<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Vulnerabilities on Research @ Cyber-Defence Campus</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/</link><description>Recent content in Vulnerabilities on Research @ Cyber-Defence Campus</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Fri, 07 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="http://cyber-defence-campus.github.io/projects/vulnerabilities/index.xml" rel="self" type="application/rss+xml"/><item><title>False Emergency or Status Messages Accepted as Legitimate</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2025-71412/</link><pubDate>Fri, 07 Aug 2026 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2025-71412/</guid><description>CPDLC over ATN-B1 accepts injected emergency or status messages as legitimate without adequate checks (CWE-754). Carried out remotely over radio frequency, this may lead to misallocation of resources, operational confusion, and improper response actions by flight crews, air traffic controllers, and ground operations.
CISA ICS advisory: ICSA-26-219-01.</description></item><item><title>Loss of CPDLC Functions via Malicious Link Control Frames</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2025-71410/</link><pubDate>Fri, 07 Aug 2026 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2025-71410/</guid><description>Unnumbered Disconnect (U DISC) and malformed Aviation Very High Frequency Link Control frames can terminate CPDLC sessions over ATN-B1 (CWE-770). An attacker operating remotely over radio frequency can cause a loss of CPDLC functions, forcing a reversion to voice communication and increasing controller workload.
CISA ICS advisory: ICSA-26-219-01.</description></item><item><title>Missing Authentication for Critical Function in VDL Messages</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2025-71409/</link><pubDate>Fri, 07 Aug 2026 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2025-71409/</guid><description>Controller-Pilot Data Link Communications (CPDLC) over ATN-B1 does not authenticate Very High Frequency Data Link messages (CWE-306). Rogue ground stations can inject CPDLC messages remotely over radio frequency, leading to unexpected or misleading clearances and potential pilot confusion.
CISA ICS advisory: ICSA-26-219-01.</description></item><item><title>Repeated Session Resets from Malformed or Out-of-Sequence Frames</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2025-71413/</link><pubDate>Fri, 07 Aug 2026 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2025-71413/</guid><description>Malformed or out-of-sequence frames at the Aviation Very High Frequency Link Control X.25 layers of CPDLC over ATN-B1 cause repeated resets (CWE-754). Carried out remotely over radio frequency, this may result in increased workload and reduced situational awareness.
CISA ICS advisory: ICSA-26-219-01.</description></item><item><title>Simultaneous Disconnection of Multiple Aircraft via Broadcast Control Frames</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2025-71411/</link><pubDate>Fri, 07 Aug 2026 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2025-71411/</guid><description>Broadcast control frames in CPDLC over ATN-B1 can disconnect multiple aircraft simultaneously (CWE-770). Carried out remotely over radio frequency, this leads to delayed clearances and air traffic controller overload.
CISA ICS advisory: ICSA-26-219-01.</description></item><item><title>Exposure of Sensitive Information in Browser localStorage</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2026-55729/</link><pubDate>Fri, 24 Jul 2026 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2026-55729/</guid><description>Loytec LWEB-802 before 5.0.8 stores management credentials in the browser&amp;rsquo;s localStorage without adequate protection (CWE-200). An unauthenticated remote attacker can leak the stored credentials by luring a user into opening a crafted link.</description></item><item><title>Improper Authentication in PAM Configuration</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2026-12504/</link><pubDate>Fri, 24 Jul 2026 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2026-12504/</guid><description>The PAM configuration of Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 (LINX-A64) accepts empty passwords (CWE-287, CWE-521). A local attacker can authenticate as a uid=0 account without a password and obtain a root shell via an /etc/passwd entry with an empty password field.</description></item><item><title>Improper Link Resolution in /usr/bin/larm_starter</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2026-12503/</link><pubDate>Fri, 24 Jul 2026 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2026-12503/</guid><description>Improper link resolution before file access (CWE-59) in /usr/bin/larm_starter on Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 (LINX-A64) allows an authenticated larmapp attacker to make /etc/passwd writable by the larmapp group via a symlink attack on /etc/lighttpd/ssl/server.pem, which leads to root privilege escalation.</description></item><item><title>Improper Privilege Management in /usr/bin/ltsudo</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2026-12502/</link><pubDate>Fri, 24 Jul 2026 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2026-12502/</guid><description>Improper privilege management (CWE-269) in /usr/bin/ltsudo on Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 (LINX-A64) allows an attacker in the superadmin group to reset the password of any LARM user, including the larmapp service account, through the set-passwd subcommand.</description></item><item><title>Out-of-bounds Read in BACnet Packet Parsing</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2026-55732/</link><pubDate>Fri, 24 Jul 2026 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2026-55732/</guid><description>An out-of-bounds read (CWE-125) in the BACnet packet parsing routine bacdt_datetime_to_tod of Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.18 (LINX-A64) allows an unauthenticated remote attacker to crash linx_a64.exe and ultimately reboot the device by sending a malformed BACnet TimeSynchronization or UTC-TimeSynchronization packet with an invalid month value. The same defect affects several further Loytec products.</description></item><item><title>Reflected Cross-Site Scripting</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2026-55730/</link><pubDate>Fri, 24 Jul 2026 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2026-55730/</guid><description>Loytec LWEB-802 before 5.0.8 fails to neutralise the project and mspParams request parameters before reflecting them into the generated page (CWE-79, CWE-116). An unauthenticated remote attacker can execute arbitrary JavaScript in a victim&amp;rsquo;s browser via a crafted link and thereby perform actions with the victim&amp;rsquo;s privileges.</description></item><item><title>Stack-based Buffer Overflow in cmd_ipaddr_conflict</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2026-55728/</link><pubDate>Fri, 24 Jul 2026 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2026-55728/</guid><description>A stack-based buffer overflow (CWE-121) in the cmd_ipaddr_conflict handler of /usr/bin/ltsudo on Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 (LINX-A64) allows an attacker in the superadmin group to abort the SUID-root process, or potentially elevate privileges, by supplying an overly long interface-name argument.</description></item><item><title>Unauthenticated Stored Cross-Site Scripting in the OPC XML-DA Server</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2026-12496/</link><pubDate>Fri, 24 Jul 2026 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2026-12496/</guid><description>The OPC XML-DA server statistics page of Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 (LINX-A64) stores and renders the User-Agent header without neutralisation (CWE-79, CWE-116). An unauthenticated remote attacker can execute arbitrary JavaScript in an administrator&amp;rsquo;s browser via a crafted User-Agent header in a POST /da request, enabling session hijacking, credential theft and device reconfiguration.</description></item><item><title>Unchecked Input for Loop Condition in the SNMP Agent</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2026-55731/</link><pubDate>Fri, 24 Jul 2026 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2026-55731/</guid><description>The SNMP agent of Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 (LINX-A64) uses attacker-controlled input as a loop condition without validation (CWE-606). An unauthenticated remote attacker can cause a persistent denial of service through CPU exhaustion by sending a crafted SNMP GETNEXT request containing a large OID component.</description></item><item><title>Arbitrary File Deletion in the bac-scanresult Method</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2026-35076/</link><pubDate>Wed, 03 Jun 2026 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2026-35076/</guid><description>The bac-scanresult method of the MBS UGW web GUI (firmware before V6_00_07) validates user-controlled input insufficiently (CWE-73). A remote attacker with user privileges can delete arbitrary local files.</description></item><item><title>Arbitrary File Deletion in the ugw-delete-file Method</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2026-35077/</link><pubDate>Wed, 03 Jun 2026 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2026-35077/</guid><description>The ugw-delete-file method of the MBS UGW web GUI (firmware before V6_00_07) validates user-controlled input insufficiently (CWE-73). A remote attacker with user privileges can delete arbitrary local files.</description></item><item><title>Arbitrary File Deletion in the ugw-logstop Method</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2026-35078/</link><pubDate>Wed, 03 Jun 2026 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2026-35078/</guid><description>The ugw-logstop method of the MBS UGW web GUI (firmware before V6_00_07) validates user-controlled input insufficiently (CWE-73). A remote attacker with user privileges can delete arbitrary local files.</description></item><item><title>Arbitrary File Deletion in the ugw-restore Method</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2026-35079/</link><pubDate>Wed, 03 Jun 2026 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2026-35079/</guid><description>The ugw-restore method of the MBS UGW web GUI (firmware before V6_00_07) validates user-controlled input insufficiently (CWE-73). A remote attacker with user privileges can delete arbitrary local files.</description></item><item><title>Arbitrary File Deletion in the ugw-restoreinfo Method</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2026-35080/</link><pubDate>Wed, 03 Jun 2026 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2026-35080/</guid><description>The ugw-restoreinfo method of the MBS UGW web GUI (firmware before V6_00_07) validates user-controlled input insufficiently (CWE-73). A remote attacker with user privileges can delete arbitrary local files.</description></item><item><title>Arbitrary Process Termination in the ugw-logstop Method</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2026-35081/</link><pubDate>Wed, 03 Jun 2026 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2026-35081/</guid><description>The ugw-logstop method of the MBS UGW web GUI (firmware before V6_00_07) validates user-supplied input insufficiently (CWE-20). A remote attacker with user privileges can terminate arbitrary processes on the device.</description></item><item><title>Path Traversal in the ugw-logread Method</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2026-35082/</link><pubDate>Wed, 03 Jun 2026 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2026-35082/</guid><description>The ugw-logread method of the MBS UGW web GUI (firmware before V6_00_07) validates user-supplied input insufficiently (CWE-22). A remote attacker with user privileges can read arbitrary local files through path traversal.</description></item><item><title>Stack-based Buffer Overflow in the bac-deviceobject Method</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2026-35083/</link><pubDate>Wed, 03 Jun 2026 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2026-35083/</guid><description>A stack-based buffer overflow (CWE-121) in the bac-deviceobject method of the MBS UGW web GUI (firmware before V6_00_07) allows a remote attacker with user privileges to gain full system access as root.</description></item><item><title>Stack-based Buffer Overflow in the dali-devconfig Method</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2026-35084/</link><pubDate>Wed, 03 Jun 2026 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2026-35084/</guid><description>A stack-based buffer overflow (CWE-121) in the dali-devconfig method of the MBS UGW web GUI (firmware before V6_00_07) allows a remote attacker with user privileges to gain full system access as root.</description></item><item><title>Stack-based Buffer Overflow in the gdv-serverconfig Method</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2026-35085/</link><pubDate>Wed, 03 Jun 2026 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2026-35085/</guid><description>A stack-based buffer overflow (CWE-121) in the gdv-serverconfig method of the MBS UGW web GUI (firmware before V6_00_07) allows a remote attacker with user privileges to gain full system access as root.</description></item><item><title>Use of Default Password for Service Account</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2026-35075/</link><pubDate>Wed, 03 Jun 2026 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2026-35075/</guid><description>The MBS UGW Universal Gateway firmware before V6_00_07 ships with a hard-coded default password for a service account (CWE-1393). An unauthenticated remote attacker can recover this password from a firmware image and thereby gain full access to all affected devices.</description></item><item><title>Remote stack buffer overflow</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2025-41730/</link><pubDate>Wed, 10 Dec 2025 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2025-41730/</guid><description>The vulnerabilities are exploitable without authentication and may allow remote code execution or cause denial of service. Exploitation can disable the web interface until manual intervention, as no automatic recovery mechanisms are in place.</description></item><item><title>Stack-based Buffer Overflow</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2025-41732/</link><pubDate>Wed, 10 Dec 2025 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2025-41732/</guid><description>An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_cookie() function to write arbitrary data into fixed-size stack buffers which leads to full device compromise.</description></item><item><title>Failure to Handle Incomplete Element</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2025-41724/</link><pubDate>Wed, 22 Oct 2025 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2025-41724/</guid><description>An unauthenticated remote attacker can crash the wscserver by sending incomplete SOAP requests. The wscserver process will not be restarted by a watchdog and a device reboot is necessary to make it work again.</description></item><item><title>Improper Neutralization of Special Elements used in a Command ('Command Injection')</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2025-41721/</link><pubDate>Wed, 22 Oct 2025 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2025-41721/</guid><description>A high privileged remote attacker can influence the parameters passed to the openssl command due to improper neutralisation of special elements when adding a password protected self-signed certificate.</description></item><item><title>Improper Validation of Syntactic Correctness of Input</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2025-41719/</link><pubDate>Wed, 22 Oct 2025 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2025-41719/</guid><description>A low privileged remote attacker can corrupt the webserver users storage on the device by setting a sequence of unsupported characters which leads to deletion of all previously configured users and the creation of the default Administrator with a known default password.</description></item><item><title>Path Traversal: '.../...//'</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2025-41723/</link><pubDate>Wed, 22 Oct 2025 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2025-41723/</guid><description>The importFile SOAP method is vulnerable to a directory traversal attack. An unauthenticated remote attacker bypass the path restriction and upload files to arbitrary locations.</description></item><item><title>Reliance on File Name or Extension of Externally-Supplied File</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2025-41720/</link><pubDate>Wed, 22 Oct 2025 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2025-41720/</guid><description>A low privileged remote attacker can upload arbitrary data masked as a png file to the affected device using the webserver API because only the file extension is verified.</description></item><item><title>Use of Hard-coded Credentials</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2025-41722/</link><pubDate>Wed, 22 Oct 2025 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2025-41722/</guid><description>The wsc server uses a hard-coded certificate to check the authenticity of SOAP messages. An unauthenticated remote attacker can extract private keys from the Software of the affected devices.</description></item><item><title>Reboot Vulnerability</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2025-1718/</link><pubDate>Tue, 24 Jun 2025 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2025-1718/</guid><description>An authenticated user with file access privilege via FTP access can cause the Relion 670/650 and SAM600-IO series device to reboot due to improper disk space management.</description></item><item><title>Buffer Copy without Checking Size of Input</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2024-13503/</link><pubDate>Fri, 17 Jan 2025 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2024-13503/</guid><description>Buffer Copy without Checking Size of Input (&amp;lsquo;Classic Buffer Overflow&amp;rsquo;) vulnerability.</description></item><item><title>Improper Neutralization of Special Elements</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2024-13502/</link><pubDate>Fri, 17 Jan 2025 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2024-13502/</guid><description>Improper Neutralisation of Special Elements used in an OS Command (&amp;lsquo;OS Command Injection&amp;rsquo;) vulnerability.</description></item><item><title>Stack buffer overflow</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/stack-buffer-overflow/</link><pubDate>Wed, 01 Jan 2025 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/stack-buffer-overflow/</guid><description/></item><item><title>Traffic Alert and Collision Avoidance System (TCAS) II</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/traffic-alert-and-collision-avoidance-system-tcas/</link><pubDate>Wed, 01 Jan 2025 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/traffic-alert-and-collision-avoidance-system-tcas/</guid><description>Successful exploitation of these vulnerabilities could allow an attacker to manipulate safety systems and cause a denial-of-service condition.
CISA ICS advisory: ICSA-25-021-01.</description></item><item><title>UBR-01 Mk2</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/ubr-01-mk2-2/</link><pubDate>Sun, 01 Sep 2024 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/ubr-01-mk2-2/</guid><description>Reported to the manufacturer and fixed.</description></item><item><title>UBR-01 Mk2</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/ubr-01-mk2-3/</link><pubDate>Sun, 01 Sep 2024 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/ubr-01-mk2-3/</guid><description>Reported to the manufacturer and fixed.</description></item><item><title>UBR-01 Mk2</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/ubr-01-mk2-4/</link><pubDate>Sun, 01 Sep 2024 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/ubr-01-mk2-4/</guid><description>Reported to the manufacturer and fixed.</description></item><item><title>UBR-01 Mk2</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/ubr-01-mk2-5/</link><pubDate>Sun, 01 Sep 2024 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/ubr-01-mk2-5/</guid><description>Reported to the manufacturer and fixed.</description></item><item><title>UBR-01 Mk2</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/ubr-01-mk2/</link><pubDate>Sun, 01 Sep 2024 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/ubr-01-mk2/</guid><description>Reported to the manufacturer and fixed.</description></item><item><title>HaloITSM</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2024-6200/</link><pubDate>Tue, 06 Aug 2024 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2024-6200/</guid><description/></item><item><title>HaloITSM</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2024-6201/</link><pubDate>Tue, 06 Aug 2024 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2024-6201/</guid><description/></item><item><title>HaloITSM</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2024-6202/</link><pubDate>Tue, 06 Aug 2024 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2024-6202/</guid><description/></item><item><title>HaloITSM</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2024-6203/</link><pubDate>Tue, 06 Aug 2024 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2024-6203/</guid><description/></item><item><title>ActaNova</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/actanova/</link><pubDate>Thu, 01 Aug 2024 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/actanova/</guid><description>Reported via the internal process and fixed.</description></item><item><title>DNS Unbound, PowerDNS, Bind</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/dns-unbound-powerdns-bind/</link><pubDate>Thu, 01 Aug 2024 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/dns-unbound-powerdns-bind/</guid><description>Published at USENIX Security 2024.</description></item><item><title>Plantronics Hub</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2024-27460/</link><pubDate>Fri, 10 May 2024 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2024-27460/</guid><description/></item><item><title>FortiClient (Windows)</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2023-41840/</link><pubDate>Wed, 01 Nov 2023 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2023-41840/</guid><description>Found independently by several entities and reported to the manufacturer before public disclosure; the CVE is typically attributed to the entity that reported it first.</description></item><item><title>Bleachbit</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2023-47113/</link><pubDate>Sun, 01 Oct 2023 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2023-47113/</guid><description/></item><item><title>FortiClient (Windows)</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2022-40681/</link><pubDate>Sun, 01 Oct 2023 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2022-40681/</guid><description>Found independently by several entities and reported to the manufacturer before public disclosure; the CVE is typically attributed to the entity that reported it first.</description></item><item><title>OPSWAT MetaDefender Kiosk</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2023-36657/</link><pubDate>Fri, 01 Sep 2023 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2023-36657/</guid><description/></item><item><title>OPSWAT MetaDefender Kiosk</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2023-36659/</link><pubDate>Fri, 01 Sep 2023 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2023-36659/</guid><description/></item><item><title>Fortiguard</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2022-40682-2/</link><pubDate>Sat, 01 Apr 2023 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2022-40682-2/</guid><description/></item><item><title>Sharekey (19 vulnerabilities)</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/2023-04_sharekey-19-vulnerabilities/</link><pubDate>Sat, 01 Apr 2023 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/2023-04_sharekey-19-vulnerabilities/</guid><description>19 vulnerabilities reported to the manufacturer.</description></item><item><title>Elvexys ISOS</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2022-4780/</link><pubDate>Thu, 01 Dec 2022 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2022-4780/</guid><description/></item><item><title>Elvexys StreamX</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2022-4778/</link><pubDate>Thu, 01 Dec 2022 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2022-4778/</guid><description/></item><item><title>Elvexys StreamX</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2022-4779/</link><pubDate>Thu, 01 Dec 2022 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2022-4779/</guid><description/></item><item><title>e***</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/2022-09_e/</link><pubDate>Thu, 01 Sep 2022 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/2022-09_e/</guid><description/></item><item><title>Plantronics Hub</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/2022-09_plantronics-hub/</link><pubDate>Thu, 01 Sep 2022 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/2022-09_plantronics-hub/</guid><description/></item><item><title>CSAF Provider</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2022-43996/</link><pubDate>Sun, 01 May 2022 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2022-43996/</guid><description/></item><item><title>CVRF-CSAF-Converter</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2022-27193/</link><pubDate>Tue, 01 Mar 2022 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2022-27193/</guid><description/></item><item><title>Combined Charging System (CCS)</title><link>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2022-0878/</link><pubDate>Tue, 01 Feb 2022 00:00:00 +0000</pubDate><guid>http://cyber-defence-campus.github.io/projects/vulnerabilities/cve-2022-0878/</guid><description/></item></channel></rss>