home.social

#ocsaf — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #ocsaf, aggregated by home.social.

  1. #OT #Advisory VDE-2026-040
    CODESYS EtherNetIP - Improper timeout handling

    CODESYS EtherNet/IP is an add‑on for the CODESYS Development System that provides a fully integrated EtherNet/IP protocol stack along with diagnostic capabilities. A flaw in the EtherNet/IP adapter protocol stack library results in a vulnerability within the generated application code. When an EtherNet/IP adapter is configured, this vulnerable protocol stack is downloaded to and executed by CODESYS Control runtime systems.
    #CVE CVE-2026-35225

    certvde.com/en/advisories/vde-
    #oCSAF
    #CSAF codesys.csaf-tp.certvde.com/.w

  2. #OT #Advisory VDE-2026-040
    CODESYS EtherNetIP - Improper timeout handling

    CODESYS EtherNet/IP is an add‑on for the CODESYS Development System that provides a fully integrated EtherNet/IP protocol stack along with diagnostic capabilities. A flaw in the EtherNet/IP adapter protocol stack library results in a vulnerability within the generated application code. When an EtherNet/IP adapter is configured, this vulnerable protocol stack is downloaded to and executed by CODESYS Control runtime systems.
    #CVE CVE-2026-35225

    certvde.com/en/advisories/vde-
    #oCSAF
    #CSAF codesys.csaf-tp.certvde.com/.w

  3. #OT #Advisory VDE-2026-040
    CODESYS EtherNetIP - Improper timeout handling

    CODESYS EtherNet/IP is an add‑on for the CODESYS Development System that provides a fully integrated EtherNet/IP protocol stack along with diagnostic capabilities. A flaw in the EtherNet/IP adapter protocol stack library results in a vulnerability within the generated application code. When an EtherNet/IP adapter is configured, this vulnerable protocol stack is downloaded to and executed by CODESYS Control runtime systems.
    #CVE CVE-2026-35225

    certvde.com/en/advisories/vde-
    #oCSAF
    #CSAF codesys.csaf-tp.certvde.com/.w

  4. #OT #Advisory VDE-2026-029
    METTLER TOLEDO: OpenSSL vulnerability in MX and MR balances

    MX/MR firmware V2.0.0 or earlier is affected by the OpenSSL vulnerability CVE-2025-15467.
    #CVE CVE-2025-15467

    certvde.com/en/advisories/vde-
    #oCSAF
    #CSAF mettler-toledo.csaf-tp.certvde

  5. #OT #Advisory VDE-2026-029
    METTLER TOLEDO: OpenSSL vulnerability in MX and MR balances

    MX/MR firmware V2.0.0 or earlier is affected by the OpenSSL vulnerability CVE-2025-15467.
    #CVE CVE-2025-15467

    certvde.com/en/advisories/vde-
    #oCSAF
    #CSAF mettler-toledo.csaf-tp.certvde

  6. #OT #Advisory VDE-2026-029
    METTLER TOLEDO: OpenSSL vulnerability in MX and MR balances

    MX/MR firmware V2.0.0 or earlier is affected by the OpenSSL vulnerability CVE-2025-15467.
    #CVE CVE-2025-15467

    certvde.com/en/advisories/vde-
    #oCSAF
    #CSAF mettler-toledo.csaf-tp.certvde

  7. #OT #Advisory VDE-2024-008
    Wago: Vulnerability in WBM through Open VPN

    A security vulnerability has been identified in the Web-Based Management (WBM) function when OpenVPN is enabled.
    #CVE CVE-2024-1490

    certvde.com/en/advisories/vde-
    #oCSAF
    #CSAF wago.csaf-tp.certvde.com/.well

  8. #OT #Advisory VDE-2024-008
    Wago: Vulnerability in WBM through Open VPN

    A security vulnerability has been identified in the Web-Based Management (WBM) function when OpenVPN is enabled.
    #CVE CVE-2024-1490

    certvde.com/en/advisories/vde-
    #oCSAF
    #CSAF wago.csaf-tp.certvde.com/.well

  9. #OT #Advisory VDE-2024-008
    Wago: Vulnerability in WBM through Open VPN

    A security vulnerability has been identified in the Web-Based Management (WBM) function when OpenVPN is enabled.
    #CVE CVE-2024-1490

    certvde.com/en/advisories/vde-
    #oCSAF
    #CSAF wago.csaf-tp.certvde.com/.well

  10. #OT #Advisory VDE-2026-013
    Helmholz: Use of a Broken or Risky Cryptographic Algorithm

    Vulnerabilities in PROFINET-Switch devices with firmware <= V1.12.010 that allow an attacker to gain control over the device.
    #CVE CVE-2016-2183

    certvde.com/en/advisories/vde-
    #oCSAF
    #CSAF helmholz.csaf-tp.certvde.com/.

  11. #OT #Advisory VDE-2026-013
    Helmholz: Use of a Broken or Risky Cryptographic Algorithm

    Vulnerabilities in PROFINET-Switch devices with firmware <= V1.12.010 that allow an attacker to gain control over the device.
    #CVE CVE-2016-2183

    certvde.com/en/advisories/vde-
    #oCSAF
    #CSAF helmholz.csaf-tp.certvde.com/.

  12. #OT #Advisory VDE-2026-013
    Helmholz: Use of a Broken or Risky Cryptographic Algorithm

    Vulnerabilities in PROFINET-Switch devices with firmware <= V1.12.010 that allow an attacker to gain control over the device.
    #CVE CVE-2016-2183

    certvde.com/en/advisories/vde-
    #oCSAF
    #CSAF helmholz.csaf-tp.certvde.com/.

  13. Congratulations, Cybersecurity and Infrastructure Security Agency, and Jen Easterly (CISA) on publishing the #OT #Advisories as #oCSAF! 👏

    This is an important step which will allow all asset owners a faster and more effective review of security advisories.
    @certbund already put you up on our #oCSAF Lister: wid.cert-bund.de/.well-known/c

  14. Die Zahl der Schwachstellen steigt - und damit der Aufwand in der Bewertung. Weil manuelle Verfahren an ihre Grenzen stoßen, braucht es Automatisierung.
    #oCSAF ist eine internationale Initiative für eine einheitliche Lösung. Als BSI stellen wir Tools für eine Nutzung bereit.

    Mehr Infos: 👉 bsi.bund.de/dok/954494

    #DeutschlandDigitalSicherBSI

  15. Es lohnt sich, bis zum Ende auf der #HM23 zu bleiben: Heute um 15:25 Uhr stellen wir das Common Security Advisory Format #oCSAF & seine Vorteile im Umgang mit Sicherheitsschwachstellen auf der Industrie 4.0 Conference Stage, Halle 8, Stand D17, vor. #DeutschlandDigitalSicherBSI