Advisories

For CVSS 2.0, 3.0 and 3.2
VDE-2021-056
May 22, 2025, 3:03 PM
Multiple vulnerabilities were reported in CODESYS 2.3 Runtime. The CODESYS 2.3 Runtime is an essential component in several WAGO PLCs. All vulnerable PLCs are listed in chapter 'Affected Products'. https://www.codesys.com/security/security-reports.html
VDE-2021-049
May 22, 2025, 3:03 PM
A Denial-of-Service Vulnerability was reported in CODESYS 2.3 Runtime. The CODESYS 2.3 Runtime is an essential component in several WAGO PLC's. All vulnerable PLCs are listed in chapter 'Affected Products'.
VDE-2021-050
Nov. 16, 2021, 12:02 PM
Multiple vulnerabilities were reported in the Nucleus Real-Time Operating System (RTOS). The Nucleus RTOS is an essential component in several WAGO PLCs and fieldbus coupler. WAGO uses older Versions of …
VDE-2021-046
Nov. 10, 2021, 8:23 AM
Cross-site scripting in web-based management and memory leak in the remote logging function of FL MGUARD 1102 and FL MGUARD 1105. CVE-2021-34582: The file upload functionality in the web-based management …
VDE-2021-051
May 22, 2025, 3:03 PM
Through specific nodes of the server configuration interface of the TwinCAT OPC UA Server administrators are able to remotely create and delete any files on the system which the server …
VDE-2021-052
May 22, 2025, 3:03 PM
PC Worx / -Express is vulnerable to a 'zip slip' style vulnerability when loading a project file.
VDE-2021-037
May 14, 2025, 2:28 PM
An issue was discovered in the mymbCONNECT24 and mbCONNECT24 software in all versions through V2.9.0.
VDE-2021-041
May 22, 2025, 3:03 PM
Critical vulnerabilities have been discovered in the utilized component log4net by Apache Software Foundation. UPDATE A: Remediation: added fixed VisuNet Products