin Validation Error'}, 'notes': [{'text': 'This vulnerability allows an attacker to use the internal WebSockets API for CodeMeter (All versions prior to 7.00 are affected, including Version 7.0 or newer with the affected WebSockets API still enabled. This is especially relevant for systems or devices where a web browser is used to access a web server) via a specifically crafted Java Script payload, which may allow alteration or creation of license files for when combined with CVE-2020-14515.', 'title': 'Vulnerability Description', 'audience': 'all', 'category': 'description'}], 'title': 'CVE-2020-14519', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N', 'temporalScore': 7.5, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'NONE', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007']}], 'remediations': [{'details': "Use the current Version 7.10 of the Software CodeMeter Runtime, available via the manufacturer's website. https://www.wibu.com/de/support/anwendersoftware/anwendersoftware.html \nOnly use the Software CodeMeter Runtime as Client. The software tools named under affected products use the Software CodeMeter Runtime as Client in their default setting.\nPilz also recommends using a local firewall to limit unwanted access to the network ser- vices of the device with Software CodeMeter Runtime installed.", 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-32004', 'CSAFPID-32005', 'CSAFPID-32006', 'CSAFPID-32007'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007']}}, {'cve': 'CVE-2020-14513', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'CodeMeter (All versions prior to 6.81) and the software using it may crash while processing a specifically crafted license file due to unverified length fields.', 'title': 'Vulnerability Description', 'audience': 'all', 'category': 'description'}], 'title': 'CVE-2020-14513', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007']}], 'remediations': [{'details': "Use the current Version 7.10 of the Software CodeMeter Runtime, available via the manufacturer's website. https://www.wibu.com/de/support/anwendersoftware/anwendersoftware.html \nOnly use the Software CodeMeter Runtime as Client. The software tools named under affected products use the Software CodeMeter Runtime as Client in their default setting.\nPilz also recommends using a local firewall to limit unwanted access to the network ser- vices of the device with Software CodeMeter Runtime installed.", 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-32004', 'CSAFPID-32005', 'CSAFPID-32006', 'CSAFPID-32007'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007']}}, {'cve': 'CVE-2020-14515', 'cwe': {'id': 'CWE-347', 'name': 'Improper Verification of Cryptographic Signature'}, 'notes': [{'text': 'Multiple memory corruption vulnerabilities exist in CodeMeter (All versions prior to 7.10) where the packet parser mechanism does not verify length fields. An attacker could send specially crafted packets to exploit these vulnerabilities.', 'title': 'Vulnerability Description', 'audience': 'all', 'category': 'description'}], 'title': 'CVE-2020-14515', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N', 'temporalScore': 7.5, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'NONE', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007']}], 'remediations': [{'details': "Use the current Version 7.10 of the Software CodeMeter Runtime, available via the manufacturer's website. https://www.wibu.com/de/support/anwendersoftware/anwendersoftware.html \nOnly use the Software CodeMeter Runtime as Client. The software tools named under affected products use the Software CodeMeter Runtime as Client in their default setting.\nPilz also recommends using a local firewall to limit unwanted access to the network ser- vices of the device with Software CodeMeter Runtime installed.", 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-32004', 'CSAFPID-32005', 'CSAFPID-32006', 'CSAFPID-32007'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007']}}]}
3a5ca1368259d13560a62211857120246ca328b3c68b179197b6dae9dfd89a18
2026-05-29 08:30:36.474121+03:00
2026-05-29 08:30:36.474121+03:00
csaf_pilzgmbhcokg.ndjson
e74550e174ec607e3880994c9c8763700b85463f37ee8b34877bf60c7b0d32ee
{'document': {'lang': 'en-US', 'notes': [{'text': 'Multiple products of PILZ utilise a third-party TCP/IP implementation - the "Niche Ethernet Stack". This TCP/IP stack contains multiple vulnerabilities which are therefore affecting the products listed above.', 'title': 'Summary', 'category': 'summary'}, {'text': 'It is adviced to use firewalls or similar network security devices to prevent unauthorized network communication to the products affected.', 'title': 'Mitigation', 'category': 'description'}, {'text': '| Produkt | Maßnahme |\n|----------------------------------------------|------------------------------------------------------|\n| PSSu-Module für dezentrales E/A-System | siehe Mitigation |\n| PSSu-Module für PSS 4000 | Firmware auf 1.22.2 aktualisieren * |\n| PNOZ m B1 | siehe Mitigation ** |\n| PNOZ m ES ETH | siehe Mitigation ** |\n| PNOZ mmc1p ETH | siehe Mitigation |\n| Base-Device PNOZ mxp ETH (PNOZmulti Classic) | siehe Mitigation |\n\n\\* CVE-2020-35685 wird in diesem Update nicht behoben, da es keine Auswirkungen auf die Sicherheit der verwendeten Dienste und Protokolle (MODBUS/TCP und RAW-TCP) hat.\n\n\\** Diese Produkte sind im Feld nicht updatefähig. Sie verwenden eine vom Hersteller vorinstallierte, feste Firmware.', 'title': 'Remediation', 'category': 'description'}, {'text': 'Die Schwachstellen ermöglichen einem entfernten Angreifer:\n\n- einen Neustart des Geräts auszulösen, was zu einer Denial-of-Service-Situation führt\n- eine TCP-Verbindung zu kapern\n\n### Betroffene Produkte und CVEs\n\n| Produkt | Betroffen von CVEs |\n|----------------------------------------------|--------------------|\n| PSSu-Module für dezentrales E/A-System | CVE-2020-35683, CVE-2020-35684, CVE-2020-35685, CVE-2021-31400, CVE-2021-31401 |\n| PSSu-Module für PSS 4000 | CVE-2020-35683, CVE-2020-35684, CVE-2020-35685, CVE-2021-31400, CVE-2021-31401 |\n| PNOZ m B1 | CVE-2020-35683, CVE-2020-35684, CVE-2020-35685 |\n| PNOZ m ES ETH | CVE-2020-35683, CVE-2020-35684, CVE-2020-35685 |\n| PNOZ mmc1p ETH | CVE-2020-35683, CVE-2020-35684, CVE-2020-35685 |\n| Base-Device PNOZ mxp ETH (PNOZmulti Classic) | CVE-2020-35683, CVE-2020-35684, CVE-2020-35685 |', 'title': 'Impact', 'category': 'description'}], 'title': 'Pilz: Multiple products prone to Niche Ethernet Stack vulnerabilities', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2021-009', 'status': 'final', 'aliases': ['VDE-2021-009'], 'version': '2', 'generator': {'date': '2025-03-05T11:49:30.977Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.20'}}, 'revision_history': [{'date': '2021-09-20T11:56:00.000Z', 'number': '1', 'summary': 'Initial revision.'}, {'date': '2025-05-14T13:00:14.000Z', 'number': '2', 'summary': 'Fix: added distribution'}], 'current_release_date': '2025-05-14T13:00:14.000Z', 'initial_release_date': '2021-09-20T11:56:00.000Z'}, 'publisher': {'name': 'Pilz GmbH & Co. KG', 'category': 'vendor', 'namespace': 'https://www.pilz.com', 'contact_details': 'security@pilz.com'}, 'references': [{'url': 'https://certvde.com/de/advisories/vendor/pilz/', 'summary': 'Pilz advisory overview at CERT@VDE', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vde-2021-009', 'summary': 'VDE-2021-009: Pilz: Multiple products prone to Niche Ethernet Stack vulnerabilities - HTML', 'category': 'self'}, {'url': 'https://pilz.csaf-tp.certvde.com/.well-known/csaf/white/2021/vde-2021-009.json', 'summary': 'VDE-2021-009: Pilz: Multiple products prone to Niche Ethernet Stack vulnerabilities - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}, {'summary': 'discovered and reported', 'organization': 'Forescout Technologies, Inc.'}]}, 'product_tree': {'branches': [{'name': 'Pilz', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'Base-Device PNOZ mxp ETH (PNOZmulti Classic)', 'product': {'name': 'Base-Device PNOZ mxp ETH (PNOZmulti Classic)', 'product_id': 'CSAFPID-11001', 'product_identification_helper': {'model_numbers': ['773103', '773104*', '773113', '773116', '773123', '7731260']}}, 'category': 'product_name'}, {'name': 'PNOZ m B1', 'product': {'name': 'PNOZ m B1', 'product_id': 'CSAFPID-11002', 'product_identification_helper': {'model_numbers': ['316020']}}, 'category': 'product_name'}, {'name': 'PNOZ m ES ETH', 'product': {'name': 'PNOZ m ES ETH', 'product_id': 'CSAFPID-11003', 'product_identification_helper': {'model_numbers': ['316020']}}, 'category': 'product_name'}, {'name': 'PNOZ mmc1p ETH', 'product': {'name': 'PNOZ mmc1p ETH', 'product_id': 'CSAFPID-11004', 'product_identification_helper': {'model_numbers': ['316020']}}, 'category': 'product_name'}, {'name': 'PSSu-Module for decentralised E/A-System', 'product': {'name': 'PSSu-Module for decentralised E/A-System', 'product_id': 'CSAFPID-11005', 'product_identification_helper': {'model_numbers': ['312041', '312042', '312043']}}, 'category': 'product_name'}, {'name': 'PSSu-Module for PSS 4000', 'product': {'name': 'PSSu-Module for PSS 4000', 'product_id': 'CSAFPID-11006', 'product_identification_helper': {'model_numbers': ['31206*', '312070*', '312071*', '312077', '312085*', '312087', '31407*', '314085', '314086', '314087', '315070*', '315071*', '315085', '315086', '316010', '316020']}}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': '<1.22.2', 'product': {'name': 'Firmware <1.22.2', 'product_id': 'CSAFPID-21001'}, 'category': 'product_version_range'}, {'name': '<v1.2', 'product': {'name': 'Firmware <v1.2', 'product_id': 'CSAFPID-21002'}, 'category': 'product_version_range'}, {'name': '<v1.8', 'product': {'name': 'Firmware <v1.8', 'product_id': 'CSAFPID-21003'}, 'category': 'product_version_range'}, {'name': 'vers:all/*', 'product': {'name': 'Firmware vers:all/*', 'product_id': 'CSAFPID-21004'}, 'category': 'product_version_range'}, {'name': '1.22.2', 'product': {'name': 'Firmware 1.22.2', 'product_id': 'CSAFPID-22001'}, 'category': 'product_version'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware vers:all/* installed on Base-Device PNOZ mxp ETH (PNOZmulti Classic)', 'product_id': 'CSAFPID-31001'}, 'product_reference': 'CSAFPID-21004', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <v1.8 installed on PNOZ m B1', 'product_id': 'CSAFPID-31002'}, 'product_reference': 'CSAFPID-21003', 'relates_to_product_reference': 'CSAFPID-11002'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <v1.2 installed on PNOZ m ES ETH', 'product_id': 'CSAFPID-31003'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11003'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware vers:all/* installed on PNOZ mmc1p ETH', 'product_id': 'CSAFPID-31004'}, 'product_reference': 'CSAFPID-21004', 'relates_to_product_reference': 'CSAFPID-11004'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware vers:all/* installed on PSSu-Module for decentralised E/A-System', 'product_id': 'CSAFPID-31005'}, 'product_reference': 'CSAFPID-21004', 'relates_to_product_reference': 'CSAFPID-11005'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 1.22.2 installed on PSSu-Module for PSS 4000', 'product_id': 'CSAFPID-31006'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11006'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 1.22.2 installed on PSSu-Module for PSS 4000 installed on PSSu-Module for PSS 4000', 'product_id': 'CSAFPID-32001'}, 'product_reference': 'CSAFPID-31006', 'relates_to_product_reference': 'CSAFPID-11006'}], 'product_groups': [{'summary': 'Affected Products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006']}]}, 'vulnerabilities': [{'cve': 'CVE-2020-35685', 'cwe': {'id': 'CWE-330', 'name': 'Use of Insufficiently Random Values'}, 'notes': [{'text': 'An issue was discovered in HCC Nichestack 3.0. The code that generates Initial Sequence Numbers (ISNs) for TCP connections derives the ISN from an insufficiently random source. As a result, an attacker may be able to determine the ISN of current and future TCP connections and either hijack existing ones or spoof future ones. (Proper ISN generation should aim to follow at least the specifications outlined in RFC 6528.)', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2021-31401', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.1, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N', 'temporalScore': 9.1, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'NONE', 'environmentalScore': 9.1, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006']}], 'remediations': [{'details': 'It is adviced to use firewalls or similar network security devices to prevent unauthorized network communication to the products affected.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': '| Produkt | Maßnahme |\n|----------------------------------------------|------------------------------------------------------|\n| PSSu-Module für dezentrales E/A-System | siehe Mitigation |\n| PSSu-Module für PSS 4000 | Firmware auf 1.22.2 aktualisieren * |\n| PNOZ m B1 | siehe Mitigation ** |\n| PNOZ m ES ETH | siehe Mitigation ** |\n| PNOZ mmc1p ETH | siehe Mitigation |\n| Base-Device PNOZ mxp ETH (PNOZmulti Classic) | siehe Mitigation |\n\n\\* CVE-2020-35685 wird in diesem Update nicht behoben, da es keine Auswirkungen auf die Sicherheit der verwendeten Dienste und Protokolle (MODBUS/TCP und RAW-TCP) hat.\n\n\\** Diese Produkte sind im Feld nicht updatefähig. Sie verwenden eine vom Hersteller vorinstallierte, feste Firmware.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006']}}, {'cve': 'CVE-2021-31401', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': "An issue was discovered in tcp_rcv() in nptcp.c in HCC embedded InterNiche 4.0.1. The TCP header processing code doesn't sanitize the value of the IP total length field (header length + data length). With a crafted IP packet, an integer overflow occurs whenever the value of the IP data length is calculated by subtracting the length of the header from the total length of the IP packet.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2021-31401', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006']}], 'remediations': [{'details': 'It is adviced to use firewalls or similar network security devices to prevent unauthorized network communication to the products affected.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': '| Produkt | Maßnahme |\n|----------------------------------------------|------------------------------------------------------|\n| PSSu-Module für dezentrales E/A-System | siehe Mitigation |\n| PSSu-Module für PSS 4000 | Firmware auf 1.22.2 aktualisieren * |\n| PNOZ m B1 | siehe Mitigation ** |\n| PNOZ m ES ETH | siehe Mitigation ** |\n| PNOZ mmc1p ETH | siehe Mitigation |\n| Base-Device PNOZ mxp ETH (PNOZmulti Classic) | siehe Mitigation |\n\n\\* CVE-2020-35685 wird in diesem Update nicht behoben, da es keine Auswirkungen auf die Sicherheit der verwendeten Dienste und Protokolle (MODBUS/TCP und RAW-TCP) hat.\n\n\\** Diese Produkte sind im Feld nicht updatefähig. Sie verwenden eine vom Hersteller vorinstallierte, feste Firmware.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006']}}, {'cve': 'CVE-2021-31400', 'cwe': {'id': 'CWE-835', 'name': "Loop with Unreachable Exit Condition ('Infinite Loop')"}, 'notes': [{'text': "An issue was discovered in tcp_pulloutofband() in tcp_in.c in HCC embedded InterNiche 4.0.1. The TCP out-of-band urgent-data processing function invokes a panic function if the pointer to the end of the out-of-band data points outside of the TCP segment's data. If the panic function hadn't a trap invocation removed, it will enter an infinite loop and therefore cause DoS (continuous loop or a device reset).", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2021-31400', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006']}], 'remediations': [{'details': 'It is adviced to use firewalls or similar network security devices to prevent unauthorized network communication to the products affected.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': '| Produkt | Maßnahme |\n|----------------------------------------------|------------------------------------------------------|\n| PSSu-Module für dezentrales E/A-System | siehe Mitigation |\n| PSSu-Module für PSS 4000 | Firmware auf 1.22.2 aktualisieren * |\n| PNOZ m B1 | siehe Mitigation ** |\n| PNOZ m ES ETH | siehe Mitigation ** |\n| PNOZ mmc1p ETH | siehe Mitigation |\n| Base-Device PNOZ mxp ETH (PNOZmulti Classic) | siehe Mitigation |\n\n\\* CVE-2020-35685 wird in diesem Update nicht behoben, da es keine Auswirkungen auf die Sicherheit der verwendeten Dienste und Protokolle (MODBUS/TCP und RAW-TCP) hat.\n\n\\** Diese Produkte sind im Feld nicht updatefähig. Sie verwenden eine vom Hersteller vorinstallierte, feste Firmware.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006']}}, {'cve': 'CVE-2020-35684', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'An issue was discovered in HCC Nichestack 3.0. The code that parses TCP packets relies on an unchecked value of the IP payload size (extracted from the IP header) to compute the length of the TCP payload within the TCP checksum computation function. When the IP payload size is set to be smaller than the size of the IP header, the TCP checksum computation function may read out of bounds (a low-impact write-out-of-bounds is also possible).', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2020-35684', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006']}], 'remediations': [{'details': 'It is adviced to use firewalls or similar network security devices to prevent unauthorized network communication to the products affected.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': '| Produkt | Maßnahme |\n|----------------------------------------------|------------------------------------------------------|\n| PSSu-Module für dezentrales E/A-System | siehe Mitigation |\n| PSSu-Module für PSS 4000 | Firmware auf 1.22.2 aktualisieren * |\n| PNOZ m B1 | siehe Mitigation ** |\n| PNOZ m ES ETH | siehe Mitigation ** |\n| PNOZ mmc1p ETH | siehe Mitigation |\n| Base-Device PNOZ mxp ETH (PNOZmulti Classic) | siehe Mitigation |\n\n\\* CVE-2020-35685 wird in diesem Update nicht behoben, da es keine Auswirkungen auf die Sicherheit der verwendeten Dienste und Protokolle (MODBUS/TCP und RAW-TCP) hat.\n\n\\** Diese Produkte sind im Feld nicht updatefähig. Sie verwenden eine vom Hersteller vorinstallierte, feste Firmware.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006']}}, {'cve': 'CVE-2020-35683', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'An issue was discovered in HCC Nichestack 3.0. The code that parses ICMP packets relies on an unchecked value of the IP payload size (extracted from the IP header) to compute the ICMP checksum. When the IP payload size is set to be smaller than the size of the IP header, the ICMP checksum computation function may read out of bounds, causing a Denial-of-Service.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2020-35683', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006']}], 'remediations': [{'details': 'It is adviced to use firewalls or similar network security devices to prevent unauthorized network communication to the products affected.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': '| Produkt | Maßnahme |\n|----------------------------------------------|------------------------------------------------------|\n| PSSu-Module für dezentrales E/A-System | siehe Mitigation |\n| PSSu-Module für PSS 4000 | Firmware auf 1.22.2 aktualisieren * |\n| PNOZ m B1 | siehe Mitigation ** |\n| PNOZ m ES ETH | siehe Mitigation ** |\n| PNOZ mmc1p ETH | siehe Mitigation |\n| Base-Device PNOZ mxp ETH (PNOZmulti Classic) | siehe Mitigation |\n\n\\* CVE-2020-35685 wird in diesem Update nicht behoben, da es keine Auswirkungen auf die Sicherheit der verwendeten Dienste und Protokolle (MODBUS/TCP und RAW-TCP) hat.\n\n\\** Diese Produkte sind im Feld nicht updatefähig. Sie verwenden eine vom Hersteller vorinstallierte, feste Firmware.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006']}}]}
d9fa6d57a43da0314fa5ffb6ce9ee71a43fd85b65ea7876e88598a49d1ad8a0c
2026-05-29 08:30:36.474121+03:00
2026-05-29 08:30:36.474121+03:00
csaf_pilzgmbhcokg.ndjson
f6add494350e57a5c8e86f072956f2aeb52ca8bd3a38840443bb4c36c616f166
{'document': {'lang': 'en-GB', 'notes': [{'text': 'Several Pilz products use Versions V2 and V3 of the CODESYS runtime system from CODESYS GmbH, which enables the execution of IEC 61131-3 PLC programs. These runtime environments contain several vulnerabilities, which an attacker can exploit via the network. Successful exploitation of the vulnerabilities results in reduced availability and, in a worst case, to the insertion of program code.', 'title': 'Summary', 'category': 'summary'}, {'text': 'The affected products use the CODESYS runtime environment from CODESYS GmbH. Either Version V2 or V3 is active, depending on the configuration. V3 is activated upon delivery. These runtime environments contain the listed vulnerabilities. Some of the vulnerabilities only affect either version V2 or V3 of the CODESYS runtime environment.', 'title': 'Impact', 'category': 'description'}, {'text': 'Use a firewall or comparable measures at network level to protect the devices from unauthorised network communication.\nEmploy user management to restrict online access to authorised persons.', 'title': 'General countermeasures', 'category': 'general'}, {'text': 'PMI 6 primo, PMCprimo C: No product-specific countermeasures available, please follow the general countermeasures.\n\n• PMCprimo C2, PMCprimo MC: \n\nInstallation of Firmware Version 03.08.00 This update does not resolve the vulnerabilities (CVE-2021-34595, CVE-2021-34596, CVE-2021-34593, CVE-2021-30186, CVE-2021-30188, CVE-2021-30195, CVE-2019-19789) in the CODESYS V2 runtime system. \n\nThe V2 runtime system is still included for compatibility reasons but is no longer supported by Pilz. Please migrate your application to the V3 runtime system or follow the general countermeasures.', 'title': 'Remediation', 'category': 'general'}], 'title': 'Pilz: Multiple vulnerabilities in CODESYS V2 and V3 runtime system', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2021-054', 'status': 'final', 'aliases': ['VDE-2021-054'], 'version': '1', 'generator': {'date': '2025-05-14T13:21:16.214Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.25'}}, 'revision_history': [{'date': '2022-04-26T10:00:00.000Z', 'number': '1', 'summary': 'Initial revision.'}], 'current_release_date': '2022-04-26T10:00:00.000Z', 'initial_release_date': '2022-04-26T10:00:00.000Z'}, 'publisher': {'name': 'Pilz GmbH & Co. KG', 'category': 'vendor', 'namespace': 'https://www.pilz.com', 'contact_details': 'security@pilz.com'}, 'references': [{'url': 'https://certvde.com/en/advisories/VDE-2021-054/', 'summary': 'VDE-2021-054: Pilz: Multiple vulnerabilities in CODESYS V2 and V3 runtime system - HTML', 'category': 'self'}, {'url': 'https://pilz.csaf-tp.certvde.com/.well-known/csaf/white/2022/vde-2021-054.json', 'summary': 'VDE-2021-054: Pilz: Multiple vulnerabilities in CODESYS V2 and V3 runtime system - CSAF', 'category': 'self'}, {'url': 'https://www.pilz.com', 'summary': 'Vendor PSIRT', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/pilz/', 'summary': 'CERT@VDE Security Advisories for Pilz GmbH & Co. KG', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}]}, 'product_tree': {'branches': [{'name': 'Pilz', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'Motion controller PMCprimo C', 'product': {'name': 'Motion controller PMCprimo C', 'product_id': 'CSAFPID-11001', 'product_identification_helper': {'model_numbers': ['680175', '680052', '680053', '680054', '680055', '680062', '680063', '680064', '680065', '680162', '680163', '680164', '680165', '680172', '680173', '680174']}}, 'category': 'product_name'}, {'name': 'Motion controller PMCprimo C2.0 (plug-in card)', 'product': {'name': 'Motion controller PMCprimo C2.0 (plug-in card)', 'product_id': 'CSAFPID-11002', 'product_identification_helper': {'model_numbers': ['680182', '680183', '680184', '680185']}}, 'category': 'product_name'}, {'name': 'Motion controller PMCprimo C2.1 (housing version)', 'product': {'name': 'Motion controller PMCprimo C2.1 (housing version)', 'product_id': 'CSAFPID-11003', 'product_identification_helper': {'model_numbers': ['680192', '680193', '680194', '680195']}}, 'category': 'product_name'}, {'name': 'Motion controller PMCprimo MC', 'product': {'name': 'Motion controller PMCprimo MC', 'product_id': 'CSAFPID-11004', 'product_identification_helper': {'model_numbers': ['680082', '680083', '680084', '680085']}}, 'category': 'product_name'}, {'name': 'Operator terminal/controller PMI 6 primo', 'product': {'name': 'Operator terminal/controller PMI 6 primo', 'product_id': 'CSAFPID-11005', 'product_identification_helper': {'model_numbers': ['265608', '265613', '264639']}}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'Firmware vers:all/*', 'product_id': 'CSAFPID-21001'}, 'category': 'product_version_range'}, {'name': '<=03.07.00', 'product': {'name': 'Firmware <=03.07.00', 'product_id': 'CSAFPID-21002'}, 'category': 'product_version_range'}, {'name': '03.08.00', 'product': {'name': 'Firmware 03.08.00', 'product_id': 'CSAFPID-22001'}, 'category': 'product_version'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware vers:all/* installed on Motion controller PMCprimo C', 'product_id': 'CSAFPID-31001'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=03.07.00 installed on Motion controller PMCprimo C2.0 (plug-in card)', 'product_id': 'CSAFPID-31002'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11002'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=03.07.00 installed on Motion controller PMCprimo C2.1 (housing version)', 'product_id': 'CSAFPID-31003'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11003'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=03.07.00 installed on Motion controller PMCprimo MC', 'product_id': 'CSAFPID-31004'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11004'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware vers:all/* installed on Operator terminal/controller PMI 6 primo', 'product_id': 'CSAFPID-31005'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11005'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 03.08.00 installed on Motion controller PMCprimo C2.0 (plug-in card)', 'product_id': 'CSAFPID-32001'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11002'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 03.08.00 installed on Motion controller PMCprimo C2.1 (housing version)', 'product_id': 'CSAFPID-32002'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11003'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 03.08.00 installed on Motion controller PMCprimo MC', 'product_id': 'CSAFPID-32003'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11004'}], 'product_groups': [{'summary': 'Affected products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}, {'summary': 'Fixed products.', 'group_id': 'CSAFGID-0002', 'product_ids': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003']}]}, 'vulnerabilities': [{'cve': 'CVE-2021-36764', 'cwe': {'id': 'CWE-476', 'name': 'NULL Pointer Dereference'}, 'notes': [{'text': 'In CODESYS Gateway V3 before 3.5.17.10, there is a NULL Pointer Dereference. Crafted communication requests may cause a Null pointer dereference in the affected CODESYS products and may result in a denial-of-service condition.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2021-36764', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}], 'remediations': [{'details': 'PMI 6 primo, PMCprimo C: No product-specific countermeasures available, please follow the general countermeasures.\n\n• PMCprimo C2, PMCprimo MC: \n\nInstallation of Firmware Version 03.08.00 This update does not resolve the vulnerabilities (CVE-2021-34595, CVE-2021-34596, CVE-2021-34593, CVE-2021-30186, CVE-2021-30188, CVE-2021-30195, CVE-2019-19789) in the CODESYS V2 runtime system. \n\nThe V2 runtime system is still included for compatibility reasons but is no longer supported by Pilz. Please migrate your application to the V3 runtime system or follow the general countermeasures.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}}, {'cve': 'CVE-2021-34596', 'cwe': {'id': 'CWE-824', 'name': 'Access of Uninitialized Pointer'}, 'notes': [{'text': 'A crafted request may cause a read access to an uninitialized pointer in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2021-34596', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 6.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'HIGH', 'environmentalScore': 6.5, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}], 'remediations': [{'details': 'PMI 6 primo, PMCprimo C: No product-specific countermeasures available, please follow the general countermeasures.\n\n• PMCprimo C2, PMCprimo MC: \n\nInstallation of Firmware Version 03.08.00 This update does not resolve the vulnerabilities (CVE-2021-34595, CVE-2021-34596, CVE-2021-34593, CVE-2021-30186, CVE-2021-30188, CVE-2021-30195, CVE-2019-19789) in the CODESYS V2 runtime system. \n\nThe V2 runtime system is still included for compatibility reasons but is no longer supported by Pilz. Please migrate your application to the V3 runtime system or follow the general countermeasures.', 'category': 'none_available', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}}, {'cve': 'CVE-2021-34595', 'cwe': {'id': 'CWE-119', 'name': 'Improper Restriction of Operations within the Bounds of a Memory Buffer'}, 'notes': [{'text': 'A crafted request with invalid offsets may cause an out-of-bounds read or write access in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition or local memory overwrite.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2021-34595', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.1, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H', 'temporalScore': 8.1, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 8.1, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}], 'remediations': [{'details': 'PMI 6 primo, PMCprimo C: No product-specific countermeasures available, please follow the general countermeasures.\n\n• PMCprimo C2, PMCprimo MC: \n\nInstallation of Firmware Version 03.08.00 This update does not resolve the vulnerabilities (CVE-2021-34595, CVE-2021-34596, CVE-2021-34593, CVE-2021-30186, CVE-2021-30188, CVE-2021-30195, CVE-2019-19789) in the CODESYS V2 runtime system. \n\nThe V2 runtime system is still included for compatibility reasons but is no longer supported by Pilz. Please migrate your application to the V3 runtime system or follow the general countermeasures.', 'category': 'none_available', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}}, {'cve': 'CVE-2021-34593', 'cwe': {'id': 'CWE-755', 'name': 'Improper Handling of Exceptional Conditions'}, 'notes': [{'text': 'In CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56 unauthenticated crafted invalid requests may result in several denial-of-service conditions. Running PLC programs may be stopped, memory may be leaked, or further communication clients may be blocked from accessing the PLC.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2021-34593', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}], 'remediations': [{'details': 'PMI 6 primo, PMCprimo C: No product-specific countermeasures available, please follow the general countermeasures.\n\n• PMCprimo C2, PMCprimo MC: \n\nInstallation of Firmware Version 03.08.00 This update does not resolve the vulnerabilities (CVE-2021-34595, CVE-2021-34596, CVE-2021-34593, CVE-2021-30186, CVE-2021-30188, CVE-2021-30195, CVE-2019-19789) in the CODESYS V2 runtime system. \n\nThe V2 runtime system is still included for compatibility reasons but is no longer supported by Pilz. Please migrate your application to the V3 runtime system or follow the general countermeasures.', 'category': 'none_available', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}}, {'cve': 'CVE-2021-30195', 'cwe': {'id': 'CWE-125', 'name': 'Out-of-bounds Read'}, 'notes': [{'text': 'CODESYS V2 runtime system before 2.4.7.55 has Improper Input Validation.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2021-30195', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}], 'remediations': [{'details': 'PMI 6 primo, PMCprimo C: No product-specific countermeasures available, please follow the general countermeasures.\n\n• PMCprimo C2, PMCprimo MC: \n\nInstallation of Firmware Version 03.08.00 This update does not resolve the vulnerabilities (CVE-2021-34595, CVE-2021-34596, CVE-2021-34593, CVE-2021-30186, CVE-2021-30188, CVE-2021-30195, CVE-2019-19789) in the CODESYS V2 runtime system. \n\nThe V2 runtime system is still included for compatibility reasons but is no longer supported by Pilz. Please migrate your application to the V3 runtime system or follow the general countermeasures.', 'category': 'none_available', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}}, {'cve': 'CVE-2021-30188', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'CODESYS V2 runtime system SP before 2.4.7.55 has a Stack-based Buffer Overflow.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2021-30188', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}], 'remediations': [{'details': 'PMI 6 primo, PMCprimo C: No product-specific countermeasures available, please follow the general countermeasures.\n\n• PMCprimo C2, PMCprimo MC: \n\nInstallation of Firmware Version 03.08.00 This update does not resolve the vulnerabilities (CVE-2021-34595, CVE-2021-34596, CVE-2021-34593, CVE-2021-30186, CVE-2021-30188, CVE-2021-30195, CVE-2019-19789) in the CODESYS V2 runtime system. \n\nThe V2 runtime system is still included for compatibility reasons but is no longer supported by Pilz. Please migrate your application to the V3 runtime system or follow the general countermeasures.', 'category': 'none_available', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}}, {'cve': 'CVE-2021-29242', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': "CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's addressing scheme and may re-route, add, remove or change low level communication packages.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2021-29242', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.3, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L', 'temporalScore': 7.3, 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'LOW', 'environmentalScore': 7.3, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}], 'remediations': [{'details': 'PMI 6 primo, PMCprimo C: No product-specific countermeasures available, please follow the general countermeasures.\n\n• PMCprimo C2, PMCprimo MC: \n\nInstallation of Firmware Version 03.08.00 This update does not resolve the vulnerabilities (CVE-2021-34595, CVE-2021-34596, CVE-2021-34593, CVE-2021-30186, CVE-2021-30188, CVE-2021-30195, CVE-2019-19789) in the CODESYS V2 runtime system. \n\nThe V2 runtime system is still included for compatibility reasons but is no longer supported by Pilz. Please migrate your application to the V3 runtime system or follow the general countermeasures.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}}, {'cve': 'CVE-2021-29241', 'cwe': {'id': 'CWE-476', 'name': 'NULL Pointer Dereference'}, 'notes': [{'text': 'CODESYS Gateway 3 before 3.5.16.70 has a NULL pointer dereference that may result in a denial of service (DoS).', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2021-29241', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}], 'remediations': [{'details': 'PMI 6 primo, PMCprimo C: No product-specific countermeasures available, please follow the general countermeasures.\n\n• PMCprimo C2, PMCprimo MC: \n\nInstallation of Firmware Version 03.08.00 This update does not resolve the vulnerabilities (CVE-2021-34595, CVE-2021-34596, CVE-2021-34593, CVE-2021-30186, CVE-2021-30188, CVE-2021-30195, CVE-2019-19789) in the CODESYS V2 runtime system. \n\nThe V2 runtime system is still included for compatibility reasons but is no longer supported by Pilz. Please migrate your application to the V3 runtime system or follow the general countermeasures.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}}, {'cve': 'CVE-2020-7052', 'cwe': {'id': 'CWE-770', 'name': 'Allocation of Resources Without Limits or Throttling'}, 'notes': [{'text': 'CODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30 allow uncontrolled memory allocation which can result in a remote denial of service condition.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2020-7052', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 6.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'HIGH', 'environmentalScore': 6.5, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}], 'remediations': [{'details': 'PMI 6 primo, PMCprimo C: No product-specific countermeasures available, please follow the general countermeasures.\n\n• PMCprimo C2, PMCprimo MC: \n\nInstallation of Firmware Version 03.08.00 This update does not resolve the vulnerabilities (CVE-2021-34595, CVE-2021-34596, CVE-2021-34593, CVE-2021-30186, CVE-2021-30188, CVE-2021-30195, CVE-2019-19789) in the CODESYS V2 runtime system. \n\nThe V2 runtime system is still included for compatibility reasons but is no longer supported by Pilz. Please migrate your application to the V3 runtime system or follow the general countermeasures.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}}, {'cve': 'CVE-2020-6081', 'cwe': {'id': 'CWE-345', 'name': 'Insufficient Verification of Data Authenticity'}, 'notes': [{'text': 'An exploitable code execution vulnerability exists in the PLC_Task functionality of 3S-Smart Software Solutions GmbH CODESYS Runtime 3.5.14.30. A specially crafted network request can cause remote code execution. An attacker can send a malicious packet to trigger this vulnerability.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2020-6081', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 8.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 8.8, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}], 'remediations': [{'details': 'PMI 6 primo, PMCprimo C: No product-specific countermeasures available, please follow the general countermeasures.\n\n• PMCprimo C2, PMCprimo MC: \n\nInstallation of Firmware Version 03.08.00 This update does not resolve the vulnerabilities (CVE-2021-34595, CVE-2021-34596, CVE-2021-34593, CVE-2021-30186, CVE-2021-30188, CVE-2021-30195, CVE-2019-19789) in the CODESYS V2 runtime system. \n\nThe V2 runtime system is still included for compatibility reasons but is no longer supported by Pilz. Please migrate your application to the V3 runtime system or follow the general countermeasures.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}}, {'cve': 'CVE-2020-12069', 'cwe': {'id': 'CWE-916', 'name': 'Use of Password Hash With Insufficient Computational Effort'}, 'notes': [{'text': 'In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords using a weak hashing algorithm. This can be used by a local attacker with low privileges to gain full control of the device.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2020-12069', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 7.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.8, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}], 'remediations': [{'details': 'PMI 6 primo, PMCprimo C: No product-specific countermeasures available, please follow the general countermeasures.\n\n• PMCprimo C2, PMCprimo MC: \n\nInstallation of Firmware Version 03.08.00 This update does not resolve the vulnerabilities (CVE-2021-34595, CVE-2021-34596, CVE-2021-34593, CVE-2021-30186, CVE-2021-30188, CVE-2021-30195, CVE-2019-19789) in the CODESYS V2 runtime system. \n\nThe V2 runtime system is still included for compatibility reasons but is no longer supported by Pilz. Please migrate your application to the V3 runtime system or follow the general countermeasures.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}}, {'cve': 'CVE-2020-12067', 'cwe': {'id': 'CWE-640', 'name': 'Weak Password Recovery Mechanism for Forgotten Password'}, 'notes': [{'text': "In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), a user's password may be changed by an attacker without knowledge of the current password.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2020-12067', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N', 'temporalScore': 7.5, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'NONE', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}], 'remediations': [{'details': 'PMI 6 primo, PMCprimo C: No product-specific countermeasures available, please follow the general countermeasures.\n\n• PMCprimo C2, PMCprimo MC: \n\nInstallation of Firmware Version 03.08.00 This update does not resolve the vulnerabilities (CVE-2021-34595, CVE-2021-34596, CVE-2021-34593, CVE-2021-30186, CVE-2021-30188, CVE-2021-30195, CVE-2019-19789) in the CODESYS V2 runtime system. \n\nThe V2 runtime system is still included for compatibility reasons but is no longer supported by Pilz. Please migrate your application to the V3 runtime system or follow the general countermeasures.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}}, {'cve': 'CVE-2019-9013', 'cwe': {'id': 'CWE-327', 'name': 'Use of a Broken or Risky Cryptographic Algorithm'}, 'notes': [{'text': 'An issue was discovered in 3S-Smart CODESYS V3 products. The application may utilize non-TLS based encryption, which results in user credentials being insufficiently protected during transport. All variants of the following CODESYS V3 products in all versions containing the CmpUserMgr component are affected regardless of the CPU type or operating system: CODESYS Control for BeagleBone, CODESYS Control for emPC-A/iMX6, CODESYS Control for IOT2000, CODESYS Control for Linux, CODESYS Control for PFC100, CODESYS Control for PFC200, CODESYS Control for Raspberry Pi, CODESYS Control RTE V3, CODESYS Control RTE V3 (for Beckhoff CX), CODESYS Control Win V3 (also part of the CODESYS Development System setup), CODESYS V3 Simulation Runtime (part of the CODESYS Development System), CODESYS Control V3 Runtime System Toolkit, CODESYS HMI V3.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2019-9013', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'ADJACENT_NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 8.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 8.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}], 'remediations': [{'details': 'PMI 6 primo, PMCprimo C: No product-specific countermeasures available, please follow the general countermeasures.\n\n• PMCprimo C2, PMCprimo MC: \n\nInstallation of Firmware Version 03.08.00 This update does not resolve the vulnerabilities (CVE-2021-34595, CVE-2021-34596, CVE-2021-34593, CVE-2021-30186, CVE-2021-30188, CVE-2021-30195, CVE-2019-19789) in the CODESYS V2 runtime system. \n\nThe V2 runtime system is still included for compatibility reasons but is no longer supported by Pilz. Please migrate your application to the V3 runtime system or follow the general countermeasures.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}}, {'cve': 'CVE-2019-9011', 'cwe': {'id': 'CWE-668', 'name': 'Exposure of Resource to Wrong Sphere'}, 'notes': [{'text': 'In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), an attacker can identify valid usernames.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2019-9011', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N', 'temporalScore': 5.3, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 5.3, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}], 'remediations': [{'details': 'PMI 6 primo, PMCprimo C: No product-specific countermeasures available, please follow the general countermeasures.\n\n• PMCprimo C2, PMCprimo MC: \n\nInstallation of Firmware Version 03.08.00 This update does not resolve the vulnerabilities (CVE-2021-34595, CVE-2021-34596, CVE-2021-34593, CVE-2021-30186, CVE-2021-30188, CVE-2021-30195, CVE-2019-19789) in the CODESYS V2 runtime system. \n\nThe V2 runtime system is still included for compatibility reasons but is no longer supported by Pilz. Please migrate your application to the V3 runtime system or follow the general countermeasures.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}}, {'cve': 'CVE-2019-9009', 'cwe': {'id': 'CWE-755', 'name': 'Improper Handling of Exceptional Conditions'}, 'notes': [{'text': 'An issue was discovered in 3S-Smart CODESYS before 3.5.15.0 . Crafted network packets cause the Control Runtime to crash.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2019-9009', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}], 'remediations': [{'details': 'PMI 6 primo, PMCprimo C: No product-specific countermeasures available, please follow the general countermeasures.\n\n• PMCprimo C2, PMCprimo MC: \n\nInstallation of Firmware Version 03.08.00 This update does not resolve the vulnerabilities (CVE-2021-34595, CVE-2021-34596, CVE-2021-34593, CVE-2021-30186, CVE-2021-30188, CVE-2021-30195, CVE-2019-19789) in the CODESYS V2 runtime system. \n\nThe V2 runtime system is still included for compatibility reasons but is no longer supported by Pilz. Please migrate your application to the V3 runtime system or follow the general countermeasures.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}}, {'cve': 'CVE-2019-5105', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'An exploitable memory corruption vulnerability exists in the Name Service Client functionality of 3S-Smart Software Solutions CODESYS GatewayService. A specially crafted packet can cause a large memcpy, resulting in an access violation and termination of the process. An attacker can send a packet to a device running the GatewayService.exe to trigger this vulnerability. All variants of the CODESYS V3 products in all versions prior V3.5.16.10 containing the CmpRouter or CmpRouterEmbedded component are affected, regardless of the CPU type or operating system: CODESYS Control for BeagleBone, CODESYS Control for emPC-A/iMX6, CODESYS Control for IOT2000, CODESYS Control for Linux, CODESYS Control for PLCnext, CODESYS Control for PFC100, CODESYS Control for PFC200, CODESYS Control for Raspberry Pi, CODESYS Control RTE V3, CODESYS Control RTE V3 (for Beckhoff CX), CODESYS Control Win V3 (also part of the CODESYS Development System setup), CODESYS Control V3 Runtime System Toolkit, CODESYS V3 Embedded Target Visu Toolkit, CODESYS V3 Remote Target Visu Toolkit, CODESYS V3 Safety SIL2, CODESYS Edge Gateway V3, CODESYS Gateway V3, CODESYS HMI V3, CODESYS OPC Server V3, CODESYS PLCHandler SDK, CODESYS V3 Simulation Runtime (part of the CODESYS Development System).', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2019-5105', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}], 'remediations': [{'details': 'PMI 6 primo, PMCprimo C: No product-specific countermeasures available, please follow the general countermeasures.\n\n• PMCprimo C2, PMCprimo MC: \n\nInstallation of Firmware Version 03.08.00 This update does not resolve the vulnerabilities (CVE-2021-34595, CVE-2021-34596, CVE-2021-34593, CVE-2021-30186, CVE-2021-30188, CVE-2021-30195, CVE-2019-19789) in the CODESYS V2 runtime system. \n\nThe V2 runtime system is still included for compatibility reasons but is no longer supported by Pilz. Please migrate your application to the V3 runtime system or follow the general countermeasures.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}}, {'cve': 'CVE-2019-19789', 'cwe': {'id': 'CWE-476', 'name': 'NULL Pointer Dereference'}, 'notes': [{'text': '3S-Smart CODESYS SP Realtime NT before V2.3.7.28, CODESYS Runtime Toolkit 32 bit full before V2.4.7.54, and CODESYS PLCWinNT before V2.4.7.54 allow a NULL pointer dereference.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2019-19789', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 6.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'HIGH', 'environmentalScore': 6.5, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}], 'remediations': [{'details': 'PMI 6 primo, PMCprimo C: No product-specific countermeasures available, please follow the general countermeasures.\n\n• PMCprimo C2, PMCprimo MC: \n\nInstallation of Firmware Version 03.08.00 This update does not resolve the vulnerabilities (CVE-2021-34595, CVE-2021-34596, CVE-2021-34593, CVE-2021-30186, CVE-2021-30188, CVE-2021-30195, CVE-2019-19789) in the CODESYS V2 runtime system. \n\nThe V2 runtime system is still included for compatibility reasons but is no longer supported by Pilz. Please migrate your application to the V3 runtime system or follow the general countermeasures.', 'category': 'none_available', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}}, {'cve': 'CVE-2021-30186', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'CODESYS V2 runtime system SP before 2.4.7.55 has a Heap-based Buffer Overflow.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2021-30186', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}], 'remediations': [{'details': 'PMI 6 primo, PMCprimo C: No product-specific countermeasures available, please follow the general countermeasures.\n\n• PMCprimo C2, PMCprimo MC: \n\nInstallation of Firmware Version 03.08.00 This update does not resolve the vulnerabilities (CVE-2021-34595, CVE-2021-34596, CVE-2021-34593, CVE-2021-30186, CVE-2021-30188, CVE-2021-30195, CVE-2019-19789) in the CODESYS V2 runtime system. \n\nThe V2 runtime system is still included for compatibility reasons but is no longer supported by Pilz. Please migrate your application to the V3 runtime system or follow the general countermeasures.', 'category': 'none_available', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005']}}]}
c39d1f4461e759e0185c6c14637a72a4351405ffc2fa73742f5ccfc356807a80
2026-05-29 08:30:36.474121+03:00
2026-05-29 08:30:36.474121+03:00
csaf_pilzgmbhcokg.ndjson
620462f4406bbd04eb1ff38135926028d9d50b348ee55df19b4bdc06e35961a6
{'document': {'lang': 'en-GB', 'notes': [{'text': 'The software product PMC programming tool from Pilz is based on the software CODESYS Development System from CODESYS GmbH. This software is affected by several vulnerabilities, which an attacker can exploit locally or via the network. This means that, in a worst case, attackers could execute arbitrary program code on the PC on which the PMC programming tool is used.', 'title': 'Summary', 'category': 'summary'}, {'text': 'In a worst case, attackers could execute arbitrary program code on the PC on which the PMC programming tool is used.', 'title': 'Impact', 'category': 'description'}, {'text': 'Use a hardware firewall, host-based firewall or comparable measures at network level toprotect against unauthorised network communication with the PC.\nUse a virus scanner or other measures to protect against malware.\nOnly use CODESYS libraries and archives from trusted sources.', 'title': 'General countermeasures', 'category': 'general'}, {'text': 'No product-specific countermeasures available, please follow the generalcountermeasures or migrate your application to the CODESYS V3 runtime system.', 'title': 'Product-specific countermeasures', 'category': 'general'}], 'title': 'Pilz: PMC programming tool 2.x.x affected by multiple vulnerabilities', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2021-055', 'status': 'final', 'aliases': ['VDE-2021-055'], 'version': '1', 'generator': {'date': '2025-05-05T11:58:19.145Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.24'}}, 'revision_history': [{'date': '2022-04-26T10:00:00.000Z', 'number': '1', 'summary': 'Initial revision.'}], 'current_release_date': '2022-04-26T10:00:00.000Z', 'initial_release_date': '2022-04-26T10:00:00.000Z'}, 'publisher': {'name': 'Pilz GmbH & Co. KG', 'category': 'vendor', 'namespace': 'https://www.pilz.com', 'contact_details': 'security@pilz.com'}, 'references': [{'url': 'https://certvde.com/en/advisories/VDE-2021-055/', 'summary': 'VDE-2021-055: Pilz: PMC programming tool 2.x.x affected by multiple vulnerabilities - HTML', 'category': 'self'}, {'url': 'https://pilz.csaf-tp.certvde.com/.well-known/csaf/white/2022/vde-2021-055.json', 'summary': 'VDE-2021-055: Pilz: PMC programming tool 2.x.x affected by multiple vulnerabilities - CSAF', 'category': 'self'}, {'url': 'https://www.pilz.com', 'summary': 'Vendor PSIRT', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/pilz/', 'summary': 'CERT@VDE Security Advisories for Pilz GmbH & Co. KG', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}]}, 'product_tree': {'branches': [{'name': 'Pilz', 'branches': [{'name': 'Software', 'branches': [{'name': 'PMC programming tool 2.x.x', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'PMC programming tool 2.x.x vers:all/*', 'product_id': 'CSAFPID-51001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2021-34596', 'cwe': {'id': 'CWE-824', 'name': 'Access of Uninitialized Pointer'}, 'notes': [{'text': 'A crafted request may cause a read access to an uninitialized pointer in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2021-34596', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 6.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'HIGH', 'environmentalScore': 6.5, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': 'No product-specific countermeasures available, please follow the general\ncountermeasures or migrate your application to the CODESYS V3 runtime system.', 'category': 'none_available', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2020-16233', 'cwe': {'id': 'CWE-404', 'name': 'Improper Resource Shutdown or Release'}, 'notes': [{'text': 'An attacker could send a specially crafted packet that could have CodeMeter (All versions prior to 7.10) send back packets containing data from the heap.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2020-16233', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'NONE', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': 'No product-specific countermeasures available, please follow the general\ncountermeasures or migrate your application to the CODESYS V3 runtime system.', 'category': 'none_available', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2020-14509', 'cwe': {'id': 'CWE-805', 'name': 'Buffer Access with Incorrect Length Value'}, 'notes': [{'text': 'Multiple memory corruption vulnerabilities exist in CodeMeter (All versions prior to 7.10) where the packet parser mechanism does not verify length fields. An attacker could send specially crafted packets to exploit these vulnerabilities.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2020-14509', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': 'No product-specific countermeasures available, please follow the general\ncountermeasures or migrate your application to the CODESYS V3 runtime system.', 'category': 'none_available', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2020-14519', 'cwe': {'id': 'CWE-346', 'name': 'Origin Validation Error'}, 'notes': [{'text': 'This vulnerability allows an attacker to use the internal WebSockets API for CodeMeter (All versions prior to 7.00 are affected, including Version 7.0 or newer with the affected WebSockets API still enabled. This is especially relevant for systems or devices where a web browser is used to access a web server) via a specifically crafted Java Script payload, which may allow alteration or creation of license files for when combined with CVE-2020-14515.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2020-14519', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N', 'temporalScore': 7.5, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'NONE', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': 'No product-specific countermeasures available, please follow the general\ncountermeasures or migrate your application to the CODESYS V3 runtime system.', 'category': 'none_available', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2020-14513', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'CodeMeter (All versions prior to 6.81) and the software using it may crash while processing a specifically crafted license file due to unverified length fields.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2020-14513', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': 'No product-specific countermeasures available, please follow the general\ncountermeasures or migrate your application to the CODESYS V3 runtime system.', 'category': 'none_available', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2020-14517', 'cwe': {'id': 'CWE-327', 'name': 'Use of a Broken or Risky Cryptographic Algorithm'}, 'notes': [{'text': 'Protocol encryption can be easily broken for CodeMeter (All versions prior to 6.90 are affected, including Version 6.90 or newer only if CodeMeter Runtime is running as server) and the server accepts external connections, which may allow an attacker to remotely communicate with the CodeMeter API.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2020-14517', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': 'No product-specific countermeasures available, please follow the general\ncountermeasures or migrate your application to the CODESYS V3 runtime system.', 'category': 'none_available', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2020-14515', 'cwe': {'id': 'CWE-347', 'name': 'Improper Verification of Cryptographic Signature'}, 'notes': [{'text': 'CodeMeter (All versions prior to 6.90 when using CmActLicense update files with CmActLicense Firm Code) has an issue in the license-file signature checking mechanism, which allows attackers to build arbitrary license files, including forging a valid license file as if it were a valid license file of an existing vendor. Only CmActLicense update files with CmActLicense Firm Code are affected.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2020-14515', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N', 'temporalScore': 7.5, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'NONE', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': 'No product-specific countermeasures available, please follow the general\ncountermeasures or migrate your application to the CODESYS V3 runtime system.', 'category': 'none_available', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2021-34593', 'cwe': {'id': 'CWE-755', 'name': 'Improper Handling of Exceptional Conditions'}, 'notes': [{'text': 'In CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56 unauthenticated crafted invalid requests may result in several denial-of-service conditions. Running PLC programs may be stopped, memory may be leaked, or further communication clients may be blocked from accessing the PLC.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2021-34593', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': 'No product-specific countermeasures available, please follow the general\ncountermeasures or migrate your application to the CODESYS V3 runtime system.', 'category': 'none_available', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2021-34595', 'cwe': {'id': 'CWE-119', 'name': 'Improper Restriction of Operations within the Bounds of a Memory Buffer'}, 'notes': [{'text': 'A crafted request with invalid offsets may cause an out-of-bounds read or write access in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition or local memory overwrite.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2021-34595', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.1, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H', 'temporalScore': 8.1, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 8.1, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': 'No product-specific countermeasures available, please follow the general\ncountermeasures or migrate your application to the CODESYS V3 runtime system.', 'category': 'none_available', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2019-16265', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'CODESYS V2.3 ENI server up to V3.2.2.24 has a Buffer Overflow.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2019-16265', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': 'No product-specific countermeasures available, please follow the general\ncountermeasures or migrate your application to the CODESYS V3 runtime system.', 'category': 'none_available', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'known_affected': ['CSAFPID-51001']}}]}
1af2aecb718dbe447ab8a88363b15e01f03603b5152607f9ba92923c9a313c06
2026-05-29 08:30:36.474121+03:00
2026-05-29 08:30:36.474121+03:00
csaf_pilzgmbhcokg.ndjson
3ca6bba963c9e927173bfb0c0bb3e02ebf6e3b6144f94b22565c348ef5a9c002
{'document': {'lang': 'en-GB', 'notes': [{'text': 'The software product PMC programming tool from Pilz is based on the software CODESYS\xa0Development System from CODESYS GmbH. This software is affected by several vulnerabilities, which an attacker can exploit locally or via the network. This means that, in a worst\xa0case, attackers could execute arbitrary program code on the PC on which the PMC programming tool is used.', 'title': 'Summary', 'category': 'summary'}, {'text': 'In a worst case, attackers could execute arbitrary program code on the PC on which the PMC programming tool is used.', 'title': 'Impact', 'category': 'description'}, {'text': 'Use a hardware firewall, host-based firewall or comparable measures at network level toprotect against unauthorised network communication with the PC.\nUse a virus scanner or other measures to protect against malware.\nOnly use CODESYS libraries and archives from trusted sources.', 'title': 'Mitigation', 'category': 'description'}, {'text': 'Installation of the software version 3.5.17', 'title': 'Remediation', 'category': 'description'}], 'title': 'Pilz: PMC programming tool 3.x.x affected by multiple vulnerabilities', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2021-061', 'status': 'final', 'aliases': ['VDE-2021-061'], 'version': '1', 'generator': {'date': '2025-05-05T09:34:10.920Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.24'}}, 'revision_history': [{'date': '2022-04-26T10:00:00.000Z', 'number': '1', 'summary': 'Initial revision.'}], 'current_release_date': '2022-04-26T10:00:00.000Z', 'initial_release_date': '2022-04-26T10:00:00.000Z'}, 'publisher': {'name': 'Pilz GmbH & Co. KG', 'category': 'vendor', 'namespace': 'https://www.pilz.com', 'contact_details': 'security@pilz.com'}, 'references': [{'url': 'https://certvde.com/en/advisories/VDE-2021-061/', 'summary': 'VDE-2021-061: Pilz: PMC programming tool 3.x.x affected by multiple vulnerabilities - HTML', 'category': 'self'}, {'url': 'https://pilz.csaf-tp.certvde.com/.well-known/csaf/white/2022/vde-2021-061.json', 'summary': 'VDE-2021-061: Pilz: PMC programming tool 3.x.x affected by multiple vulnerabilities - CSAF', 'category': 'self'}, {'url': 'https://www.pilz.com/en-INT/products/industrial-security/security-incident-management', 'summary': 'Pilz PSIRT', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/pilz/', 'summary': 'CERT@VDE Security Advisories for Pilz GmbH & Co. KG', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}]}, 'product_tree': {'branches': [{'name': 'Pilz', 'branches': [{'name': 'Software', 'branches': [{'name': 'PMC programming tool 3.x.x', 'branches': [{'name': '3.0.0<=3.5.15', 'product': {'name': 'PMC programming tool 3.x.x 3.0.0 <= 3.5.15', 'product_id': 'CSAFPID-51001'}, 'category': 'product_version_range'}, {'name': '3.5.17', 'product': {'name': 'PMC programming tool 3.x.x 3.5.17', 'product_id': 'CSAFPID-52001'}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2020-14513', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'CodeMeter (All versions prior to 6.81) and the software using it may crash while processing a specifically crafted license file due to unverified length fields.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2020-14513', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': 'Use a hardware firewall, host-based firewall or comparable measures at network level toprotect against unauthorised network communication with the PC.\nUse a virus scanner or other measures to protect against malware.\nOnly use CODESYS libraries and archives from trusted sources.', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Installation of the software version 3.5.17', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2020-14509', 'cwe': {'id': 'CWE-805', 'name': 'Buffer Access with Incorrect Length Value'}, 'notes': [{'text': 'Multiple memory corruption vulnerabilities exist in CodeMeter (All versions prior to 7.10) where the packet parser mechanism does not verify length fields. An attacker could send specially crafted packets to exploit these vulnerabilities.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2020-14509', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': 'Use a hardware firewall, host-based firewall or comparable measures at network level toprotect against unauthorised network communication with the PC.\nUse a virus scanner or other measures to protect against malware.\nOnly use CODESYS libraries and archives from trusted sources.', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Installation of the software version 3.5.17', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2019-13538', 'cwe': {'id': 'CWE-79', 'name': "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"}, 'notes': [{'text': '3S-Smart Software Solutions GmbH CODESYS V3 Library Manager, all versions prior to 3.5.16.0, allows the system to display active library content without checking its validity, which may allow the contents of manipulated libraries to be displayed or executed. The issue also exists for source libraries, but 3S-Smart Software Solutions GmbH strongly recommends distributing compiled libraries only.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2019-13538', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 8.6, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H', 'temporalScore': 8.6, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 8.6, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': 'Use a hardware firewall, host-based firewall or comparable measures at network level toprotect against unauthorised network communication with the PC.\nUse a virus scanner or other measures to protect against malware.\nOnly use CODESYS libraries and archives from trusted sources.', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Installation of the software version 3.5.17', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2021-29240', 'notes': [{'text': 'The Package Manager of CODESYS Development System 3 before 3.5.17.0 does not check the validity of packages before installation and may be used to install CODESYS packages with malicious content.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2021-29240', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'temporalScore': 7.8, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': 'Use a hardware firewall, host-based firewall or comparable measures at network level toprotect against unauthorised network communication with the PC.\nUse a virus scanner or other measures to protect against malware.\nOnly use CODESYS libraries and archives from trusted sources.', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Installation of the software version 3.5.17', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2021-29239', 'cwe': {'id': 'CWE-345', 'name': 'Insufficient Verification of Data Authenticity'}, 'notes': [{'text': 'CODESYS Development System 3 before 3.5.17.0 displays or executes malicious documents or files embedded in libraries without first checking their validity.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2021-29239', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 7.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.8, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': 'Use a hardware firewall, host-based firewall or comparable measures at network level toprotect against unauthorised network communication with the PC.\nUse a virus scanner or other measures to protect against malware.\nOnly use CODESYS libraries and archives from trusted sources.', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Installation of the software version 3.5.17', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2021-21869', 'cwe': {'id': 'CWE-502', 'name': 'Deserialization of Untrusted Data'}, 'notes': [{'text': 'An unsafe deserialization vulnerability exists in the Engine.plugin ProfileInformation ProfileData functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2021-21869', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'temporalScore': 7.8, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': 'Use a hardware firewall, host-based firewall or comparable measures at network level toprotect against unauthorised network communication with the PC.\nUse a virus scanner or other measures to protect against malware.\nOnly use CODESYS libraries and archives from trusted sources.', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Installation of the software version 3.5.17', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2021-21868', 'cwe': {'id': 'CWE-502', 'name': 'Deserialization of Untrusted Data'}, 'notes': [{'text': 'An unsafe deserialization vulnerability exists in the ObjectManager.plugin Project.get_MissingTypes() functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2021-21868', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'temporalScore': 7.8, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': 'Use a hardware firewall, host-based firewall or comparable measures at network level toprotect against unauthorised network communication with the PC.\nUse a virus scanner or other measures to protect against malware.\nOnly use CODESYS libraries and archives from trusted sources.', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Installation of the software version 3.5.17', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2021-21867', 'cwe': {'id': 'CWE-502', 'name': 'Deserialization of Untrusted Data'}, 'notes': [{'text': 'An unsafe deserialization vulnerability exists in the ObjectManager.plugin ObjectStream.ProfileByteArray functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2021-21867', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'temporalScore': 7.8, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': 'Use a hardware firewall, host-based firewall or comparable measures at network level toprotect against unauthorised network communication with the PC.\nUse a virus scanner or other measures to protect against malware.\nOnly use CODESYS libraries and archives from trusted sources.', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Installation of the software version 3.5.17', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2021-21866', 'cwe': {'id': 'CWE-502', 'name': 'Deserialization of Untrusted Data'}, 'notes': [{'text': 'A unsafe deserialization vulnerability exists in the ObjectManager.plugin ProfileInformation.ProfileData functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2021-21866', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'temporalScore': 7.8, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': 'Use a hardware firewall, host-based firewall or comparable measures at network level toprotect against unauthorised network communication with the PC.\nUse a virus scanner or other measures to protect against malware.\nOnly use CODESYS libraries and archives from trusted sources.', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Installation of the software version 3.5.17', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2021-21865', 'cwe': {'id': 'CWE-502', 'name': 'Deserialization of Untrusted Data'}, 'notes': [{'text': 'A unsafe deserialization vulnerability exists in the PackageManagement.plugin ExtensionMethods.Clone() functionality of CODESYS GmbH CODESYS Development System 3.5.16. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2021-21865', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'temporalScore': 7.8, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': 'Use a hardware firewall, host-based firewall or comparable measures at network level toprotect against unauthorised network communication with the PC.\nUse a virus scanner or other measures to protect against malware.\nOnly use CODESYS libraries and archives from trusted sources.', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Installation of the software version 3.5.17', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2021-21864', 'cwe': {'id': 'CWE-502', 'name': 'Deserialization of Untrusted Data'}, 'notes': [{'text': 'A unsafe deserialization vulnerability exists in the ComponentModel ComponentManager.StartupCultureSettings functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2021-21864', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'temporalScore': 7.8, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': 'Use a hardware firewall, host-based firewall or comparable measures at network level toprotect against unauthorised network communication with the PC.\nUse a virus scanner or other measures to protect against malware.\nOnly use CODESYS libraries and archives from trusted sources.', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Installation of the software version 3.5.17', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2021-21863', 'cwe': {'id': 'CWE-502', 'name': 'Deserialization of Untrusted Data'}, 'notes': [{'text': 'A unsafe deserialization vulnerability exists in the ComponentModel Profile.FromFile() functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2021-21863', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'temporalScore': 7.8, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': 'Use a hardware firewall, host-based firewall or comparable measures at network level toprotect against unauthorised network communication with the PC.\nUse a virus scanner or other measures to protect against malware.\nOnly use CODESYS libraries and archives from trusted sources.', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Installation of the software version 3.5.17', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2019-9009', 'cwe': {'id': 'CWE-755', 'name': 'Improper Handling of Exceptional Conditions'}, 'notes': [{'text': 'An issue was discovered in 3S-Smart CODESYS before 3.5.15.0 . Crafted network packets cause the Control Runtime to crash.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2019-9009', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': 'Use a hardware firewall, host-based firewall or comparable measures at network level toprotect against unauthorised network communication with the PC.\nUse a virus scanner or other measures to protect against malware.\nOnly use CODESYS libraries and archives from trusted sources.', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Installation of the software version 3.5.17', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2020-14515', 'cwe': {'id': 'CWE-347', 'name': 'Improper Verification of Cryptographic Signature'}, 'notes': [{'text': 'CodeMeter (All versions prior to 6.90 when using CmActLicense update files with CmActLicense Firm Code) has an issue in the license-file signature checking mechanism, which allows attackers to build arbitrary license files, including forging a valid license file as if it were a valid license file of an existing vendor. Only CmActLicense update files with CmActLicense Firm Code are affected.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2020-14515', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N', 'temporalScore': 7.5, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'NONE', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': 'Use a hardware firewall, host-based firewall or comparable measures at network level toprotect against unauthorised network communication with the PC.\nUse a virus scanner or other measures to protect against malware.\nOnly use CODESYS libraries and archives from trusted sources.', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Installation of the software version 3.5.17', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2019-9011', 'cwe': {'id': 'CWE-668', 'name': 'Exposure of Resource to Wrong Sphere'}, 'notes': [{'text': 'In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), an attacker can identify valid usernames.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2019-9011', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N', 'temporalScore': 5.3, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 5.3, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': 'Use a hardware firewall, host-based firewall or comparable measures at network level toprotect against unauthorised network communication with the PC.\nUse a virus scanner or other measures to protect against malware.\nOnly use CODESYS libraries and archives from trusted sources.', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Installation of the software version 3.5.17', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2019-9013', 'cwe': {'id': 'CWE-327', 'name': 'Use of a Broken or Risky Cryptographic Algorithm'}, 'notes': [{'text': 'An issue was discovered in 3S-Smart CODESYS V3 products. The application may utilize non-TLS based encryption, which results in user credentials being insufficiently protected during transport. All variants of the following CODESYS V3 products in all versions containing the CmpUserMgr component are affected regardless of the CPU type or operating system: CODESYS Control for BeagleBone, CODESYS Control for emPC-A/iMX6, CODESYS Control for IOT2000, CODESYS Control for Linux, CODESYS Control for PFC100, CODESYS Control for PFC200, CODESYS Control for Raspberry Pi, CODESYS Control RTE V3, CODESYS Control RTE V3 (for Beckhoff CX), CODESYS Control Win V3 (also part of the CODESYS Development System setup), CODESYS V3 Simulation Runtime (part of the CODESYS Development System), CODESYS Control V3 Runtime System Toolkit, CODESYS HMI V3.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2019-9013', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'ADJACENT_NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 8.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 8.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': 'Use a hardware firewall, host-based firewall or comparable measures at network level toprotect against unauthorised network communication with the PC.\nUse a virus scanner or other measures to protect against malware.\nOnly use CODESYS libraries and archives from trusted sources.', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Installation of the software version 3.5.17', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2020-12067', 'cwe': {'id': 'CWE-640', 'name': 'Weak Password Recovery Mechanism for Forgotten Password'}, 'notes': [{'text': "In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), a user's password may be changed by an attacker without knowledge of the current password.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2020-12067', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N', 'temporalScore': 7.5, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'NONE', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': 'Use a hardware firewall, host-based firewall or comparable measures at network level toprotect against unauthorised network communication with the PC.\nUse a virus scanner or other measures to protect against malware.\nOnly use CODESYS libraries and archives from trusted sources.', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Installation of the software version 3.5.17', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2020-12069', 'cwe': {'id': 'CWE-916', 'name': 'Use of Password Hash With Insufficient Computational Effort'}, 'notes': [{'text': 'In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords using a weak hashing algorithm. This can be used by a local attacker with low privileges to gain full control of the device.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2020-12069', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 7.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.8, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': 'Use a hardware firewall, host-based firewall or comparable measures at network level toprotect against unauthorised network communication with the PC.\nUse a virus scanner or other measures to protect against malware.\nOnly use CODESYS libraries and archives from trusted sources.', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Installation of the software version 3.5.17', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2020-6081', 'cwe': {'id': 'CWE-345', 'name': 'Insufficient Verification of Data Authenticity'}, 'notes': [{'text': 'An exploitable code execution vulnerability exists in the PLC_Task functionality of 3S-Smart Software Solutions GmbH CODESYS Runtime 3.5.14.30. A specially crafted network request can cause remote code execution. An attacker can send a malicious packet to trigger this vulnerability.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2020-6081', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 8.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 8.8, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': 'Use a hardware firewall, host-based firewall or comparable measures at network level toprotect against unauthorised network communication with the PC.\nUse a virus scanner or other measures to protect against malware.\nOnly use CODESYS libraries and archives from trusted sources.', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Installation of the software version 3.5.17', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2021-36764', 'cwe': {'id': 'CWE-476', 'name': 'NULL Pointer Dereference'}, 'notes': [{'text': 'In CODESYS Gateway V3 before 3.5.17.10, there is a NULL Pointer Dereference. Crafted communication requests may cause a Null pointer dereference in the affected CODESYS products and may result in a denial-of-service condition.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2021-36764', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': 'Use a hardware firewall, host-based firewall or comparable measures at network level toprotect against unauthorised network communication with the PC.\nUse a virus scanner or other measures to protect against malware.\nOnly use CODESYS libraries and archives from trusted sources.', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Installation of the software version 3.5.17', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2020-14517', 'cwe': {'id': 'CWE-327', 'name': 'Use of a Broken or Risky Cryptographic Algorithm'}, 'notes': [{'text': 'Protocol encryption can be easily broken for CodeMeter (All versions prior to 6.90 are affected, including Version 6.90 or newer only if CodeMeter Runtime is running as server) and the server accepts external connections, which may allow an attacker to remotely communicate with the CodeMeter API.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2020-14517', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': 'Use a hardware firewall, host-based firewall or comparable measures at network level toprotect against unauthorised network communication with the PC.\nUse a virus scanner or other measures to protect against malware.\nOnly use CODESYS libraries and archives from trusted sources.', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Installation of the software version 3.5.17', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2020-7052', 'cwe': {'id': 'CWE-770', 'name': 'Allocation of Resources Without Limits or Throttling'}, 'notes': [{'text': 'CODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30 allow uncontrolled memory allocation which can result in a remote denial of service condition.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2020-7052', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 6.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'HIGH', 'environmentalScore': 6.5, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': 'Use a hardware firewall, host-based firewall or comparable measures at network level toprotect against unauthorised network communication with the PC.\nUse a virus scanner or other measures to protect against malware.\nOnly use CODESYS libraries and archives from trusted sources.', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Installation of the software version 3.5.17', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2020-14519', 'cwe': {'id': 'CWE-346', 'name': 'Origin Validation Error'}, 'notes': [{'text': 'This vulnerability allows an attacker to use the internal WebSockets API for CodeMeter (All versions prior to 7.00 are affected, including Version 7.0 or newer with the affected WebSockets API still enabled. This is especially relevant for systems or devices where a web browser is used to access a web server) via a specifically crafted Java Script payload, which may allow alteration or creation of license files for when combined with CVE-2020-14515.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2020-14519', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N', 'temporalScore': 7.5, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'NONE', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': 'Use a hardware firewall, host-based firewall or comparable measures at network level toprotect against unauthorised network communication with the PC.\nUse a virus scanner or other measures to protect against malware.\nOnly use CODESYS libraries and archives from trusted sources.', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Installation of the software version 3.5.17', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2021-29241', 'cwe': {'id': 'CWE-476', 'name': 'NULL Pointer Dereference'}, 'notes': [{'text': 'CODESYS Gateway 3 before 3.5.16.70 has a NULL pointer dereference that may result in a denial of service (DoS).', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2021-29241', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': 'Use a hardware firewall, host-based firewall or comparable measures at network level toprotect against unauthorised network communication with the PC.\nUse a virus scanner or other measures to protect against malware.\nOnly use CODESYS libraries and archives from trusted sources.', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Installation of the software version 3.5.17', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2021-29242', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': "CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's addressing scheme and may re-route, add, remove or change low level communication packages.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2021-29242', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.3, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L', 'temporalScore': 7.3, 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'LOW', 'environmentalScore': 7.3, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': 'Use a hardware firewall, host-based firewall or comparable measures at network level toprotect against unauthorised network communication with the PC.\nUse a virus scanner or other measures to protect against malware.\nOnly use CODESYS libraries and archives from trusted sources.', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Installation of the software version 3.5.17', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2020-16233', 'cwe': {'id': 'CWE-404', 'name': 'Improper Resource Shutdown or Release'}, 'notes': [{'text': 'An attacker could send a specially crafted packet that could have CodeMeter (All versions prior to 7.10) send back packets containing data from the heap.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2020-16233', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'NONE', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': 'Use a hardware firewall, host-based firewall or comparable measures at network level toprotect against unauthorised network communication with the PC.\nUse a virus scanner or other measures to protect against malware.\nOnly use CODESYS libraries and archives from trusted sources.', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Installation of the software version 3.5.17', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2019-5105', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'An exploitable memory corruption vulnerability exists in the Name Service Client functionality of 3S-Smart Software Solutions CODESYS GatewayService. A specially crafted packet can cause a large memcpy, resulting in an access violation and termination of the process. An attacker can send a packet to a device running the GatewayService.exe to trigger this vulnerability. All variants of the CODESYS V3 products in all versions prior V3.5.16.10 containing the CmpRouter or CmpRouterEmbedded component are affected, regardless of the CPU type or operating system: CODESYS Control for BeagleBone, CODESYS Control for emPC-A/iMX6, CODESYS Control for IOT2000, CODESYS Control for Linux, CODESYS Control for PLCnext, CODESYS Control for PFC100, CODESYS Control for PFC200, CODESYS Control for Raspberry Pi, CODESYS Control RTE V3, CODESYS Control RTE V3 (for Beckhoff CX), CODESYS Control Win V3 (also part of the CODESYS Development System setup), CODESYS Control V3 Runtime System Toolkit, CODESYS V3 Embedded Target Visu Toolkit, CODESYS V3 Remote Target Visu Toolkit, CODESYS V3 Safety SIL2, CODESYS Edge Gateway V3, CODESYS Gateway V3, CODESYS HMI V3, CODESYS OPC Server V3, CODESYS PLCHandler SDK, CODESYS V3 Simulation Runtime (part of the CODESYS Development System).', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2019-5105', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': 'Use a hardware firewall, host-based firewall or comparable measures at network level toprotect against unauthorised network communication with the PC.\nUse a virus scanner or other measures to protect against malware.\nOnly use CODESYS libraries and archives from trusted sources.', 'category': 'mitigation', 'product_ids': ['CSAFPID-51001']}, {'details': 'Installation of the software version 3.5.17', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'fixed': ['CSAFPID-52001'], 'known_affected': ['CSAFPID-51001']}}]}
f91e50c1ca165d456a094a8473c1d04d4731ddb44917fd1e4a2a1bd12134a8dd
2026-05-29 08:30:36.474121+03:00
2026-05-29 08:30:36.474121+03:00
csaf_pilzgmbhcokg.ndjson
6e478115a1f9918b521ddb388a0cb57ce77f2db5b3e327b326ee446010bde266
{'document': {'lang': 'en-GB', 'notes': [{'text': 'PASvisu is an HMI solution for Machine Visualization. It is available as a standalone software product,\xa0but it is also included in various models of the PMI product family. The PASvisu Server component\xa0contains multiple vulnerabilities which can be utilised to write arbitrary files, potentially leading to\xa0code execution.', 'title': 'Summary', 'category': 'summary'}, {'text': 'The PASvisu Server provides an integrated web server which is also used to send the configuration\xa0from the PASvisu Builder to the server component. When receiving and processing a configuration, it\xa0does not properly check pathnames. If the PASvisu Server is not properly protected by setting an\xa0administration password, the listed vulnerabilities can be exploited by an attacker to\xa0write arbitrary files. In the worst case scenario this could lead to remote code execution.', 'title': 'Impact', 'category': 'description'}, {'text': 'PASvisu software, PMI v7xx, PMI v8xx: Configure an administration password.\nPASvisu, PMI v7xx, PMI v8xx: Install the fixed version as soon as\xa0it is available. Please visit the Pilz Shop (www.pilz.com/enINT/eshop) to check for a fixed version.', 'title': 'Remediation', 'category': 'description'}], 'title': 'Pilz: PASvisu and PMI affected by multiple vulnerabilities', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2022-033', 'status': 'final', 'aliases': ['VDE-2022-033'], 'version': '1', 'generator': {'date': '2025-05-14T14:26:04.960Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.25'}}, 'revision_history': [{'date': '2022-11-24T09:00:00.000Z', 'number': '1', 'summary': 'Initial revision.'}], 'current_release_date': '2022-11-24T09:00:00.000Z', 'initial_release_date': '2022-11-24T09:00:00.000Z'}, 'publisher': {'name': 'Pilz GmbH & Co. KG', 'category': 'vendor', 'namespace': 'https://www.pilz.com', 'contact_details': 'security@pilz.com'}, 'references': [{'url': 'https://certvde.com/en/advisories/VDE-2022-033/', 'summary': 'VDE-2022-033: Pilz: PASvisu and PMI affected by multiple vulnerabilities - HTML', 'category': 'self'}, {'url': 'https://pilz.csaf-tp.certvde.com/.well-known/csaf/white/2022/vde-2022-033.json', 'summary': 'VDE-2022-033: Pilz: PASvisu and PMI affected by multiple vulnerabilities - CSAF', 'category': 'self'}, {'url': 'https://www.pilz.com', 'summary': 'Vendor PSIRT', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/pilz/', 'summary': 'CERT@VDE Security Advisories for Pilz GmbH & Co. KG', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}]}, 'product_tree': {'branches': [{'name': 'Pilz', 'branches': [{'name': 'Software', 'branches': [{'name': 'PASvisu Software', 'branches': [{'name': '<1.12.0', 'product': {'name': 'PASvisu Software <1.12.0', 'product_id': 'CSAFPID-51001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'PMI v5xx', 'branches': [{'name': '<=1.3.58', 'product': {'name': 'PMI v5xx <=1.3.58', 'product_id': 'CSAFPID-51002', 'product_identification_helper': {'model_numbers': ['265507']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'PMI v7xx', 'branches': [{'name': '<2.2.0', 'product': {'name': 'PMI v7xx <2.2.0', 'product_id': 'CSAFPID-51003', 'product_identification_helper': {'model_numbers': ['266704']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'PMI v8xx', 'branches': [{'name': '<1.6.102', 'product': {'name': 'PMI v8xx <1.6.102', 'product_id': 'CSAFPID-51004', 'product_identification_helper': {'model_numbers': ['266807']}}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}], 'product_groups': [{'summary': 'Affected products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003', 'CSAFPID-51004']}]}, 'vulnerabilities': [{'cve': 'CVE-2022-40977', 'cwe': {'id': 'CWE-22', 'name': "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"}, 'notes': [{'text': "A path traversal vulnerability was discovered in Pilz PASvisu Server before 1.12.0. An unauthenticated remote attacker could use a zipped, malicious configuration file to trigger arbitrary file writes ('zip-slip'). File writes do not affect confidentiality or availability.\n", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2022-40977', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N', 'temporalScore': 7.5, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'NONE', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003', 'CSAFPID-51004']}], 'remediations': [{'details': 'PASvisu software, PMI v7xx, PMI v8xx: Configure an administration password.\nPASvisu, PMI v7xx, PMI v8xx: Install the fixed version as soon as\xa0it is available. Please visit the Pilz Shop (www.pilz.com/enINT/eshop) to check for a fixed version.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003', 'CSAFPID-51004']}}, {'cve': 'CVE-2022-25299', 'cwe': {'id': 'CWE-552', 'name': 'Files or Directories Accessible to External Parties'}, 'notes': [{'text': 'This affects the package cesanta/mongoose before 7.6. The unsafe handling of file names during upload using mg_http_upload() method may enable attackers to write files to arbitrary locations outside the designated target folder.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2022-25299', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N', 'temporalScore': 7.5, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'NONE', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003', 'CSAFPID-51004']}], 'remediations': [{'details': 'PASvisu software, PMI v7xx, PMI v8xx: Configure an administration password.\nPASvisu, PMI v7xx, PMI v8xx: Install the fixed version as soon as\xa0it is available. Please visit the Pilz Shop (www.pilz.com/enINT/eshop) to check for a fixed version.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003', 'CSAFPID-51004']}}]}
6568915884dd43e3efc45c7649f99cacd6635dfd91a0298e3bfcb76203e0a87b
2026-05-29 08:30:36.474121+03:00
2026-05-29 08:30:36.474121+03:00
csaf_pilzgmbhcokg.ndjson
bfe7982d80e5b0789e0e780d7b67608af39b76d00b36ffbf2d68d0e69cece0e1
{'document': {'lang': 'en-GB', 'notes': [{'text': 'Several Pilz software products do not properly check pathnames contained in archives. An attacker can utilise this vulnerability to write arbitrary files, potentially leading to code execution.', 'title': 'Summary', 'category': 'summary'}, {'text': "The affected software products are using ZIP archives to save and load project backups and libraries. When loading a ZIP archive, the contained pathnames are not checked properly for relative path components. If a user\xa0loads a manipulated ZIP archive the vulnerability can be used to place potentially malicious files outside of the application's working directory. Depending on the user's privileges this\xa0can lead to code execution.", 'title': 'Impact', 'category': 'description'}, {'text': 'Please visit the Pilz Shop (www.pilz.com/en-INT/eshop) to check for the fixed version', 'title': 'Remediation', 'category': 'description'}, {'text': 'Do not use .zip or .par files from untrusted sources. If you need to load a file from an\nuntrusted source, please contact your local Pilz support.', 'title': 'General Countermeasures', 'category': 'general'}], 'title': 'Pilz: Multiple products affected by ZipSlip', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2022-044', 'status': 'final', 'aliases': ['VDE-2022-044'], 'version': '2', 'generator': {'date': '2025-05-07T08:00:35.611Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.24'}}, 'revision_history': [{'date': '2022-11-24T09:00:00.000Z', 'number': '1', 'summary': 'Initial revision.'}, {'date': '2025-06-05T13:28:13.000Z', 'number': '2', 'summary': 'Fix: quotation mark'}], 'current_release_date': '2025-06-05T13:28:13.000Z', 'initial_release_date': '2022-11-24T09:00:00.000Z'}, 'publisher': {'name': 'Pilz GmbH & Co. KG', 'category': 'vendor', 'namespace': 'https://www.pilz.com', 'contact_details': 'security@pilz.com'}, 'references': [{'url': 'https://certvde.com/en/advisories/VDE-2022-044/', 'summary': 'VDE-2022-044: Pilz: Multiple products affected by ZipSlip - HTML', 'category': 'self'}, {'url': 'https://pilz.csaf-tp.certvde.com/.well-known/csaf/white/2022/vde-2022-044.json', 'summary': 'VDE-2022-044: Pilz: Multiple products affected by ZipSlip - CSAF', 'category': 'self'}, {'url': 'https://www.pilz.com', 'summary': 'Vendor PSIRT', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/pilz/', 'summary': 'CERT@VDE Security Advisories for Pilz GmbH & Co. KG', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}]}, 'product_tree': {'branches': [{'name': 'Pilz', 'branches': [{'name': 'Software', 'branches': [{'name': 'PAScal', 'branches': [{'name': '<=1.9.1', 'product': {'name': 'PAScal <=1.9.1', 'product_id': 'CSAFPID-51001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'PASconnect', 'branches': [{'name': '<1.4.0', 'product': {'name': 'PASconnect <1.4.0', 'product_id': 'CSAFPID-51002'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'PASmotion', 'branches': [{'name': '<1.4.1', 'product': {'name': 'PASmotion <1.4.1', 'product_id': 'CSAFPID-51003'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'PNOZmulti Configurator', 'branches': [{'name': '<11.2.0', 'product': {'name': 'PNOZmulti Configurator <11.2.0', 'product_id': 'CSAFPID-51004'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'PNOZmulti Configurator LTS', 'branches': [{'name': '<10.14.4', 'product': {'name': 'PNOZmulti Configurator LTS <10.14.4', 'product_id': 'CSAFPID-51005'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}], 'product_groups': [{'summary': 'Affected products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003', 'CSAFPID-51004', 'CSAFPID-51005']}]}, 'vulnerabilities': [{'cve': 'CVE-2022-40976', 'cwe': {'id': 'CWE-22', 'name': "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"}, 'notes': [{'text': "A path traversal vulnerability was discovered in multiple Pilz products. An unauthenticated local attacker could use a zipped, malicious configuration file to trigger arbitrary file writes ('zip-slip'). File writes do not affect confidentiality or availability.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2022-40976', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N', 'temporalScore': 5.5, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 5.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003', 'CSAFPID-51004', 'CSAFPID-51005']}], 'remediations': [{'details': 'Please visit the Pilz Shop (www.pilz.com/en-INT/eshop) to check for the fixed version', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003', 'CSAFPID-51004', 'CSAFPID-51005']}}]}
2df195ebbeda917474d39823ddd784150c5324f43765d0caa9ff091c0138a5d5
2026-05-29 08:30:36.474121+03:00
2026-05-29 08:30:36.474121+03:00
csaf_pilzgmbhcokg.ndjson
2dad56f528c78c0c0e019f22b6a8cf56a39bec88657f6af4f1714caf62c26e45
{'document': {'lang': 'en-GB', 'notes': [{'text': 'PAS4000 is the software platform for the Automation System PSS 4000.\xa0PAS 4000 does not properly check pathnames contained in archives. An attacker can utilise this vulnerability to write arbitrary files, potentially leading to code execution.', 'title': 'Summary', 'category': 'summary'}, {'text': "PAS 4000 uses ZIP archives to save and load project backups and libraries. Also, ZIP archives are used as a container for firmware updates. \n\nWhen loading a ZIP archive the contained pathnames are not checked properly for relative path components. If a user loads a manipulated ZIP archive, the vulnerability can be used to place potentially malicious files outside of the application's working directory. \n\nDepending on the user's privileges this can lead to code execution.", 'title': 'Impact', 'category': 'description'}, {'text': 'Install the fixed version as soon as it is available. Please visit the Pilz Shop (www.pilz.com/en-INT/eshop) to check for the fixed version', 'title': 'Remediation', 'category': 'description'}, {'text': 'Do not use .zip or .par files from untrusted sources. If you need to load a file from an\nuntrusted source, please contact your local Pilz support.', 'title': 'General Countermeasures', 'category': 'general'}], 'title': 'Pilz: PAS 4000 prone to ZipSlip', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2022-045', 'status': 'final', 'aliases': ['VDE-2022-045'], 'version': '2', 'generator': {'date': '2025-05-05T12:03:38.525Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.24'}}, 'revision_history': [{'date': '2022-11-24T09:00:00.000Z', 'number': '1', 'summary': 'Initial revision.'}, {'date': '2025-05-22T13:03:10.000Z', 'number': '2', 'summary': 'Fix: quotation mark'}], 'current_release_date': '2025-05-22T13:03:10.000Z', 'initial_release_date': '2022-11-24T09:00:00.000Z'}, 'publisher': {'name': 'Pilz GmbH & Co. KG', 'category': 'vendor', 'namespace': 'https://www.pilz.com', 'contact_details': 'security@pilz.com'}, 'references': [{'url': 'https://certvde.com/en/advisories/VDE-2022-045/', 'summary': 'VDE-2022-045: Pilz: PAS 4000 prone to ZipSlip - HTML', 'category': 'self'}, {'url': 'https://pilz.csaf-tp.certvde.com/.well-known/csaf/white/2022/vde-2022-045.json', 'summary': 'VDE-2022-045: Pilz: PAS 4000 prone to ZipSlip - CSAF', 'category': 'self'}, {'url': 'https://www.pilz.com', 'summary': 'Vendor PSIRT', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/pilz/', 'summary': 'CERT@VDE Security Advisories for Pilz GmbH & Co. KG', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}]}, 'product_tree': {'branches': [{'name': 'Pilz', 'branches': [{'name': 'Software', 'branches': [{'name': 'PAS4000', 'branches': [{'name': '<1.25.0', 'product': {'name': 'PAS4000 <1.25.0', 'product_id': 'CSAFPID-51001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2022-40976', 'cwe': {'id': 'CWE-22', 'name': "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"}, 'notes': [{'text': "A path traversal vulnerability was discovered in multiple Pilz products. An unauthenticated local attacker could use a zipped, malicious configuration file to trigger arbitrary file writes ('zip-slip'). File writes do not affect confidentiality or availability.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2022-40976', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N', 'temporalScore': 5.5, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 5.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': 'Install the fixed version as soon as it is available. Please visit the Pilz Shop (www.pilz.com/en-INT/eshop) to check for the fixed version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'known_affected': ['CSAFPID-51001']}}, {'cve': 'CVE-2018-1002202', 'cwe': {'id': 'CWE-22', 'name': "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"}, 'notes': [{'text': "zip4j before 1.3.3 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.", 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2018-1002202', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N', 'temporalScore': 6.5, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 6.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001']}], 'remediations': [{'details': 'Install the fixed version as soon as it is available. Please visit the Pilz Shop (www.pilz.com/en-INT/eshop) to check for the fixed version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-51001']}], 'product_status': {'known_affected': ['CSAFPID-51001']}}]}
e7e0f17d25ccc7b756f7671c03ecd87d7195e95bc61df0e2d0355f03d5d874cc
2026-05-29 08:30:36.474121+03:00
2026-05-29 08:30:36.474121+03:00
csaf_pilzgmbhcokg.ndjson
2625cabbf3f687432a412f7639d4be45c44215650b2736c8a3c7576f7cc9d3d5
{'document': {'lang': 'en-GB', 'notes': [{'text': 'Several Pilz products use the 3rd party component "CodeMeter Runtime" from WIBU-SYSTEM AG to manage software licenses. This component is affected by a vulnerability, which may enable an attacker to gain full control over the system running the software product. The vulnerability can be exploited locally or over the network.\n\nUpdate A, 2023-12-05\n\nchanged affected version of "Software PASvisu < 1.15.0" to "Software PASvisu < 1.14.1"\nremoved CVE-2023-4701 because it was revoked.', 'title': 'Summary', 'category': 'summary'}, {'text': 'When running WIBU CodeMeter Runtime in non-server mode, a local user may grant themselves improper elevated privileges. When running in server mode, a remote attacker may gain full control over the system. By default, the CodeMeter Runtime is running in non-server mode.', 'title': 'Impact', 'category': 'description'}, {'text': 'PAS4000, PASvisu, PIT User Authentication Service, PNOZsigma Configurator, PMIv8: Installthe fixed version as soon as it is available. Please visit the Pilz eShop(https://www.pilz.com/en-INT/eshop) to check for the fixed version.\nPASloto, Live Video Server, SafetyEYE Configurator, PMC programming tool: These productsare end-of-live, please follow the general countermeasures.', 'title': 'Remediation', 'category': 'description'}, {'text': "- Download and install CodeMeter Runtime version 7.60c or later from WIBU-SYSTEM's website https://www.wibu.com/de/support.html\n\n- When CodeMeter Runtime is used in server mode, restrict access on the network-level by using a firewall or comparable measures.\n\n- Restrict local access to authorized users only on the system running the CodeMeter runtime.\n\n- Also deploy strong hardening measures and endpoint protection solutions.", 'title': 'General Countermeasures', 'category': 'general'}], 'title': 'Pilz: WIBU Vulnerabilitiy in multiple Products', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2023-033', 'status': 'final', 'aliases': ['VDE-2023-033'], 'version': '3', 'generator': {'date': '2025-05-05T12:05:40.075Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.24'}}, 'revision_history': [{'date': '2023-10-12T06:00:00.000Z', 'number': '1', 'summary': 'Initial revision.'}, {'date': '2023-12-05T11:00:00.000Z', 'number': '2', 'summary': 'Update A'}, {'date': '2025-05-22T13:03:10.000Z', 'number': '3', 'summary': 'Fix: quotation mark'}], 'current_release_date': '2025-05-22T13:03:10.000Z', 'initial_release_date': '2023-10-12T06:00:00.000Z'}, 'publisher': {'name': 'Pilz GmbH & Co. KG', 'category': 'vendor', 'namespace': 'https://www.pilz.com', 'contact_details': 'security@pilz.com'}, 'references': [{'url': 'https://certvde.com/en/advisories/VDE-2023-033/', 'summary': 'VDE-2023-033: Pilz: WIBU Vulnerabilitiy in multiple Products - HTML', 'category': 'self'}, {'url': 'https://pilz.csaf-tp.certvde.com/.well-known/csaf/white/2023/vde-2023-033.json', 'summary': 'VDE-2023-033: Pilz: WIBU Vulnerabilitiy in multiple Products - CSAF', 'category': 'self'}, {'url': 'https://www.pilz.com/en-INT/products/industrial-security/security-incident-management', 'summary': 'Pilz PSIRT', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/pilz/', 'summary': 'CERT@VDE Security Advisories for Pilz GmbH & Co. KG', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}]}, 'product_tree': {'branches': [{'name': 'Pilz', 'branches': [{'name': 'Software', 'branches': [{'name': 'PASloto', 'branches': [{'name': '<=1.1.3', 'product': {'name': 'PASloto <= 1.1.3', 'product_id': 'CSAFPID-51001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'PMC programming tool 3.x.x', 'branches': [{'name': '3.0.0<=3.5.18.2', 'product': {'name': 'PMC programming tool 3.x.x 3.0.0 <= 3.5.18.2', 'product_id': 'CSAFPID-51002'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'PMI v8xx', 'branches': [{'name': '<=2.0.33992', 'product': {'name': 'PMI v8xx <= 2.0.33992', 'product_id': 'CSAFPID-51003', 'product_identification_helper': {'model_numbers': ['266807, 266812, 266815']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'PNOZsigma Configurator', 'branches': [{'name': '<1.5.0', 'product': {'name': 'PNOZsigma Configurator < 1.5.0', 'product_id': 'CSAFPID-51004'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Software Live Video Server', 'branches': [{'name': '<=1.1.0', 'product': {'name': 'Software Live Video Server <= 1.1.0', 'product_id': 'CSAFPID-51005'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Software PAS4000', 'branches': [{'name': '<1.26.0', 'product': {'name': 'Software PAS4000 < 1.26.0', 'product_id': 'CSAFPID-51006'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Software PASvisu', 'branches': [{'name': '<1.14.1', 'product': {'name': 'Software PASvisu < 1.14.1', 'product_id': 'CSAFPID-51007'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Software PIT User Authentication Service', 'branches': [{'name': '<1.1.2', 'product': {'name': 'Software PIT User Authentication Service < 1.1.2', 'product_id': 'CSAFPID-51008'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Software SafetyEYE Configurator', 'branches': [{'name': '3.0.0<=3.0.1', 'product': {'name': 'Software SafetyEYE Configurator 3.0.0<= 3.0.1', 'product_id': 'CSAFPID-51009'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}], 'product_groups': [{'summary': 'Affected products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003', 'CSAFPID-51004', 'CSAFPID-51005', 'CSAFPID-51006', 'CSAFPID-51007', 'CSAFPID-51008', 'CSAFPID-51009']}]}, 'vulnerabilities': [{'cve': 'CVE-2023-3935', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2023-3935', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003', 'CSAFPID-51004', 'CSAFPID-51005', 'CSAFPID-51006', 'CSAFPID-51007', 'CSAFPID-51008', 'CSAFPID-51009']}], 'remediations': [{'details': 'PAS4000, PASvisu, PIT User Authentication Service, PNOZsigma Configurator, PMIv8: Installthe fixed version as soon as it is available. Please visit the Pilz eShop(https://www.pilz.com/en-INT/eshop) to check for the fixed version.\nPASloto, Live Video Server, SafetyEYE Configurator, PMC programming tool: These productsare end-of-live, please follow the general countermeasures.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003', 'CSAFPID-51004', 'CSAFPID-51005', 'CSAFPID-51006', 'CSAFPID-51007', 'CSAFPID-51008', 'CSAFPID-51009']}}]}
7f1fcbf2cc348fc6b203254d6207ff95df00c242509290f1d64da4c869196bbd
2026-05-29 08:30:36.474121+03:00
2026-05-29 08:30:36.474121+03:00
csaf_pilzgmbhcokg.ndjson
340db9924b3cab527ae0a5173d9800a9726109969589115a352d9bdab7d7adfb
{'document': {'lang': 'en-GB', 'notes': [{'text': "Several Pilz products use the 3rd-party component 'libwebp' for decoding of images in WebP format. This component is affected by a vulnerability, which may enable an attacker to gain full control over the system running the software product. Depending on the affected product, the vulnerabilities can be exploited locally or over the network.", 'title': 'Summary', 'category': 'summary'}, {'text': 'Decoding of a specially crafted image leads to a heap buffer overflow. In a worst-case scenario, a successful exploitation of the vulnerability can lead to execution of arbitrary code using the privileges of the user running the affected software. In case of PIT Transponder Manager and the PASvisu Builder, the vulnerability can only be exploited locally. Depending on the configuration of the PASvisu Runtime, a remote exploitation may be possible.', 'title': 'Impact', 'category': 'description'}, {'text': 'Install the fixed product version as soon as it is available. Please visit the Pilz eShop(https://www.pilz.com/en-INT/eshop) to check for the fixed version.\nPASvisu Runtime: Limit network access to legitimate connections by using a firewall or similarmeasures. Restrict administrative access by setting up user authentication properly.', 'title': 'Remediation', 'category': 'description'}, {'text': '- Only use project and image files from trustworthy sources.\n- Protect project and image files against modification by unauthorized users.', 'title': 'General Countermeasures', 'category': 'general'}], 'title': 'Pilz: Multiple products prone to libwebp vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2023-048', 'status': 'final', 'aliases': ['VDE-2023-048'], 'version': '2', 'generator': {'date': '2025-05-05T11:57:25.417Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.24'}}, 'revision_history': [{'date': '2023-12-05T07:00:00.000Z', 'number': '1', 'summary': 'Initial revision.'}, {'date': '2025-05-22T13:03:10.000Z', 'number': '2', 'summary': 'Fix: quotation mark'}], 'current_release_date': '2025-05-22T13:03:10.000Z', 'initial_release_date': '2023-12-05T07:00:00.000Z'}, 'publisher': {'name': 'Pilz GmbH & Co. KG', 'category': 'vendor', 'namespace': 'https://www.pilz.com', 'contact_details': 'security@pilz.com'}, 'references': [{'url': 'https://certvde.com/en/advisories/VDE-2023-048/', 'summary': 'VDE-2023-048: Pilz: Multiple products prone to libwebp vulnerability - HTML', 'category': 'self'}, {'url': 'https://pilz.csaf-tp.certvde.com/.well-known/csaf/white/2023/vde-2023-048.json', 'summary': 'VDE-2023-048: Pilz: Multiple products prone to libwebp vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.pilz.com/en-INT/products/industrial-security/security-incident-management', 'summary': 'Pilz PSIRT', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/pilz/', 'summary': 'CERT@VDE Security Advisories for Pilz GmbH & Co. KG', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}]}, 'product_tree': {'branches': [{'name': 'Pilz', 'branches': [{'name': 'Software', 'branches': [{'name': 'PASvisu', 'branches': [{'name': '<1.14.1', 'product': {'name': 'PASvisu < 1.14.1', 'product_id': 'CSAFPID-51001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'PIT Transponder Manager', 'branches': [{'name': '<1.2.0', 'product': {'name': 'PIT Transponder Manager < 1.2.0', 'product_id': 'CSAFPID-51002'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'PMI v8xx', 'branches': [{'name': '<=2.0.33992', 'product': {'name': 'PMI v8xx <= 2.0.33992', 'product_id': 'CSAFPID-51003', 'product_identification_helper': {'model_numbers': ['266807', '266812', '266815']}}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}], 'product_groups': [{'summary': 'Affected products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003']}]}, 'vulnerabilities': [{'cve': 'CVE-2023-4863', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2023-4863', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'temporalScore': 8.8, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 8.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003']}], 'remediations': [{'details': 'Install the fixed product version as soon as it is available. Please visit the Pilz eShop(https://www.pilz.com/en-INT/eshop) to check for the fixed version.\nPASvisu Runtime: Limit network access to legitimate connections by using a firewall or similarmeasures. Restrict administrative access by setting up user authentication properly.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003']}}]}
6cb3a4251f3dfe4da7763049f5c6d0fc54122c0abf62e8774ab98b33aa40a49c
2026-05-29 08:30:36.474121+03:00
2026-05-29 08:30:36.474121+03:00
csaf_pilzgmbhcokg.ndjson
a1e2734e37f1785497c36ba4ccfa7405aac83a7227be2a8bc1ff64ea9b191cc8
{'document': {'lang': 'en-GB', 'notes': [{'text': 'Multiple Pilz products are affected by stored cross-site-scripting (XSS) vulnerabilities. The vulnerabilities may enable an attacker to gain full control over the system.\n\nUpdate: 27.02.2024 Fix typo in advisory title', 'title': 'Summary', 'category': 'summary'}, {'text': 'The vulnerabilities allow an attacker to inject malicious Javascript code into the system. With PASvisu\nBuilder in a worst-case scenario this can lead to execution of arbitrary code using the privileges of the\nuser running the affected software. With PASvisu Runtime (including PMI v8xx) in a worst-case\nscenario this could have an impact on the controlled automation application.', 'title': 'Impact', 'category': 'description'}, {'text': ' * Only use project files from trustworthy sources.\n * Protect project files against modification by unauthorized users.\n * PASvisu Runtime: Limit network access to legitimate connections by using a firewall or similar\nmeasures. Use password protection on the online project.', 'title': 'Mitigation', 'category': 'description'}, {'text': 'Install the fixed product version as soon as it is available. Please visit the Pilz eShop\n(https://www.pilz.com/en-INT/eshop external link) to check for the fixed version', 'title': 'Remediation', 'category': 'description'}], 'title': 'Pilz: Vulnerability in PASvisu and PMI v8xx', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2023-050', 'status': 'final', 'aliases': ['VDE-2023-050'], 'version': '4', 'generator': {'date': '2024-06-10T06:39:45.830Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.4'}}, 'revision_history': [{'date': '2024-01-30T07:00:00.000Z', 'number': '1', 'summary': 'Initial revision.'}, {'date': '2024-02-27T14:00:00.000Z', 'number': '2', 'summary': 'Updated Title.'}, {'date': '2024-11-06T11:27:01.000Z', 'number': '3', 'summary': 'Fix: correct certvde domain, added self-reference'}, {'date': '2025-04-10T13:00:00.000Z', 'number': '4', 'summary': 'fixed version operators'}], 'current_release_date': '2025-04-10T13:00:00.000Z', 'initial_release_date': '2024-01-30T07:00:00.000Z'}, 'publisher': {'name': 'Pilz GmbH & Co. KG', 'category': 'vendor', 'namespace': 'https://www.pilz.com', 'contact_details': 'security@pilz.com'}, 'references': [{'url': 'https://www.pilz.com/de-DE/company/news/articles/200605', 'summary': 'PILZ PSIRT', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/pilz/', 'summary': 'CERT@VDE Security Advisories for PILZ products', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/VDE-2023-050/', 'summary': 'VDE-2023-050: Pilz: Vulnerability in PASvisu and PMI v8xx - HTML', 'category': 'self'}, {'url': 'https://pilz.csaf-tp.certvde.com/.well-known/csaf/white/2024/vde-2023-050.json', 'summary': 'VDE-2023-050: Pilz: Vulnerability in PASvisu and PMI v8xx - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}]}, 'product_tree': {'branches': [{'name': 'PILZ', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'PMI v8xx', 'product': {'name': 'PILZ Hardware PMI v8xx', 'product_id': 'CSAFPID-1101', 'product_identification_helper': {'model_numbers': ['266807', '266812', '266815']}}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Software', 'branches': [{'name': 'PASvisu', 'branches': [{'name': '<1.14.1', 'product': {'name': 'PILZ Software PASvisu <1.14.1', 'product_id': 'CSAFPID-5101'}, 'category': 'product_version_range'}, {'name': '1.14.1', 'product': {'name': 'PILZ Software PASvisu 1.14.1', 'product_id': 'CSAFPID-5201'}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': 'PMI v8xx', 'branches': [{'name': '<=2.0.33992', 'product': {'name': 'PILZ Firmware PMI v8xx <=2.0.33992', 'product_id': 'CSAFPID-2101'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'PILZ Firmware PMI v8xx <=2.0.33992 installed on PILZ Hardware PMI v8xx', 'product_id': 'CSAFPID-3101'}, 'product_reference': 'CSAFPID-2101', 'relates_to_product_reference': 'CSAFPID-1101'}], 'product_groups': [{'summary': 'Affected products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-3101', 'CSAFPID-5101']}]}, 'vulnerabilities': [{'cve': 'CVE-2023-45795', 'cwe': {'id': 'CWE-79', 'name': "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"}, 'notes': [{'text': 'A cross-site scripting vulnerability in the Builder Component of Pilz PASvisu before 1.14.1 allows a local unauthenticated attacker to inject malicious javascript and gain full control over the device.', 'title': 'Vulnerability Description', 'audience': 'all', 'category': 'description'}], 'title': 'CVE-2023-45795', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'temporalScore': 7.8, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-3101', 'CSAFPID-5101']}], 'remediations': [{'details': ' * Only use project files from trustworthy sources.\n * Protect project files against modification by unauthorized users.\n * PASvisu Runtime: Limit network access to legitimate connections by using a firewall or similar\nmeasures. Use password protection on the online project.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': ' Install the fixed product version as soon as it is available. Please visit the Pilz eShop\n(https://www.pilz.com/en-INT/eshop external link) to check for the fixed version', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-3101', 'CSAFPID-5101']}}, {'cve': 'CVE-2023-45796', 'cwe': {'id': 'CWE-79', 'name': "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"}, 'notes': [{'text': 'A stored cross-site scripting vulnerability in the Runtime component of Pilz PASvisu before 1.14.1 and PMI v8xx up to and including 2.0.33992 allows a low-privileged remote unauthenticated attacker to manipulate process data with potential impact on integrity and/or availability.', 'title': 'Vulnerability Description', 'audience': 'all', 'category': 'description'}], 'title': 'CVE-2023-45796', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.1, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H', 'temporalScore': 8.1, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 8.1, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-3101', 'CSAFPID-5101']}], 'remediations': [{'details': ' * Only use project files from trustworthy sources.\n * Protect project files against modification by unauthorized users.\n * PASvisu Runtime: Limit network access to legitimate connections by using a firewall or similar\nmeasures. Use password protection on the online project.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': ' Install the fixed product version as soon as it is available. Please visit the Pilz eShop\n(https://www.pilz.com/en-INT/eshop external link) to check for the fixed version', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-3101', 'CSAFPID-5101']}}]}
2dc86c14b43d494cfc14fac411522a4e6136e10c1763ba5e522a0a5a945a09b3
2026-05-29 08:30:36.474121+03:00
2026-05-29 08:30:36.474121+03:00
csaf_pilzgmbhcokg.ndjson
197bffd09ce2be3b6b25fa8f83514b8d88eb7656b631ebfc15f6e84f5dcc5ec9
{'document': {'lang': 'en-GB', 'notes': [{'text': 'The Builder and Viewer components of the product PASvisu are based on the 3rd-party-component Electron. Electron contains several other open-source components which are affected by vulnerabilities. The vulnerabilities may enable an attacker to gain full control over the system. The vulnerabilities can be exploited locally or over the network.', 'title': 'Summary', 'category': 'summary'}, {'text': 'Displaying of a specially crafted HTML page can lead to heap buffer overflow or heap corruption. In a\xa0worst-case scenario, a successful exploitation of the vulnerabilities can lead to execution of arbitrary\xa0code using the privileges of the user running the affected software. In the case of the PASvisu\xa0Builder, the vulnerability can only be exploited locally.', 'title': 'Impact', 'category': 'description'}, {'text': 'Install the fixed product version as soon as it is available. Please visit the Pilz eShop(https://www.pilz.com/en-INT/eshop) to check for the fixed version.\nOnly use project files from trustworthy sources.\nProtect project files against modification by unauthorized users.\nLimit network access to legitimate connections by using a firewall or similar measures. Usepassword protection on the online project.', 'title': 'Remediation', 'category': 'description'}], 'title': 'Pilz: Electron Vulnerabilities in PASvisu and PMI v8xx', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2023-059', 'status': 'final', 'aliases': ['VDE-2023-059'], 'version': '1', 'generator': {'date': '2025-04-30T13:57:22.468Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.24'}}, 'revision_history': [{'date': '2023-12-05T07:06:00.000Z', 'number': '1', 'summary': 'Initial revision.'}], 'current_release_date': '2023-12-05T07:06:00.000Z', 'initial_release_date': '2023-12-05T07:06:00.000Z'}, 'publisher': {'name': 'Pilz GmbH & Co. KG', 'category': 'vendor', 'namespace': 'https://www.pilz.com', 'contact_details': 'security@pilz.com'}, 'references': [{'url': 'https://certvde.com/en/advisories/VDE-2023-059/', 'summary': 'VDE-2023-059: Pilz: Electron Vulnerabilities in PASvisu and PMI v8xx - HTML', 'category': 'self'}, {'url': 'https://pilz.csaf-tp.certvde.com/.well-known/csaf/white/2023/vde-2023-059.json', 'summary': 'VDE-2023-059: Pilz: Electron Vulnerabilities in PASvisu and PMI v8xx - CSAF', 'category': 'self'}, {'url': 'https://www.pilz.com', 'summary': 'Vendor PSIRT', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/pilz/', 'summary': 'CERT@VDE Security Advisories for Pilz GmbH & Co. KG', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}]}, 'product_tree': {'branches': [{'name': 'Pilz', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'PASvisu', 'product': {'name': 'PASvisu', 'product_id': 'CSAFPID-11001'}, 'category': 'product_name'}, {'name': 'PMI v8xx', 'product': {'name': 'PMI v8xx', 'product_id': 'CSAFPID-11002', 'product_identification_helper': {'model_numbers': ['266807', '266812', '266815']}}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': '<1.14.1', 'product': {'name': 'Firmware <1.14.1', 'product_id': 'CSAFPID-21001'}, 'category': 'product_version_range'}, {'name': '<=2.0.33992', 'product': {'name': 'Firmware <=2.0.33992', 'product_id': 'CSAFPID-21002'}, 'category': 'product_version_range'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware <1.14.1 installed on PASvisu', 'product_id': 'CSAFPID-31001'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=2.0.33992 installed on PMI v8xx', 'product_id': 'CSAFPID-31002'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11002'}], 'product_groups': [{'summary': 'Affected products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-31001', 'CSAFPID-31002']}]}, 'vulnerabilities': [{'cve': 'CVE-2023-5217', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2023-5217', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'temporalScore': 8.8, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 8.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002']}], 'remediations': [{'details': 'Install the fixed product version as soon as it is available. Please visit the Pilz eShop(https://www.pilz.com/en-INT/eshop) to check for the fixed version.\nOnly use project files from trustworthy sources.\nProtect project files against modification by unauthorized users.\nLimit network access to legitimate connections by using a firewall or similar measures. Usepassword protection on the online project.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-31001', 'CSAFPID-31002']}}, {'cve': 'CVE-2023-5218', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'Use after free in Site Isolation in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2023-5218', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'temporalScore': 8.8, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 8.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002']}], 'remediations': [{'details': 'Install the fixed product version as soon as it is available. Please visit the Pilz eShop(https://www.pilz.com/en-INT/eshop) to check for the fixed version.\nOnly use project files from trustworthy sources.\nProtect project files against modification by unauthorized users.\nLimit network access to legitimate connections by using a firewall or similar measures. Usepassword protection on the online project.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-31001', 'CSAFPID-31002']}}]}
cd776001665aff3446b333180c6bad7ea0bdc24af2cbebeb4c2c0005e0643af9
2026-05-29 08:30:36.474121+03:00
2026-05-29 08:30:36.474121+03:00
csaf_pilzgmbhcokg.ndjson
592493745e1ddff25be3509832149ae26018cc0939fc350827cd477f933065a7
{'document': {'lang': 'en-GB', 'notes': [{'text': 'The PITreader product family is using the 3rd -party-component uC/HTTP to implement the web server functionality. uC/HTTP is affected by multiple vulnerabilities. These vulnerabilities may enable an attacker to gain full control over the system.', 'title': 'Summary', 'category': 'summary'}, {'text': 'An unauthenticated attacker can exploit the vulnerabilities by sending specially crafted HTTP packets to the system. Depending on the vulnerability, memory content can be overwritten or corrupted. In a worst-case scenario this can be used by the attacker to execute arbitrary code on the system to gain full control over it.', 'title': 'Impact', 'category': 'description'}, {'text': 'Install the fixed firmware version. Please visit the Pilz Website\xa0to download the latest firmware update. Instructions about installing the firmware update can be found in the user manual.\nLimit network access to legitimate connections by using a firewall or similar measures.', 'title': 'Remediation', 'category': 'description'}], 'title': 'Pilz: Multiple products affected by uC/HTTP vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2024-002', 'status': 'final', 'aliases': ['VDE-2024-002'], 'version': '1', 'generator': {'date': '2025-05-14T09:53:25.219Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.25'}}, 'revision_history': [{'date': '2024-02-06T07:00:00.000Z', 'number': '1', 'summary': 'Initial revision.'}], 'current_release_date': '2024-02-06T07:00:00.000Z', 'initial_release_date': '2024-02-06T07:00:00.000Z'}, 'publisher': {'name': 'Pilz GmbH & Co. KG', 'category': 'vendor', 'namespace': 'https://www.pilz.com', 'contact_details': 'security@pilz.com'}, 'references': [{'url': 'https://certvde.com/en/advisories/VDE-2024-002/', 'summary': 'VDE-2024-002: Pilz: Multiple products affected by uC/HTTP vulnerability - HTML', 'category': 'self'}, {'url': 'https://pilz.csaf-tp.certvde.com/.well-known/csaf/white/2024/vde-2024-002.json', 'summary': 'VDE-2024-002: Pilz: Multiple products affected by uC/HTTP vulnerability - CSAF', 'category': 'self'}, {'url': 'https://www.pilz.com', 'summary': 'Vendor PSIRT', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/pilz/', 'summary': 'CERT@VDE Security Advisories for Pilz GmbH & Co. KG', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}]}, 'product_tree': {'branches': [{'name': 'Pilz', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'PIT gb RLLE y down ETH', 'product': {'name': 'PIT gb RLLE y down ETH', 'product_id': 'CSAFPID-11001', 'product_identification_helper': {'model_numbers': ['G1000021']}}, 'category': 'product_name'}, {'name': 'PIT gb RLLE y up ETH', 'product': {'name': 'PIT gb RLLE y up ETH', 'product_id': 'CSAFPID-11002', 'product_identification_helper': {'model_numbers': ['G1000020']}}, 'category': 'product_name'}, {'name': 'PITreader base unit (HR 01)', 'product': {'name': 'PITreader base unit (HR 01)', 'product_id': 'CSAFPID-11003', 'product_identification_helper': {'model_numbers': ['402255']}}, 'category': 'product_name'}, {'name': 'PITreader base unit (HR 02)', 'product': {'name': 'PITreader base unit (HR 02)', 'product_id': 'CSAFPID-11004', 'product_identification_helper': {'model_numbers': ['402255']}}, 'category': 'product_name'}, {'name': 'PITreader card unit', 'product': {'name': 'PITreader card unit', 'product_id': 'CSAFPID-11005', 'product_identification_helper': {'model_numbers': ['402320']}}, 'category': 'product_name'}, {'name': 'PITreader S base unit', 'product': {'name': 'PITreader S base unit', 'product_id': 'CSAFPID-11006', 'product_identification_helper': {'model_numbers': ['402256']}}, 'category': 'product_name'}, {'name': 'PITreader S card unit', 'product': {'name': 'PITreader S card unit', 'product_id': 'CSAFPID-11007', 'product_identification_helper': {'model_numbers': ['402321']}}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': '<02.02.00', 'product': {'name': 'Firmware <02.02.00', 'product_id': 'CSAFPID-21001'}, 'category': 'product_version_range'}, {'name': '<01.05.04', 'product': {'name': 'Firmware <01.05.04', 'product_id': 'CSAFPID-21002'}, 'category': 'product_version_range'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware <02.02.00 installed on PIT gb RLLE y down ETH', 'product_id': 'CSAFPID-31001'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <02.02.00 installed on PIT gb RLLE y up ETH', 'product_id': 'CSAFPID-31002'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11002'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <01.05.04 installed on PITreader base unit (HR 01)', 'product_id': 'CSAFPID-31003'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11003'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <02.02.00 installed on PITreader base unit (HR 02)', 'product_id': 'CSAFPID-31004'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11004'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <02.02.00 installed on PITreader card unit', 'product_id': 'CSAFPID-31005'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11005'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <02.02.00 installed on PITreader S base unit', 'product_id': 'CSAFPID-31006'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11006'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <02.02.00 installed on PITreader S card unit', 'product_id': 'CSAFPID-31007'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11007'}], 'product_groups': [{'summary': 'Affected products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007']}]}, 'vulnerabilities': [{'cve': 'CVE-2023-31247', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A memory corruption vulnerability exists in the HTTP Server Host header parsing functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2023-31247', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007']}], 'remediations': [{'details': 'Install the fixed firmware version. Please visit the Pilz Website\xa0to download the latest firmware update. Instructions about installing the firmware update can be found in the user manual.\nLimit network access to legitimate connections by using a firewall or similar measures.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007']}}, {'cve': 'CVE-2023-28379', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A memory corruption vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2023-28379', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007']}], 'remediations': [{'details': 'Install the fixed firmware version. Please visit the Pilz Website\xa0to download the latest firmware update. Instructions about installing the firmware update can be found in the user manual.\nLimit network access to legitimate connections by using a firewall or similar measures.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007']}}, {'cve': 'CVE-2023-28391', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A memory corruption vulnerability exists in the HTTP Server header parsing functionality of Weston Embedded uC-HTTP v3.01.01. Specially crafted network packets can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2023-28391', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007']}], 'remediations': [{'details': 'Install the fixed firmware version. Please visit the Pilz Website\xa0to download the latest firmware update. Instructions about installing the firmware update can be found in the user manual.\nLimit network access to legitimate connections by using a firewall or similar measures.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007']}}, {'cve': 'CVE-2023-27882', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A heap-based buffer overflow vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2023-27882', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007']}], 'remediations': [{'details': 'Install the fixed firmware version. Please visit the Pilz Website\xa0to download the latest firmware update. Instructions about installing the firmware update can be found in the user manual.\nLimit network access to legitimate connections by using a firewall or similar measures.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007']}}, {'cve': 'CVE-2023-25181', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted set of network packets can lead to arbitrary code execution. An attacker can send a malicious packet to trigger this vulnerability.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2023-25181', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007']}], 'remediations': [{'details': 'Install the fixed firmware version. Please visit the Pilz Website\xa0to download the latest firmware update. Instructions about installing the firmware update can be found in the user manual.\nLimit network access to legitimate connections by using a firewall or similar measures.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007']}}, {'cve': 'CVE-2023-24585', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'An out-of-bounds write vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2023-24585', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007']}], 'remediations': [{'details': 'Install the fixed firmware version. Please visit the Pilz Website\xa0to download the latest firmware update. Instructions about installing the firmware update can be found in the user manual.\nLimit network access to legitimate connections by using a firewall or similar measures.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007']}}]}
a5cb31743a536bc135d62cca2345fa1b28476242a138eb3251cb24a87a5402b3
2026-05-29 08:30:36.474121+03:00
2026-05-29 08:30:36.474121+03:00
csaf_endresshauserag.ndjson
4e0fa4b4de3aa04ec169007758f997b657f500902f097182f76b3d02d8372011
{'document': {'lang': 'en-GB', 'notes': [{'text': 'Multiple security issues and vulnerabilities within the WPA2 standard have been identified and publicized by Mr. Mathy Vanhoef of KU Leuven. These vulnerabilities may allow the reinstallation of a pairwise transient key, a group key, or an integrity key on either a wireless client or a wireless access point (AP). In consequence, an attacker could establish a man-in-the-middle position between AP and client facilitating packet decryption and injection.\nThe Field Xpert SFX370 and SFX350 handhelds are manufactured by Pepperl+Fuchs/ecom instruments for Endress+Hauser.\nThe Advisory for Pepperl+Fuchs/ecom instruments can be found here: VDE-2017-005', 'title': 'Summary', 'category': 'summary'}, {'text': 'The devices are in theory attackable by replay, decryption and faking of packets. However, to perform the attack, the attacker must be significantly closer to the ecom device than to the access point. The WPA2 password cannot be compromised using a KRACK attack. Note if WPA-TKIP is used instead of AES-CCMP, an attacker can easily fake and inject packets directly into the WIFI.', 'title': 'Impact', 'category': 'description'}, {'text': 'For Field Xpert handheld devices (SFX350/SFX370) running Windows Mobile, Endress+Hauser recommends to apply the security updates provided by Microsoft.\n\nIntermec/Honeywell as producer of the basis of the handheld provide the following security patch for the Windows Mobile operating system: SR18012500_802T_Cx70_WM65_ALL.CAB\n\nTo obtain this patch, please contact your local Endress+Hauser representative.\nIf you are using WPA-TKIP in your WLAN, you should switch to AES-CCMP immediately.\nFor Field Xpert tablet PC for device configuration (SMT70) running Windows 10 Pro 1703 64 EN, Endress+Hauser strongly recommends updating to the newest available Windows version.\nAs a general security measure Endress+Hauser strongly recommends to protect network access to the WIFI network with appropriate mechanisms. It is advised to configure the environment in order to run the devices in a protected IT environment.\n\nNote: This advisory will be updated as further details and/or software updates become available.', 'title': 'Remediation', 'category': 'description'}], 'title': 'Endress+Hauser: WIFI enabled products utilising WPA2', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2019-005', 'status': 'final', 'aliases': ['VDE-2019-005'], 'version': '1', 'generator': {'date': '2025-05-26T13:13:31.733Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.26'}}, 'revision_history': [{'date': '2019-03-19T15:34:00.000Z', 'number': '1', 'summary': 'Initial revision.'}], 'current_release_date': '2019-03-19T15:34:00.000Z', 'initial_release_date': '2019-03-19T15:34:00.000Z'}, 'publisher': {'name': 'Endress+Hauser AG', 'category': 'vendor', 'namespace': 'https://www.endress.com', 'contact_details': 'psirt@endress.com'}, 'references': [{'url': 'https://certvde.com/en/advisories/VDE-2019-005/', 'summary': 'VDE-2019-005: Endress+Hauser: WIFI enabled products utilising WPA2 - HTML', 'category': 'self'}, {'url': 'https://endress-hauser.csaf-tp.certvde.com/.well-known/csaf/white/2019/vde-2019-005.json', 'summary': 'VDE-2019-005: Endress+Hauser: WIFI enabled products utilising WPA2 - CSAF', 'category': 'self'}, {'url': 'https://www.endress.com', 'summary': 'Vendor PSIRT', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/endress-hauser/', 'summary': 'CERT@VDE Security Advisories for Endress+Hauser AG', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}, {'urls': ['https://www.krackattacks.com/'], 'names': ['KU Leuven'], 'summary': 'reporting', 'organization': 'krack attacks'}, {'names': ['Mathy Vanhoef'], 'summary': 'reporting', 'organization': 'imec-DistriNet '}]}, 'product_tree': {'branches': [{'name': 'Vendor', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'Field Xpert SFX350', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'Field Xpert SFX350 vers:all/*', 'product_id': 'CSAFPID-11001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Field Xpert SFX370', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'Field Xpert SFX370 vers:all/*', 'product_id': 'CSAFPID-11002'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Field Xpert SMT70', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'Field Xpert SMT70 vers:all/*', 'product_id': 'CSAFPID-11003'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}], 'product_groups': [{'summary': 'Affected products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-11001', 'CSAFPID-11002', 'CSAFPID-11003']}]}, 'vulnerabilities': [{'cve': 'CVE-2017-13077', 'cwe': {'id': 'CWE-330', 'name': 'Use of Insufficiently Random Values'}, 'notes': [{'text': 'Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the four-way handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2017-13077', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 6.8, 'attackVector': 'ADJACENT_NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 6.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-11001', 'CSAFPID-11002', 'CSAFPID-11003']}], 'remediations': [{'details': 'For Field Xpert handheld devices (SFX350/SFX370) running Windows Mobile, Endress+Hauser recommends to apply the security updates provided by Microsoft.\n\nIntermec/Honeywell as producer of the basis of the handheld provide the following security patch for the Windows Mobile operating system: SR18012500_802T_Cx70_WM65_ALL.CAB\n\nTo obtain this patch, please contact your local Endress+Hauser representative.\nIf you are using WPA-TKIP in your WLAN, you should switch to AES-CCMP immediately.\nFor Field Xpert tablet PC for device configuration (SMT70) running Windows 10 Pro 1703 64 EN, Endress+Hauser strongly recommends updating to the newest available Windows version.\nAs a general security measure Endress+Hauser strongly recommends to protect network access to the WIFI network with appropriate mechanisms. It is advised to configure the environment in order to run the devices in a protected IT environment.\n\nNote: This advisory will be updated as further details and/or software updates become available.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-11001', 'CSAFPID-11002', 'CSAFPID-11003']}}, {'cve': 'CVE-2017-13078', 'cwe': {'id': 'CWE-330', 'name': 'Use of Insufficiently Random Values'}, 'notes': [{'text': 'Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the four-way handshake, allowing an attacker within radio range to replay frames from access points to clients.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2017-13078', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 5.3, 'attackVector': 'ADJACENT_NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N', 'temporalScore': 5.3, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 5.3, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-11001', 'CSAFPID-11002', 'CSAFPID-11003']}], 'remediations': [{'details': 'For Field Xpert handheld devices (SFX350/SFX370) running Windows Mobile, Endress+Hauser recommends to apply the security updates provided by Microsoft.\n\nIntermec/Honeywell as producer of the basis of the handheld provide the following security patch for the Windows Mobile operating system: SR18012500_802T_Cx70_WM65_ALL.CAB\n\nTo obtain this patch, please contact your local Endress+Hauser representative.\nIf you are using WPA-TKIP in your WLAN, you should switch to AES-CCMP immediately.\nFor Field Xpert tablet PC for device configuration (SMT70) running Windows 10 Pro 1703 64 EN, Endress+Hauser strongly recommends updating to the newest available Windows version.\nAs a general security measure Endress+Hauser strongly recommends to protect network access to the WIFI network with appropriate mechanisms. It is advised to configure the environment in order to run the devices in a protected IT environment.\n\nNote: This advisory will be updated as further details and/or software updates become available.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-11001', 'CSAFPID-11002', 'CSAFPID-11003']}}, {'cve': 'CVE-2017-13080', 'cwe': {'id': 'CWE-330', 'name': 'Use of Insufficiently Random Values'}, 'notes': [{'text': 'Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the group key handshake, allowing an attacker within radio range to replay frames from access points to clients.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2017-13080', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 5.3, 'attackVector': 'ADJACENT_NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N', 'temporalScore': 5.3, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 5.3, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-11001', 'CSAFPID-11002', 'CSAFPID-11003']}], 'remediations': [{'details': 'For Field Xpert handheld devices (SFX350/SFX370) running Windows Mobile, Endress+Hauser recommends to apply the security updates provided by Microsoft.\n\nIntermec/Honeywell as producer of the basis of the handheld provide the following security patch for the Windows Mobile operating system: SR18012500_802T_Cx70_WM65_ALL.CAB\n\nTo obtain this patch, please contact your local Endress+Hauser representative.\nIf you are using WPA-TKIP in your WLAN, you should switch to AES-CCMP immediately.\nFor Field Xpert tablet PC for device configuration (SMT70) running Windows 10 Pro 1703 64 EN, Endress+Hauser strongly recommends updating to the newest available Windows version.\nAs a general security measure Endress+Hauser strongly recommends to protect network access to the WIFI network with appropriate mechanisms. It is advised to configure the environment in order to run the devices in a protected IT environment.\n\nNote: This advisory will be updated as further details and/or software updates become available.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-11001', 'CSAFPID-11002', 'CSAFPID-11003']}}, {'cve': 'CVE-2017-13079', 'cwe': {'id': 'CWE-330', 'name': 'Use of Insufficiently Random Values'}, 'notes': [{'text': 'Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the four-way handshake, allowing an attacker within radio range to spoof frames from access points to clients.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2017-13079', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 5.3, 'attackVector': 'ADJACENT_NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N', 'temporalScore': 5.3, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 5.3, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-11001', 'CSAFPID-11002', 'CSAFPID-11003']}], 'remediations': [{'details': 'For Field Xpert handheld devices (SFX350/SFX370) running Windows Mobile, Endress+Hauser recommends to apply the security updates provided by Microsoft.\n\nIntermec/Honeywell as producer of the basis of the handheld provide the following security patch for the Windows Mobile operating system: SR18012500_802T_Cx70_WM65_ALL.CAB\n\nTo obtain this patch, please contact your local Endress+Hauser representative.\nIf you are using WPA-TKIP in your WLAN, you should switch to AES-CCMP immediately.\nFor Field Xpert tablet PC for device configuration (SMT70) running Windows 10 Pro 1703 64 EN, Endress+Hauser strongly recommends updating to the newest available Windows version.\nAs a general security measure Endress+Hauser strongly recommends to protect network access to the WIFI network with appropriate mechanisms. It is advised to configure the environment in order to run the devices in a protected IT environment.\n\nNote: This advisory will be updated as further details and/or software updates become available.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-11001', 'CSAFPID-11002', 'CSAFPID-11003']}}, {'cve': 'CVE-2017-13081', 'cwe': {'id': 'CWE-330', 'name': 'Use of Insufficiently Random Values'}, 'notes': [{'text': 'Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the group key handshake, allowing an attacker within radio range to spoof frames from access points to clients.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2017-13081', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 5.3, 'attackVector': 'ADJACENT_NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N', 'temporalScore': 5.3, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 5.3, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-11001', 'CSAFPID-11002', 'CSAFPID-11003']}], 'remediations': [{'details': 'For Field Xpert handheld devices (SFX350/SFX370) running Windows Mobile, Endress+Hauser recommends to apply the security updates provided by Microsoft.\n\nIntermec/Honeywell as producer of the basis of the handheld provide the following security patch for the Windows Mobile operating system: SR18012500_802T_Cx70_WM65_ALL.CAB\n\nTo obtain this patch, please contact your local Endress+Hauser representative.\nIf you are using WPA-TKIP in your WLAN, you should switch to AES-CCMP immediately.\nFor Field Xpert tablet PC for device configuration (SMT70) running Windows 10 Pro 1703 64 EN, Endress+Hauser strongly recommends updating to the newest available Windows version.\nAs a general security measure Endress+Hauser strongly recommends to protect network access to the WIFI network with appropriate mechanisms. It is advised to configure the environment in order to run the devices in a protected IT environment.\n\nNote: This advisory will be updated as further details and/or software updates become available.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-11001', 'CSAFPID-11002', 'CSAFPID-11003']}}, {'cve': 'CVE-2017-13082', 'cwe': {'id': 'CWE-330', 'name': 'Use of Insufficiently Random Values'}, 'notes': [{'text': 'Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11r allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the fast BSS transmission (FT) handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2017-13082', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 8.1, 'attackVector': 'ADJACENT_NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N', 'temporalScore': 8.1, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'NONE', 'environmentalScore': 8.1, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-11001', 'CSAFPID-11002', 'CSAFPID-11003']}], 'remediations': [{'details': 'For Field Xpert handheld devices (SFX350/SFX370) running Windows Mobile, Endress+Hauser recommends to apply the security updates provided by Microsoft.\n\nIntermec/Honeywell as producer of the basis of the handheld provide the following security patch for the Windows Mobile operating system: SR18012500_802T_Cx70_WM65_ALL.CAB\n\nTo obtain this patch, please contact your local Endress+Hauser representative.\nIf you are using WPA-TKIP in your WLAN, you should switch to AES-CCMP immediately.\nFor Field Xpert tablet PC for device configuration (SMT70) running Windows 10 Pro 1703 64 EN, Endress+Hauser strongly recommends updating to the newest available Windows version.\nAs a general security measure Endress+Hauser strongly recommends to protect network access to the WIFI network with appropriate mechanisms. It is advised to configure the environment in order to run the devices in a protected IT environment.\n\nNote: This advisory will be updated as further details and/or software updates become available.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-11001', 'CSAFPID-11002', 'CSAFPID-11003']}}, {'cve': 'CVE-2017-13086', 'cwe': {'id': 'CWE-330', 'name': 'Use of Insufficiently Random Values'}, 'notes': [{'text': 'Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Tunneled Direct-Link Setup (TDLS) Peer Key (TPK) during the TDLS handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2017-13086', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 6.8, 'attackVector': 'ADJACENT_NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 6.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-11001', 'CSAFPID-11002', 'CSAFPID-11003']}], 'remediations': [{'details': 'For Field Xpert handheld devices (SFX350/SFX370) running Windows Mobile, Endress+Hauser recommends to apply the security updates provided by Microsoft.\n\nIntermec/Honeywell as producer of the basis of the handheld provide the following security patch for the Windows Mobile operating system: SR18012500_802T_Cx70_WM65_ALL.CAB\n\nTo obtain this patch, please contact your local Endress+Hauser representative.\nIf you are using WPA-TKIP in your WLAN, you should switch to AES-CCMP immediately.\nFor Field Xpert tablet PC for device configuration (SMT70) running Windows 10 Pro 1703 64 EN, Endress+Hauser strongly recommends updating to the newest available Windows version.\nAs a general security measure Endress+Hauser strongly recommends to protect network access to the WIFI network with appropriate mechanisms. It is advised to configure the environment in order to run the devices in a protected IT environment.\n\nNote: This advisory will be updated as further details and/or software updates become available.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-11001', 'CSAFPID-11002', 'CSAFPID-11003']}}, {'cve': 'CVE-2017-13087', 'cwe': {'id': 'CWE-330', 'name': 'Use of Insufficiently Random Values'}, 'notes': [{'text': 'Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Group Temporal Key (GTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame, allowing an attacker within radio range to replay frames from access points to clients.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2017-13087', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 5.3, 'attackVector': 'ADJACENT_NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N', 'temporalScore': 5.3, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 5.3, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-11001', 'CSAFPID-11002', 'CSAFPID-11003']}], 'remediations': [{'details': 'For Field Xpert handheld devices (SFX350/SFX370) running Windows Mobile, Endress+Hauser recommends to apply the security updates provided by Microsoft.\n\nIntermec/Honeywell as producer of the basis of the handheld provide the following security patch for the Windows Mobile operating system: SR18012500_802T_Cx70_WM65_ALL.CAB\n\nTo obtain this patch, please contact your local Endress+Hauser representative.\nIf you are using WPA-TKIP in your WLAN, you should switch to AES-CCMP immediately.\nFor Field Xpert tablet PC for device configuration (SMT70) running Windows 10 Pro 1703 64 EN, Endress+Hauser strongly recommends updating to the newest available Windows version.\nAs a general security measure Endress+Hauser strongly recommends to protect network access to the WIFI network with appropriate mechanisms. It is advised to configure the environment in order to run the devices in a protected IT environment.\n\nNote: This advisory will be updated as further details and/or software updates become available.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-11001', 'CSAFPID-11002', 'CSAFPID-11003']}}, {'cve': 'CVE-2017-13088', 'cwe': {'id': 'CWE-330', 'name': 'Use of Insufficiently Random Values'}, 'notes': [{'text': 'Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Integrity Group Temporal Key (IGTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame, allowing an attacker within radio range to replay frames from access points to clients.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2017-13088', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 5.3, 'attackVector': 'ADJACENT_NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N', 'temporalScore': 5.3, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 5.3, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-11001', 'CSAFPID-11002', 'CSAFPID-11003']}], 'remediations': [{'details': 'For Field Xpert handheld devices (SFX350/SFX370) running Windows Mobile, Endress+Hauser recommends to apply the security updates provided by Microsoft.\n\nIntermec/Honeywell as producer of the basis of the handheld provide the following security patch for the Windows Mobile operating system: SR18012500_802T_Cx70_WM65_ALL.CAB\n\nTo obtain this patch, please contact your local Endress+Hauser representative.\nIf you are using WPA-TKIP in your WLAN, you should switch to AES-CCMP immediately.\nFor Field Xpert tablet PC for device configuration (SMT70) running Windows 10 Pro 1703 64 EN, Endress+Hauser strongly recommends updating to the newest available Windows version.\nAs a general security measure Endress+Hauser strongly recommends to protect network access to the WIFI network with appropriate mechanisms. It is advised to configure the environment in order to run the devices in a protected IT environment.\n\nNote: This advisory will be updated as further details and/or software updates become available.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-11001', 'CSAFPID-11002', 'CSAFPID-11003']}}]}
50e6049d2a703bba166e01b3371ec039b993e2c8395b2020ba2702137be3e541
2026-05-29 08:30:37.139460+03:00
2026-05-29 08:30:37.139460+03:00
csaf_endresshauserag.ndjson
78cc7a6beecae6ccdd63fc5bc5fccf560322f2b91eb5384b680381bb7a0cef5f
{'document': {'lang': 'en-GB', 'notes': [{'text': 'The affected device has a web-based user interface with a role-based access system. Users with different roles have different write and read privileges. The access system is based on dynamic "tokens".', 'title': 'Summary', 'category': 'summary'}, {'text': 'The vulnerability is that user sessions are not closed correctly and a user with fewer rights is assigned the higher rights when he logs on.', 'title': 'Impact', 'category': 'description'}, {'text': 'Customers should configure a perimeter firewall to block traffic from untrusted networks and users to the device. These recommendations will be incorporated into the device documentation (operating instructions).\n\nChange default password for operator, service and admin account.\n\nEndress+Hauser will not change this behavior.\nCustomers are recommended to take the measures for Temporary Fix / Mitigation as described above.', 'title': 'Mitigation', 'category': 'description'}], 'title': 'Endress+Hauser: Ecograph T utilizing Webserver firmware version 1.x suffers from improper privilege management', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2020-021', 'status': 'final', 'aliases': ['VDE-2020-021'], 'version': '2', 'generator': {'date': '2025-04-11T07:53:45.584Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.23'}}, 'revision_history': [{'date': '2020-11-19T14:48:00.000Z', 'number': '1', 'summary': 'Initial revision.'}, {'date': '2025-04-11T07:00:00.000Z', 'number': '2', 'summary': 'Fix: version range'}], 'current_release_date': '2025-04-11T07:00:00.000Z', 'initial_release_date': '2020-11-19T14:48:00.000Z'}, 'publisher': {'name': 'Endress+Hauser AG', 'category': 'vendor', 'namespace': 'https://www.endress.com', 'contact_details': 'psirt@endress.com'}, 'references': [{'url': 'https://certvde.com/en/advisories/vendor/endress+hauser/', 'summary': 'CERT@VDE Security Advisories for Endress+Hauser', 'category': 'external'}, {'url': 'https://certvde.com/de/advisories/VDE-2020-021/', 'summary': 'VDE-2020-021: Endress+Hauser: Ecograph T utilizing Webserver firmware version 1.x suffers from improper privilege management - HTML', 'category': 'self'}, {'url': 'https://endress-hauser.csaf-tp.certvde.com/.well-known/csaf/white/2020/vde-2020-021.json', 'summary': 'VDE-2020-021: Endress+Hauser: Ecograph T utilizing Webserver firmware version 1.x suffers from improper privilege management - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}, {'summary': 'reported', 'organization': 'Maxim Rupp'}]}, 'product_tree': {'branches': [{'name': 'Endress+Hauser', 'branches': [{'name': 'Firmware', 'branches': [{'name': 'V1.0.0 (07/2013)<V2.0.0 (08/2015)', 'product': {'name': 'Firmware V1.0.0 (07/2013)<V2.0.0 (08/2015)', 'product_id': 'CSAFPID-21003'}, 'category': 'product_version_range'}], 'category': 'product_family'}, {'name': 'Hardware', 'branches': [{'name': 'Ecograph T', 'product': {'name': 'Hardware Ecograph T', 'product_id': 'CSAFPID-11002', 'product_identification_helper': {'model_numbers': ['RSG35']}}, 'category': 'product_name'}, {'name': 'Ecograph T Neutral/Private Label', 'product': {'name': 'Hardware Ecograph T Neutral/Private Label', 'product_id': 'CSAFPID-11001', 'product_identification_helper': {'model_numbers': ['ORSG35']}}, 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware V1.0.0 (07/2013)<V2.0.0 (08/2015) installed on Hardware Ecograph T Neutral/Private Label', 'product_id': 'CSAFPID-31001'}, 'product_reference': 'CSAFPID-21003', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware V1.0.0 (07/2013)<V2.0.0 (08/2015) installed on Hardware Ecograph T', 'product_id': 'CSAFPID-31002'}, 'product_reference': 'CSAFPID-21003', 'relates_to_product_reference': 'CSAFPID-11002'}], 'product_groups': [{'summary': 'Affected products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-31001', 'CSAFPID-31002']}]}, 'vulnerabilities': [{'cve': 'CVE-2020-12495', 'cwe': {'id': 'CWE-269', 'name': 'Improper Privilege Management'}, 'notes': [{'text': 'Endress+Hauser Ecograph T (Neutral/Private Label) (RSG35, ORSG35) with Firmware version prior to V2.0.0 is prone to improper privilege management. The affected device has a web-based user interface with a role-based access system. Users with different roles have different write and read privileges. The access system is based on dynamic "tokens". The vulnerability is that user sessions are not closed correctly and a user with fewer rights is assigned the higher rights when he logs on.', 'title': 'Description', 'category': 'description'}], 'title': 'CVE-2020-12495', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 8.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 8.8, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002']}], 'remediations': [{'details': 'Customers should configure a perimeter firewall to block traffic from untrusted networks and users to the device. These recommendations will be incorporated into the device documentation (operating instructions).\n\nChange default password for operator, service and admin account.\n\nEndress+Hauser will not change this behavior.\nCustomers are recommended to take the measures for Temporary Fix / Mitigation as described above.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-31001', 'CSAFPID-31002']}}]}
00813a8769ccf4046156cf0a54fcfcf9948e8fa659cbd5a0a2ea0affc9b09d94
2026-05-29 08:30:37.139460+03:00
2026-05-29 08:30:37.139460+03:00
csaf_endresshauserag.ndjson
fc3433c8b504ee115bcc83a4641bb21bab84a902b700d48dd2ea474c5bfb76db
{'document': {'lang': 'en-GB', 'notes': [{'text': "The firmware release has a dynamic token for each request submitted to the server, which makes repeating requests and analysis complex enough. Nevertheless, it's possible and during the analysis it was discovered that it also has an issue with the access-control matrix on the server-side.", 'title': 'Summary', 'category': 'summary'}, {'text': 'It was found that a user with low rights can get information from endpoints that should not be available to this user.', 'title': 'Impact', 'category': 'description'}, {'text': 'Customers should configure a perimeter firewall to block traffic from untrusted networks and users to the device. These recommendations will be incorporated into the device documentation (operating instructions)\nChange default password for operator, service and admin account.\n\nEndress+Hauser will not change this behavior.\nCustomers are recommended to take the measures for Temporary Fix / Mitigation as described above.', 'title': 'Mitigation', 'category': 'description'}], 'title': 'Endress+Hauser: Ecograph T utilizing Webserver firmware version 2.x exposes sensitive information', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2020-022', 'status': 'final', 'aliases': ['VDE-2020-022'], 'version': '4', 'generator': {'date': '2025-04-11T07:57:45.402Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.23'}}, 'revision_history': [{'date': '2020-11-19T14:48:00.000Z', 'number': '1', 'summary': 'Initial revision.'}, {'date': '2024-11-06T11:27:01.000Z', 'number': '2', 'summary': 'Fix: correct certvde domain, added alias, added self-reference'}, {'date': '2025-04-11T07:00:00.000Z', 'number': '3', 'summary': 'Fix: version range'}, {'date': '2025-05-14T13:00:14.000Z', 'number': '4', 'summary': 'Fix: added distribution'}], 'current_release_date': '2025-05-14T13:00:14.000Z', 'initial_release_date': '2020-11-19T14:48:00.000Z'}, 'publisher': {'name': 'Endress+Hauser AG', 'category': 'vendor', 'namespace': 'https://www.endress.com', 'contact_details': 'psirt@endress.com'}, 'references': [{'url': 'https://certvde.com/de/advisories/VDE-2020-022/', 'summary': 'VDE-2020-022: Endress+Hauser: Ecograph T utilizing Webserver firmware version 2.x exposes sensitive information - HTML', 'category': 'self'}, {'url': 'https://certvde.com/en/advisories/vendor/endress+hauser/', 'summary': 'CERT@VDE Security Advisories for Endress+Hauser', 'category': 'external'}, {'url': 'https://endress-hauser.csaf-tp.certvde.com/.well-known/csaf/white/2020/vde-2020-022.json', 'summary': 'VDE-2020-022: Endress+Hauser: Ecograph T utilizing Webserver firmware version 2.x exposes sensitive information - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'summary': 'coordination', 'organization': 'CERT@VDE'}, {'summary': 'reporting', 'organization': 'Maxim Rupp'}]}, 'product_tree': {'branches': [{'name': 'Endress+Hauser', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'Ecograph T', 'product': {'name': 'Endress+Hauser Hardware Ecograph T', 'product_id': 'CSAFPID-11003', 'product_identification_helper': {'model_numbers': ['RSG35']}}, 'category': 'product_name'}, {'name': 'Ecograph T Neutral/Private Label', 'product': {'name': 'Endress+Hauser Hardware Ecograph T Neutral/Private Label', 'product_id': 'CSAFPID-11004', 'product_identification_helper': {'model_numbers': ['ORSG35']}}, 'category': 'product_name'}, {'name': 'Memograph M', 'product': {'name': 'Endress+Hauser Hardware Memograph M', 'product_id': 'CSAFPID-11005', 'product_identification_helper': {'model_numbers': ['RSG45']}}, 'category': 'product_name'}, {'name': 'Memograph M Neutral/Private Label', 'product': {'name': 'Endress+Hauser Hardware Memograph M Neutral/Private Label', 'product_id': 'CSAFPID-11006', 'product_identification_helper': {'model_numbers': ['ORSG45']}}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': '>=V2.0.0 (08/2015)', 'product': {'name': 'Firmware >=V2.0.0 (08/2015)', 'product_id': 'CSAFPID-21002'}, 'category': 'product_version_range'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware >=V2.0.0 (08/2015) installed on Endress+Hauser Hardware Ecograph T', 'product_id': 'CSAFPID-31007'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11003'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware >=V2.0.0 (08/2015) installed on Endress+Hauser Hardware Ecograph T Neutral/Private Label', 'product_id': 'CSAFPID-31008'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11004'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware >=V2.0.0 (08/2015) installed on Endress+Hauser Hardware Memograph M', 'product_id': 'CSAFPID-31009'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11005'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware >=V2.0.0 (08/2015) installed on Endress+Hauser Hardware Memograph M Neutral/Private Label', 'product_id': 'CSAFPID-31010'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11006'}], 'product_groups': [{'summary': 'Affected products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-31007', 'CSAFPID-31008', 'CSAFPID-31009', 'CSAFPID-31010']}]}, 'vulnerabilities': [{'cve': 'CVE-2020-12496', 'cwe': {'id': 'CWE-200', 'name': 'Exposure of Sensitive Information to an Unauthorized Actor'}, 'notes': [{'text': "Endress+Hauser Ecograph T (Neutral/Private Label) (RSG35, ORSG35) and Memograph M (Neutral/Private Label) (RSG45, ORSG45) with Firmware version V2.0.0 and above is prone to exposure of sensitive information to an unauthorized actor. The firmware release has a dynamic token for each request submitted to the server, which makes repeating requests and analysis complex enough. Nevertheless, it's possible and during the analysis it was discovered that it also has an issue with the access-control matrix on the server-side. It was found that a user with low rights can get information from endpoints that should not be available to this user.", 'title': 'Description', 'category': 'description'}], 'title': 'CVE-2020-12496', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N', 'temporalScore': 6.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 6.5, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-31007', 'CSAFPID-31008', 'CSAFPID-31009', 'CSAFPID-31010']}], 'remediations': [{'details': 'Customers should configure a perimeter firewall to block traffic from untrusted networks and users to the device. These recommendations will be incorporated into the device documentation (operating instructions)\nChange default password for operator, service and admin account.\n\nEndress+Hauser will not change this behavior.\nCustomers are recommended to take the measures for Temporary Fix / Mitigation as described above.', 'category': 'mitigation', 'product_ids': ['CSAFPID-31007', 'CSAFPID-31008', 'CSAFPID-31009', 'CSAFPID-31010']}], 'product_status': {'known_affected': ['CSAFPID-31007', 'CSAFPID-31008', 'CSAFPID-31009', 'CSAFPID-31010']}}]}
ead2eebb7c48c84e56522ea232d9d702c6adfbb65639489d5f080081caa9585d
2026-05-29 08:30:37.139460+03:00
2026-05-29 08:30:37.139460+03:00
csaf_endresshauserag.ndjson
50d84f7b02dc5d940ff7414582d50278a70191984423e3a58ae256d46aa8bb99
{'document': {'lang': 'en-GB', 'notes': [{'text': 'For further Information please refer to WIBU Advisories directly at https://wibu.com/support/security-advisories.html and the aforementioned CVE-IDs.', 'title': 'Summary', 'category': 'summary'}, {'text': 'For further Information please refer to WIBU Advisories directly at https://wibu.com/support/security-advisories.html external link and the aforementioned CVE-IDs.', 'title': 'Impact', 'category': 'description'}, {'text': 'Most vulnerabilities have already been fixed in the current Code Meter versions 7.10. Use of this version requires additional mitigation measures to fix all CVEs. For detailed information please refer to WIBU SYSTEMS original Advisories at https://wibu.com/support/security-advisories.html.', 'title': 'Mitigation', 'category': 'description'}, {'text': 'WIBU SYSTEMS has released a new Code Meter Runtime version 7.10a dated on 16.9.2020. All the known vulnerabilities are fixed with this version. The version is available at https://www.wibu.com/support', 'title': 'Remedation', 'category': 'description'}], 'title': 'Endress+Hauser: Multiple products prone to WIBU CodeMeter vulnerabilities', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2020-031', 'status': 'final', 'aliases': ['VDE-2020-031'], 'version': '4', 'generator': {'date': '2025-04-11T08:10:32.428Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.23'}}, 'revision_history': [{'date': '2020-10-27T13:10:00.000Z', 'number': '1', 'summary': 'Initial revision.'}, {'date': '2024-11-06T11:27:01.000Z', 'number': '2', 'summary': 'Fix: added self-reference'}, {'date': '2025-04-11T07:00:00.000Z', 'number': '3', 'summary': 'Fix: version range, remove Issuing authority'}, {'date': '2025-05-14T13:00:14.000Z', 'number': '4', 'summary': 'Fix: added distribution'}], 'current_release_date': '2025-05-14T13:00:14.000Z', 'initial_release_date': '2020-10-27T13:10:00.000Z'}, 'publisher': {'name': 'Endress+Hauser AG', 'category': 'vendor', 'namespace': 'https://www.endress.com', 'contact_details': 'psirt@endress.com'}, 'references': [{'url': 'https://certvde.com/de/advisories/VDE-2020-031/', 'summary': 'VDE-2020-031: Endress+Hauser: Multiple products prone to WIBU CodeMeter vulnerabilities - HTML', 'category': 'self'}, {'url': 'https://certvde.com/de/advisories/vendor/endress+hauser/', 'summary': 'CERT@VDE Security Advisories for Endress+Hauser AG', 'category': 'external'}, {'url': 'https://endress-hauser.csaf-tp.certvde.com/.well-known/csaf/white/2020/vde-2020-031.json', 'summary': 'VDE-2020-031: Endress+Hauser: Multiple products prone to WIBU CodeMeter vulnerabilities - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'names': ['Sharon Brizinov', 'Tal Keren'], 'summary': 'reported', 'organization': 'Claroty'}, {'summary': 'coordination', 'organization': 'CERT@VDE'}, {'summary': 'coordination', 'organization': 'CISA'}, {'summary': 'coordination', 'organization': 'BSI'}]}, 'product_tree': {'branches': [{'name': 'Endress+Hauser', 'branches': [{'name': 'Software', 'branches': [{'name': 'DeviceCare', 'branches': [{'name': '1.02<=1.07', 'product': {'name': 'Software DeviceCare 1.02<=1.07', 'product_id': 'CSAFPID-51001', 'product_identification_helper': {'model_numbers': ['SFE 100']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'FieldCare', 'branches': [{'name': '2.15.00', 'product': {'name': 'Software FieldCare 2.15.00', 'product_id': 'CSAFPID-51002', 'product_identification_helper': {'model_numbers': ['SFE 500']}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Field Data Manager', 'branches': [{'name': '1.4.0<=1.5.1', 'product': {'name': 'Software Field Data Manager 1.4.0<=1.5.1', 'product_id': 'CSAFPID-51003', 'product_identification_helper': {'model_numbers': ['MS20', 'MS21']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'FieldXpert', 'branches': [{'name': '1.03<=1.05', 'product': {'name': 'Software FieldXpert 1.03<=1.05', 'product_id': 'CSAFPID-51004', 'product_identification_helper': {'model_numbers': ['SMT70', 'SMT77']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'OPC UA Connectivity Server', 'branches': [{'name': '1.2.0', 'product': {'name': 'Software OPC UA Connectivity Server 1.2.0', 'product_id': 'CSAFPID-51005'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'SupplyCare Enterprise', 'branches': [{'name': '3.0<=3.3', 'product': {'name': 'Software SupplyCare Enterprise 3.0<=3.3', 'product_id': 'CSAFPID-51006', 'product_identification_helper': {'model_numbers': ['SCE30B', 'SCE31B', 'SCE32B']}}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}, {'name': 'Wibu-Systems', 'branches': [{'name': 'Software', 'branches': [{'name': 'Codemeter', 'branches': [{'name': '<=7.10.', 'product': {'name': 'Software Codemeter <=7.10.', 'product_id': 'CSAFPID-51007'}, 'category': 'product_version_range'}, {'name': '7.10a', 'product': {'name': 'Software Codemeter 7.10a', 'product_id': 'CSAFPID-52008'}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'external_component_of', 'full_product_name': {'name': 'Software DeviceCare 1.02<=1.07 external component of Software Codemeter <=7.10.', 'product_id': 'CSAFPID-31001'}, 'product_reference': 'CSAFPID-51001', 'relates_to_product_reference': 'CSAFPID-51007'}, {'category': 'external_component_of', 'full_product_name': {'name': 'Software FieldCare 2.15.00 external component of Software Codemeter <=7.10.', 'product_id': 'CSAFPID-31002'}, 'product_reference': 'CSAFPID-51002', 'relates_to_product_reference': 'CSAFPID-51007'}, {'category': 'external_component_of', 'full_product_name': {'name': 'Software Field Data Manager 1.4.0<=1.5.1 external component of Software Codemeter <=7.10.', 'product_id': 'CSAFPID-31003'}, 'product_reference': 'CSAFPID-51003', 'relates_to_product_reference': 'CSAFPID-51007'}, {'category': 'external_component_of', 'full_product_name': {'name': 'Software FieldXpert 1.03<=1.05 external component of Software Codemeter <=7.10.', 'product_id': 'CSAFPID-31004'}, 'product_reference': 'CSAFPID-51004', 'relates_to_product_reference': 'CSAFPID-51007'}, {'category': 'external_component_of', 'full_product_name': {'name': 'Software OPC UA Connectivity Server 1.2.0 external component of Software Codemeter <=7.10.', 'product_id': 'CSAFPID-31005'}, 'product_reference': 'CSAFPID-51005', 'relates_to_product_reference': 'CSAFPID-51007'}, {'category': 'external_component_of', 'full_product_name': {'name': 'Software SupplyCare Enterprise 3.0<=3.3 external component of Software Codemeter <=7.10.', 'product_id': 'CSAFPID-31006'}, 'product_reference': 'CSAFPID-51006', 'relates_to_product_reference': 'CSAFPID-51007'}, {'category': 'external_component_of', 'full_product_name': {'name': 'Software DeviceCare 1.02<=1.07 external component of Software Codemeter 7.10a', 'product_id': 'CSAFPID-32001'}, 'product_reference': 'CSAFPID-51001', 'relates_to_product_reference': 'CSAFPID-52008'}, {'category': 'external_component_of', 'full_product_name': {'name': 'Software FieldCare 2.15.00 external component of Software Codemeter 7.10a', 'product_id': 'CSAFPID-32002'}, 'product_reference': 'CSAFPID-51002', 'relates_to_product_reference': 'CSAFPID-52008'}, {'category': 'external_component_of', 'full_product_name': {'name': 'Software Field Data Manager 1.4.0<=1.5.1 external component of Software Codemeter 7.10a', 'product_id': 'CSAFPID-32003'}, 'product_reference': 'CSAFPID-51003', 'relates_to_product_reference': 'CSAFPID-52008'}, {'category': 'external_component_of', 'full_product_name': {'name': 'Software FieldXpert 1.03<=1.05 external component of Software Codemeter 7.10a', 'product_id': 'CSAFPID-32004'}, 'product_reference': 'CSAFPID-51004', 'relates_to_product_reference': 'CSAFPID-52008'}, {'category': 'external_component_of', 'full_product_name': {'name': 'Software OPC UA Connectivity Server 1.2.0 external component of Software Codemeter 7.10a', 'product_id': 'CSAFPID-32005'}, 'product_reference': 'CSAFPID-51005', 'relates_to_product_reference': 'CSAFPID-52008'}, {'category': 'external_component_of', 'full_product_name': {'name': 'Software SupplyCare Enterprise 3.0<=3.3 external component of Software Codemeter 7.10a', 'product_id': 'CSAFPID-32006'}, 'product_reference': 'CSAFPID-51006', 'relates_to_product_reference': 'CSAFPID-52008'}], 'product_groups': [{'summary': 'Affected products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006']}, {'summary': 'Fixed products.', 'group_id': 'CSAFGID-0002', 'product_ids': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-32004', 'CSAFPID-32005', 'CSAFPID-32006']}]}, 'vulnerabilities': [{'cve': 'CVE-2020-14509', 'cwe': {'id': 'CWE-805', 'name': 'Buffer Access with Incorrect Length Value'}, 'notes': [{'text': '\nMultiple memory corruption vulnerabilities exist in CodeMeter (All versions prior to 7.10) where the packet parser mechanism does not verify length fields. An attacker could send specially crafted packets to exploit these vulnerabilities.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2020-14509', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006']}], 'remediations': [{'details': 'WIBU SYSTEMS has released a new Code Meter Runtime version 7.10a dated on 16.9.2020. All the known vulnerabilities are fixed with this version. The version is available at https://www.wibu.com/support ', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}, {'details': 'Most vulnerabilities have already been fixed in the current Code Meter versions 7.10. Use of this version requires additional mitigation measures to fix all CVEs. For detailed information please refer to WIBU SYSTEMS original Advisories at https://wibu.com/support/security-advisories.html.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-32004', 'CSAFPID-32005', 'CSAFPID-32006'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006']}}, {'cve': 'CVE-2020-14517', 'cwe': {'id': 'CWE-326', 'name': 'Inadequate Encryption Strength'}, 'notes': [{'text': 'Protocol encryption can be easily broken for CodeMeter (All versions prior to 6.90 are affected, including Version 6.90 or newer only if CodeMeter Runtime is running as server) and the server accepts external connections, which may allow an attacker to remotely communicate with the CodeMeter API.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2020-14517', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006']}], 'remediations': [{'details': 'WIBU SYSTEMS has released a new Code Meter Runtime version 7.10a dated on 16.9.2020. All the known vulnerabilities are fixed with this version. The version is available at https://www.wibu.com/support ', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}, {'details': 'Most vulnerabilities have already been fixed in the current Code Meter versions 7.10. Use of this version requires additional mitigation measures to fix all CVEs. For detailed information please refer to WIBU SYSTEMS original Advisories at https://wibu.com/support/security-advisories.html.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-32004', 'CSAFPID-32005', 'CSAFPID-32006'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006']}}, {'cve': 'CVE-2020-16233', 'cwe': {'id': 'CWE-404', 'name': 'Improper Resource Shutdown or Release'}, 'notes': [{'text': 'An attacker could send a specially crafted packet that could have CodeMeter (All versions prior to 7.10) send back packets containing data from the heap.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2020-16233', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'NONE', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006']}], 'remediations': [{'details': 'WIBU SYSTEMS has released a new Code Meter Runtime version 7.10a dated on 16.9.2020. All the known vulnerabilities are fixed with this version. The version is available at https://www.wibu.com/support ', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}, {'details': 'Most vulnerabilities have already been fixed in the current Code Meter versions 7.10. Use of this version requires additional mitigation measures to fix all CVEs. For detailed information please refer to WIBU SYSTEMS original Advisories at https://wibu.com/support/security-advisories.html.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-32004', 'CSAFPID-32005', 'CSAFPID-32006'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006']}}, {'cve': 'CVE-2020-14519', 'cwe': {'id': 'CWE-346', 'name': 'Origin Validation Error'}, 'notes': [{'text': '\nThis vulnerability allows an attacker to use the internal WebSockets API for CodeMeter (All versions prior to 7.00 are affected, including Version 7.0 or newer with the affected WebSockets API still enabled. This is especially relevant for systems or devices where a web browser is used to access a web server) via a specifically crafted Java Script payload, which may allow alteration or creation of license files for when combined with CVE-2020-14515.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2020-14519', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N', 'temporalScore': 7.5, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'NONE', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006']}], 'remediations': [{'details': 'WIBU SYSTEMS has released a new Code Meter Runtime version 7.10a dated on 16.9.2020. All the known vulnerabilities are fixed with this version. The version is available at https://www.wibu.com/support ', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}, {'details': 'Most vulnerabilities have already been fixed in the current Code Meter versions 7.10. Use of this version requires additional mitigation measures to fix all CVEs. For detailed information please refer to WIBU SYSTEMS original Advisories at https://wibu.com/support/security-advisories.html.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-32004', 'CSAFPID-32005', 'CSAFPID-32006'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006']}}, {'cve': 'CVE-2020-14513', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'CodeMeter (All versions prior to 6.81) and the software using it may crash while processing a specifically crafted license file due to unverified length fields.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2020-14513', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006']}], 'remediations': [{'details': 'WIBU SYSTEMS has released a new Code Meter Runtime version 7.10a dated on 16.9.2020. All the known vulnerabilities are fixed with this version. The version is available at https://www.wibu.com/support ', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}, {'details': 'Most vulnerabilities have already been fixed in the current Code Meter versions 7.10. Use of this version requires additional mitigation measures to fix all CVEs. For detailed information please refer to WIBU SYSTEMS original Advisories at https://wibu.com/support/security-advisories.html.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-32004', 'CSAFPID-32005', 'CSAFPID-32006'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006']}}, {'cve': 'CVE-2020-14515', 'cwe': {'id': 'CWE-347', 'name': 'Improper Verification of Cryptographic Signature'}, 'notes': [{'text': 'CodeMeter (All versions prior to 6.90 when using CmActLicense update files with CmActLicense Firm Code) has an issue in the license-file signature checking mechanism, which allows attackers to build arbitrary license files, including forging a valid license file as if it were a valid license file of an existing vendor. Only CmActLicense update files with CmActLicense Firm Code are affected.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2020-14515', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N', 'temporalScore': 7.5, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'NONE', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006']}], 'remediations': [{'details': 'WIBU SYSTEMS has released a new Code Meter Runtime version 7.10a dated on 16.9.2020. All the known vulnerabilities are fixed with this version. The version is available at https://www.wibu.com/support ', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}, {'details': 'Most vulnerabilities have already been fixed in the current Code Meter versions 7.10. Use of this version requires additional mitigation measures to fix all CVEs. For detailed information please refer to WIBU SYSTEMS original Advisories at https://wibu.com/support/security-advisories.html.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-32001', 'CSAFPID-32002', 'CSAFPID-32003', 'CSAFPID-32004', 'CSAFPID-32005', 'CSAFPID-32006'], 'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006']}}]}
7ba7103c403a4a1f75023b478803dd98e81051f236ec0e80651b8ea1f5d57c6b
2026-05-29 08:30:37.139460+03:00
2026-05-29 08:30:37.139460+03:00
csaf_endresshauserag.ndjson
8a1c67d6a997931b3781c63b72b8a539d3fdba5f8014f29b9b6f17d72ce6356a
{'document': {'lang': 'en-US', 'notes': [{'text': 'The fdtCONTAINER component is integrated into an application (host application). The fdtCONTAINER application is a specific host application which integrates the fdtCONTAINER component.\n\nThe fdtCONTAINER component exchanges binary data blobs with such a host application. Typically, the host application saves these binary data blobs into a project storage (project file or a project database).\n\nTo manipulate the data inside the project storage, the attacker needs write access to this project storage. Additionally, the manipulated project needs to be opened by the host application. It depends on the host application whether opening the project requires a user action or not. In\nfdtCONTAINER applications, the user has to open the manipulated project file manually.\n\nIn the case of opening a stored project, the deserialization of the manipulated data can be exploited.', 'title': 'Summary', 'category': 'summary'}, {'text': 'The engineering workstation, on which the host application is executed, might execute malicious code with the user rights of the host application.', 'title': 'Impact', 'category': 'description'}, {'text': '1. Exchange project data only via secure exchange services\n2. Use appropriate means to protect the project storage from unauthorized manipulation\n3. Do not open project data from an unknown source\n4. Reduce the user rights of the host application to the necessary minimum', 'title': 'Mitigation', 'category': 'description'}, {'text': 'Planned for future versions', 'title': 'Remediation', 'category': 'description'}], 'title': 'Endress+Hauser: Multiple Devices affected by fdtContainer vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2021-005', 'status': 'final', 'aliases': ['VDE-2021-005'], 'version': '2', 'generator': {'date': '2025-03-12T10:58:11.003Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.20'}}, 'revision_history': [{'date': '2021-03-01T06:39:00.000Z', 'number': '1', 'summary': 'Initial revision.'}, {'date': '2025-05-14T13:00:14.000Z', 'number': '2', 'summary': 'Fix: added distribution'}], 'current_release_date': '2025-05-14T13:00:14.000Z', 'initial_release_date': '2021-03-01T06:39:00.000Z'}, 'publisher': {'name': 'Endress+Hauser AG', 'category': 'vendor', 'namespace': 'https://www.endress.com', 'contact_details': 'psirt@endress.com'}, 'references': [{'url': 'https://certvde.com/de/advisories/vendor/endress+hauser/', 'summary': 'Endress+Hauser advisory overview at CERT@VDE', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/VDE-2021-005', 'summary': 'VDE-2021-005: Endress+Hauser: Multiple Devices affected by fdtContainer vulnerability - HTML', 'category': 'self'}, {'url': 'https://endress-hauser.csaf-tp.certvde.com/.well-known/csaf/white/2021/vde-2021-005.json', 'summary': 'VDE-2021-005: Endress+Hauser: Multiple Devices affected by fdtContainer vulnerability - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}, {'summary': 'reporting.', 'organization': 'M&M Software GmbH'}]}, 'product_tree': {'branches': [{'name': 'Endress+Hauser', 'branches': [{'name': 'Software', 'branches': [{'name': 'Asset Health Monitoring (FieldCare SFE500)', 'branches': [{'name': '<=2.15.01', 'product': {'name': 'Asset Health Monitoring (FieldCare SFE500) <=2.15.01', 'product_id': 'CSAFPID-51001', 'product_identification_helper': {'model_numbers': ['SRP700']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DeviceCare', 'branches': [{'name': '<=1.07.00', 'product': {'name': 'DeviceCare <=1.07.00', 'product_id': 'CSAFPID-51002', 'product_identification_helper': {'model_numbers': ['SFE100']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'FieldCare', 'branches': [{'name': '<=2.15.01', 'product': {'name': 'FieldCare <=2.15.01', 'product_id': 'CSAFPID-51003', 'product_identification_helper': {'model_numbers': ['SFE500']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Field Xpert', 'branches': [{'name': '<=1.05.00', 'product': {'name': 'Field Xpert <=1.05.00', 'product_id': 'CSAFPID-51004', 'product_identification_helper': {'model_numbers': ['SMT50', 'SMT70', 'SMT77']}}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}], 'product_groups': [{'summary': 'Affected Products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003', 'CSAFPID-51004']}]}, 'vulnerabilities': [{'cve': 'CVE-2020-12525', 'cwe': {'id': 'CWE-502', 'name': 'Deserialization of Untrusted Data'}, 'notes': [{'text': 'M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage.', 'category': 'description'}], 'title': 'CVE-2020-12525', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 7.3, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H', 'temporalScore': 7.3, 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.3, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003', 'CSAFPID-51004']}], 'remediations': [{'details': '1. Exchange project data only via secure exchange services\n2. Use appropriate means to protect the project storage from unauthorized manipulation\n3. Do not open project data from an unknown source\n4. Reduce the user rights of the host application to the necessary minimum', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Planned for future versions', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003', 'CSAFPID-51004']}}]}
6b3eea94b550c46977595c3ee114e6f089ef149c1d379b17eeab3ca6d619ebb1
2026-05-29 08:30:37.139460+03:00
2026-05-29 08:30:37.139460+03:00
csaf_endresshauserag.ndjson
7b45bfb70226740a4b245864a7f68b129713dc679f212397a62e9458d1855a9f
{'document': {'lang': 'en-US', 'notes': [{'text': 'Endress+Hauser products utilizing WPA2 are vulnerable to KRACK attacks.\nProline portfolio is a flow meter with an optional WLAN interface in the display. The flowmeters are only affected if the optional WLAN display is present.', 'title': 'Summary', 'category': 'summary'}, {'text': "The feasibility of modifying the configuration of the device depends on the configuration settings regarding the used protocol (for example: OPC UA, http) to communicate via WLAN.\n\n- Access to operator network via device isn't possible because bridging in the device isn't supported.\n- The WLAN passphrase isn't readable.\n- Via OPC UA: read/write data access isn't possible if encryption is activated.\n- Via Webserver and CDI-RJ45: read data is possible. Write data isn't possible if individual password is used.", 'title': 'Impact', 'category': 'description'}, {'text': 'If an immediate firmware update is not possible, the WLAN on the unit can also be switched off as a precautionary measure.', 'title': 'Mitigation', 'category': 'description'}, {'text': 'As a general security measure Endress+Hauser strongly recommends protecting network access to the WLAN network with appropriate mechanisms. It is advised to configure the environment according to best practices to run the devices in a protected IT environment. Further general recommendations apply for the affected products:\n\nActivate encryption for OPC UA\nFor Webserver and CDI-RJ45: Change device default password to individual password\nFor WLAN: Change WLAN default password to individual WLAN password', 'title': 'Recommendations', 'category': 'description'}, {'text': 'Endress+Hauser provides updated firmware versions for all related products from the Proline portfolio which fixes the vulnerability and recommends customers to update to the new fixed version. For support, please contact your local service center.', 'title': 'Remediation', 'category': 'description'}], 'title': 'Endress+Hauser: products utilizing WPA2 vulnerable to KRACK attacks', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2021-010', 'status': 'final', 'aliases': ['VDE-2021-010'], 'version': '2', 'generator': {'date': '2024-12-09T10:29:39.482Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.16'}}, 'revision_history': [{'date': '2021-05-15T09:00:00.000Z', 'number': '1', 'summary': 'Initial revision.'}, {'date': '2025-05-14T12:28:19.000Z', 'number': '2', 'summary': 'Fix: version space, added distribution'}], 'current_release_date': '2025-05-14T12:28:19.000Z', 'initial_release_date': '2021-05-18T09:00:00.000Z'}, 'publisher': {'name': 'Endress+Hauser AG', 'category': 'vendor', 'namespace': 'https://www.endress.com', 'contact_details': 'psirt@endress.com'}, 'references': [{'url': 'https://certvde.com/de/advisories/vendor/endress+hauser/', 'summary': 'Endress+Hauser advisory overview at CERT@VDE', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/VDE-2021-010', 'summary': 'VDE-2021-010: Endress+Hauser: products utilizing WPA2 vulnerable to KRACK attacks - HTML', 'category': 'self'}, {'url': 'https://endress-hauser.csaf-tp.certvde.com/.well-known/csaf/white/2021/vde-2021-010.json', 'summary': 'VDE-2021-010: Endress+Hauser: products utilizing WPA2 vulnerable to KRACK attacks - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}, {'names': ['Mathy Vanhoef'], 'summary': 'reporting.', 'organization': 'imec-DistriNet'}, {'names': ['KU Leuven'], 'summary': 'reporting.', 'organization': 'krackattacks'}]}, 'product_tree': {'branches': [{'name': 'Pepperl+Fuchs', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'Promag 300 with EtherNet/IP', 'product': {'name': 'Promag 300 with EtherNet/IP', 'product_id': 'CSAFPID-11001'}, 'category': 'product_name'}, {'name': 'Promag 300 with Foundation Fieldbus', 'product': {'name': 'Promag 300 with Foundation Fieldbus', 'product_id': 'CSAFPID-11002'}, 'category': 'product_name'}, {'name': 'Promag 300 with HART', 'product': {'name': 'Promag 300 with HART', 'product_id': 'CSAFPID-11003'}, 'category': 'product_name'}, {'name': 'Promag 300 with MODBUS', 'product': {'name': 'Promag 300 with MODBUS', 'product_id': 'CSAFPID-11004'}, 'category': 'product_name'}, {'name': 'Promag 300 with Profibus PA', 'product': {'name': 'Promag 300 with Profibus PA', 'product_id': 'CSAFPID-11005'}, 'category': 'product_name'}, {'name': 'Promag 300 with PROFINET', 'product': {'name': 'Promag 300 with PROFINET', 'product_id': 'CSAFPID-11006'}, 'category': 'product_name'}, {'name': 'Promag 400 with HART', 'product': {'name': 'Promag 400 with HART', 'product_id': 'CSAFPID-11007'}, 'category': 'product_name'}, {'name': 'Promag 500 with EtherNet/IP', 'product': {'name': 'Promag 500 with EtherNet/IP', 'product_id': 'CSAFPID-11008'}, 'category': 'product_name'}, {'name': 'Promag 500 with Foundation Fieldbus', 'product': {'name': 'Promag 500 with Foundation Fieldbus', 'product_id': 'CSAFPID-11009'}, 'category': 'product_name'}, {'name': 'Promag 500 with HART', 'product': {'name': 'Promag 500 with HART', 'product_id': 'CSAFPID-11010'}, 'category': 'product_name'}, {'name': 'Promag 500 with MODBUS', 'product': {'name': 'Promag 500 with MODBUS', 'product_id': 'CSAFPID-11011'}, 'category': 'product_name'}, {'name': 'Promag 500 with Profibus PA', 'product': {'name': 'Promag 500 with Profibus PA', 'product_id': 'CSAFPID-11012'}, 'category': 'product_name'}, {'name': 'Promag 500 with PROFINET', 'product': {'name': 'Promag 500 with PROFINET', 'product_id': 'CSAFPID-11013'}, 'category': 'product_name'}, {'name': 'Promass 300 with EtherNet/IP', 'product': {'name': 'Promass 300 with EtherNet/IP', 'product_id': 'CSAFPID-11014'}, 'category': 'product_name'}, {'name': 'Promass 300 with Foundation Fieldbus', 'product': {'name': 'Promass 300 with Foundation Fieldbus', 'product_id': 'CSAFPID-11015'}, 'category': 'product_name'}, {'name': 'Promass 300 with HART', 'product': {'name': 'Promass 300 with HART', 'product_id': 'CSAFPID-11016'}, 'category': 'product_name'}, {'name': 'Promass 300 with MODBUS', 'product': {'name': 'Promass 300 with MODBUS', 'product_id': 'CSAFPID-11017'}, 'category': 'product_name'}, {'name': 'Promass 300 with Profibus PA', 'product': {'name': 'Promass 300 with Profibus PA', 'product_id': 'CSAFPID-11018'}, 'category': 'product_name'}, {'name': 'Promass 300 with PROFINET', 'product': {'name': 'Promass 300 with PROFINET', 'product_id': 'CSAFPID-11019'}, 'category': 'product_name'}, {'name': 'Promass 500 with EtherNet/IP', 'product': {'name': 'Promass 500 with EtherNet/IP', 'product_id': 'CSAFPID-11020'}, 'category': 'product_name'}, {'name': 'Promass 500 with Foundation Fieldbus', 'product': {'name': 'Promass 500 with Foundation Fieldbus', 'product_id': 'CSAFPID-11021'}, 'category': 'product_name'}, {'name': 'Promass 500 with HART', 'product': {'name': 'Promass 500 with HART', 'product_id': 'CSAFPID-11022'}, 'category': 'product_name'}, {'name': 'Promass 500 with MODBUS', 'product': {'name': 'Promass 500 with MODBUS', 'product_id': 'CSAFPID-11023'}, 'category': 'product_name'}, {'name': 'Promass 500 with Profibus PA', 'product': {'name': 'Promass 500 with Profibus PA', 'product_id': 'CSAFPID-11024'}, 'category': 'product_name'}, {'name': 'Promass 500 with PROFINET', 'product': {'name': 'Promass 500 with PROFINET', 'product_id': 'CSAFPID-11025'}, 'category': 'product_name'}, {'name': 'Spare Display for Promag 300', 'product': {'name': 'Spare Display for Promag 300', 'product_id': 'CSAFPID-11026'}, 'category': 'product_name'}, {'name': 'Spare Display for Promag 400', 'product': {'name': 'Spare Display for Promag 400', 'product_id': 'CSAFPID-11027'}, 'category': 'product_name'}, {'name': 'Spare Display for Promag 500', 'product': {'name': 'Spare Display for Promag 500', 'product_id': 'CSAFPID-11028'}, 'category': 'product_name'}, {'name': 'Spare Display for Promass 300', 'product': {'name': 'Spare Display for Promass 300', 'product_id': 'CSAFPID-11029'}, 'category': 'product_name'}, {'name': 'Spare Display for Promass 500', 'product': {'name': 'Spare Display for Promass 500', 'product_id': 'CSAFPID-11030'}, 'category': 'product_name'}, {'name': 'Spare Transmitter for Promag 300 with EtherNet/IP', 'product': {'name': 'Spare Transmitter for Promag 300 with EtherNet/IP', 'product_id': 'CSAFPID-11031'}, 'category': 'product_name'}, {'name': 'Spare Transmitter for Promag 300 with Foundation Fieldbus', 'product': {'name': 'Spare Transmitter for Promag 300 with Foundation Fieldbus', 'product_id': 'CSAFPID-11032'}, 'category': 'product_name'}, {'name': 'Spare Transmitter for Promag 300 with HART', 'product': {'name': 'Spare Transmitter for Promag 300 with HART', 'product_id': 'CSAFPID-11033'}, 'category': 'product_name'}, {'name': 'Spare Transmitter for Promag 300 with MODBUS', 'product': {'name': 'Spare Transmitter for Promag 300 with MODBUS', 'product_id': 'CSAFPID-11034'}, 'category': 'product_name'}, {'name': 'Spare Transmitter for Promag 300 with Profibus PA', 'product': {'name': 'Spare Transmitter for Promag 300 with Profibus PA', 'product_id': 'CSAFPID-11035'}, 'category': 'product_name'}, {'name': 'Spare Transmitter for Promag 300 with PROFINET', 'product': {'name': 'Spare Transmitter for Promag 300 with PROFINET', 'product_id': 'CSAFPID-11036'}, 'category': 'product_name'}, {'name': 'Spare Transmitter for Promag 400 with HART', 'product': {'name': 'Spare Transmitter for Promag 400 with HART', 'product_id': 'CSAFPID-11037'}, 'category': 'product_name'}, {'name': 'Spare Transmitter for Promag 500 with EtherNet/IP', 'product': {'name': 'Spare Transmitter for Promag 500 with EtherNet/IP', 'product_id': 'CSAFPID-11038'}, 'category': 'product_name'}, {'name': 'Spare Transmitter for Promag 500 with Foundation Fieldbus', 'product': {'name': 'Spare Transmitter for Promag 500 with Foundation Fieldbus', 'product_id': 'CSAFPID-11039'}, 'category': 'product_name'}, {'name': 'Spare Transmitter for Promag 500 with HART', 'product': {'name': 'Spare Transmitter for Promag 500 with HART', 'product_id': 'CSAFPID-11040'}, 'category': 'product_name'}, {'name': 'Spare Transmitter for Promag 500 with MODBUS', 'product': {'name': 'Spare Transmitter for Promag 500 with MODBUS', 'product_id': 'CSAFPID-11041'}, 'category': 'product_name'}, {'name': 'Spare Transmitter for Promag 500 with Profibus PA', 'product': {'name': 'Spare Transmitter for Promag 500 with Profibus PA', 'product_id': 'CSAFPID-11042'}, 'category': 'product_name'}, {'name': 'Spare Transmitter for Promag 500 with PROFINET', 'product': {'name': 'Spare Transmitter for Promag 500 with PROFINET', 'product_id': 'CSAFPID-11043'}, 'category': 'product_name'}, {'name': 'Spare Transmitter for Promass 300 with EtherNet/IP', 'product': {'name': 'Spare Transmitter for Promass 300 with EtherNet/IP', 'product_id': 'CSAFPID-11044'}, 'category': 'product_name'}, {'name': 'Spare Transmitter for Promass 300 with Foundation Fieldbus', 'product': {'name': 'Spare Transmitter for Promass 300 with Foundation Fieldbus', 'product_id': 'CSAFPID-11045'}, 'category': 'product_name'}, {'name': 'Spare Transmitter for Promass 300 with HART', 'product': {'name': 'Spare Transmitter for Promass 300 with HART', 'product_id': 'CSAFPID-11046'}, 'category': 'product_name'}, {'name': 'Spare Transmitter for Promass 300 with MODBUS', 'product': {'name': 'Spare Transmitter for Promass 300 with MODBUS', 'product_id': 'CSAFPID-11047'}, 'category': 'product_name'}, {'name': 'Spare Transmitter for Promass 300 with Profibus PA', 'product': {'name': 'Spare Transmitter for Promass 300 with Profibus PA', 'product_id': 'CSAFPID-11048'}, 'category': 'product_name'}, {'name': 'Spare Transmitter for Promass 300 with PROFINET', 'product': {'name': 'Spare Transmitter for Promass 300 with PROFINET', 'product_id': 'CSAFPID-11049'}, 'category': 'product_name'}, {'name': 'Spare Transmitter for Promass 500 with EtherNet/IP', 'product': {'name': 'Spare Transmitter for Promass 500 with EtherNet/IP', 'product_id': 'CSAFPID-11050'}, 'category': 'product_name'}, {'name': 'Spare Transmitter for Promass 500 with Foundation Fieldbus', 'product': {'name': 'Spare Transmitter for Promass 500 with Foundation Fieldbus', 'product_id': 'CSAFPID-0061'}, 'category': 'product_name'}, {'name': 'Spare Transmitter for Promass 500 with HART', 'product': {'name': 'Spare Transmitter for Promass 500 with HART', 'product_id': 'CSAFPID-11052'}, 'category': 'product_name'}, {'name': 'Spare Transmitter for Promass 500 with MODBUS', 'product': {'name': 'Spare Transmitter for Promass 500 with MODBUS', 'product_id': 'CSAFPID-11053'}, 'category': 'product_name'}, {'name': 'Spare Transmitter for Promass 500 with Profibus PA', 'product': {'name': 'Spare Transmitter for Promass 500 with Profibus PA', 'product_id': 'CSAFPID-11054'}, 'category': 'product_name'}, {'name': 'Spare Transmitter for Promass 500 with PROFINET', 'product': {'name': 'Spare Transmitter for Promass 500 with PROFINET', 'product_id': 'CSAFPID-11055'}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': '<=01.01.02', 'product': {'name': 'Firmware <=01.01.02', 'product_id': 'CSAFPID-21001'}, 'category': 'product_version_range'}, {'name': '<=01.00.01', 'product': {'name': 'Firmware <=01.00.01', 'product_id': 'CSAFPID-21002'}, 'category': 'product_version_range'}, {'name': '<=01.01.01', 'product': {'name': 'Firmware <=01.01.01', 'product_id': 'CSAFPID-21003'}, 'category': 'product_version_range'}, {'name': '<=01.00.02', 'product': {'name': 'Firmware <=01.00.02', 'product_id': 'CSAFPID-21004'}, 'category': 'product_version_range'}, {'name': '<=01.00.03', 'product': {'name': 'Firmware <=01.00.03', 'product_id': 'CSAFPID-21005'}, 'category': 'product_version_range'}, {'name': '<=02.00.01', 'product': {'name': 'Firmware <=02.00.01', 'product_id': 'CSAFPID-21006'}, 'category': 'product_version_range'}, {'name': '<=01.01.00', 'product': {'name': 'Firmware <=01.01.00', 'product_id': 'CSAFPID-21007'}, 'category': 'product_version_range'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.01.02 installed on Promag 300 with EtherNet/IP', 'product_id': 'CSAFPID-31001'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.00.01 installed on Promag 300 with Foundation Fieldbus', 'product_id': 'CSAFPID-31002'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11002'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.01.01 installed on Promag 300 with HART', 'product_id': 'CSAFPID-31003'}, 'product_reference': 'CSAFPID-21003', 'relates_to_product_reference': 'CSAFPID-11003'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.00.02 installed on Promag 300 with MODBUS', 'product_id': 'CSAFPID-31004'}, 'product_reference': 'CSAFPID-21004', 'relates_to_product_reference': 'CSAFPID-11004'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.00.03 installed on Promag 300 with Profibus PA', 'product_id': 'CSAFPID-31005'}, 'product_reference': 'CSAFPID-21005', 'relates_to_product_reference': 'CSAFPID-11005'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.00.01 installed on Promag 300 with PROFINET', 'product_id': 'CSAFPID-31006'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11006'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=02.00.01 installed on Promag 400 with HART', 'product_id': 'CSAFPID-31007'}, 'product_reference': 'CSAFPID-21006', 'relates_to_product_reference': 'CSAFPID-11007'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.01.02 installed on Promag 500 with EtherNet/IP', 'product_id': 'CSAFPID-31008'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11008'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.00.01 installed on Promag 500 with Foundation Fieldbus', 'product_id': 'CSAFPID-31009'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11009'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.01.01 installed on Promag 500 with HART', 'product_id': 'CSAFPID-31010'}, 'product_reference': 'CSAFPID-21003', 'relates_to_product_reference': 'CSAFPID-11010'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.00.02 installed on Promag 500 with MODBUS', 'product_id': 'CSAFPID-31011'}, 'product_reference': 'CSAFPID-21004', 'relates_to_product_reference': 'CSAFPID-11011'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.00.03 installed on Promag 500 with Profibus PA', 'product_id': 'CSAFPID-31012'}, 'product_reference': 'CSAFPID-21005', 'relates_to_product_reference': 'CSAFPID-11012'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.00.01 installed on Promag 500 with PROFINET', 'product_id': 'CSAFPID-31013'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11013'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.01.02 installed on Promass 300 with EtherNet/IP', 'product_id': 'CSAFPID-31014'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11014'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.00.01 installed on Promass 300 with Foundation Fieldbus', 'product_id': 'CSAFPID-31015'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11015'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.01.02 installed on Promass 300 with HART', 'product_id': 'CSAFPID-31016'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11016'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.00.02 installed on Promass 300 with MODBUS', 'product_id': 'CSAFPID-31017'}, 'product_reference': 'CSAFPID-21004', 'relates_to_product_reference': 'CSAFPID-11017'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.00.03 installed on Promass 300 with Profibus PA', 'product_id': 'CSAFPID-31018'}, 'product_reference': 'CSAFPID-21005', 'relates_to_product_reference': 'CSAFPID-11018'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.00.01 installed on Promass 300 with PROFINET', 'product_id': 'CSAFPID-31019'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11019'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.01.02 installed on Promass 500 with EtherNet/IP', 'product_id': 'CSAFPID-31020'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11020'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.00.01 installed on Spare Transmitter for Promass 500 with Foundation Fieldbus', 'product_id': 'CSAFPID-31021'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-0061'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.01.02 installed on Promass 500 with HART', 'product_id': 'CSAFPID-31022'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11022'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.00.02 installed on Promass 500 with MODBUS', 'product_id': 'CSAFPID-31023'}, 'product_reference': 'CSAFPID-21004', 'relates_to_product_reference': 'CSAFPID-11023'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.00.03 installed on Promass 500 with Profibus PA', 'product_id': 'CSAFPID-31024'}, 'product_reference': 'CSAFPID-21005', 'relates_to_product_reference': 'CSAFPID-11024'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.00.01 installed on Promass 500 with PROFINET', 'product_id': 'CSAFPID-31025'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11025'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.00.01 installed on Spare Transmitter for Promag 300 with Foundation Fieldbus', 'product_id': 'CSAFPID-31026'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11032'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.01.01 installed on Spare Transmitter for Promag 300 with HART', 'product_id': 'CSAFPID-31027'}, 'product_reference': 'CSAFPID-21003', 'relates_to_product_reference': 'CSAFPID-11033'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.00.02 installed on Spare Transmitter for Promag 300 with MODBUS', 'product_id': 'CSAFPID-31028'}, 'product_reference': 'CSAFPID-21004', 'relates_to_product_reference': 'CSAFPID-11034'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.00.03 installed on Spare Transmitter for Promag 300 with Profibus PA', 'product_id': 'CSAFPID-31029'}, 'product_reference': 'CSAFPID-21005', 'relates_to_product_reference': 'CSAFPID-11035'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.00.01 installed on Spare Transmitter for Promag 300 with PROFINET', 'product_id': 'CSAFPID-31030'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11036'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=02.00.01 installed on Spare Transmitter for Promag 400 with HART', 'product_id': 'CSAFPID-31031'}, 'product_reference': 'CSAFPID-21006', 'relates_to_product_reference': 'CSAFPID-11037'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.01.02 installed on Spare Transmitter for Promag 500 with EtherNet/IP', 'product_id': 'CSAFPID-31032'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11038'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.00.01 installed on Spare Transmitter for Promag 500 with Foundation Fieldbus', 'product_id': 'CSAFPID-31033'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11039'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.01.01 installed on Spare Transmitter for Promag 500 with HART', 'product_id': 'CSAFPID-31034'}, 'product_reference': 'CSAFPID-21003', 'relates_to_product_reference': 'CSAFPID-11040'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.00.02 installed on Spare Transmitter for Promag 500 with MODBUS', 'product_id': 'CSAFPID-31035'}, 'product_reference': 'CSAFPID-21004', 'relates_to_product_reference': 'CSAFPID-11041'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.00.03 installed on Spare Transmitter for Promag 500 with Profibus PA', 'product_id': 'CSAFPID-31036'}, 'product_reference': 'CSAFPID-21005', 'relates_to_product_reference': 'CSAFPID-11042'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.00.01 installed on Spare Transmitter for Promag 500 with PROFINET', 'product_id': 'CSAFPID-31037'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11043'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.01.02 installed on Spare Transmitter for Promass 300 with EtherNet/IP', 'product_id': 'CSAFPID-31038'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11044'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.00.01 installed on Spare Transmitter for Promass 300 with Foundation Fieldbus', 'product_id': 'CSAFPID-31039'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11045'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.01.02 installed on Spare Transmitter for Promass 300 with HART', 'product_id': 'CSAFPID-31040'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11046'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.00.02 installed on Spare Transmitter for Promass 300 with MODBUS', 'product_id': 'CSAFPID-31041'}, 'product_reference': 'CSAFPID-21004', 'relates_to_product_reference': 'CSAFPID-11047'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.00.03 installed on Spare Transmitter for Promass 300 with Profibus PA', 'product_id': 'CSAFPID-31042'}, 'product_reference': 'CSAFPID-21005', 'relates_to_product_reference': 'CSAFPID-11048'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.00.01 installed on Spare Transmitter for Promass 300 with PROFINET', 'product_id': 'CSAFPID-31043'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11049'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.01.02 installed on Spare Transmitter for Promass 500 with EtherNet/IP', 'product_id': 'CSAFPID-31044'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11050'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.00.01 installed on Spare Transmitter for Promass 500 with Foundation Fieldbus', 'product_id': 'CSAFPID-31045'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-0061'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.01.02 installed on Spare Transmitter for Promass 500 with HART', 'product_id': 'CSAFPID-31046'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11052'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.00.02 installed on Spare Transmitter for Promass 500 with MODBUS', 'product_id': 'CSAFPID-31047'}, 'product_reference': 'CSAFPID-21004', 'relates_to_product_reference': 'CSAFPID-11053'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.00.03 installed on Spare Transmitter for Promass 500 with Profibus PA', 'product_id': 'CSAFPID-31048'}, 'product_reference': 'CSAFPID-21005', 'relates_to_product_reference': 'CSAFPID-11054'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.00.01 installed on Spare Transmitter for Promass 500 with PROFINET', 'product_id': 'CSAFPID-31049'}, 'product_reference': 'CSAFPID-21002', 'relates_to_product_reference': 'CSAFPID-11055'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.01.00 installed on Spare Display for Promag 300', 'product_id': 'CSAFPID-31050'}, 'product_reference': 'CSAFPID-21007', 'relates_to_product_reference': 'CSAFPID-11026'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.01.00 installed on Spare Display for Promag 400', 'product_id': 'CSAFPID-31051'}, 'product_reference': 'CSAFPID-21007', 'relates_to_product_reference': 'CSAFPID-11027'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.01.00 installed on Spare Display for Promag 500', 'product_id': 'CSAFPID-31052'}, 'product_reference': 'CSAFPID-21007', 'relates_to_product_reference': 'CSAFPID-11028'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.01.00 installed on Spare Display for Promass 300', 'product_id': 'CSAFPID-31053'}, 'product_reference': 'CSAFPID-21007', 'relates_to_product_reference': 'CSAFPID-11029'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.01.00 installed on Spare Display for Promass 500', 'product_id': 'CSAFPID-31054'}, 'product_reference': 'CSAFPID-21007', 'relates_to_product_reference': 'CSAFPID-11030'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware <=01.01.02 installed on Spare Transmitter for Promag 300 with EtherNet/IP', 'product_id': 'CSAFPID-31055'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11031'}], 'product_groups': [{'summary': 'Affected Products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007', 'CSAFPID-31008', 'CSAFPID-31009', 'CSAFPID-31010', 'CSAFPID-31011', 'CSAFPID-31012', 'CSAFPID-31013', 'CSAFPID-31014', 'CSAFPID-31015', 'CSAFPID-31016', 'CSAFPID-31017', 'CSAFPID-31018', 'CSAFPID-31019', 'CSAFPID-31020', 'CSAFPID-31021', 'CSAFPID-31022', 'CSAFPID-31023', 'CSAFPID-31024', 'CSAFPID-31025', 'CSAFPID-31026', 'CSAFPID-31027', 'CSAFPID-31028', 'CSAFPID-31029', 'CSAFPID-31030', 'CSAFPID-31031', 'CSAFPID-31032', 'CSAFPID-31033', 'CSAFPID-31034', 'CSAFPID-31035', 'CSAFPID-31036', 'CSAFPID-31037', 'CSAFPID-31038', 'CSAFPID-31039', 'CSAFPID-31040', 'CSAFPID-31041', 'CSAFPID-31042', 'CSAFPID-31043', 'CSAFPID-31044', 'CSAFPID-31045', 'CSAFPID-31046', 'CSAFPID-31047', 'CSAFPID-31048', 'CSAFPID-31049', 'CSAFPID-31050', 'CSAFPID-31051', 'CSAFPID-31052', 'CSAFPID-31053', 'CSAFPID-31054', 'CSAFPID-31055']}]}, 'vulnerabilities': [{'cve': 'CVE-2017-13077', 'cwe': {'id': 'CWE-330', 'name': 'Use of Insufficiently Random Values'}, 'notes': [{'text': 'Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the four-way handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.', 'title': 'Vulnerability Description', 'audience': 'all', 'category': 'description'}], 'title': 'CVE-2017-13077', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 6.8, 'attackVector': 'ADJACENT_NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N', 'temporalScore': 6.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 6.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007', 'CSAFPID-31008', 'CSAFPID-31009', 'CSAFPID-31010', 'CSAFPID-31011', 'CSAFPID-31012', 'CSAFPID-31013', 'CSAFPID-31014', 'CSAFPID-31015', 'CSAFPID-31016', 'CSAFPID-31017', 'CSAFPID-31018', 'CSAFPID-31019', 'CSAFPID-31020', 'CSAFPID-31021', 'CSAFPID-31022', 'CSAFPID-31023', 'CSAFPID-31024', 'CSAFPID-31025', 'CSAFPID-31026', 'CSAFPID-31027', 'CSAFPID-31028', 'CSAFPID-31029', 'CSAFPID-31030', 'CSAFPID-31031', 'CSAFPID-31032', 'CSAFPID-31033', 'CSAFPID-31034', 'CSAFPID-31035', 'CSAFPID-31036', 'CSAFPID-31037', 'CSAFPID-31038', 'CSAFPID-31039', 'CSAFPID-31040', 'CSAFPID-31041', 'CSAFPID-31042', 'CSAFPID-31043', 'CSAFPID-31044', 'CSAFPID-31045', 'CSAFPID-31046', 'CSAFPID-31047', 'CSAFPID-31048', 'CSAFPID-31049', 'CSAFPID-31050', 'CSAFPID-31051', 'CSAFPID-31052', 'CSAFPID-31053', 'CSAFPID-31054', 'CSAFPID-31055']}], 'remediations': [{'details': 'If an immediate firmware update is not possible, the WLAN on the unit can also be switched off as a precautionary measure.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Endress+Hauser provides updated firmware versions for all related products from the Proline portfolio which fixes the vulnerability and recommends customers to update to the new fixed version. For support, please contact your local service center.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007', 'CSAFPID-31008', 'CSAFPID-31009', 'CSAFPID-31010', 'CSAFPID-31011', 'CSAFPID-31012', 'CSAFPID-31013', 'CSAFPID-31014', 'CSAFPID-31015', 'CSAFPID-31016', 'CSAFPID-31017', 'CSAFPID-31018', 'CSAFPID-31019', 'CSAFPID-31020', 'CSAFPID-31021', 'CSAFPID-31022', 'CSAFPID-31023', 'CSAFPID-31024', 'CSAFPID-31025', 'CSAFPID-31026', 'CSAFPID-31027', 'CSAFPID-31028', 'CSAFPID-31029', 'CSAFPID-31030', 'CSAFPID-31031', 'CSAFPID-31032', 'CSAFPID-31033', 'CSAFPID-31034', 'CSAFPID-31035', 'CSAFPID-31036', 'CSAFPID-31037', 'CSAFPID-31038', 'CSAFPID-31039', 'CSAFPID-31040', 'CSAFPID-31041', 'CSAFPID-31042', 'CSAFPID-31043', 'CSAFPID-31044', 'CSAFPID-31045', 'CSAFPID-31046', 'CSAFPID-31047', 'CSAFPID-31048', 'CSAFPID-31049', 'CSAFPID-31050', 'CSAFPID-31051', 'CSAFPID-31052', 'CSAFPID-31053', 'CSAFPID-31054', 'CSAFPID-31055']}}, {'cve': 'CVE-2017-13078', 'cwe': {'id': 'CWE-330', 'name': 'Use of Insufficiently Random Values'}, 'notes': [{'text': 'Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the four-way handshake, allowing an attacker within radio range to replay frames from access points to clients.', 'title': 'Vulnerability Description', 'audience': 'all', 'category': 'description'}], 'title': 'CVE-2017-13078', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 5.3, 'attackVector': 'ADJACENT_NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N', 'temporalScore': 5.3, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 5.3, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007', 'CSAFPID-31008', 'CSAFPID-31009', 'CSAFPID-31010', 'CSAFPID-31011', 'CSAFPID-31012', 'CSAFPID-31013', 'CSAFPID-31014', 'CSAFPID-31015', 'CSAFPID-31016', 'CSAFPID-31017', 'CSAFPID-31018', 'CSAFPID-31019', 'CSAFPID-31020', 'CSAFPID-31021', 'CSAFPID-31022', 'CSAFPID-31023', 'CSAFPID-31024', 'CSAFPID-31025', 'CSAFPID-31026', 'CSAFPID-31027', 'CSAFPID-31028', 'CSAFPID-31029', 'CSAFPID-31030', 'CSAFPID-31031', 'CSAFPID-31032', 'CSAFPID-31033', 'CSAFPID-31034', 'CSAFPID-31035', 'CSAFPID-31036', 'CSAFPID-31037', 'CSAFPID-31038', 'CSAFPID-31039', 'CSAFPID-31040', 'CSAFPID-31041', 'CSAFPID-31042', 'CSAFPID-31043', 'CSAFPID-31044', 'CSAFPID-31045', 'CSAFPID-31046', 'CSAFPID-31047', 'CSAFPID-31048', 'CSAFPID-31049', 'CSAFPID-31050', 'CSAFPID-31051', 'CSAFPID-31052', 'CSAFPID-31053', 'CSAFPID-31054', 'CSAFPID-31055']}], 'remediations': [{'details': 'If an immediate firmware update is not possible, the WLAN on the unit can also be switched off as a precautionary measure.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Endress+Hauser provides updated firmware versions for all related products from the Proline portfolio which fixes the vulnerability and recommends customers to update to the new fixed version. For support, please contact your local service center.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007', 'CSAFPID-31008', 'CSAFPID-31009', 'CSAFPID-31010', 'CSAFPID-31011', 'CSAFPID-31012', 'CSAFPID-31013', 'CSAFPID-31014', 'CSAFPID-31015', 'CSAFPID-31016', 'CSAFPID-31017', 'CSAFPID-31018', 'CSAFPID-31019', 'CSAFPID-31020', 'CSAFPID-31021', 'CSAFPID-31022', 'CSAFPID-31023', 'CSAFPID-31024', 'CSAFPID-31025', 'CSAFPID-31026', 'CSAFPID-31027', 'CSAFPID-31028', 'CSAFPID-31029', 'CSAFPID-31030', 'CSAFPID-31031', 'CSAFPID-31032', 'CSAFPID-31033', 'CSAFPID-31034', 'CSAFPID-31035', 'CSAFPID-31036', 'CSAFPID-31037', 'CSAFPID-31038', 'CSAFPID-31039', 'CSAFPID-31040', 'CSAFPID-31041', 'CSAFPID-31042', 'CSAFPID-31043', 'CSAFPID-31044', 'CSAFPID-31045', 'CSAFPID-31046', 'CSAFPID-31047', 'CSAFPID-31048', 'CSAFPID-31049', 'CSAFPID-31050', 'CSAFPID-31051', 'CSAFPID-31052', 'CSAFPID-31053', 'CSAFPID-31054', 'CSAFPID-31055']}}, {'cve': 'CVE-2017-13080', 'cwe': {'id': 'CWE-330', 'name': 'Use of Insufficiently Random Values'}, 'notes': [{'text': 'Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the group key handshake, allowing an attacker within radio range to replay frames from access points to clients.', 'title': 'Vulnerability Description', 'audience': 'all', 'category': 'description'}], 'title': 'CVE-2017-13080', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 5.3, 'attackVector': 'ADJACENT_NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N', 'temporalScore': 5.3, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 5.3, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007', 'CSAFPID-31008', 'CSAFPID-31009', 'CSAFPID-31010', 'CSAFPID-31011', 'CSAFPID-31012', 'CSAFPID-31013', 'CSAFPID-31014', 'CSAFPID-31015', 'CSAFPID-31016', 'CSAFPID-31017', 'CSAFPID-31018', 'CSAFPID-31019', 'CSAFPID-31020', 'CSAFPID-31021', 'CSAFPID-31022', 'CSAFPID-31023', 'CSAFPID-31024', 'CSAFPID-31025', 'CSAFPID-31026', 'CSAFPID-31027', 'CSAFPID-31028', 'CSAFPID-31029', 'CSAFPID-31030', 'CSAFPID-31031', 'CSAFPID-31032', 'CSAFPID-31033', 'CSAFPID-31034', 'CSAFPID-31035', 'CSAFPID-31036', 'CSAFPID-31037', 'CSAFPID-31038', 'CSAFPID-31039', 'CSAFPID-31040', 'CSAFPID-31041', 'CSAFPID-31042', 'CSAFPID-31043', 'CSAFPID-31044', 'CSAFPID-31045', 'CSAFPID-31046', 'CSAFPID-31047', 'CSAFPID-31048', 'CSAFPID-31049', 'CSAFPID-31050', 'CSAFPID-31051', 'CSAFPID-31052', 'CSAFPID-31053', 'CSAFPID-31054', 'CSAFPID-31055']}], 'remediations': [{'details': 'If an immediate firmware update is not possible, the WLAN on the unit can also be switched off as a precautionary measure.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Endress+Hauser provides updated firmware versions for all related products from the Proline portfolio which fixes the vulnerability and recommends customers to update to the new fixed version. For support, please contact your local service center.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006', 'CSAFPID-31007', 'CSAFPID-31008', 'CSAFPID-31009', 'CSAFPID-31010', 'CSAFPID-31011', 'CSAFPID-31012', 'CSAFPID-31013', 'CSAFPID-31014', 'CSAFPID-31015', 'CSAFPID-31016', 'CSAFPID-31017', 'CSAFPID-31018', 'CSAFPID-31019', 'CSAFPID-31020', 'CSAFPID-31021', 'CSAFPID-31022', 'CSAFPID-31023', 'CSAFPID-31024', 'CSAFPID-31025', 'CSAFPID-31026', 'CSAFPID-31027', 'CSAFPID-31028', 'CSAFPID-31029', 'CSAFPID-31030', 'CSAFPID-31031', 'CSAFPID-31032', 'CSAFPID-31033', 'CSAFPID-31034', 'CSAFPID-31035', 'CSAFPID-31036', 'CSAFPID-31037', 'CSAFPID-31038', 'CSAFPID-31039', 'CSAFPID-31040', 'CSAFPID-31041', 'CSAFPID-31042', 'CSAFPID-31043', 'CSAFPID-31044', 'CSAFPID-31045', 'CSAFPID-31046', 'CSAFPID-31047', 'CSAFPID-31048', 'CSAFPID-31049', 'CSAFPID-31050', 'CSAFPID-31051', 'CSAFPID-31052', 'CSAFPID-31053', 'CSAFPID-31054', 'CSAFPID-31055']}}]}
24ca4fc1f9942c18b435a1c43b066f02af8dbf4220c9001c0077c33a1812daf3
2026-05-29 08:30:37.139460+03:00
2026-05-29 08:30:37.139460+03:00
csaf_endresshauserag.ndjson
da81f656dde6037998d26abdd9484dd34de6ef46a71bc5d6704f4fff5a594f51
{'document': {'lang': 'en-US', 'notes': [{'text': 'Promass 83 devices utilizing 499ES EtherNet/IP (ENIP) Stack by Real Time Automation (RTA) are vulnerable to a stack-based buffer overflow.\n\nUpdate A, 2021-10-07:\n\nadded credits\nchanged title from "ENDRESS+HAUSER: Promass 83 with Ether/IP affected by DoS vulnerability" to "ENDRESS+HAUSER: Promass 83 with EtherNet/IP affected by a stack-based buffer overflow"', 'title': 'Summary', 'category': 'summary'}, {'text': 'The vulnerability described can lead to a denial of service or even remote code execution.', 'title': 'Impact', 'category': 'description'}, {'text': 'If an immediate firmware update is not possible, the only way to prevent an attack is to disable communication via EtherNet/IP.', 'title': 'Mitigation', 'category': 'description'}, {'text': 'Endress+Hauser provides updated firmware versions (Firmware versions >1.00.00) for the related product from the Proline portfolio which fixes the vulnerability. Endress+Hauser strongly recommends customers to update to the new fixed version. For support, please contact your local service center.', 'title': 'Remediation', 'category': 'description'}], 'title': 'Endress+Hauser: Promass 83 with EtherNet/IP affected by a stack-based buffer overflow', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2021-040', 'status': 'final', 'aliases': ['VDE-2021-040'], 'version': '3', 'generator': {'date': '2025-01-22T15:06:26.010Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.17'}}, 'revision_history': [{'date': '2021-10-04T12:30:00.000Z', 'number': '1', 'summary': 'Initial revision.'}, {'date': '2021-10-07T10:00:00.000Z', 'number': '2', 'summary': 'Update A'}, {'date': '2025-05-14T12:28:19.000Z', 'number': '3', 'summary': 'Fix: firmware category, added distribution'}], 'current_release_date': '2025-05-14T12:28:19.000Z', 'initial_release_date': '2021-10-04T12:30:00.000Z'}, 'publisher': {'name': 'Endress+Hauser AG', 'category': 'vendor', 'namespace': 'https://www.endress.com', 'contact_details': 'psirt@endress.com'}, 'references': [{'url': 'https://certvde.com/de/advisories/vendor/endress+hauser/', 'summary': 'Endress+Hauser advisory overview at CERT@VDE', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/VDE-2021-040', 'summary': 'VDE-2021-040: Endress+Hauser: Promass 83 with EtherNet/IP affected by a stack-based buffer overflow - HTML', 'category': 'self'}, {'url': 'https://endress-hauser.csaf-tp.certvde.com/.well-known/csaf/white/2021/vde-2021-040.json', 'summary': 'VDE-2021-040: Endress+Hauser: Promass 83 with EtherNet/IP affected by a stack-based buffer overflow - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}, {'names': [' Sharon Brizinov'], 'summary': 'reported', 'organization': 'Claroty'}]}, 'product_tree': {'branches': [{'name': 'Endress+Hauser', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'Promass 83', 'product': {'name': 'Promass 83', 'product_id': 'CSAFPID-11001'}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': '1.00.00', 'product': {'name': 'Firmware 1.00.00', 'product_id': 'CSAFPID-21001'}, 'category': 'product_version'}, {'name': '>1.00.00', 'product': {'name': 'Firmware >1.00.00', 'product_id': 'CSAFPID-22001'}, 'category': 'product_version_range'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware 1.00.00 installed on Promass 83', 'product_id': 'CSAFPID-31001'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware >1.00.00 installed on Promass 83', 'product_id': 'CSAFPID-32001'}, 'product_reference': 'CSAFPID-22001', 'relates_to_product_reference': 'CSAFPID-11001'}]}, 'vulnerabilities': [{'cve': 'CVE-2020-25159', 'cwe': {'id': 'CWE-121', 'name': 'Stack-based Buffer Overflow'}, 'notes': [{'text': 'The install.c module in the Pengutronix RAUC update client prior to version 1.5 has a Time-of-Check Time-of-Use vulnerability, where signature verification on an update file takes place before the file is reopened for installation. An attacker who can modify the update file just before it is reopened can install arbitrary code on the device.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2020-25159', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-31001']}], 'remediations': [{'details': 'If an immediate firmware update is not possible, the only way to prevent an attack is to disable communication via EtherNet/IP.', 'category': 'mitigation', 'product_ids': ['CSAFPID-31001']}, {'details': 'Endress+Hauser provides updated firmware versions (Firmware versions >1.00.00) for the related product from the Proline portfolio which fixes the vulnerability. Endress+Hauser strongly recommends customers to update to the new fixed version. For support, please contact your local service center.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-31001']}], 'product_status': {'fixed': ['CSAFPID-32001'], 'known_affected': ['CSAFPID-31001']}}]}
d955f3aade870fbede823e581432866c7ddc7957c1124371597961a7645973f0
2026-05-29 08:30:37.139460+03:00
2026-05-29 08:30:37.139460+03:00
csaf_endresshauserag.ndjson
ec96609860615e4b69f5cbcdb12337872d7d7c5cfc7d6c149e36ab2e2083af1b
{'document': {'lang': 'en-US', 'notes': [{'text': 'Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.', 'title': 'Summary', 'category': 'summary'}, {'text': 'Microprocessors from Intel and AMD using the x86 architecture and some microprocessors using the ARM, PowerPC, and MIPS architecture may be susceptible to a group of attacks named Meltdown and Spectre. These attacks may lead to a (complete) disclosure of information in the memory of systems. Integrity and availability are not affected, but information gained using these weaknesses may be used in further attacks.\n\nMeltdown [CVE-2017-5754] allows reading the complete memory of the attacked system using a specifically crafted executable code.\n\nSpectre [version 1: CVE-2017-5753, version 2: CVE-2017-5715] allows reading the memory of other processes using a specifically crafted executable code or dynamic code as used in web browsers.\n\nOnly those systems can be affected that allow the installation/execution of custom code or load dynamic contents from foreign/untrusted sources. If only the root/administrative user can install/execute custom code, no additional risk exists, as the root/administrative user can read the information without exploiting this vulnerability. If a web browser can be used to view foreign web pages, the Spectre attack must be considered.\n\nSystems that do not allow installation/execution of custom code are not affected.', 'title': 'Impact', 'category': 'description'}, {'text': 'Make sure that no unauthorized access to the production environment is possible.\nAvoid using the above listed software with Windows administrator privileges if other users with lower privileges have access to the same software installation.', 'title': 'Mitigation', 'category': 'description'}, {'text': 'Endress+Hauser has provided the following updates with remediation of the vulnerability:\n\n- FieldCare Version 2.16\n- DeviceCare Version 1.07.05\n- Field Xpert Version 1.05.05\n- OPC UA Connectivity Server Version 1.3.7818\n\nFurther updates are currently not planned by Endress+Hauser.', 'title': 'Remediation', 'category': 'description'}], 'title': 'Endress+Hauser: Multiple products affected by log4net vulnerability', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2021-044', 'status': 'final', 'aliases': ['VDE-2021-044'], 'version': '3', 'generator': {'date': '2025-01-23T19:23:44.306Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.17'}}, 'revision_history': [{'date': '2022-01-20T08:06:00.000Z', 'number': '1', 'summary': 'Initial revision.'}, {'date': '2025-02-12T16:48:47.000Z', 'number': '2', 'summary': 'Fix: corrected self-reference, fixed version'}, {'date': '2025-05-14T13:00:14.000Z', 'number': '3', 'summary': 'Fix: added distribution'}], 'current_release_date': '2025-05-14T13:00:14.000Z', 'initial_release_date': '2022-01-20T08:06:00.000Z'}, 'publisher': {'name': 'Endress+Hauser AG', 'category': 'vendor', 'namespace': 'https://www.endress.com', 'contact_details': 'psirt@endress.com'}, 'references': [{'url': 'https://certvde.com/en/advisories/vendor/phoenixcontact/', 'summary': 'Endress+Hauser advisory overview at CERT@VDE', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/VDE-2021-044', 'summary': 'VDE-2021-044: Endress+Hauser: Multiple products affected by log4net vulnerability - HTML', 'category': 'self'}, {'url': 'https://endress-hauser.csaf-tp.certvde.com/.well-known/csaf/white/2022/vde-2021-044.json', 'summary': 'VDE-2021-044: Endress+Hauser: Multiple products affected by log4net vulnerability - CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}, {'summary': 'reported', 'organization': 'CodeWrights GmbH'}]}, 'product_tree': {'branches': [{'name': 'Endress+Hauser', 'branches': [{'name': 'Software', 'branches': [{'name': 'DeviceCare', 'branches': [{'name': '<=1.07.03', 'product': {'name': 'DeviceCare <=1.07.03', 'product_id': 'CSAFPID-51001', 'product_identification_helper': {'model_numbers': ['SFE100']}}, 'category': 'product_version_range'}, {'name': '1.07.05', 'product': {'name': 'DeviceCare 1.07.05', 'product_id': 'CSAFPID-52001'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'DTM for Cerabar / 5xB/7xB / HART', 'branches': [{'name': '<=1.67.0.805', 'product': {'name': 'DTM for Cerabar / 5xB/7xB / HART <=1.67.0.805', 'product_id': 'CSAFPID-51002'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for CLD18 / CI / CDI', 'branches': [{'name': '<=1.2.0.0', 'product': {'name': 'DTM for CLD18 / CI / CDI <=1.2.0.0', 'product_id': 'CSAFPID-51003'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for CM14 / CC / CDI', 'branches': [{'name': '<=1.2.0.0', 'product': {'name': 'DTM for CM14 / CC / CDI <=1.2.0.0', 'product_id': 'CSAFPID-51004'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for CM14 / CI / CDI', 'branches': [{'name': '<=1.2.0.0', 'product': {'name': 'DTM for CM14 / CI / CDI <=1.2.0.0', 'product_id': 'CSAFPID-51005'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for CM14 / DO / CDI', 'branches': [{'name': '<=1.2.0.0', 'product': {'name': 'DTM for CM14 / DO / CDI <=1.2.0.0', 'product_id': 'CSAFPID-51006'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for CM14 / pH / CDI', 'branches': [{'name': '<=1.2.0.0', 'product': {'name': 'DTM for CM14 / pH / CDI <=1.2.0.0', 'product_id': 'CSAFPID-51007'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Deltabar / 5xB/7xB / HART', 'branches': [{'name': '<=1.67.0.805', 'product': {'name': 'DTM for Deltabar / 5xB/7xB / HART <=1.67.0.805', 'product_id': 'CSAFPID-51008'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Display / RID1x / CDI', 'branches': [{'name': '<=1.1.1.400', 'product': {'name': 'DTM for Display / RID1x / CDI <=1.1.1.400', 'product_id': 'CSAFPID-51009'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Dosimag / 5BH / CDI', 'branches': [{'name': '<=1.4.0.64', 'product': {'name': 'DTM for Dosimag / 5BH / CDI <=1.4.0.64', 'product_id': 'CSAFPID-51010'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Dosimag / 5BH / MR4', 'branches': [{'name': '<=1.4.1.78', 'product': {'name': 'DTM for Dosimag / 5BH / MR4 <=1.4.1.78', 'product_id': 'CSAFPID-51011'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Dosimass / 8BE / CDI', 'branches': [{'name': '<=1.4.0.112', 'product': {'name': 'DTM for Dosimass / 8BE / CDI <=1.4.0.112', 'product_id': 'CSAFPID-51012'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Dosimass / 8BE / MR4', 'branches': [{'name': '<=1.4.1.121', 'product': {'name': 'DTM for Dosimass / 8BE / MR4 <=1.4.1.121', 'product_id': 'CSAFPID-51013'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Ecograph T / RSG35 / CDI', 'branches': [{'name': '<=2.4.0.0', 'product': {'name': 'DTM for Ecograph T / RSG35 / CDI <=2.4.0.0', 'product_id': 'CSAFPID-51014'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for EngyCal / RH33 / CDI', 'branches': [{'name': '<=1.7.0.5', 'product': {'name': 'DTM for EngyCal / RH33 / CDI <=1.7.0.5', 'product_id': 'CSAFPID-51015'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for EngyCal / RS33 / CDI', 'branches': [{'name': '<=1.1.6.3352', 'product': {'name': 'DTM for EngyCal / RS33 / CDI <=1.1.6.3352', 'product_id': 'CSAFPID-51016'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Fieldgate /SFG500 / Profibus', 'branches': [{'name': '<=1.10.00', 'product': {'name': 'DTM for Fieldgate /SFG500 / Profibus <=1.10.00', 'product_id': 'CSAFPID-51017'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for FXA195 / HART', 'branches': [{'name': '<=1.0.57', 'product': {'name': 'DTM for FXA195 / HART <=1.0.57', 'product_id': 'CSAFPID-51018'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Gammapilot 5x / FMG50 / HART', 'branches': [{'name': '<=1.43.0.1953', 'product': {'name': 'DTM for Gammapilot 5x / FMG50 / HART <=1.43.0.1953', 'product_id': 'CSAFPID-51019'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for iTEMP / TMT142B / HART', 'branches': [{'name': '<=3.1.4.795', 'product': {'name': 'DTM for iTEMP / TMT142B / HART <=3.1.4.795', 'product_id': 'CSAFPID-51020'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for iTEMP / TMT162 / HART', 'branches': [{'name': '<=1.13.132.5451', 'product': {'name': 'DTM for iTEMP / TMT162 / HART <=1.13.132.5451', 'product_id': 'CSAFPID-51021'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for iTEMP / TMT71 / CDI', 'branches': [{'name': '<=1.13.18.5253', 'product': {'name': 'DTM for iTEMP / TMT71 / CDI <=1.13.18.5253', 'product_id': 'CSAFPID-51022'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for iTEMP / TMT72 / HART', 'branches': [{'name': '<=1.13.258.2304', 'product': {'name': 'DTM for iTEMP / TMT72 / HART <=1.13.258.2304', 'product_id': 'CSAFPID-51023'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for iTEMP / TMT82 / HART', 'branches': [{'name': '<=1.10.423.4213', 'product': {'name': 'DTM for iTEMP / TMT82 / HART <=1.10.423.4213', 'product_id': 'CSAFPID-51024'}, 'category': 'product_version_range'}, {'name': '<=1.11.480.5368', 'product': {'name': 'DTM for iTEMP / TMT82 / HART <=1.11.480.5368', 'product_id': 'CSAFPID-51025'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Levelflex / FMP5x / FF', 'branches': [{'name': '<=1.11.0.1471', 'product': {'name': 'DTM for Levelflex / FMP5x / FF <=1.11.0.1471', 'product_id': 'CSAFPID-51026'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Levelflex / FMP 5x / HART', 'branches': [{'name': '<=1.10.1.2369', 'product': {'name': 'DTM for Levelflex / FMP 5x / HART <=1.10.1.2369', 'product_id': 'CSAFPID-51027'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Levelflex / FMP 5x / PA', 'branches': [{'name': '<=1.11.0.1017', 'product': {'name': 'DTM for Levelflex / FMP 5x / PA <=1.11.0.1017', 'product_id': 'CSAFPID-51028'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Liquiline CA80xx / CDI', 'branches': [{'name': '<=1.0.22.0', 'product': {'name': 'DTM for Liquiline CA80xx / CDI <=1.0.22.0', 'product_id': 'CSAFPID-51029'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Liquiline / CA80xx / DP', 'branches': [{'name': '<=1.11.0.0', 'product': {'name': 'DTM for Liquiline / CA80xx / DP <=1.11.0.0', 'product_id': 'CSAFPID-51030'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Liquiline / CM442 / CDI', 'branches': [{'name': '<=1.0.22.0', 'product': {'name': 'DTM for Liquiline / CM442 / CDI <=1.0.22.0', 'product_id': 'CSAFPID-51031'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Liquiline CM44x / CDI', 'branches': [{'name': '<=1.0.22.0', 'product': {'name': 'DTM for Liquiline CM44x / CDI <=1.0.22.0', 'product_id': 'CSAFPID-51032'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Liquiline / CM44x / DP', 'branches': [{'name': '<=1.11.0.0', 'product': {'name': 'DTM for Liquiline / CM44x / DP <=1.11.0.0', 'product_id': 'CSAFPID-51033'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Liquiline Compact / CM82 / HART', 'branches': [{'name': '<=1.2.0.796', 'product': {'name': 'DTM for Liquiline Compact / CM82 / HART <=1.2.0.796', 'product_id': 'CSAFPID-51034'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Liquiline Cond / CM42 / FF', 'branches': [{'name': '<=2.4.0.22', 'product': {'name': 'DTM for Liquiline Cond / CM42 / FF <=2.4.0.22', 'product_id': 'CSAFPID-51035'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Liquiline Cond / CM42 / HART', 'branches': [{'name': '<=2.4.0.22', 'product': {'name': 'DTM for Liquiline Cond / CM42 / HART <=2.4.0.22', 'product_id': 'CSAFPID-51036'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Liquiline Cond / CM42 / PA', 'branches': [{'name': '<=2.4.0.22', 'product': {'name': 'DTM for Liquiline Cond / CM42 / PA <=2.4.0.22', 'product_id': 'CSAFPID-51037'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Liquiline Oxygen / CM42 / FF', 'branches': [{'name': '<=2.4.0.22', 'product': {'name': 'DTM for Liquiline Oxygen / CM42 / FF <=2.4.0.22', 'product_id': 'CSAFPID-51038'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Liquiline Oxygen / CM42 / HART', 'branches': [{'name': '<=2.4.0.22', 'product': {'name': 'DTM for Liquiline Oxygen / CM42 / HART <=2.4.0.22', 'product_id': 'CSAFPID-51039'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Liquiline Oxygen / CM42 / PA', 'branches': [{'name': '<=2.4.0.22', 'product': {'name': 'DTM for Liquiline Oxygen / CM42 / PA <=2.4.0.22', 'product_id': 'CSAFPID-51040'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Liquiline pHORP / CM42 / FF', 'branches': [{'name': '<=2.4.0.22', 'product': {'name': 'DTM for Liquiline pHORP / CM42 / FF <=2.4.0.22', 'product_id': 'CSAFPID-51041'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Liquiline pHORP / CM42 / HART', 'branches': [{'name': '<=2.4.0.22', 'product': {'name': 'DTM for Liquiline pHORP / CM42 / HART <=2.4.0.22', 'product_id': 'CSAFPID-51042'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Liquiline pHORP / CM42 / PA', 'branches': [{'name': '<=2.4.0.22', 'product': {'name': 'DTM for Liquiline pHORP / CM42 / PA <=2.4.0.22', 'product_id': 'CSAFPID-51043'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Liquistation / CSF22 / CDI', 'branches': [{'name': '<=1.0.22.0', 'product': {'name': 'DTM for Liquistation / CSF22 / CDI <=1.0.22.0', 'product_id': 'CSAFPID-51044'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Liquistation / CSF48 / CDI', 'branches': [{'name': '<=1.0.22.0', 'product': {'name': 'DTM for Liquistation / CSF48 / CDI <=1.0.22.0', 'product_id': 'CSAFPID-51045'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Liquistation CSFxx / CDI', 'branches': [{'name': '<=1.0.22.0', 'product': {'name': 'DTM for Liquistation CSFxx / CDI <=1.0.22.0', 'product_id': 'CSAFPID-51046'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Liquistation / CSFxx / DP', 'branches': [{'name': '<=1.11.0.0', 'product': {'name': 'DTM for Liquistation / CSFxx / DP <=1.11.0.0', 'product_id': 'CSAFPID-51047'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Memograph M / RSG45 / CDI', 'branches': [{'name': '<=2.4.0.0', 'product': {'name': 'DTM for Memograph M / RSG45 / CDI <=2.4.0.0', 'product_id': 'CSAFPID-51048'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Micropilot / FMR20 / HART', 'branches': [{'name': '<=1.9.0.358', 'product': {'name': 'DTM for Micropilot / FMR20 / HART <=1.9.0.358', 'product_id': 'CSAFPID-51049'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Micropilot / FMR5x / FF', 'branches': [{'name': '<=1.11.0.745', 'product': {'name': 'DTM for Micropilot / FMR5x / FF <=1.11.0.745', 'product_id': 'CSAFPID-51050'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Micropilot / FMR5x / HART', 'branches': [{'name': '<=1.10.0.913', 'product': {'name': 'DTM for Micropilot / FMR5x / HART <=1.10.0.913', 'product_id': 'CSAFPID-51051'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Micropilot / FMR5x / PA', 'branches': [{'name': '<=1.11.0.375', 'product': {'name': 'DTM for Micropilot / FMR5x / PA <=1.11.0.375', 'product_id': 'CSAFPID-51052'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Micropilot / FMR6x / HART', 'branches': [{'name': '<=1.10.0.807', 'product': {'name': 'DTM for Micropilot / FMR6x / HART <=1.10.0.807', 'product_id': 'CSAFPID-51053'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promag 100 / 5x1B / DP', 'branches': [{'name': '<=1.7.0.86', 'product': {'name': 'DTM for Promag 100 / 5x1B / DP <=1.7.0.86', 'product_id': 'CSAFPID-51054'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promag 100 / 5x1B / EIP', 'branches': [{'name': '<=1.6.0.175', 'product': {'name': 'DTM for Promag 100 / 5x1B / EIP <=1.6.0.175', 'product_id': 'CSAFPID-51055'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promag 100 / 5x1B / EIP-CDIE', 'branches': [{'name': '<=1.5.0.174', 'product': {'name': 'DTM for Promag 100 / 5x1B / EIP-CDIE <=1.5.0.174', 'product_id': 'CSAFPID-51056'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promag 100 / 5x1B / HART', 'branches': [{'name': '<=1.3.0.201', 'product': {'name': 'DTM for Promag 100 / 5x1B / HART <=1.3.0.201', 'product_id': 'CSAFPID-51057'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promag 100 / 5x1B / MR4', 'branches': [{'name': '<=1.4.1.354', 'product': {'name': 'DTM for Promag 100 / 5x1B / MR4 <=1.4.1.354', 'product_id': 'CSAFPID-51058'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promag 100 / 5x1B / MR4-CDIS', 'branches': [{'name': '<=1.4.1.354', 'product': {'name': 'DTM for Promag 100 / 5x1B / MR4-CDIS <=1.4.1.354', 'product_id': 'CSAFPID-51059'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promag 100 / 5x1B / PNIO-CDIE', 'branches': [{'name': '<=1.6.0.37', 'product': {'name': 'DTM for Promag 100 / 5x1B / PNIO-CDIE <=1.6.0.37', 'product_id': 'CSAFPID-51060'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promag 10 / 5xBB / HART', 'branches': [{'name': '<=1.76.0.184', 'product': {'name': 'DTM for Promag 10 / 5xBB / HART <=1.76.0.184', 'product_id': 'CSAFPID-51061'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promag 10 / 5xBB / HART-CDIS', 'branches': [{'name': '<=1.76.0.184', 'product': {'name': 'DTM for Promag 10 / 5xBB / HART-CDIS <=1.76.0.184', 'product_id': 'CSAFPID-51062'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promag 10 / 5xBB / MR4', 'branches': [{'name': '<=1.76.0.159', 'product': {'name': 'DTM for Promag 10 / 5xBB / MR4 <=1.76.0.159', 'product_id': 'CSAFPID-51063'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promag 10 / 5xBB / MR4-CDIS', 'branches': [{'name': '<=1.76.0.159', 'product': {'name': 'DTM for Promag 10 / 5xBB / MR4-CDIS <=1.76.0.159', 'product_id': 'CSAFPID-51064'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promag 200 / 5x2B / FF', 'branches': [{'name': '<=1.6.0.73', 'product': {'name': 'DTM for Promag 200 / 5x2B / FF <=1.6.0.73', 'product_id': 'CSAFPID-51065'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promag 200 / 5x2B / HART', 'branches': [{'name': '<=1.5.0.219', 'product': {'name': 'DTM for Promag 200 / 5x2B / HART <=1.5.0.219', 'product_id': 'CSAFPID-51066'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promag 200 / 5x2B / PA', 'branches': [{'name': '<=1.7.0.57', 'product': {'name': 'DTM for Promag 200 / 5x2B / PA <=1.7.0.57', 'product_id': 'CSAFPID-51067'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promag 300 500 / 5x3x 5x5x / DP', 'branches': [{'name': '<=1.11.0.65', 'product': {'name': 'DTM for Promag 300 500 / 5x3x 5x5x / DP <=1.11.0.65', 'product_id': 'CSAFPID-51068'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promag 300 500 / 5x3x 5x5x / EIP', 'branches': [{'name': '<=1.10.0.59', 'product': {'name': 'DTM for Promag 300 500 / 5x3x 5x5x / EIP <=1.10.0.59', 'product_id': 'CSAFPID-51069'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promag 300 500 / 5x3x 5x5x / EIP-CDIE', 'branches': [{'name': '<=1.10.0.59', 'product': {'name': 'DTM for Promag 300 500 / 5x3x 5x5x / EIP-CDIE <=1.10.0.59', 'product_id': 'CSAFPID-51070'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promag 300 500 / 5x3x 5x5x / FF', 'branches': [{'name': '<=1.9.0.122', 'product': {'name': 'DTM for Promag 300 500 / 5x3x 5x5x / FF <=1.9.0.122', 'product_id': 'CSAFPID-51071'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promag 300 500 / 5x3x 5x5x / HART', 'branches': [{'name': '<=1.39.0.285', 'product': {'name': 'DTM for Promag 300 500 / 5x3x 5x5x / HART <=1.39.0.285', 'product_id': 'CSAFPID-51072'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promag 300 500 / 5x3x 5x5x / MR4', 'branches': [{'name': '<=1.39.0.230', 'product': {'name': 'DTM for Promag 300 500 / 5x3x 5x5x / MR4 <=1.39.0.230', 'product_id': 'CSAFPID-51073'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promag 300 500 / 5x3x 5x5x / MR4-CDIE', 'branches': [{'name': '<=1.39.0.230', 'product': {'name': 'DTM for Promag 300 500 / 5x3x 5x5x / MR4-CDIE <=1.39.0.230', 'product_id': 'CSAFPID-51074'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promag 300 500 / 5x3x 5x5x / PA', 'branches': [{'name': '<=1.11.0.104', 'product': {'name': 'DTM for Promag 300 500 / 5x3x 5x5x / PA <=1.11.0.104', 'product_id': 'CSAFPID-51075'}, 'category': 'product_version_range'}, {'name': '<=1.12.0.161', 'product': {'name': 'DTM for Promag 300 500 / 5x3x 5x5x / PA <=1.12.0.161', 'product_id': 'CSAFPID-51076'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promag 300 500 / 5x3x 5x5x / PN-CDIE', 'branches': [{'name': '<=1.39.0.136', 'product': {'name': 'DTM for Promag 300 500 / 5x3x 5x5x / PN-CDIE <=1.39.0.136', 'product_id': 'CSAFPID-51077'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promag 400 / 5x4Bxx / HART', 'branches': [{'name': '<=1.0.0.349', 'product': {'name': 'DTM for Promag 400 / 5x4Bxx / HART <=1.0.0.349', 'product_id': 'CSAFPID-51078'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promag 400 / 5x4C / DP', 'branches': [{'name': '<=1.8.0.58', 'product': {'name': 'DTM for Promag 400 / 5x4C / DP <=1.8.0.58', 'product_id': 'CSAFPID-51079'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promag 400 / 5x4C / EIP', 'branches': [{'name': '<=1.8.0.101', 'product': {'name': 'DTM for Promag 400 / 5x4C / EIP <=1.8.0.101', 'product_id': 'CSAFPID-51080'}, 'category': 'product_version_range'}, {'name': '<=1.3.0.84', 'product': {'name': 'DTM for Promag 400 / 5x4C / EIP <=1.3.0.84', 'product_id': 'CSAFPID-51081'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promag 400 / 5x4C / HART', 'branches': [{'name': '<=1.3.0.132', 'product': {'name': 'DTM for Promag 400 / 5x4C / HART <=1.3.0.132', 'product_id': 'CSAFPID-51082'}, 'category': 'product_version_range'}, {'name': '<=1.39.0.276', 'product': {'name': 'DTM for Promag 400 / 5x4C / HART <=1.39.0.276', 'product_id': 'CSAFPID-51083'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promag 400 / 5x4C / MR4', 'branches': [{'name': '<=1.39.0.191', 'product': {'name': 'DTM for Promag 400 / 5x4C / MR4 <=1.39.0.191', 'product_id': 'CSAFPID-51084'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promag 400 / 5x4C / MR4-CDIE', 'branches': [{'name': '<=1.5.0.59', 'product': {'name': 'DTM for Promag 400 / 5x4C / MR4-CDIE <=1.5.0.59', 'product_id': 'CSAFPID-51085'}, 'category': 'product_version_range'}, {'name': '<=1.10.0.148', 'product': {'name': 'DTM for Promag 400 / 5x4C / MR4-CDIE <=1.10.0.148', 'product_id': 'CSAFPID-51086'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promag 400 / 5x4Cxx / HART', 'branches': [{'name': '<=1.0.0.32', 'product': {'name': 'DTM for Promag 400 / 5x4Cxx / HART <=1.0.0.32', 'product_id': 'CSAFPID-51087'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promass 100 / 8x1B / DP', 'branches': [{'name': '<=1.7.0.141', 'product': {'name': 'DTM for Promass 100 / 8x1B / DP <=1.7.0.141', 'product_id': 'CSAFPID-51088'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promass 100 / 8x1B / EIP', 'branches': [{'name': '<=1.6.0.463', 'product': {'name': 'DTM for Promass 100 / 8x1B / EIP <=1.6.0.463', 'product_id': 'CSAFPID-51089'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promass 100 / 8x1B / EIP-CDIE', 'branches': [{'name': '<=1.5.0.463', 'product': {'name': 'DTM for Promass 100 / 8x1B / EIP-CDIE <=1.5.0.463', 'product_id': 'CSAFPID-51090'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promass 100 / 8x1B / HART', 'branches': [{'name': '<=1.4.0.282', 'product': {'name': 'DTM for Promass 100 / 8x1B / HART <=1.4.0.282', 'product_id': 'CSAFPID-51091'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promass 100 / 8x1B / MB', 'branches': [{'name': '<=1.4.1.519', 'product': {'name': 'DTM for Promass 100 / 8x1B / MB <=1.4.1.519', 'product_id': 'CSAFPID-51092'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promass 100 / 8x1B / PNIO-CDIE', 'branches': [{'name': '<=1.6.0.70', 'product': {'name': 'DTM for Promass 100 / 8x1B / PNIO-CDIE <=1.6.0.70', 'product_id': 'CSAFPID-51093'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promass 100 / 8x1Bxx / MB', 'branches': [{'name': '<=1.0.0.0', 'product': {'name': 'DTM for Promass 100 / 8x1Bxx / MB <=1.0.0.0', 'product_id': 'CSAFPID-51094'}, 'category': 'product_version_range'}, {'name': '<=1.4.0.513', 'product': {'name': 'DTM for Promass 100 / 8x1Bxx / MB <=1.4.0.513', 'product_id': 'CSAFPID-51095'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promass 100 / 8x1Bxx / MR4', 'branches': [{'name': '<=1.2.0.476', 'product': {'name': 'DTM for Promass 100 / 8x1Bxx / MR4 <=1.2.0.476', 'product_id': 'CSAFPID-51096'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promass 10 / 8xBB / HART', 'branches': [{'name': '<=1.76.0.271', 'product': {'name': 'DTM for Promass 10 / 8xBB / HART <=1.76.0.271', 'product_id': 'CSAFPID-51097'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promass 10 / 8xBB / HART-CDIS', 'branches': [{'name': '<=1.76.0.271', 'product': {'name': 'DTM for Promass 10 / 8xBB / HART-CDIS <=1.76.0.271', 'product_id': 'CSAFPID-51098'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promass 10 / 8xBB / MR4', 'branches': [{'name': '<=1.76.0.158', 'product': {'name': 'DTM for Promass 10 / 8xBB / MR4 <=1.76.0.158', 'product_id': 'CSAFPID-51099'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promass 10 / 8xBB / MR4-CDIS', 'branches': [{'name': '<=1.76.0.158', 'product': {'name': 'DTM for Promass 10 / 8xBB / MR4-CDIS <=1.76.0.158', 'product_id': 'CSAFPID-51100'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promass 200 / 8x2B / FF', 'branches': [{'name': '<=1.3.0.150', 'product': {'name': 'DTM for Promass 200 / 8x2B / FF <=1.3.0.150', 'product_id': 'CSAFPID-51101'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promass 200 / 8x2B / HART', 'branches': [{'name': '<=1.5.0.1133', 'product': {'name': 'DTM for Promass 200 / 8x2B / HART <=1.5.0.1133', 'product_id': 'CSAFPID-51102'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promass 200 / 8x2B / PA', 'branches': [{'name': '<=1.7.0.236', 'product': {'name': 'DTM for Promass 200 / 8x2B / PA <=1.7.0.236', 'product_id': 'CSAFPID-51103'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promass 300 500 / 8x3x 8x5x / DP', 'branches': [{'name': '<=1.11.0.93', 'product': {'name': 'DTM for Promass 300 500 / 8x3x 8x5x / DP <=1.11.0.93', 'product_id': 'CSAFPID-51104'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promass 300 500 / 8x3x 8x5x / EIP', 'branches': [{'name': '<=1.10.0.94', 'product': {'name': 'DTM for Promass 300 500 / 8x3x 8x5x / EIP <=1.10.0.94', 'product_id': 'CSAFPID-51105'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promass 300 500 / 8x3x 8x5x / EIP-CDIE', 'branches': [{'name': '<=1.10.0.94', 'product': {'name': 'DTM for Promass 300 500 / 8x3x 8x5x / EIP-CDIE <=1.10.0.94', 'product_id': 'CSAFPID-51106'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promass 300 500 / 8x3x 8x5x / FF', 'branches': [{'name': '<=1.9.0.197', 'product': {'name': 'DTM for Promass 300 500 / 8x3x 8x5x / FF <=1.9.0.197', 'product_id': 'CSAFPID-51107'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promass 300 500 / 8x3x 8x5x / HART', 'branches': [{'name': '<=1.39.0.646', 'product': {'name': 'DTM for Promass 300 500 / 8x3x 8x5x / HART <=1.39.0.646', 'product_id': 'CSAFPID-51108'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promass 300 500 / 8x3x 8x5x / MR4', 'branches': [{'name': '<=1.39.0.289', 'product': {'name': 'DTM for Promass 300 500 / 8x3x 8x5x / MR4 <=1.39.0.289', 'product_id': 'CSAFPID-51109'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promass 300 500 / 8x3x 8x5x / MR4-CDIE', 'branches': [{'name': '<=1.39.0.289', 'product': {'name': 'DTM for Promass 300 500 / 8x3x 8x5x / MR4-CDIE <=1.39.0.289', 'product_id': 'CSAFPID-51110'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promass 300 500 / 8x3x 8x5x / PA', 'branches': [{'name': '<=1.12.0.193', 'product': {'name': 'DTM for Promass 300 500 / 8x3x 8x5x / PA <=1.12.0.193', 'product_id': 'CSAFPID-51111'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Promass 300 500 / 8x3x 8x5x / PN-CDIE', 'branches': [{'name': '<=1.39.0.222', 'product': {'name': 'DTM for Promass 300 500 / 8x3x 8x5x / PN-CDIE <=1.39.0.222', 'product_id': 'CSAFPID-51112'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Proservo / NMS8x / HART', 'branches': [{'name': '<=1.9.2.887', 'product': {'name': 'DTM for Proservo / NMS8x / HART <=1.9.2.887', 'product_id': 'CSAFPID-51113'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Prosonic Flow 100 / 9E1B / CDI', 'branches': [{'name': '<=1.10.0.172', 'product': {'name': 'DTM for Prosonic Flow 100 / 9E1B / CDI <=1.10.0.172', 'product_id': 'CSAFPID-51114'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Prosonic Flow 100 / 9E1B / HART', 'branches': [{'name': '<=1.10.0.151', 'product': {'name': 'DTM for Prosonic Flow 100 / 9E1B / HART <=1.10.0.151', 'product_id': 'CSAFPID-51115'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Prosonic Flow 300 500 / 9x3x 9x5x / HART', 'branches': [{'name': '<=1.45.0.327', 'product': {'name': 'DTM for Prosonic Flow 300 500 / 9x3x 9x5x / HART <=1.45.0.327', 'product_id': 'CSAFPID-51116'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Prosonic Flow 300 500 / 9x3x 9x5x / MR4', 'branches': [{'name': '<=1.45.0.128', 'product': {'name': 'DTM for Prosonic Flow 300 500 / 9x3x 9x5x / MR4 <=1.45.0.128', 'product_id': 'CSAFPID-51117'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Prosonic Flow 300 500 / 9x3x 9x5x / MR4-CDIE', 'branches': [{'name': '<=1.38.0.88', 'product': {'name': 'DTM for Prosonic Flow 300 500 / 9x3x 9x5x / MR4-CDIE <=1.38.0.88', 'product_id': 'CSAFPID-51118'}, 'category': 'product_version_range'}, {'name': '<=1.45.0.128', 'product': {'name': 'DTM for Prosonic Flow 300 500 / 9x3x 9x5x / MR4-CDIE <=1.45.0.128', 'product_id': 'CSAFPID-51119'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Prosonic Flow B 200 / 9B2B / HART', 'branches': [{'name': '<=1.6.0.800', 'product': {'name': 'DTM for Prosonic Flow B 200 / 9B2B / HART <=1.6.0.800', 'product_id': 'CSAFPID-51120'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Prothermo / NMT8x / HART', 'branches': [{'name': '<=1.73.0.317', 'product': {'name': 'DTM for Prothermo / NMT8x / HART <=1.73.0.317', 'product_id': 'CSAFPID-51121'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Prowirl 200 / 7x2B / FF', 'branches': [{'name': '<=1.11.0.174', 'product': {'name': 'DTM for Prowirl 200 / 7x2B / FF <=1.11.0.174', 'product_id': 'CSAFPID-51122'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Prowirl 200 / 7x2B / HART', 'branches': [{'name': '<=1.12.0.537', 'product': {'name': 'DTM for Prowirl 200 / 7x2B / HART <=1.12.0.537', 'product_id': 'CSAFPID-51123'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Prowirl 200 / 7x2Bxx / PA', 'branches': [{'name': '<=1.11.0.135', 'product': {'name': 'DTM for Prowirl 200 / 7x2Bxx / PA <=1.11.0.135', 'product_id': 'CSAFPID-51124'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for RA33 / CDI', 'branches': [{'name': '<=1.1.6.3352', 'product': {'name': 'DTM for RA33 / CDI <=1.1.6.3352', 'product_id': 'CSAFPID-51125'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Tank Gauging Radar / NMR8x / HART', 'branches': [{'name': '<=1.9.2.799', 'product': {'name': 'DTM for Tank Gauging Radar / NMR8x / HART <=1.9.2.799', 'product_id': 'CSAFPID-51126'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for Tank Side Monitor / NRF8x / HART', 'branches': [{'name': '<=1.9.2.669', 'product': {'name': 'DTM for Tank Side Monitor / NRF8x / HART <=1.9.2.669', 'product_id': 'CSAFPID-51127'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for t-mass 150 / 6xABxx / HART', 'branches': [{'name': '<=1.0.0.162', 'product': {'name': 'DTM for t-mass 150 / 6xABxx / HART <=1.0.0.162', 'product_id': 'CSAFPID-51128'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for t-mass 150 L T 150 / 6xAB / HART', 'branches': [{'name': '<=1.2.0.42', 'product': {'name': 'DTM for t-mass 150 L T 150 / 6xAB / HART <=1.2.0.42', 'product_id': 'CSAFPID-51129'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for t-mass 300 500 / 6x3B 6x5B / HART', 'branches': [{'name': '<=1.45.0.280', 'product': {'name': 'DTM for t-mass 300 500 / 6x3B 6x5B / HART <=1.45.0.280', 'product_id': 'CSAFPID-51130'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for t-mass 300 500 / 6x3B 6x5B / MR4', 'branches': [{'name': '<=1.45.0.127', 'product': {'name': 'DTM for t-mass 300 500 / 6x3B 6x5B / MR4 <=1.45.0.127', 'product_id': 'CSAFPID-51131'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for t-mass 300 500 / 6x3B 6x5B / MR4-CDIE', 'branches': [{'name': '<=1.45.0.127', 'product': {'name': 'DTM for t-mass 300 500 / 6x3B 6x5B / MR4-CDIE <=1.45.0.127', 'product_id': 'CSAFPID-51132'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM for TrustSens / TM371-TM372 / HART', 'branches': [{'name': '<=1.11.301.4871', 'product': {'name': 'DTM for TrustSens / TM371-TM372 / HART <=1.11.301.4871', 'product_id': 'CSAFPID-51133'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM library for SWA50', 'branches': [{'name': '<=1.0.2.4', 'product': {'name': 'DTM library for SWA50 <=1.0.2.4', 'product_id': 'CSAFPID-51134'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM library for SWA70', 'branches': [{'name': '<=1.0.2.4', 'product': {'name': 'DTM library for SWA70 <=1.0.2.4', 'product_id': 'CSAFPID-51135'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DTM library for SWG70 / WirelessHART', 'branches': [{'name': '<=1.0.2.4', 'product': {'name': 'DTM library for SWG70 / WirelessHART <=1.0.2.4', 'product_id': 'CSAFPID-51136'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'FieldCare', 'branches': [{'name': '<=2.15.01', 'product': {'name': 'FieldCare <=2.15.01', 'product_id': 'CSAFPID-51137', 'product_identification_helper': {'model_numbers': ['SFE500']}}, 'category': 'product_version_range'}, {'name': '2.16', 'product': {'name': 'FieldCare 2.16', 'product_id': 'CSAFPID-52002'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Field Xpert', 'branches': [{'name': '<=1.05.03', 'product': {'name': 'Field Xpert <=1.05.03', 'product_id': 'CSAFPID-51138', 'product_identification_helper': {'model_numbers': ['SMT50', 'SMT70', 'SMT77']}}, 'category': 'product_version_range'}, {'name': '1.05.05', 'product': {'name': 'Field Xpert 1.05.05', 'product_id': 'CSAFPID-52003'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'HoP DTM', 'branches': [{'name': '<=1.0.2', 'product': {'name': 'HoP DTM <=1.0.2', 'product_id': 'CSAFPID-51139'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'iDTM FF', 'branches': [{'name': '<=2.00.289', 'product': {'name': 'iDTM FF <=2.00.289', 'product_id': 'CSAFPID-51140'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'iDTM HART', 'branches': [{'name': '<=2.00.289', 'product': {'name': 'iDTM HART <=2.00.289', 'product_id': 'CSAFPID-51141'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'IO-Link IODD Interpreter DTM', 'branches': [{'name': '<=3.12.0', 'product': {'name': 'IO-Link IODD Interpreter DTM <=3.12.0', 'product_id': 'CSAFPID-51142'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'OPC Server for SWG70', 'branches': [{'name': '<=1.00.01', 'product': {'name': 'OPC Server for SWG70 <=1.00.01', 'product_id': 'CSAFPID-51143'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'OPC UA Connectivity Server', 'branches': [{'name': '<=1.3.7817', 'product': {'name': 'OPC UA Connectivity Server <=1.3.7817', 'product_id': 'CSAFPID-51144'}, 'category': 'product_version_range'}, {'name': '1.3.7818', 'product': {'name': 'OPC UA Connectivity Server 1.3.7818', 'product_id': 'CSAFPID-52004'}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}], 'product_groups': [{'summary': 'affected product.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003', 'CSAFPID-51004', 'CSAFPID-51005', 'CSAFPID-51006', 'CSAFPID-51007', 'CSAFPID-51008', 'CSAFPID-51009', 'CSAFPID-51010', 'CSAFPID-51011', 'CSAFPID-51012', 'CSAFPID-51013', 'CSAFPID-51014', 'CSAFPID-51015', 'CSAFPID-51016', 'CSAFPID-51017', 'CSAFPID-51018', 'CSAFPID-51019', 'CSAFPID-51020', 'CSAFPID-51021', 'CSAFPID-51022', 'CSAFPID-51023', 'CSAFPID-51024', 'CSAFPID-51025', 'CSAFPID-51026', 'CSAFPID-51027', 'CSAFPID-51028', 'CSAFPID-51029', 'CSAFPID-51030', 'CSAFPID-51031', 'CSAFPID-51032', 'CSAFPID-51033', 'CSAFPID-51034', 'CSAFPID-51035', 'CSAFPID-51036', 'CSAFPID-51037', 'CSAFPID-51038', 'CSAFPID-51039', 'CSAFPID-51040', 'CSAFPID-51041', 'CSAFPID-51042', 'CSAFPID-51043', 'CSAFPID-51044', 'CSAFPID-51045', 'CSAFPID-51046', 'CSAFPID-51047', 'CSAFPID-51048', 'CSAFPID-51049', 'CSAFPID-51050', 'CSAFPID-51051', 'CSAFPID-51052', 'CSAFPID-51053', 'CSAFPID-51054', 'CSAFPID-51055', 'CSAFPID-51056', 'CSAFPID-51057', 'CSAFPID-51058', 'CSAFPID-51059', 'CSAFPID-51060', 'CSAFPID-51061', 'CSAFPID-51062', 'CSAFPID-51063', 'CSAFPID-51064', 'CSAFPID-51065', 'CSAFPID-51066', 'CSAFPID-51067', 'CSAFPID-51068', 'CSAFPID-51069', 'CSAFPID-51070', 'CSAFPID-51071', 'CSAFPID-51072', 'CSAFPID-51073', 'CSAFPID-51074', 'CSAFPID-51075', 'CSAFPID-51076', 'CSAFPID-51077', 'CSAFPID-51078', 'CSAFPID-51079', 'CSAFPID-51080', 'CSAFPID-51081', 'CSAFPID-51082', 'CSAFPID-51083', 'CSAFPID-51084', 'CSAFPID-51085', 'CSAFPID-51086', 'CSAFPID-51087', 'CSAFPID-51088', 'CSAFPID-51089', 'CSAFPID-51090', 'CSAFPID-51091', 'CSAFPID-51092', 'CSAFPID-51093', 'CSAFPID-51094', 'CSAFPID-51095', 'CSAFPID-51096', 'CSAFPID-51097', 'CSAFPID-51098', 'CSAFPID-51099', 'CSAFPID-51100', 'CSAFPID-51101', 'CSAFPID-51102', 'CSAFPID-51103', 'CSAFPID-51104', 'CSAFPID-51105', 'CSAFPID-51106', 'CSAFPID-51107', 'CSAFPID-51108', 'CSAFPID-51109', 'CSAFPID-51110', 'CSAFPID-51111', 'CSAFPID-51112', 'CSAFPID-51113', 'CSAFPID-51114', 'CSAFPID-51115', 'CSAFPID-51116', 'CSAFPID-51117', 'CSAFPID-51118', 'CSAFPID-51119', 'CSAFPID-51120', 'CSAFPID-51121', 'CSAFPID-51122', 'CSAFPID-51123', 'CSAFPID-51124', 'CSAFPID-51125', 'CSAFPID-51126', 'CSAFPID-51127', 'CSAFPID-51128', 'CSAFPID-51129', 'CSAFPID-51130', 'CSAFPID-51131', 'CSAFPID-51132', 'CSAFPID-51133', 'CSAFPID-51134', 'CSAFPID-51135', 'CSAFPID-51136', 'CSAFPID-51137', 'CSAFPID-51138', 'CSAFPID-51139', 'CSAFPID-51140', 'CSAFPID-51141', 'CSAFPID-51142', 'CSAFPID-51143', 'CSAFPID-51144']}, {'summary': 'fixed products', 'group_id': 'CSAFGID-0004', 'product_ids': ['CSAFPID-52001', 'CSAFPID-52002', 'CSAFPID-52003', 'CSAFPID-52004']}]}, 'vulnerabilities': [{'cve': 'CVE-2017-5753', 'cwe': {'id': 'CWE-611', 'name': 'Improper Restriction of XML External Entity Reference'}, 'notes': [{'text': 'Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2017-5753', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 9.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.8, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003', 'CSAFPID-51004', 'CSAFPID-51005', 'CSAFPID-51006', 'CSAFPID-51007', 'CSAFPID-51008', 'CSAFPID-51009', 'CSAFPID-51010', 'CSAFPID-51011', 'CSAFPID-51012', 'CSAFPID-51013', 'CSAFPID-51014', 'CSAFPID-51015', 'CSAFPID-51016', 'CSAFPID-51017', 'CSAFPID-51018', 'CSAFPID-51019', 'CSAFPID-51020', 'CSAFPID-51021', 'CSAFPID-51022', 'CSAFPID-51023', 'CSAFPID-51024', 'CSAFPID-51025', 'CSAFPID-51026', 'CSAFPID-51027', 'CSAFPID-51028', 'CSAFPID-51029', 'CSAFPID-51030', 'CSAFPID-51031', 'CSAFPID-51032', 'CSAFPID-51033', 'CSAFPID-51034', 'CSAFPID-51035', 'CSAFPID-51036', 'CSAFPID-51037', 'CSAFPID-51038', 'CSAFPID-51039', 'CSAFPID-51040', 'CSAFPID-51041', 'CSAFPID-51042', 'CSAFPID-51043', 'CSAFPID-51044', 'CSAFPID-51045', 'CSAFPID-51046', 'CSAFPID-51047', 'CSAFPID-51048', 'CSAFPID-51049', 'CSAFPID-51050', 'CSAFPID-51051', 'CSAFPID-51052', 'CSAFPID-51053', 'CSAFPID-51054', 'CSAFPID-51055', 'CSAFPID-51056', 'CSAFPID-51057', 'CSAFPID-51058', 'CSAFPID-51059', 'CSAFPID-51060', 'CSAFPID-51061', 'CSAFPID-51062', 'CSAFPID-51063', 'CSAFPID-51064', 'CSAFPID-51065', 'CSAFPID-51066', 'CSAFPID-51067', 'CSAFPID-51068', 'CSAFPID-51069', 'CSAFPID-51070', 'CSAFPID-51071', 'CSAFPID-51072', 'CSAFPID-51073', 'CSAFPID-51074', 'CSAFPID-51075', 'CSAFPID-51076', 'CSAFPID-51077', 'CSAFPID-51078', 'CSAFPID-51079', 'CSAFPID-51080', 'CSAFPID-51081', 'CSAFPID-51082', 'CSAFPID-51083', 'CSAFPID-51084', 'CSAFPID-51085', 'CSAFPID-51086', 'CSAFPID-51087', 'CSAFPID-51088', 'CSAFPID-51089', 'CSAFPID-51090', 'CSAFPID-51091', 'CSAFPID-51092', 'CSAFPID-51093', 'CSAFPID-51094', 'CSAFPID-51095', 'CSAFPID-51096', 'CSAFPID-51097', 'CSAFPID-51098', 'CSAFPID-51099', 'CSAFPID-51100', 'CSAFPID-51101', 'CSAFPID-51102', 'CSAFPID-51103', 'CSAFPID-51104', 'CSAFPID-51105', 'CSAFPID-51106', 'CSAFPID-51107', 'CSAFPID-51108', 'CSAFPID-51109', 'CSAFPID-51110', 'CSAFPID-51111', 'CSAFPID-51112', 'CSAFPID-51113', 'CSAFPID-51114', 'CSAFPID-51115', 'CSAFPID-51116', 'CSAFPID-51117', 'CSAFPID-51118', 'CSAFPID-51119', 'CSAFPID-51120', 'CSAFPID-51121', 'CSAFPID-51122', 'CSAFPID-51123', 'CSAFPID-51124', 'CSAFPID-51125', 'CSAFPID-51126', 'CSAFPID-51127', 'CSAFPID-51128', 'CSAFPID-51129', 'CSAFPID-51130', 'CSAFPID-51131', 'CSAFPID-51132', 'CSAFPID-51133', 'CSAFPID-51134', 'CSAFPID-51135', 'CSAFPID-51136', 'CSAFPID-51137', 'CSAFPID-51138', 'CSAFPID-51139', 'CSAFPID-51140', 'CSAFPID-51141', 'CSAFPID-51142', 'CSAFPID-51143', 'CSAFPID-51144']}], 'remediations': [{'details': 'Make sure that no unauthorized access to the production environment is possible.\nAvoid using the above listed software with Windows administrator privileges if other users with lower privileges have access to the same software installation.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Endress+Hauser has provided the following updates with remediation of the vulnerability:\n\n- FieldCare Version 2.16\n- DeviceCare Version 1.07.05\n- Field Xpert Version 1.05.05\n- OPC UA Connectivity Server Version 1.3.7818\n\nFurther updates are currently not planned by Endress+Hauser.', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-52001', 'CSAFPID-52002', 'CSAFPID-52003', 'CSAFPID-52004'], 'known_affected': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003', 'CSAFPID-51004', 'CSAFPID-51005', 'CSAFPID-51006', 'CSAFPID-51007', 'CSAFPID-51008', 'CSAFPID-51009', 'CSAFPID-51010', 'CSAFPID-51011', 'CSAFPID-51012', 'CSAFPID-51013', 'CSAFPID-51014', 'CSAFPID-51015', 'CSAFPID-51016', 'CSAFPID-51017', 'CSAFPID-51018', 'CSAFPID-51019', 'CSAFPID-51020', 'CSAFPID-51021', 'CSAFPID-51022', 'CSAFPID-51023', 'CSAFPID-51024', 'CSAFPID-51025', 'CSAFPID-51026', 'CSAFPID-51027', 'CSAFPID-51028', 'CSAFPID-51029', 'CSAFPID-51030', 'CSAFPID-51031', 'CSAFPID-51032', 'CSAFPID-51033', 'CSAFPID-51034', 'CSAFPID-51035', 'CSAFPID-51036', 'CSAFPID-51037', 'CSAFPID-51038', 'CSAFPID-51039', 'CSAFPID-51040', 'CSAFPID-51041', 'CSAFPID-51042', 'CSAFPID-51043', 'CSAFPID-51044', 'CSAFPID-51045', 'CSAFPID-51046', 'CSAFPID-51047', 'CSAFPID-51048', 'CSAFPID-51049', 'CSAFPID-51050', 'CSAFPID-51051', 'CSAFPID-51052', 'CSAFPID-51053', 'CSAFPID-51054', 'CSAFPID-51055', 'CSAFPID-51056', 'CSAFPID-51057', 'CSAFPID-51058', 'CSAFPID-51059', 'CSAFPID-51060', 'CSAFPID-51061', 'CSAFPID-51062', 'CSAFPID-51063', 'CSAFPID-51064', 'CSAFPID-51065', 'CSAFPID-51066', 'CSAFPID-51067', 'CSAFPID-51068', 'CSAFPID-51069', 'CSAFPID-51070', 'CSAFPID-51071', 'CSAFPID-51072', 'CSAFPID-51073', 'CSAFPID-51074', 'CSAFPID-51075', 'CSAFPID-51076', 'CSAFPID-51077', 'CSAFPID-51078', 'CSAFPID-51079', 'CSAFPID-51080', 'CSAFPID-51081', 'CSAFPID-51082', 'CSAFPID-51083', 'CSAFPID-51084', 'CSAFPID-51085', 'CSAFPID-51086', 'CSAFPID-51087', 'CSAFPID-51088', 'CSAFPID-51089', 'CSAFPID-51090', 'CSAFPID-51091', 'CSAFPID-51092', 'CSAFPID-51093', 'CSAFPID-51094', 'CSAFPID-51095', 'CSAFPID-51096', 'CSAFPID-51097', 'CSAFPID-51098', 'CSAFPID-51099', 'CSAFPID-51100', 'CSAFPID-51101', 'CSAFPID-51102', 'CSAFPID-51103', 'CSAFPID-51104', 'CSAFPID-51105', 'CSAFPID-51106', 'CSAFPID-51107', 'CSAFPID-51108', 'CSAFPID-51109', 'CSAFPID-51110', 'CSAFPID-51111', 'CSAFPID-51112', 'CSAFPID-51113', 'CSAFPID-51114', 'CSAFPID-51115', 'CSAFPID-51116', 'CSAFPID-51117', 'CSAFPID-51118', 'CSAFPID-51119', 'CSAFPID-51120', 'CSAFPID-51121', 'CSAFPID-51122', 'CSAFPID-51123', 'CSAFPID-51124', 'CSAFPID-51125', 'CSAFPID-51126', 'CSAFPID-51127', 'CSAFPID-51128', 'CSAFPID-51129', 'CSAFPID-51130', 'CSAFPID-51131', 'CSAFPID-51132', 'CSAFPID-51133', 'CSAFPID-51134', 'CSAFPID-51135', 'CSAFPID-51136', 'CSAFPID-51137', 'CSAFPID-51138', 'CSAFPID-51139', 'CSAFPID-51140', 'CSAFPID-51141', 'CSAFPID-51142', 'CSAFPID-51143', 'CSAFPID-51144']}}]}
26ddb58f39288da73f0a893f8522680e0c34685ea7d1a125fe049360418fe125
2026-05-29 08:30:37.139460+03:00
2026-05-29 08:30:37.139460+03:00
csaf_endresshauserag.ndjson
c11fc13815d8a270a6901aa2c0d803e7ab127c18b2e64f693367da6e0a08959e
{'document': {'lang': 'en-GB', 'notes': [{'text': 'Possible memory corruption in BT controller when it receives an oversized LMP packet over 2-DH1 link and leads to denial of service.', 'title': 'Summary', 'category': 'summary'}, {'text': 'Please consult the CVE entry above.', 'title': 'Impact', 'category': 'description'}, {'text': 'Endress+Hauser recommends using the FieldPort SFP50 only in secure environment and to allow access tothe devices only to authorized persons.', 'title': 'Mitigation', 'category': 'description'}, {'text': 'Currently no fix planned from chip supplier.', 'title': 'Remediation', 'category': 'description'}], 'title': 'Endress+Hauser: FieldPort SFP50 Memory Corruption in Bluetooth Controller Firmware', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2022-006', 'status': 'final', 'aliases': ['VDE-2022-006'], 'version': '1', 'generator': {'date': '2025-04-28T08:42:41.132Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.24'}}, 'revision_history': [{'date': '2022-03-24T10:48:00.000Z', 'number': '1', 'summary': 'Initial revision.'}], 'current_release_date': '2022-03-24T10:48:00.000Z', 'initial_release_date': '2022-03-24T10:48:00.000Z'}, 'publisher': {'name': 'Endress+Hauser AG', 'category': 'vendor', 'namespace': 'https://www.endress.com', 'contact_details': 'psirt@endress.com'}, 'references': [{'url': 'https://certvde.com/en/advisories/VDE-2022-006/', 'summary': 'VDE-2022-006: Endress+Hauser: FieldPort SFP50 Memory Corruption in Bluetooth Controller Firmware - HTML', 'category': 'self'}, {'url': 'https://endress-hauser.csaf-tp.certvde.com/.well-known/csaf/white/2022/vde-2022-006.json', 'summary': 'VDE-2022-006: Endress+Hauser: FieldPort SFP50 Memory Corruption in Bluetooth Controller Firmware - CSAF', 'category': 'self'}, {'url': 'https://www.endress.com', 'summary': 'Vendor PSIRT', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/endress-hauser/', 'summary': 'CERT@VDE Security Advisories for Endress+Hauser AG', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}]}, 'product_tree': {'branches': [{'name': 'Endress+Hauser', 'branches': [{'name': 'Hardware', 'branches': [{'name': 'FieldPort SFP50 (mobiLink)', 'product': {'name': 'FieldPort SFP50 (mobiLink)', 'product_id': 'CSAFPID-11001', 'product_identification_helper': {'model_numbers': ['SFP50-*']}}, 'category': 'product_name'}, {'name': 'mobiLink Bluetooth and USB modem in bundle with Field Xpert SMT50', 'product': {'name': 'mobiLink Bluetooth and USB modem in bundle with Field Xpert SMT50', 'product_id': 'CSAFPID-11002', 'product_identification_helper': {'model_numbers': ['SMT50-*MH']}}, 'category': 'product_name'}, {'name': 'mobiLink Bluetooth and USB modem in bundle with Field Xpert SMT70', 'product': {'name': 'mobiLink Bluetooth and USB modem in bundle with Field Xpert SMT70', 'product_id': 'CSAFPID-11003', 'product_identification_helper': {'model_numbers': ['SMT70-*MH', 'SMT70-*+MH']}}, 'category': 'product_name'}, {'name': 'mobiLink Bluetooth and USB modem in bundle with Field Xpert SMT77', 'product': {'name': 'mobiLink Bluetooth and USB modem in bundle with Field Xpert SMT77', 'product_id': 'CSAFPID-11004', 'product_identification_helper': {'model_numbers': ['SMT77-*+MH', 'SMT77-*MH']}}, 'category': 'product_name'}, {'name': 'mobiLink BT and USB modem CN+KR in bundle with Field Xpert SMT70', 'product': {'name': 'mobiLink BT and USB modem CN+KR in bundle with Field Xpert SMT70', 'product_id': 'CSAFPID-11005', 'product_identification_helper': {'model_numbers': ['SMT70-*MJ', 'SMT70-*+MJ']}}, 'category': 'product_name'}, {'name': 'mobiLink BT and USB modem CN+KR in bundle with Field Xpert SMT77', 'product': {'name': 'mobiLink BT and USB modem CN+KR in bundle with Field Xpert SMT77', 'product_id': 'CSAFPID-11006', 'product_identification_helper': {'model_numbers': ['SMT77-*+MJ', 'SMT77-*MJ']}}, 'category': 'product_name'}], 'category': 'product_family'}, {'name': 'Firmware', 'branches': [{'name': '1.31<=1.40', 'product': {'name': 'Firmware 1.31<=1.40', 'product_id': 'CSAFPID-21001'}, 'category': 'product_version_range'}], 'category': 'product_family'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Firmware 1.31<=1.40 installed on FieldPort SFP50 (mobiLink)', 'product_id': 'CSAFPID-31001'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11001'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 1.31<=1.40 installed on mobiLink Bluetooth and USB modem in bundle with Field Xpert SMT50', 'product_id': 'CSAFPID-31002'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11002'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 1.31<=1.40 installed on mobiLink Bluetooth and USB modem in bundle with Field Xpert SMT70', 'product_id': 'CSAFPID-31003'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11003'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 1.31<=1.40 installed on mobiLink Bluetooth and USB modem in bundle with Field Xpert SMT70', 'product_id': 'CSAFPID-31004'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11004'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 1.31<=1.40 installed on mobiLink Bluetooth and USB modem in bundle with Field Xpert SMT77', 'product_id': 'CSAFPID-31005'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11005'}, {'category': 'installed_on', 'full_product_name': {'name': 'Firmware 1.31<=1.40 installed on mobiLink Bluetooth and USB modem in bundle with Field Xpert SMT77', 'product_id': 'CSAFPID-31006'}, 'product_reference': 'CSAFPID-21001', 'relates_to_product_reference': 'CSAFPID-11006'}], 'product_groups': [{'summary': 'Affected products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006']}]}, 'vulnerabilities': [{'cve': 'CVE-2021-35093', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'Possible memory corruption in BT controller when it receives an oversized LMP packet over 2-DH1 link and leads to denial of service in BlueCore', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2021-35093', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'ADJACENT_NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 6.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'HIGH', 'environmentalScore': 6.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006']}], 'remediations': [{'details': 'Endress+Hauser recommends using the FieldPort SFP50 only in secure environment and to allow access tothe devices only to authorized persons.', 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Currently no fix planned from chip supplier.', 'category': 'no_fix_planned', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'known_affected': ['CSAFPID-31001', 'CSAFPID-31002', 'CSAFPID-31003', 'CSAFPID-31004', 'CSAFPID-31005', 'CSAFPID-31006']}}]}
ba933d835454bbceee53aff8a3bbe0711efbb7ad225b8f94f3259e8ae7e329ed
2026-05-29 08:30:37.139460+03:00
2026-05-29 08:30:37.139460+03:00
csaf_endresshauserag.ndjson
3687dc6ed6063ed9b3981fb2a059dc2034d197f3d5cd6afe04519b70c7c7f869
{'document': {'lang': 'en-GB', 'notes': [{'text': 'For detailed information please refer to WIBU SYSTEMS original Advisories at https://wibu.com/support/security-advisories.html.', 'title': 'Summary', 'category': 'summary'}, {'text': "All vulnerabilities have already been fixed in several CodeMeter versions. Endress+Hauser recommends to use CodeMeter version >=7.40b.\nThe version is available at https://www.wibu.com/support.\nFor the Operating System WIN 7 it's recommended to update the operating system, use/re-install the Endress+Hauser Software Application supporting the newer operating system and update Code Meter to version >= 7.40b.", 'title': 'Mitigation', 'category': 'description'}, {'text': 'Update the software application of the affected products:\n\n| # | Product Name | Fixed Version |\n|----------------------------------|-----------------------------------------------|-------------------|\n| SCE30B | | |\n| SCE31B | SupplyCare Enterprise | >= 3.5.1 |\n| SCE32B | | |\n| SFE100 | DeviceCare | >= 1.07.07 |\n| SFE500 | FieldCare | >= 2.17.00 |\n| SMT50 | | |\n| SMT70 | Field Xpert | >= 1.06.00 |\n| SMT77 | | |\n| MS20 | | |\n| MS21 | Field Data Manager | >= 1.6.3 |\n| Freeware for the | | |\n| Proline Promag W 800/5W8C | Proline Promag W 800 OPC/UA Connectivity Server | > V1.3.7926 |\n| via Endress+Hauser Download Portal | | |', 'title': 'Remediation', 'category': 'description'}], 'title': 'Endress+Hauser: Multiple products utilizing vulnerable WIBU-SYSTEMS CodeMeter components', 'category': 'csaf_security_advisory', 'tracking': {'id': 'VDE-2022-019', 'status': 'final', 'aliases': ['VDE-2022-019'], 'version': '1.0.0', 'generator': {'date': '2025-06-23T09:40:56.803Z', 'engine': {'name': 'Secvisogram', 'version': '2.5.28'}}, 'revision_history': [{'date': '2022-06-02T15:11:00.000Z', 'number': '1.0.0', 'summary': 'Initial revision.'}], 'current_release_date': '2022-06-02T15:11:00.000Z', 'initial_release_date': '2022-06-02T15:11:00.000Z'}, 'publisher': {'name': 'Endress+Hauser AG', 'category': 'vendor', 'namespace': 'https://www.endress.com', 'contact_details': 'psirt@endress.com'}, 'references': [{'url': 'https://certvde.com/en/advisories/VDE-2022-019/', 'summary': 'VDE-2022-019: Endress+Hauser: Multiple products utilizing vulnerable WIBU-SYSTEMS CodeMeter components - HTML', 'category': 'self'}, {'url': 'https://endress-hauser.csaf-tp.certvde.com/.well-known/csaf/white/2022/vde-2022-019.json', 'summary': 'VDE-2022-019: Endress+Hauser: Multiple products utilizing vulnerable WIBU-SYSTEMS CodeMeter components - CSAF', 'category': 'self'}, {'url': 'https://www.endress.com', 'summary': 'Vendor PSIRT', 'category': 'external'}, {'url': 'https://certvde.com/en/advisories/vendor/endress-hauser/', 'summary': 'CERT@VDE Security Advisories for Endress+Hauser AG', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.first.org/tlp/', 'label': 'WHITE'}}, 'acknowledgments': [{'urls': ['https://certvde.com'], 'summary': 'coordination', 'organization': 'CERT@VDE'}]}, 'product_tree': {'branches': [{'name': 'Endress+Hauser', 'branches': [{'name': 'Software', 'branches': [{'name': 'DeviceCare', 'branches': [{'name': '1.02.xx<=1.07.06', 'product': {'name': 'DeviceCare 1.02.xx<=1.07.06', 'product_id': 'CSAFPID-51001', 'product_identification_helper': {'model_numbers': ['SFE100']}}, 'category': 'product_version_range'}, {'name': '1.07.07', 'product': {'name': 'DeviceCare 1.07.07', 'product_id': 'CSAFPID-52001', 'product_identification_helper': {'model_numbers': ['SFE100']}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'FieldCare', 'branches': [{'name': '2.15.xx<=2.16.xx', 'product': {'name': 'FieldCare 2.15.xx<=2.16.xx', 'product_id': 'CSAFPID-51002', 'product_identification_helper': {'model_numbers': ['SFE500']}}, 'category': 'product_version_range'}, {'name': '2.17.00', 'product': {'name': 'FieldCare 2.17.00', 'product_id': 'CSAFPID-52002', 'product_identification_helper': {'model_numbers': ['SFE500']}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Field Data Manager', 'branches': [{'name': '1.4.0<=1.6.2', 'product': {'name': 'Field Data Manager 1.4.0<=1.6.2', 'product_id': 'CSAFPID-51003', 'product_identification_helper': {'model_numbers': ['MS21']}}, 'category': 'product_version_range'}, {'name': '1.6.3', 'product': {'name': 'Field Data Manager 1.6.3', 'product_id': 'CSAFPID-52003', 'product_identification_helper': {'model_numbers': ['MS21']}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Field Xpert', 'branches': [{'name': '1.03.xx<=1.05.xx', 'product': {'name': 'Field Xpert 1.03.xx<=1.05.xx', 'product_id': 'CSAFPID-51004', 'product_identification_helper': {'model_numbers': ['SMT50']}}, 'category': 'product_version_range'}, {'name': '1.06.00', 'product': {'name': 'Field Xpert 1.06.00', 'product_id': 'CSAFPID-52004', 'product_identification_helper': {'model_numbers': ['SMT50']}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Proline Promag W 800 OPC/UA Connectivity Server', 'branches': [{'name': 'V1.3.7926', 'product': {'name': 'Proline Promag W 800 OPC/UA Connectivity Server V1.3.7926', 'product_id': 'CSAFPID-51005'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'SupplyCare Enterprise', 'branches': [{'name': '3.0.x<=3.4.x', 'product': {'name': 'SupplyCare Enterprise 3.0.x<=3.4.x', 'product_id': 'CSAFPID-51006', 'product_identification_helper': {'model_numbers': ['SCE31B']}}, 'category': 'product_version_range'}, {'name': '3.5.1', 'product': {'name': 'SupplyCare Enterprise 3.5.1', 'product_id': 'CSAFPID-52005', 'product_identification_helper': {'model_numbers': ['SCE31B']}}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'product_family'}], 'category': 'vendor'}], 'product_groups': [{'summary': 'Affected products.', 'group_id': 'CSAFGID-0001', 'product_ids': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003', 'CSAFPID-51004', 'CSAFPID-51005', 'CSAFPID-51006']}, {'summary': 'Fixed products.', 'group_id': 'CSAFGID-0002', 'product_ids': ['CSAFPID-52001', 'CSAFPID-52002', 'CSAFPID-52003', 'CSAFPID-52004', 'CSAFPID-52005']}]}, 'vulnerabilities': [{'cve': 'CVE-2021-22901', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malicious server can use this in rare unfortunate circumstances to potentially reach remote code execution in the client. When libcurl at run-time sets up support for TLS 1.3 session tickets on a connection using OpenSSL, it stores pointers to the transfer in-memory object for later retrieval when a session ticket arrives. If the connection is used by multiple transfers (like with a reused HTTP/1.1 connection or multiplexed HTTP/2 connection) that first transfer object might be freed before the new session is established on that connection and then the function will access a memory buffer that might be freed. When using that memory, libcurl might even call a function pointer in the object, making it possible for a remote code execution if the server could somehow manage to get crafted memory content into the correct place in memory.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2021-22901', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.1, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 8.1, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 8.1, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003', 'CSAFPID-51004', 'CSAFPID-51005', 'CSAFPID-51006']}], 'remediations': [{'details': "All vulnerabilities have already been fixed in several CodeMeter versions. Endress+Hauser recommends to use CodeMeter version >=7.40b.\nThe version is available at https://www.wibu.com/support.\nFor the Operating System WIN 7 it's recommended to update the operating system, use/re-install the Endress+Hauser Software Application supporting the newer operating system and update Code Meter to version >= 7.40b.", 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Update the software application of the affected products:\n\n| # | Product Name | Fixed Version |\n|----------------------------------|-----------------------------------------------|-------------------|\n| SCE30B | | |\n| SCE31B | SupplyCare Enterprise | >= 3.5.1 |\n| SCE32B | | |\n| SFE100 | DeviceCare | >= 1.07.07 |\n| SFE500 | FieldCare | >= 2.17.00 |\n| SMT50 | | |\n| SMT70 | Field Xpert | >= 1.06.00 |\n| SMT77 | | |\n| MS20 | | |\n| MS21 | Field Data Manager | >= 1.6.3 |\n| Freeware for the | | |\n| Proline Promag W 800/5W8C | Proline Promag W 800 OPC/UA Connectivity Server | > V1.3.7926 |\n| via Endress+Hauser Download Portal | | |', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-52001', 'CSAFPID-52002', 'CSAFPID-52003', 'CSAFPID-52004', 'CSAFPID-52005'], 'known_affected': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003', 'CSAFPID-51004', 'CSAFPID-51005', 'CSAFPID-51006']}}, {'cve': 'CVE-2021-41183', 'cwe': {'id': 'CWE-79', 'name': "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"}, 'notes': [{'text': 'jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` options are now always treated as pure text, not HTML. A workaround is to not accept the value of the `*Text` options from untrusted sources.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2021-41183', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 6.1, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N', 'temporalScore': 6.1, 'integrityImpact': 'LOW', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 6.1, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003', 'CSAFPID-51004', 'CSAFPID-51005', 'CSAFPID-51006']}], 'remediations': [{'details': "All vulnerabilities have already been fixed in several CodeMeter versions. Endress+Hauser recommends to use CodeMeter version >=7.40b.\nThe version is available at https://www.wibu.com/support.\nFor the Operating System WIN 7 it's recommended to update the operating system, use/re-install the Endress+Hauser Software Application supporting the newer operating system and update Code Meter to version >= 7.40b.", 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Update the software application of the affected products:\n\n| # | Product Name | Fixed Version |\n|----------------------------------|-----------------------------------------------|-------------------|\n| SCE30B | | |\n| SCE31B | SupplyCare Enterprise | >= 3.5.1 |\n| SCE32B | | |\n| SFE100 | DeviceCare | >= 1.07.07 |\n| SFE500 | FieldCare | >= 2.17.00 |\n| SMT50 | | |\n| SMT70 | Field Xpert | >= 1.06.00 |\n| SMT77 | | |\n| MS20 | | |\n| MS21 | Field Data Manager | >= 1.6.3 |\n| Freeware for the | | |\n| Proline Promag W 800/5W8C | Proline Promag W 800 OPC/UA Connectivity Server | > V1.3.7926 |\n| via Endress+Hauser Download Portal | | |', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-52001', 'CSAFPID-52002', 'CSAFPID-52003', 'CSAFPID-52004', 'CSAFPID-52005'], 'known_affected': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003', 'CSAFPID-51004', 'CSAFPID-51005', 'CSAFPID-51006']}}, {'cve': 'CVE-2021-41182', 'cwe': {'id': 'CWE-79', 'name': "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"}, 'notes': [{'text': 'jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `altField` option is now treated as a CSS selector. A workaround is to not accept the value of the `altField` option from untrusted sources.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2021-41182', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 6.1, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N', 'temporalScore': 6.1, 'integrityImpact': 'LOW', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 6.1, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003', 'CSAFPID-51004', 'CSAFPID-51005', 'CSAFPID-51006']}], 'remediations': [{'details': "All vulnerabilities have already been fixed in several CodeMeter versions. Endress+Hauser recommends to use CodeMeter version >=7.40b.\nThe version is available at https://www.wibu.com/support.\nFor the Operating System WIN 7 it's recommended to update the operating system, use/re-install the Endress+Hauser Software Application supporting the newer operating system and update Code Meter to version >= 7.40b.", 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Update the software application of the affected products:\n\n| # | Product Name | Fixed Version |\n|----------------------------------|-----------------------------------------------|-------------------|\n| SCE30B | | |\n| SCE31B | SupplyCare Enterprise | >= 3.5.1 |\n| SCE32B | | |\n| SFE100 | DeviceCare | >= 1.07.07 |\n| SFE500 | FieldCare | >= 2.17.00 |\n| SMT50 | | |\n| SMT70 | Field Xpert | >= 1.06.00 |\n| SMT77 | | |\n| MS20 | | |\n| MS21 | Field Data Manager | >= 1.6.3 |\n| Freeware for the | | |\n| Proline Promag W 800/5W8C | Proline Promag W 800 OPC/UA Connectivity Server | > V1.3.7926 |\n| via Endress+Hauser Download Portal | | |', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-52001', 'CSAFPID-52002', 'CSAFPID-52003', 'CSAFPID-52004', 'CSAFPID-52005'], 'known_affected': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003', 'CSAFPID-51004', 'CSAFPID-51005', 'CSAFPID-51006']}}, {'cve': 'CVE-2020-8286', 'cwe': {'id': 'CWE-295', 'name': 'Improper Certificate Validation'}, 'notes': [{'text': 'curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2020-8286', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N', 'temporalScore': 7.5, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'NONE', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003', 'CSAFPID-51004', 'CSAFPID-51005', 'CSAFPID-51006']}], 'remediations': [{'details': "All vulnerabilities have already been fixed in several CodeMeter versions. Endress+Hauser recommends to use CodeMeter version >=7.40b.\nThe version is available at https://www.wibu.com/support.\nFor the Operating System WIN 7 it's recommended to update the operating system, use/re-install the Endress+Hauser Software Application supporting the newer operating system and update Code Meter to version >= 7.40b.", 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Update the software application of the affected products:\n\n| # | Product Name | Fixed Version |\n|----------------------------------|-----------------------------------------------|-------------------|\n| SCE30B | | |\n| SCE31B | SupplyCare Enterprise | >= 3.5.1 |\n| SCE32B | | |\n| SFE100 | DeviceCare | >= 1.07.07 |\n| SFE500 | FieldCare | >= 2.17.00 |\n| SMT50 | | |\n| SMT70 | Field Xpert | >= 1.06.00 |\n| SMT77 | | |\n| MS20 | | |\n| MS21 | Field Data Manager | >= 1.6.3 |\n| Freeware for the | | |\n| Proline Promag W 800/5W8C | Proline Promag W 800 OPC/UA Connectivity Server | > V1.3.7926 |\n| via Endress+Hauser Download Portal | | |', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-52001', 'CSAFPID-52002', 'CSAFPID-52003', 'CSAFPID-52004', 'CSAFPID-52005'], 'known_affected': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003', 'CSAFPID-51004', 'CSAFPID-51005', 'CSAFPID-51006']}}, {'cve': 'CVE-2021-41184', 'cwe': {'id': 'CWE-79', 'name': "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"}, 'notes': [{'text': 'jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `of` option is now treated as a CSS selector. A workaround is to not accept the value of the `of` option from untrusted sources.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2021-41184', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 6.1, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N', 'temporalScore': 6.1, 'integrityImpact': 'LOW', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 6.1, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003', 'CSAFPID-51004', 'CSAFPID-51005', 'CSAFPID-51006']}], 'remediations': [{'details': "All vulnerabilities have already been fixed in several CodeMeter versions. Endress+Hauser recommends to use CodeMeter version >=7.40b.\nThe version is available at https://www.wibu.com/support.\nFor the Operating System WIN 7 it's recommended to update the operating system, use/re-install the Endress+Hauser Software Application supporting the newer operating system and update Code Meter to version >= 7.40b.", 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Update the software application of the affected products:\n\n| # | Product Name | Fixed Version |\n|----------------------------------|-----------------------------------------------|-------------------|\n| SCE30B | | |\n| SCE31B | SupplyCare Enterprise | >= 3.5.1 |\n| SCE32B | | |\n| SFE100 | DeviceCare | >= 1.07.07 |\n| SFE500 | FieldCare | >= 2.17.00 |\n| SMT50 | | |\n| SMT70 | Field Xpert | >= 1.06.00 |\n| SMT77 | | |\n| MS20 | | |\n| MS21 | Field Data Manager | >= 1.6.3 |\n| Freeware for the | | |\n| Proline Promag W 800/5W8C | Proline Promag W 800 OPC/UA Connectivity Server | > V1.3.7926 |\n| via Endress+Hauser Download Portal | | |', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-52001', 'CSAFPID-52002', 'CSAFPID-52003', 'CSAFPID-52004', 'CSAFPID-52005'], 'known_affected': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003', 'CSAFPID-51004', 'CSAFPID-51005', 'CSAFPID-51006']}}, {'cve': 'CVE-2021-20093', 'cwe': {'id': 'CWE-125', 'name': 'Out-of-bounds Read'}, 'notes': [{'text': 'A buffer over-read vulnerability exists in Wibu-Systems CodeMeter versions < 7.21a. An unauthenticated remote attacker can exploit this issue to disclose heap memory contents or crash the CodeMeter Runtime Server.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2021-20093', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.1, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H', 'temporalScore': 9.1, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'CRITICAL', 'availabilityImpact': 'HIGH', 'environmentalScore': 9.1, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'CRITICAL'}, 'products': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003', 'CSAFPID-51004', 'CSAFPID-51005', 'CSAFPID-51006']}], 'remediations': [{'details': "All vulnerabilities have already been fixed in several CodeMeter versions. Endress+Hauser recommends to use CodeMeter version >=7.40b.\nThe version is available at https://www.wibu.com/support.\nFor the Operating System WIN 7 it's recommended to update the operating system, use/re-install the Endress+Hauser Software Application supporting the newer operating system and update Code Meter to version >= 7.40b.", 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Update the software application of the affected products:\n\n| # | Product Name | Fixed Version |\n|----------------------------------|-----------------------------------------------|-------------------|\n| SCE30B | | |\n| SCE31B | SupplyCare Enterprise | >= 3.5.1 |\n| SCE32B | | |\n| SFE100 | DeviceCare | >= 1.07.07 |\n| SFE500 | FieldCare | >= 2.17.00 |\n| SMT50 | | |\n| SMT70 | Field Xpert | >= 1.06.00 |\n| SMT77 | | |\n| MS20 | | |\n| MS21 | Field Data Manager | >= 1.6.3 |\n| Freeware for the | | |\n| Proline Promag W 800/5W8C | Proline Promag W 800 OPC/UA Connectivity Server | > V1.3.7926 |\n| via Endress+Hauser Download Portal | | |', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-52001', 'CSAFPID-52002', 'CSAFPID-52003', 'CSAFPID-52004', 'CSAFPID-52005'], 'known_affected': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003', 'CSAFPID-51004', 'CSAFPID-51005', 'CSAFPID-51006']}}, {'cve': 'CVE-2021-41057', 'cwe': {'id': 'CWE-59', 'name': "Improper Link Resolution Before File Access ('Link Following')"}, 'notes': [{'text': 'In WIBU CodeMeter Runtime before 7.30a, creating a crafted CmDongles symbolic link will overwrite the linked file without checking permissions.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2021-41057', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.1, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H', 'temporalScore': 7.1, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.1, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003', 'CSAFPID-51004', 'CSAFPID-51005', 'CSAFPID-51006']}], 'remediations': [{'details': "All vulnerabilities have already been fixed in several CodeMeter versions. Endress+Hauser recommends to use CodeMeter version >=7.40b.\nThe version is available at https://www.wibu.com/support.\nFor the Operating System WIN 7 it's recommended to update the operating system, use/re-install the Endress+Hauser Software Application supporting the newer operating system and update Code Meter to version >= 7.40b.", 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Update the software application of the affected products:\n\n| # | Product Name | Fixed Version |\n|----------------------------------|-----------------------------------------------|-------------------|\n| SCE30B | | |\n| SCE31B | SupplyCare Enterprise | >= 3.5.1 |\n| SCE32B | | |\n| SFE100 | DeviceCare | >= 1.07.07 |\n| SFE500 | FieldCare | >= 2.17.00 |\n| SMT50 | | |\n| SMT70 | Field Xpert | >= 1.06.00 |\n| SMT77 | | |\n| MS20 | | |\n| MS21 | Field Data Manager | >= 1.6.3 |\n| Freeware for the | | |\n| Proline Promag W 800/5W8C | Proline Promag W 800 OPC/UA Connectivity Server | > V1.3.7926 |\n| via Endress+Hauser Download Portal | | |', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-52001', 'CSAFPID-52002', 'CSAFPID-52003', 'CSAFPID-52004', 'CSAFPID-52005'], 'known_affected': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003', 'CSAFPID-51004', 'CSAFPID-51005', 'CSAFPID-51006']}}, {'cve': 'CVE-2021-20094', 'cwe': {'id': 'CWE-125', 'name': 'Out-of-bounds Read'}, 'notes': [{'text': 'A denial of service vulnerability exists in Wibu-Systems CodeMeter versions < 7.21a. An unauthenticated remote attacker can exploit this issue to crash the CodeMeter Runtime Server.', 'title': 'Vulnerability Description', 'category': 'description'}], 'title': 'CVE-2021-20094', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'temporalScore': 7.5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.5, 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003', 'CSAFPID-51004', 'CSAFPID-51005', 'CSAFPID-51006']}], 'remediations': [{'details': "All vulnerabilities have already been fixed in several CodeMeter versions. Endress+Hauser recommends to use CodeMeter version >=7.40b.\nThe version is available at https://www.wibu.com/support.\nFor the Operating System WIN 7 it's recommended to update the operating system, use/re-install the Endress+Hauser Software Application supporting the newer operating system and update Code Meter to version >= 7.40b.", 'category': 'mitigation', 'group_ids': ['CSAFGID-0001']}, {'details': 'Update the software application of the affected products:\n\n| # | Product Name | Fixed Version |\n|----------------------------------|-----------------------------------------------|-------------------|\n| SCE30B | | |\n| SCE31B | SupplyCare Enterprise | >= 3.5.1 |\n| SCE32B | | |\n| SFE100 | DeviceCare | >= 1.07.07 |\n| SFE500 | FieldCare | >= 2.17.00 |\n| SMT50 | | |\n| SMT70 | Field Xpert | >= 1.06.00 |\n| SMT77 | | |\n| MS20 | | |\n| MS21 | Field Data Manager | >= 1.6.3 |\n| Freeware for the | | |\n| Proline Promag W 800/5W8C | Proline Promag W 800 OPC/UA Connectivity Server | > V1.3.7926 |\n| via Endress+Hauser Download Portal | | |', 'category': 'vendor_fix', 'group_ids': ['CSAFGID-0001']}], 'product_status': {'fixed': ['CSAFPID-52001', 'CSAFPID-52002', 'CSAFPID-52003', 'CSAFPID-52004', 'CSAFPID-52005'], 'known_affected': ['CSAFPID-51001', 'CSAFPID-51002', 'CSAFPID-51003', 'CSAFPID-51004', 'CSAFPID-51005', 'CSAFPID-51006']}}]}
6932eacf26091f8b5e8d64d3f3ee31e2c60aca0af274e838a8a0c2b8ad98c21c
2026-05-29 08:30:37.139460+03:00
2026-05-29 08:30:37.139460+03:00