Action not permitted
Modal body text goes here.
Modal Title
Modal Body
CVE-2023-6780 (GCVE-0-2023-6780)
Vulnerability from cvelistv5
Published
2024-01-31 14:08
Modified
2025-06-17 21:29
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-131 - Incorrect Calculation of Buffer Size
Summary
An integer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when these functions are called with a very long message, leading to an incorrect calculation of the buffer size to store the message, resulting in undefined behavior. This issue affects glibc 2.37 and newer.
References
Impacted products
Vendor | Product | Version | |||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
► | n/a | glibc | |||||||||||||||||||||||||||||||||||||
|
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2025-02-07T17:02:41.644Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "http://packetstormsecurity.com/files/176932/glibc-syslog-Heap-Based-Buffer-Overflow.html" }, { "tags": [ "x_transferred" ], "url": "http://seclists.org/fulldisclosure/2024/Feb/3" }, { "tags": [ "vdb-entry", "x_refsource_REDHAT", "x_transferred" ], "url": "https://access.redhat.com/security/cve/CVE-2023-6780" }, { "name": "RHBZ#2254396", "tags": [ "issue-tracking", "x_refsource_REDHAT", "x_transferred" ], "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2254396" }, { "tags": [ "x_transferred" ], "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D2FIH77VHY3KCRROCXOT6L27WMZXSJ2G/" }, { "tags": [ "x_transferred" ], "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MWQ6BZJ6CV5UAW4VZSKJ6TO4KIW2KWAQ/" }, { "tags": [ "x_transferred" ], "url": "https://security.gentoo.org/glsa/202402-01" }, { "tags": [ "x_transferred" ], "url": "https://www.openwall.com/lists/oss-security/2024/01/30/6" }, { "tags": [ "x_transferred" ], "url": "https://www.qualys.com/2024/01/30/cve-2023-6246/syslog.txt" }, { "url": "https://security.netapp.com/advisory/ntap-20250207-0010/" } ], "title": "CVE Program Container" }, { "metrics": [ { "other": { "content": { "id": "CVE-2023-6780", "options": [ { "Exploitation": "poc" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "timestamp": "2024-01-31T16:36:34.378685Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-06-17T21:29:19.534Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "product": "glibc", "vendor": "n/a", "versions": [ { "status": "unaffected", "version": "2.39" } ] }, { "collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": [ "cpe:/o:redhat:enterprise_linux:6" ], "defaultStatus": "unaffected", "packageName": "compat-glibc", "product": "Red Hat Enterprise Linux 6", "vendor": "Red Hat" }, { "collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": [ "cpe:/o:redhat:enterprise_linux:6" ], "defaultStatus": "unaffected", "packageName": "glibc", "product": "Red Hat Enterprise Linux 6", "vendor": "Red Hat" }, { "collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": [ "cpe:/o:redhat:enterprise_linux:7" ], "defaultStatus": "unaffected", "packageName": "compat-glibc", "product": "Red Hat Enterprise Linux 7", "vendor": "Red Hat" }, { "collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": [ "cpe:/o:redhat:enterprise_linux:7" ], "defaultStatus": "unaffected", "packageName": "glibc", "product": "Red Hat Enterprise Linux 7", "vendor": "Red Hat" }, { "collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": [ "cpe:/o:redhat:enterprise_linux:8" ], "defaultStatus": "unaffected", "packageName": "glibc", "product": "Red Hat Enterprise Linux 8", "vendor": "Red Hat" }, { "collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": [ "cpe:/o:redhat:enterprise_linux:9" ], "defaultStatus": "unaffected", "packageName": "glibc", "product": "Red Hat Enterprise Linux 9", "vendor": "Red Hat" }, { "collectionURL": "https://packages.fedoraproject.org/", "defaultStatus": "affected", "packageName": "glibc", "product": "Fedora", "vendor": "Fedora" } ], "credits": [ { "lang": "en", "value": "Red Hat would like to thank Qualys Threat Research Unit for reporting this issue." } ], "datePublic": "2024-01-30T00:00:00.000Z", "descriptions": [ { "lang": "en", "value": "An integer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when these functions are called with a very long message, leading to an incorrect calculation of the buffer size to store the message, resulting in undefined behavior. This issue affects glibc 2.37 and newer." } ], "metrics": [ { "other": { "content": { "namespace": "https://access.redhat.com/security/updates/classification/", "value": "Low" }, "type": "Red Hat severity rating" } }, { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "LOW", "baseScore": 5.3, "baseSeverity": "MEDIUM", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.1" }, "format": "CVSS" } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-131", "description": "Incorrect Calculation of Buffer Size", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2024-03-26T15:30:47.720Z", "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749", "shortName": "redhat" }, "references": [ { "url": "http://packetstormsecurity.com/files/176932/glibc-syslog-Heap-Based-Buffer-Overflow.html" }, { "url": "http://seclists.org/fulldisclosure/2024/Feb/3" }, { "tags": [ "vdb-entry", "x_refsource_REDHAT" ], "url": "https://access.redhat.com/security/cve/CVE-2023-6780" }, { "name": "RHBZ#2254396", "tags": [ "issue-tracking", "x_refsource_REDHAT" ], "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2254396" }, { "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D2FIH77VHY3KCRROCXOT6L27WMZXSJ2G/" }, { "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MWQ6BZJ6CV5UAW4VZSKJ6TO4KIW2KWAQ/" }, { "url": "https://security.gentoo.org/glsa/202402-01" }, { "url": "https://www.openwall.com/lists/oss-security/2024/01/30/6" }, { "url": "https://www.qualys.com/2024/01/30/cve-2023-6246/syslog.txt" } ], "timeline": [ { "lang": "en", "time": "2023-12-08T00:00:00+00:00", "value": "Reported to Red Hat." }, { "lang": "en", "time": "2024-01-30T00:00:00+00:00", "value": "Made public." } ], "title": "Glibc: integer overflow in __vsyslog_internal()", "x_redhatCweChain": "CWE-190-\u003eCWE-131: Integer Overflow or Wraparound leads to Incorrect Calculation of Buffer Size" } }, "cveMetadata": { "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749", "assignerShortName": "redhat", "cveId": "CVE-2023-6780", "datePublished": "2024-01-31T14:08:02.610Z", "dateReserved": "2023-12-13T14:37:40.684Z", "dateUpdated": "2025-06-17T21:29:19.534Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1", "vulnerability-lookup:meta": { "nvd": "{\"cve\":{\"id\":\"CVE-2023-6780\",\"sourceIdentifier\":\"secalert@redhat.com\",\"published\":\"2024-01-31T14:15:48.917\",\"lastModified\":\"2025-02-07T17:15:29.880\",\"vulnStatus\":\"Modified\",\"cveTags\":[],\"descriptions\":[{\"lang\":\"en\",\"value\":\"An integer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when these functions are called with a very long message, leading to an incorrect calculation of the buffer size to store the message, resulting in undefined behavior. This issue affects glibc 2.37 and newer.\"},{\"lang\":\"es\",\"value\":\"Se encontr\u00f3 un desbordamiento de enteros en la funci\u00f3n __vsyslog_internal de la liibrer\u00eda glibc. Esta funci\u00f3n es llamada por las funciones syslog y vsyslog. Este problema ocurre cuando estas funciones se llaman con un mensaje muy largo, lo que genera un c\u00e1lculo incorrecto del tama\u00f1o del b\u00fafer para almacenar el mensaje, lo que genera un comportamiento indefinido. Este problema afecta a glibc 2.37 y posteriores.\"}],\"metrics\":{\"cvssMetricV31\":[{\"source\":\"secalert@redhat.com\",\"type\":\"Secondary\",\"cvssData\":{\"version\":\"3.1\",\"vectorString\":\"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L\",\"baseScore\":5.3,\"baseSeverity\":\"MEDIUM\",\"attackVector\":\"NETWORK\",\"attackComplexity\":\"LOW\",\"privilegesRequired\":\"NONE\",\"userInteraction\":\"NONE\",\"scope\":\"UNCHANGED\",\"confidentialityImpact\":\"NONE\",\"integrityImpact\":\"NONE\",\"availabilityImpact\":\"LOW\"},\"exploitabilityScore\":3.9,\"impactScore\":1.4},{\"source\":\"nvd@nist.gov\",\"type\":\"Primary\",\"cvssData\":{\"version\":\"3.1\",\"vectorString\":\"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L\",\"baseScore\":5.3,\"baseSeverity\":\"MEDIUM\",\"attackVector\":\"NETWORK\",\"attackComplexity\":\"LOW\",\"privilegesRequired\":\"NONE\",\"userInteraction\":\"NONE\",\"scope\":\"UNCHANGED\",\"confidentialityImpact\":\"NONE\",\"integrityImpact\":\"NONE\",\"availabilityImpact\":\"LOW\"},\"exploitabilityScore\":3.9,\"impactScore\":1.4}]},\"weaknesses\":[{\"source\":\"secalert@redhat.com\",\"type\":\"Primary\",\"description\":[{\"lang\":\"en\",\"value\":\"CWE-131\"}]},{\"source\":\"nvd@nist.gov\",\"type\":\"Secondary\",\"description\":[{\"lang\":\"en\",\"value\":\"CWE-131\"},{\"lang\":\"en\",\"value\":\"CWE-190\"}]}],\"configurations\":[{\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:*\",\"versionStartIncluding\":\"2.37\",\"versionEndExcluding\":\"2.39\",\"matchCriteriaId\":\"8A5153FA-49E9-457F-94BB-202CACA41C76\"}]}]},{\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"CC559B26-5DFC-4B7A-A27C-B77DE755DFF9\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"B8EDB836-4E6A-4B71-B9B2-AA3E03E0F646\"}]}]}],\"references\":[{\"url\":\"http://packetstormsecurity.com/files/176932/glibc-syslog-Heap-Based-Buffer-Overflow.html\",\"source\":\"secalert@redhat.com\",\"tags\":[\"Exploit\",\"Third Party Advisory\",\"VDB Entry\"]},{\"url\":\"http://seclists.org/fulldisclosure/2024/Feb/3\",\"source\":\"secalert@redhat.com\",\"tags\":[\"Exploit\",\"Mailing List\",\"Third Party Advisory\"]},{\"url\":\"https://access.redhat.com/security/cve/CVE-2023-6780\",\"source\":\"secalert@redhat.com\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"https://bugzilla.redhat.com/show_bug.cgi?id=2254396\",\"source\":\"secalert@redhat.com\",\"tags\":[\"Issue Tracking\"]},{\"url\":\"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D2FIH77VHY3KCRROCXOT6L27WMZXSJ2G/\",\"source\":\"secalert@redhat.com\",\"tags\":[\"Mailing List\"]},{\"url\":\"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MWQ6BZJ6CV5UAW4VZSKJ6TO4KIW2KWAQ/\",\"source\":\"secalert@redhat.com\",\"tags\":[\"Mailing List\"]},{\"url\":\"https://security.gentoo.org/glsa/202402-01\",\"source\":\"secalert@redhat.com\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"https://www.openwall.com/lists/oss-security/2024/01/30/6\",\"source\":\"secalert@redhat.com\",\"tags\":[\"Exploit\",\"Mailing List\"]},{\"url\":\"https://www.qualys.com/2024/01/30/cve-2023-6246/syslog.txt\",\"source\":\"secalert@redhat.com\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"http://packetstormsecurity.com/files/176932/glibc-syslog-Heap-Based-Buffer-Overflow.html\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Exploit\",\"Third Party Advisory\",\"VDB Entry\"]},{\"url\":\"http://seclists.org/fulldisclosure/2024/Feb/3\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Exploit\",\"Mailing List\",\"Third Party Advisory\"]},{\"url\":\"https://access.redhat.com/security/cve/CVE-2023-6780\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"https://bugzilla.redhat.com/show_bug.cgi?id=2254396\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Issue Tracking\"]},{\"url\":\"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D2FIH77VHY3KCRROCXOT6L27WMZXSJ2G/\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Mailing List\"]},{\"url\":\"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MWQ6BZJ6CV5UAW4VZSKJ6TO4KIW2KWAQ/\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Mailing List\"]},{\"url\":\"https://security.gentoo.org/glsa/202402-01\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"https://security.netapp.com/advisory/ntap-20250207-0010/\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\"},{\"url\":\"https://www.openwall.com/lists/oss-security/2024/01/30/6\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Exploit\",\"Mailing List\"]},{\"url\":\"https://www.qualys.com/2024/01/30/cve-2023-6246/syslog.txt\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Third Party Advisory\"]}]}}", "vulnrichment": { "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"http://packetstormsecurity.com/files/176932/glibc-syslog-Heap-Based-Buffer-Overflow.html\", \"tags\": [\"x_transferred\"]}, {\"url\": \"http://seclists.org/fulldisclosure/2024/Feb/3\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://access.redhat.com/security/cve/CVE-2023-6780\", \"tags\": [\"vdb-entry\", \"x_refsource_REDHAT\", \"x_transferred\"]}, {\"url\": \"https://bugzilla.redhat.com/show_bug.cgi?id=2254396\", \"name\": \"RHBZ#2254396\", \"tags\": [\"issue-tracking\", \"x_refsource_REDHAT\", \"x_transferred\"]}, {\"url\": \"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D2FIH77VHY3KCRROCXOT6L27WMZXSJ2G/\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MWQ6BZJ6CV5UAW4VZSKJ6TO4KIW2KWAQ/\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://security.gentoo.org/glsa/202402-01\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://www.openwall.com/lists/oss-security/2024/01/30/6\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://www.qualys.com/2024/01/30/cve-2023-6246/syslog.txt\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://security.netapp.com/advisory/ntap-20250207-0010/\"}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2025-02-07T17:02:41.644Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2023-6780\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"poc\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-01-31T16:36:34.378685Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2025-06-17T21:23:00.532Z\"}}], \"cna\": {\"title\": \"Glibc: integer overflow in __vsyslog_internal()\", \"credits\": [{\"lang\": \"en\", \"value\": \"Red Hat would like to thank Qualys Threat Research Unit for reporting this issue.\"}], \"metrics\": [{\"other\": {\"type\": \"Red Hat severity rating\", \"content\": {\"value\": \"Low\", \"namespace\": \"https://access.redhat.com/security/updates/classification/\"}}}, {\"format\": \"CVSS\", \"cvssV3_1\": {\"scope\": \"UNCHANGED\", \"version\": \"3.1\", \"baseScore\": 5.3, \"attackVector\": \"NETWORK\", \"baseSeverity\": \"MEDIUM\", \"vectorString\": \"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L\", \"integrityImpact\": \"NONE\", \"userInteraction\": \"NONE\", \"attackComplexity\": \"LOW\", \"availabilityImpact\": \"LOW\", \"privilegesRequired\": \"NONE\", \"confidentialityImpact\": \"NONE\"}}], \"affected\": [{\"vendor\": \"n/a\", \"product\": \"glibc\", \"versions\": [{\"status\": \"unaffected\", \"version\": \"2.39\"}]}, {\"cpes\": [\"cpe:/o:redhat:enterprise_linux:6\"], \"vendor\": \"Red Hat\", \"product\": \"Red Hat Enterprise Linux 6\", \"packageName\": \"compat-glibc\", \"collectionURL\": \"https://access.redhat.com/downloads/content/package-browser/\", \"defaultStatus\": \"unaffected\"}, {\"cpes\": [\"cpe:/o:redhat:enterprise_linux:6\"], \"vendor\": \"Red Hat\", \"product\": \"Red Hat Enterprise Linux 6\", \"packageName\": \"glibc\", \"collectionURL\": \"https://access.redhat.com/downloads/content/package-browser/\", \"defaultStatus\": \"unaffected\"}, {\"cpes\": [\"cpe:/o:redhat:enterprise_linux:7\"], \"vendor\": \"Red Hat\", \"product\": \"Red Hat Enterprise Linux 7\", \"packageName\": \"compat-glibc\", \"collectionURL\": \"https://access.redhat.com/downloads/content/package-browser/\", \"defaultStatus\": \"unaffected\"}, {\"cpes\": [\"cpe:/o:redhat:enterprise_linux:7\"], \"vendor\": \"Red Hat\", \"product\": \"Red Hat Enterprise Linux 7\", \"packageName\": \"glibc\", \"collectionURL\": \"https://access.redhat.com/downloads/content/package-browser/\", \"defaultStatus\": \"unaffected\"}, {\"cpes\": [\"cpe:/o:redhat:enterprise_linux:8\"], \"vendor\": \"Red Hat\", \"product\": \"Red Hat Enterprise Linux 8\", \"packageName\": \"glibc\", \"collectionURL\": \"https://access.redhat.com/downloads/content/package-browser/\", \"defaultStatus\": \"unaffected\"}, {\"cpes\": [\"cpe:/o:redhat:enterprise_linux:9\"], \"vendor\": \"Red Hat\", \"product\": \"Red Hat Enterprise Linux 9\", \"packageName\": \"glibc\", \"collectionURL\": \"https://access.redhat.com/downloads/content/package-browser/\", \"defaultStatus\": \"unaffected\"}, {\"vendor\": \"Fedora\", \"product\": \"Fedora\", \"packageName\": \"glibc\", \"collectionURL\": \"https://packages.fedoraproject.org/\", \"defaultStatus\": \"affected\"}], \"timeline\": [{\"lang\": \"en\", \"time\": \"2023-12-08T00:00:00+00:00\", \"value\": \"Reported to Red Hat.\"}, {\"lang\": \"en\", \"time\": \"2024-01-30T00:00:00+00:00\", \"value\": \"Made public.\"}], \"datePublic\": \"2024-01-30T00:00:00.000Z\", \"references\": [{\"url\": \"http://packetstormsecurity.com/files/176932/glibc-syslog-Heap-Based-Buffer-Overflow.html\"}, {\"url\": \"http://seclists.org/fulldisclosure/2024/Feb/3\"}, {\"url\": \"https://access.redhat.com/security/cve/CVE-2023-6780\", \"tags\": [\"vdb-entry\", \"x_refsource_REDHAT\"]}, {\"url\": \"https://bugzilla.redhat.com/show_bug.cgi?id=2254396\", \"name\": \"RHBZ#2254396\", \"tags\": [\"issue-tracking\", \"x_refsource_REDHAT\"]}, {\"url\": \"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D2FIH77VHY3KCRROCXOT6L27WMZXSJ2G/\"}, {\"url\": \"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MWQ6BZJ6CV5UAW4VZSKJ6TO4KIW2KWAQ/\"}, {\"url\": \"https://security.gentoo.org/glsa/202402-01\"}, {\"url\": \"https://www.openwall.com/lists/oss-security/2024/01/30/6\"}, {\"url\": \"https://www.qualys.com/2024/01/30/cve-2023-6246/syslog.txt\"}], \"descriptions\": [{\"lang\": \"en\", \"value\": \"An integer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when these functions are called with a very long message, leading to an incorrect calculation of the buffer size to store the message, resulting in undefined behavior. This issue affects glibc 2.37 and newer.\"}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"cweId\": \"CWE-131\", \"description\": \"Incorrect Calculation of Buffer Size\"}]}], \"providerMetadata\": {\"orgId\": \"53f830b8-0a3f-465b-8143-3b8a9948e749\", \"shortName\": \"redhat\", \"dateUpdated\": \"2024-03-26T15:30:47.720Z\"}, \"x_redhatCweChain\": \"CWE-190-\u003eCWE-131: Integer Overflow or Wraparound leads to Incorrect Calculation of Buffer Size\"}}", "cveMetadata": "{\"cveId\": \"CVE-2023-6780\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2025-06-17T21:29:19.534Z\", \"dateReserved\": \"2023-12-13T14:37:40.684Z\", \"assignerOrgId\": \"53f830b8-0a3f-465b-8143-3b8a9948e749\", \"datePublished\": \"2024-01-31T14:08:02.610Z\", \"assignerShortName\": \"redhat\"}", "dataType": "CVE_RECORD", "dataVersion": "5.1" } } }
gsd-2023-6780
Vulnerability from gsd
Modified
2023-12-14 06:01
Details
An integer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when these functions are called with a very long message, leading to an incorrect calculation of the buffer size to store the message, resulting in undefined behavior. This issue affects glibc 2.37 and newer.
Aliases
{ "gsd": { "metadata": { "exploitCode": "unknown", "remediation": "unknown", "reportConfidence": "confirmed", "type": "vulnerability" }, "osvSchema": { "aliases": [ "CVE-2023-6780" ], "details": "An integer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when these functions are called with a very long message, leading to an incorrect calculation of the buffer size to store the message, resulting in undefined behavior. This issue affects glibc 2.37 and newer.", "id": "GSD-2023-6780", "modified": "2023-12-14T06:01:34.719382Z", "schema_version": "1.4.0" } }, "namespaces": { "cve.org": { "CVE_data_meta": { "ASSIGNER": "secalert@redhat.com", "ID": "CVE-2023-6780", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "glibc", "version": { "version_data": [ { "version_value": "not down converted", "x_cve_json_5_version_data": { "versions": [ { "status": "unaffected", "version": "2.39" } ] } } ] } } ] }, "vendor_name": "n/a" }, { "product": { "product_data": [ { "product_name": "Red Hat Enterprise Linux 6", "version": { "version_data": [ { "version_value": "not down converted", "x_cve_json_5_version_data": { "defaultStatus": "unaffected" } }, { "version_value": "not down converted", "x_cve_json_5_version_data": { "defaultStatus": "unaffected" } } ] } }, { "product_name": "Red Hat Enterprise Linux 7", "version": { "version_data": [ { "version_value": "not down converted", "x_cve_json_5_version_data": { "defaultStatus": "unaffected" } }, { "version_value": "not down converted", "x_cve_json_5_version_data": { "defaultStatus": "unaffected" } } ] } }, { "product_name": "Red Hat Enterprise Linux 8", "version": { "version_data": [ { "version_value": "not down converted", "x_cve_json_5_version_data": { "defaultStatus": "unaffected" } } ] } }, { "product_name": "Red Hat Enterprise Linux 9", "version": { "version_data": [ { "version_value": "not down converted", "x_cve_json_5_version_data": { "defaultStatus": "unaffected" } } ] } } ] }, "vendor_name": "Red Hat" }, { "product": { "product_data": [ { "product_name": "Fedora", "version": { "version_data": [ { "version_value": "not down converted", "x_cve_json_5_version_data": { "defaultStatus": "affected" } } ] } } ] }, "vendor_name": "Fedora" } ] } }, "credits": [ { "lang": "en", "value": "Red Hat would like to thank Qualys Threat Research Unit for reporting this issue." } ], "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "An integer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when these functions are called with a very long message, leading to an incorrect calculation of the buffer size to store the message, resulting in undefined behavior. This issue affects glibc 2.37 and newer." } ] }, "impact": { "cvss": [ { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "LOW", "baseScore": 5.3, "baseSeverity": "MEDIUM", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.1" } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "cweId": "CWE-131", "lang": "eng", "value": "Incorrect Calculation of Buffer Size" } ] } ] }, "references": { "reference_data": [ { "name": "http://packetstormsecurity.com/files/176932/glibc-syslog-Heap-Based-Buffer-Overflow.html", "refsource": "MISC", "url": "http://packetstormsecurity.com/files/176932/glibc-syslog-Heap-Based-Buffer-Overflow.html" }, { "name": "http://seclists.org/fulldisclosure/2024/Feb/3", "refsource": "MISC", "url": "http://seclists.org/fulldisclosure/2024/Feb/3" }, { "name": "https://access.redhat.com/security/cve/CVE-2023-6780", "refsource": "MISC", "url": "https://access.redhat.com/security/cve/CVE-2023-6780" }, { "name": "https://bugzilla.redhat.com/show_bug.cgi?id=2254396", "refsource": "MISC", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2254396" }, { "name": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D2FIH77VHY3KCRROCXOT6L27WMZXSJ2G/", "refsource": "MISC", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D2FIH77VHY3KCRROCXOT6L27WMZXSJ2G/" }, { "name": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MWQ6BZJ6CV5UAW4VZSKJ6TO4KIW2KWAQ/", "refsource": "MISC", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MWQ6BZJ6CV5UAW4VZSKJ6TO4KIW2KWAQ/" }, { "name": "https://security.gentoo.org/glsa/202402-01", "refsource": "MISC", "url": "https://security.gentoo.org/glsa/202402-01" }, { "name": "https://www.openwall.com/lists/oss-security/2024/01/30/6", "refsource": "MISC", "url": "https://www.openwall.com/lists/oss-security/2024/01/30/6" }, { "name": "https://www.qualys.com/2024/01/30/cve-2023-6246/syslog.txt", "refsource": "MISC", "url": "https://www.qualys.com/2024/01/30/cve-2023-6246/syslog.txt" } ] } }, "nvd.nist.gov": { "cve": { "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:*", "matchCriteriaId": "8A5153FA-49E9-457F-94BB-202CACA41C76", "versionEndExcluding": "2.39", "versionStartIncluding": "2.37", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*", "matchCriteriaId": "CC559B26-5DFC-4B7A-A27C-B77DE755DFF9", "vulnerable": true }, { "criteria": "cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*", "matchCriteriaId": "B8EDB836-4E6A-4B71-B9B2-AA3E03E0F646", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "descriptions": [ { "lang": "en", "value": "An integer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when these functions are called with a very long message, leading to an incorrect calculation of the buffer size to store the message, resulting in undefined behavior. This issue affects glibc 2.37 and newer." }, { "lang": "es", "value": "Se encontr\u00f3 un desbordamiento de enteros en la funci\u00f3n __vsyslog_internal de la liibrer\u00eda glibc. Esta funci\u00f3n es llamada por las funciones syslog y vsyslog. Este problema ocurre cuando estas funciones se llaman con un mensaje muy largo, lo que genera un c\u00e1lculo incorrecto del tama\u00f1o del b\u00fafer para almacenar el mensaje, lo que genera un comportamiento indefinido. Este problema afecta a glibc 2.37 y posteriores." } ], "id": "CVE-2023-6780", "lastModified": "2024-03-26T16:15:10.083", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "LOW", "baseScore": 5.3, "baseSeverity": "MEDIUM", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.1" }, "exploitabilityScore": 3.9, "impactScore": 1.4, "source": "nvd@nist.gov", "type": "Primary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "LOW", "baseScore": 5.3, "baseSeverity": "MEDIUM", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.1" }, "exploitabilityScore": 3.9, "impactScore": 1.4, "source": "secalert@redhat.com", "type": "Secondary" } ] }, "published": "2024-01-31T14:15:48.917", "references": [ { "source": "secalert@redhat.com", "tags": [ "Exploit", "Third Party Advisory", "VDB Entry" ], "url": "http://packetstormsecurity.com/files/176932/glibc-syslog-Heap-Based-Buffer-Overflow.html" }, { "source": "secalert@redhat.com", "tags": [ "Exploit", "Mailing List", "Third Party Advisory" ], "url": "http://seclists.org/fulldisclosure/2024/Feb/3" }, { "source": "secalert@redhat.com", "tags": [ "Third Party Advisory" ], "url": "https://access.redhat.com/security/cve/CVE-2023-6780" }, { "source": "secalert@redhat.com", "tags": [ "Issue Tracking" ], "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2254396" }, { "source": "secalert@redhat.com", "tags": [ "Mailing List" ], "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D2FIH77VHY3KCRROCXOT6L27WMZXSJ2G/" }, { "source": "secalert@redhat.com", "tags": [ "Mailing List" ], "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MWQ6BZJ6CV5UAW4VZSKJ6TO4KIW2KWAQ/" }, { "source": "secalert@redhat.com", "tags": [ "Third Party Advisory" ], "url": "https://security.gentoo.org/glsa/202402-01" }, { "source": "secalert@redhat.com", "tags": [ "Exploit", "Mailing List" ], "url": "https://www.openwall.com/lists/oss-security/2024/01/30/6" }, { "source": "secalert@redhat.com", "tags": [ "Third Party Advisory" ], "url": "https://www.qualys.com/2024/01/30/cve-2023-6246/syslog.txt" } ], "sourceIdentifier": "secalert@redhat.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-131" } ], "source": "secalert@redhat.com", "type": "Primary" }, { "description": [ { "lang": "en", "value": "CWE-131" }, { "lang": "en", "value": "CWE-190" } ], "source": "nvd@nist.gov", "type": "Secondary" } ] } } } }
fkie_cve-2023-6780
Vulnerability from fkie_nvd
Published
2024-01-31 14:15
Modified
2025-02-07 17:15
Severity ?
5.3 (Medium) - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
5.3 (Medium) - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
5.3 (Medium) - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Summary
An integer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when these functions are called with a very long message, leading to an incorrect calculation of the buffer size to store the message, resulting in undefined behavior. This issue affects glibc 2.37 and newer.
References
▶ | URL | Tags | |
---|---|---|---|
secalert@redhat.com | http://packetstormsecurity.com/files/176932/glibc-syslog-Heap-Based-Buffer-Overflow.html | Exploit, Third Party Advisory, VDB Entry | |
secalert@redhat.com | http://seclists.org/fulldisclosure/2024/Feb/3 | Exploit, Mailing List, Third Party Advisory | |
secalert@redhat.com | https://access.redhat.com/security/cve/CVE-2023-6780 | Third Party Advisory | |
secalert@redhat.com | https://bugzilla.redhat.com/show_bug.cgi?id=2254396 | Issue Tracking | |
secalert@redhat.com | https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D2FIH77VHY3KCRROCXOT6L27WMZXSJ2G/ | Mailing List | |
secalert@redhat.com | https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MWQ6BZJ6CV5UAW4VZSKJ6TO4KIW2KWAQ/ | Mailing List | |
secalert@redhat.com | https://security.gentoo.org/glsa/202402-01 | Third Party Advisory | |
secalert@redhat.com | https://www.openwall.com/lists/oss-security/2024/01/30/6 | Exploit, Mailing List | |
secalert@redhat.com | https://www.qualys.com/2024/01/30/cve-2023-6246/syslog.txt | Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | http://packetstormsecurity.com/files/176932/glibc-syslog-Heap-Based-Buffer-Overflow.html | Exploit, Third Party Advisory, VDB Entry | |
af854a3a-2127-422b-91ae-364da2661108 | http://seclists.org/fulldisclosure/2024/Feb/3 | Exploit, Mailing List, Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://access.redhat.com/security/cve/CVE-2023-6780 | Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://bugzilla.redhat.com/show_bug.cgi?id=2254396 | Issue Tracking | |
af854a3a-2127-422b-91ae-364da2661108 | https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D2FIH77VHY3KCRROCXOT6L27WMZXSJ2G/ | Mailing List | |
af854a3a-2127-422b-91ae-364da2661108 | https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MWQ6BZJ6CV5UAW4VZSKJ6TO4KIW2KWAQ/ | Mailing List | |
af854a3a-2127-422b-91ae-364da2661108 | https://security.gentoo.org/glsa/202402-01 | Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://security.netapp.com/advisory/ntap-20250207-0010/ | ||
af854a3a-2127-422b-91ae-364da2661108 | https://www.openwall.com/lists/oss-security/2024/01/30/6 | Exploit, Mailing List | |
af854a3a-2127-422b-91ae-364da2661108 | https://www.qualys.com/2024/01/30/cve-2023-6246/syslog.txt | Third Party Advisory |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
gnu | glibc | * | |
fedoraproject | fedora | 38 | |
fedoraproject | fedora | 39 |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:*", "matchCriteriaId": "8A5153FA-49E9-457F-94BB-202CACA41C76", "versionEndExcluding": "2.39", "versionStartIncluding": "2.37", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*", "matchCriteriaId": "CC559B26-5DFC-4B7A-A27C-B77DE755DFF9", "vulnerable": true }, { "criteria": "cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*", "matchCriteriaId": "B8EDB836-4E6A-4B71-B9B2-AA3E03E0F646", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "An integer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when these functions are called with a very long message, leading to an incorrect calculation of the buffer size to store the message, resulting in undefined behavior. This issue affects glibc 2.37 and newer." }, { "lang": "es", "value": "Se encontr\u00f3 un desbordamiento de enteros en la funci\u00f3n __vsyslog_internal de la liibrer\u00eda glibc. Esta funci\u00f3n es llamada por las funciones syslog y vsyslog. Este problema ocurre cuando estas funciones se llaman con un mensaje muy largo, lo que genera un c\u00e1lculo incorrecto del tama\u00f1o del b\u00fafer para almacenar el mensaje, lo que genera un comportamiento indefinido. Este problema afecta a glibc 2.37 y posteriores." } ], "id": "CVE-2023-6780", "lastModified": "2025-02-07T17:15:29.880", "metrics": { "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "LOW", "baseScore": 5.3, "baseSeverity": "MEDIUM", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.1" }, "exploitabilityScore": 3.9, "impactScore": 1.4, "source": "secalert@redhat.com", "type": "Secondary" }, { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "LOW", "baseScore": 5.3, "baseSeverity": "MEDIUM", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.1" }, "exploitabilityScore": 3.9, "impactScore": 1.4, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2024-01-31T14:15:48.917", "references": [ { "source": "secalert@redhat.com", "tags": [ "Exploit", "Third Party Advisory", "VDB Entry" ], "url": "http://packetstormsecurity.com/files/176932/glibc-syslog-Heap-Based-Buffer-Overflow.html" }, { "source": "secalert@redhat.com", "tags": [ "Exploit", "Mailing List", "Third Party Advisory" ], "url": "http://seclists.org/fulldisclosure/2024/Feb/3" }, { "source": "secalert@redhat.com", "tags": [ "Third Party Advisory" ], "url": "https://access.redhat.com/security/cve/CVE-2023-6780" }, { "source": "secalert@redhat.com", "tags": [ "Issue Tracking" ], "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2254396" }, { "source": "secalert@redhat.com", "tags": [ "Mailing List" ], "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D2FIH77VHY3KCRROCXOT6L27WMZXSJ2G/" }, { "source": "secalert@redhat.com", "tags": [ "Mailing List" ], "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MWQ6BZJ6CV5UAW4VZSKJ6TO4KIW2KWAQ/" }, { "source": "secalert@redhat.com", "tags": [ "Third Party Advisory" ], "url": "https://security.gentoo.org/glsa/202402-01" }, { "source": "secalert@redhat.com", "tags": [ "Exploit", "Mailing List" ], "url": "https://www.openwall.com/lists/oss-security/2024/01/30/6" }, { "source": "secalert@redhat.com", "tags": [ "Third Party Advisory" ], "url": "https://www.qualys.com/2024/01/30/cve-2023-6246/syslog.txt" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Exploit", "Third Party Advisory", "VDB Entry" ], "url": "http://packetstormsecurity.com/files/176932/glibc-syslog-Heap-Based-Buffer-Overflow.html" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Exploit", "Mailing List", "Third Party Advisory" ], "url": "http://seclists.org/fulldisclosure/2024/Feb/3" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory" ], "url": "https://access.redhat.com/security/cve/CVE-2023-6780" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Issue Tracking" ], "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2254396" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Mailing List" ], "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D2FIH77VHY3KCRROCXOT6L27WMZXSJ2G/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Mailing List" ], "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MWQ6BZJ6CV5UAW4VZSKJ6TO4KIW2KWAQ/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory" ], "url": "https://security.gentoo.org/glsa/202402-01" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://security.netapp.com/advisory/ntap-20250207-0010/" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Exploit", "Mailing List" ], "url": "https://www.openwall.com/lists/oss-security/2024/01/30/6" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory" ], "url": "https://www.qualys.com/2024/01/30/cve-2023-6246/syslog.txt" } ], "sourceIdentifier": "secalert@redhat.com", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-131" } ], "source": "secalert@redhat.com", "type": "Primary" }, { "description": [ { "lang": "en", "value": "CWE-131" }, { "lang": "en", "value": "CWE-190" } ], "source": "nvd@nist.gov", "type": "Secondary" } ] }
ghsa-jjr8-97p7-vmmg
Vulnerability from github
Published
2024-01-31 15:30
Modified
2025-02-07 18:31
Severity ?
VLAI Severity ?
Details
An integer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when these functions are called with a very long message, leading to an incorrect calculation of the buffer size to store the message, resulting in undefined behavior. This issue affects glibc 2.37 and newer.
{ "affected": [], "aliases": [ "CVE-2023-6780" ], "database_specific": { "cwe_ids": [ "CWE-131", "CWE-190" ], "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-01-31T14:15:48Z", "severity": "MODERATE" }, "details": "An integer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when these functions are called with a very long message, leading to an incorrect calculation of the buffer size to store the message, resulting in undefined behavior. This issue affects glibc 2.37 and newer.", "id": "GHSA-jjr8-97p7-vmmg", "modified": "2025-02-07T18:31:11Z", "published": "2024-01-31T15:30:20Z", "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6780" }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2023-6780" }, { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2254396" }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D2FIH77VHY3KCRROCXOT6L27WMZXSJ2G" }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MWQ6BZJ6CV5UAW4VZSKJ6TO4KIW2KWAQ" }, { "type": "WEB", "url": "https://security.gentoo.org/glsa/202402-01" }, { "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20250207-0010" }, { "type": "WEB", "url": "https://www.openwall.com/lists/oss-security/2024/01/30/6" }, { "type": "WEB", "url": "https://www.qualys.com/2024/01/30/cve-2023-6246/syslog.txt" }, { "type": "WEB", "url": "http://packetstormsecurity.com/files/176932/glibc-syslog-Heap-Based-Buffer-Overflow.html" }, { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2024/Feb/3" } ], "schema_version": "1.4.0", "severity": [ { "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "type": "CVSS_V3" } ] }
wid-sec-w-2024-0246
Vulnerability from csaf_certbund
Published
2024-01-30 23:00
Modified
2025-06-10 22:00
Summary
GNU libc: Mehrere Schwachstellen
Notes
Das BSI ist als Anbieter für die eigenen, zur Nutzung bereitgestellten Inhalte nach den allgemeinen Gesetzen verantwortlich. Nutzerinnen und Nutzer sind jedoch dafür verantwortlich, die Verwendung und/oder die Umsetzung der mit den Inhalten bereitgestellten Informationen sorgfältig im Einzelfall zu prüfen.
Produktbeschreibung
Die GNU libc ist die Basis C Bibliothek unter Linux sowie anderen Unix-Betriebssystemen, welche die Systemaufrufe sowie Basisfunktionalität bereitstellt.
Angriff
Ein lokaler Angreifer kann mehrere Schwachstellen in GNU libc ausnutzen, um seine Privilegien zu erhöhen oder einen Denial of Service Zustand herbeizuführen.
Betroffene Betriebssysteme
- Linux
- UNIX
{ "document": { "aggregate_severity": { "text": "hoch" }, "category": "csaf_base", "csaf_version": "2.0", "distribution": { "tlp": { "label": "WHITE", "url": "https://www.first.org/tlp/" } }, "lang": "de-DE", "notes": [ { "category": "legal_disclaimer", "text": "Das BSI ist als Anbieter f\u00fcr die eigenen, zur Nutzung bereitgestellten Inhalte nach den allgemeinen Gesetzen verantwortlich. Nutzerinnen und Nutzer sind jedoch daf\u00fcr verantwortlich, die Verwendung und/oder die Umsetzung der mit den Inhalten bereitgestellten Informationen sorgf\u00e4ltig im Einzelfall zu pr\u00fcfen." }, { "category": "description", "text": "Die GNU libc ist die Basis C Bibliothek unter Linux sowie anderen Unix-Betriebssystemen, welche die Systemaufrufe sowie Basisfunktionalit\u00e4t bereitstellt.", "title": "Produktbeschreibung" }, { "category": "summary", "text": "Ein lokaler Angreifer kann mehrere Schwachstellen in GNU libc ausnutzen, um seine Privilegien zu erh\u00f6hen oder einen Denial of Service Zustand herbeizuf\u00fchren.", "title": "Angriff" }, { "category": "general", "text": "- Linux\n- UNIX", "title": "Betroffene Betriebssysteme" } ], "publisher": { "category": "other", "contact_details": "csaf-provider@cert-bund.de", "name": "Bundesamt f\u00fcr Sicherheit in der Informationstechnik", "namespace": "https://www.bsi.bund.de" }, "references": [ { "category": "self", "summary": "WID-SEC-W-2024-0246 - CSAF Version", "url": "https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-0246.json" }, { "category": "self", "summary": "WID-SEC-2024-0246 - Portal Version", "url": "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-0246" }, { "category": "external", "summary": "glibc advisory announcement vom 2024-01-30", "url": "https://sourceware.org/pipermail/libc-announce/2024/000037.html" }, { "category": "external", "summary": "Qualys Blog vom 2024-01-30", "url": "https://blog.qualys.com/vulnerabilities-threat-research/2024/01/30/qualys-tru-discovers-important-vulnerabilities-in-gnu-c-librarys-syslog" }, { "category": "external", "summary": "Qualys Security Advisory mit PoC vom 2024-01-30", "url": "https://www.qualys.com/2024/01/30/cve-2023-6246/syslog.txt" }, { "category": "external", "summary": "Fedora Security Advisory vom 2024-01-30", "url": "https://bodhi.fedoraproject.org/updates/FEDORA-2024-07597a0fb3" }, { "category": "external", "summary": "Fedora Security Advisory vom 2024-01-30", "url": "https://bodhi.fedoraproject.org/updates/FEDORA-2024-aec80d6e8a" }, { "category": "external", "summary": "Debian Security Advisory vom 2024-01-30", "url": "https://lists.debian.org/debian-security-announce/2024/msg00018.html" }, { "category": "external", "summary": "glibc advisory announcement vom 2024-01-30", "url": "https://sourceware.org/pipermail/libc-announce/2024/000037.html" }, { "category": "external", "summary": "Gentoo Linux Security Advisory GLSA-202402-01 vom 2024-02-02", "url": "https://security.gentoo.org/glsa/202402-01" }, { "category": "external", "summary": "Ubuntu Security Notice USN-6620-1 vom 2024-02-01", "url": "https://ubuntu.com/security/notices/USN-6620-1" }, { "category": "external", "summary": "Dell Security Advisory DSA-2025-146 vom 2025-04-08", "url": "https://www.dell.com/support/kbdoc/en-us/000299628/dsa-2025-146-security-update-for-dell-idrac9-vulnerabilities" }, { "category": "external", "summary": "Siemens Security Advisory SSA-082556 vom 2025-06-10", "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html" } ], "source_lang": "en-US", "title": "GNU libc: Mehrere Schwachstellen", "tracking": { "current_release_date": "2025-06-10T22:00:00.000+00:00", "generator": { "date": "2025-06-11T06:23:06.138+00:00", "engine": { "name": "BSI-WID", "version": "1.3.12" } }, "id": "WID-SEC-W-2024-0246", "initial_release_date": "2024-01-30T23:00:00.000+00:00", "revision_history": [ { "date": "2024-01-30T23:00:00.000+00:00", "number": "1", "summary": "Initiale Fassung" }, { "date": "2024-02-01T23:00:00.000+00:00", "number": "2", "summary": "Neue Updates von Gentoo und Ubuntu aufgenommen" }, { "date": "2025-04-08T22:00:00.000+00:00", "number": "3", "summary": "Neue Updates von Dell aufgenommen" }, { "date": "2025-06-10T22:00:00.000+00:00", "number": "4", "summary": "Neue Updates von Siemens aufgenommen" } ], "status": "final", "version": "4" } }, "product_tree": { "branches": [ { "branches": [ { "branches": [ { "category": "product_version_range", "name": "\u003c7.00.00.181", "product": { "name": "Dell integrated Dell Remote Access Controller \u003c7.00.00.181", "product_id": "T042656" } }, { "category": "product_version", "name": "7.00.00.181", "product": { "name": "Dell integrated Dell Remote Access Controller 7.00.00.181", "product_id": "T042656-fixed", "product_identification_helper": { "cpe": "cpe:/h:dell:idrac:7.00.00.181" } } }, { "category": "product_version_range", "name": "\u003c7.20.30.50", "product": { "name": "Dell integrated Dell Remote Access Controller \u003c7.20.30.50", "product_id": "T042657" } }, { "category": "product_version", "name": "7.20.30.50", "product": { "name": "Dell integrated Dell Remote Access Controller 7.20.30.50", "product_id": "T042657-fixed", "product_identification_helper": { "cpe": "cpe:/h:dell:idrac:7.20.30.50" } } } ], "category": "product_name", "name": "integrated Dell Remote Access Controller" } ], "category": "vendor", "name": "Dell" }, { "branches": [ { "category": "product_name", "name": "Gentoo Linux", "product": { "name": "Gentoo Linux", "product_id": "T012167", "product_identification_helper": { "cpe": "cpe:/o:gentoo:linux:-" } } } ], "category": "vendor", "name": "Gentoo" }, { "branches": [ { "branches": [ { "category": "product_version_range", "name": "\u003c2.36-9+deb12u4", "product": { "name": "Open Source GNU libc \u003c2.36-9+deb12u4", "product_id": "T032430" } }, { "category": "product_version", "name": "2.36-9+deb12u4", "product": { "name": "Open Source GNU libc 2.36-9+deb12u4", "product_id": "T032430-fixed", "product_identification_helper": { "cpe": "cpe:/a:gnu:glibc:2.36-9deb12u4" } } } ], "category": "product_name", "name": "GNU libc" } ], "category": "vendor", "name": "Open Source" }, { "branches": [ { "branches": [ { "category": "product_version", "name": "1500 CPU", "product": { "name": "Siemens SIMATIC S7 1500 CPU", "product_id": "T025776", "product_identification_helper": { "cpe": "cpe:/h:siemens:simatic_s7:1500_cpu" } } } ], "category": "product_name", "name": "SIMATIC S7" } ], "category": "vendor", "name": "Siemens" }, { "branches": [ { "category": "product_name", "name": "Ubuntu Linux", "product": { "name": "Ubuntu Linux", "product_id": "T000126", "product_identification_helper": { "cpe": "cpe:/o:canonical:ubuntu_linux:-" } } } ], "category": "vendor", "name": "Ubuntu" } ] }, "vulnerabilities": [ { "cve": "CVE-2023-6246", "product_status": { "known_affected": [ "T042656", "T000126", "T042657", "T025776", "T012167", "T032430" ] }, "release_date": "2024-01-30T23:00:00.000+00:00", "title": "CVE-2023-6246" }, { "cve": "CVE-2023-6779", "product_status": { "known_affected": [ "T042656", "T000126", "T042657", "T025776", "T012167", "T032430" ] }, "release_date": "2024-01-30T23:00:00.000+00:00", "title": "CVE-2023-6779" }, { "cve": "CVE-2023-6780", "product_status": { "known_affected": [ "T042656", "T000126", "T042657", "T025776", "T012167", "T032430" ] }, "release_date": "2024-01-30T23:00:00.000+00:00", "title": "CVE-2023-6780" } ] }
ncsc-2025-0187
Vulnerability from csaf_ncscnl
Published
2025-06-10 13:11
Modified
2025-06-10 13:11
Summary
Kwetsbaarheden verholpen in Siemens producten
Notes
The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this page to enhance access to its information and security advisories. The use of this security advisory is subject to the following terms and conditions:
NCSC-NL makes every reasonable effort to ensure that the content of this page is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or continuous keeping up-to-date. The information contained in this security advisory is intended solely for the purpose of providing general information to professional users. No rights can be derived from the information provided therein.
NCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of this security advisory. This includes damage resulting from the inaccuracy of incompleteness of the information contained in the advisory.
This security advisory is subject to Dutch law. All disputes related to or arising from the use of this advisory will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings.
Feiten
Siemens heeft kwetsbaarheden verholpen in diverse producten als RUGGEDCOM, SCALANCE, SIMATIC en Tecnomatix
Interpretaties
De kwetsbaarheden stellen een kwaadwillende mogelijk in staat aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade:
- Denial-of-Service (DoS)
- Manipulatie van gegevens
- Omzeilen van een beveiligingsmaatregel
- Omzeilen van authenticatie
- (Remote) code execution (root/admin rechten)
- (Remote) code execution (Gebruikersrechten)
- Toegang tot systeemgegevens
- Toegang tot gevoelige gegevens
- Spoofing
De kwaadwillende heeft hiervoor toegang nodig tot de productieomgeving. Het is goed gebruik een dergelijke omgeving niet publiek toegankelijk te hebben.
Oplossingen
Siemens heeft beveiligingsupdates uitgebracht om de kwetsbaarheden te verhelpen. Voor de kwetsbaarheden waar nog geen updates voor zijn, heeft Siemens mitigerende maatregelen gepubliceerd om de risico's zoveel als mogelijk te beperken. Zie de bijgevoegde referenties voor meer informatie.
Kans
medium
Schade
high
CWE-395
Use of NullPointerException Catch to Detect NULL Pointer Dereference
CWE-332
Insufficient Entropy in PRNG
CWE-940
Improper Verification of Source of a Communication Channel
CWE-466
Return of Pointer Value Outside of Expected Range
CWE-390
Detection of Error Condition Without Action
CWE-826
Premature Release of Resource During Expected Lifetime
CWE-222
Truncation of Security-relevant Information
CWE-310
CWE-310
CWE-273
Improper Check for Dropped Privileges
CWE-364
Signal Handler Race Condition
CWE-911
Improper Update of Reference Count
CWE-131
Incorrect Calculation of Buffer Size
CWE-304
Missing Critical Step in Authentication
CWE-684
Incorrect Provision of Specified Functionality
CWE-130
Improper Handling of Length Parameter Inconsistency
CWE-268
Privilege Chaining
CWE-366
Race Condition within a Thread
CWE-150
Improper Neutralization of Escape, Meta, or Control Sequences
CWE-201
Insertion of Sensitive Information Into Sent Data
CWE-407
Inefficient Algorithmic Complexity
CWE-371
CWE-371
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
CWE-667
Improper Locking
CWE-311
Missing Encryption of Sensitive Data
CWE-703
Improper Check or Handling of Exceptional Conditions
CWE-908
Use of Uninitialized Resource
CWE-617
Reachable Assertion
CWE-129
Improper Validation of Array Index
CWE-124
Buffer Underwrite ('Buffer Underflow')
CWE-843
Access of Resource Using Incompatible Type ('Type Confusion')
CWE-345
Insufficient Verification of Data Authenticity
CWE-354
Improper Validation of Integrity Check Value
CWE-325
Missing Cryptographic Step
CWE-190
Integer Overflow or Wraparound
CWE-290
Authentication Bypass by Spoofing
CWE-99
Improper Control of Resource Identifiers ('Resource Injection')
CWE-665
Improper Initialization
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CWE-125
Out-of-bounds Read
CWE-404
Improper Resource Shutdown or Release
CWE-284
Improper Access Control
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
CWE-416
Use After Free
CWE-476
NULL Pointer Dereference
CWE-757
Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')
CWE-400
Uncontrolled Resource Consumption
CWE-770
Allocation of Resources Without Limits or Throttling
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CWE-611
Improper Restriction of XML External Entity Reference
CWE-787
Out-of-bounds Write
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
CWE-122
Heap-based Buffer Overflow
CWE-121
Stack-based Buffer Overflow
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
CWE-73
External Control of File Name or Path
CWE-20
Improper Input Validation
CWE-863
Incorrect Authorization
CWE-276
Incorrect Default Permissions
{ "document": { "category": "csaf_security_advisory", "csaf_version": "2.0", "distribution": { "tlp": { "label": "WHITE" } }, "lang": "nl", "notes": [ { "category": "legal_disclaimer", "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this page to enhance access to its information and security advisories. The use of this security advisory is subject to the following terms and conditions:\n\n NCSC-NL makes every reasonable effort to ensure that the content of this page is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or continuous keeping up-to-date. The information contained in this security advisory is intended solely for the purpose of providing general information to professional users. No rights can be derived from the information provided therein.\n\n NCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of this security advisory. This includes damage resulting from the inaccuracy of incompleteness of the information contained in the advisory.\n This security advisory is subject to Dutch law. All disputes related to or arising from the use of this advisory will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings." }, { "category": "description", "text": "Siemens heeft kwetsbaarheden verholpen in diverse producten als RUGGEDCOM, SCALANCE, SIMATIC en Tecnomatix", "title": "Feiten" }, { "category": "description", "text": "De kwetsbaarheden stellen een kwaadwillende mogelijk in staat aanvallen uit te voeren die kunnen leiden tot de volgende categorie\u00ebn schade:\n\n- Denial-of-Service (DoS)\n- Manipulatie van gegevens\n- Omzeilen van een beveiligingsmaatregel\n- Omzeilen van authenticatie\n- (Remote) code execution (root/admin rechten)\n- (Remote) code execution (Gebruikersrechten)\n- Toegang tot systeemgegevens\n- Toegang tot gevoelige gegevens\n- Spoofing\n\nDe kwaadwillende heeft hiervoor toegang nodig tot de productieomgeving. Het is goed gebruik een dergelijke omgeving niet publiek toegankelijk te hebben.", "title": "Interpretaties" }, { "category": "description", "text": "Siemens heeft beveiligingsupdates uitgebracht om de kwetsbaarheden te verhelpen. Voor de kwetsbaarheden waar nog geen updates voor zijn, heeft Siemens mitigerende maatregelen gepubliceerd om de risico\u0027s zoveel als mogelijk te beperken. Zie de bijgevoegde referenties voor meer informatie.", "title": "Oplossingen" }, { "category": "general", "text": "medium", "title": "Kans" }, { "category": "general", "text": "high", "title": "Schade" }, { "category": "general", "text": "Use of NullPointerException Catch to Detect NULL Pointer Dereference", "title": "CWE-395" }, { "category": "general", "text": "Insufficient Entropy in PRNG", "title": "CWE-332" }, { "category": "general", "text": "Improper Verification of Source of a Communication Channel", "title": "CWE-940" }, { "category": "general", "text": "Return of Pointer Value Outside of Expected Range", "title": "CWE-466" }, { "category": "general", "text": "Detection of Error Condition Without Action", "title": "CWE-390" }, { "category": "general", "text": "Premature Release of Resource During Expected Lifetime", "title": "CWE-826" }, { "category": "general", "text": "Truncation of Security-relevant Information", "title": "CWE-222" }, { "category": "general", "text": "CWE-310", "title": "CWE-310" }, { "category": "general", "text": "Improper Check for Dropped Privileges", "title": "CWE-273" }, { "category": "general", "text": "Signal Handler Race Condition", "title": "CWE-364" }, { "category": "general", "text": "Improper Update of Reference Count", "title": "CWE-911" }, { "category": "general", "text": "Incorrect Calculation of Buffer Size", "title": "CWE-131" }, { "category": "general", "text": "Missing Critical Step in Authentication", "title": "CWE-304" }, { "category": "general", "text": "Incorrect Provision of Specified Functionality", "title": "CWE-684" }, { "category": "general", "text": "Improper Handling of Length Parameter Inconsistency", "title": "CWE-130" }, { "category": "general", "text": "Privilege Chaining", "title": "CWE-268" }, { "category": "general", "text": "Race Condition within a Thread", "title": "CWE-366" }, { "category": "general", "text": "Improper Neutralization of Escape, Meta, or Control Sequences", "title": "CWE-150" }, { "category": "general", "text": "Insertion of Sensitive Information Into Sent Data", "title": "CWE-201" }, { "category": "general", "text": "Inefficient Algorithmic Complexity", "title": "CWE-407" }, { "category": "general", "text": "CWE-371", "title": "CWE-371" }, { "category": "general", "text": "Time-of-check Time-of-use (TOCTOU) Race Condition", "title": "CWE-367" }, { "category": "general", "text": "Improper Locking", "title": "CWE-667" }, { "category": "general", "text": "Missing Encryption of Sensitive Data", "title": "CWE-311" }, { "category": "general", "text": "Improper Check or Handling of Exceptional Conditions", "title": "CWE-703" }, { "category": "general", "text": "Use of Uninitialized Resource", "title": "CWE-908" }, { "category": "general", "text": "Reachable Assertion", "title": "CWE-617" }, { "category": "general", "text": "Improper Validation of Array Index", "title": "CWE-129" }, { "category": "general", "text": "Buffer Underwrite (\u0027Buffer Underflow\u0027)", "title": "CWE-124" }, { "category": "general", "text": "Access of Resource Using Incompatible Type (\u0027Type Confusion\u0027)", "title": "CWE-843" }, { "category": "general", "text": "Insufficient Verification of Data Authenticity", "title": "CWE-345" }, { "category": "general", "text": "Improper Validation of Integrity Check Value", "title": "CWE-354" }, { "category": "general", "text": "Missing Cryptographic Step", "title": "CWE-325" }, { "category": "general", "text": "Integer Overflow or Wraparound", "title": "CWE-190" }, { "category": "general", "text": "Authentication Bypass by Spoofing", "title": "CWE-290" }, { "category": "general", "text": "Improper Control of Resource Identifiers (\u0027Resource Injection\u0027)", "title": "CWE-99" }, { "category": "general", "text": "Improper Initialization", "title": "CWE-665" }, { "category": "general", "text": "Concurrent Execution using Shared Resource with Improper Synchronization (\u0027Race Condition\u0027)", "title": "CWE-362" }, { "category": "general", "text": "Out-of-bounds Read", "title": "CWE-125" }, { "category": "general", "text": "Improper Resource Shutdown or Release", "title": "CWE-404" }, { "category": "general", "text": "Improper Access Control", "title": "CWE-284" }, { "category": "general", "text": "Improper Restriction of Operations within the Bounds of a Memory Buffer", "title": "CWE-119" }, { "category": "general", "text": "Use After Free", "title": "CWE-416" }, { "category": "general", "text": "NULL Pointer Dereference", "title": "CWE-476" }, { "category": "general", "text": "Selection of Less-Secure Algorithm During Negotiation (\u0027Algorithm Downgrade\u0027)", "title": "CWE-757" }, { "category": "general", "text": "Uncontrolled Resource Consumption", "title": "CWE-400" }, { "category": "general", "text": "Allocation of Resources Without Limits or Throttling", "title": "CWE-770" }, { "category": "general", "text": "Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)", "title": "CWE-78" }, { "category": "general", "text": "Improper Restriction of XML External Entity Reference", "title": "CWE-611" }, { "category": "general", "text": "Out-of-bounds Write", "title": "CWE-787" }, { "category": "general", "text": "Exposure of Sensitive Information to an Unauthorized Actor", "title": "CWE-200" }, { "category": "general", "text": "Heap-based Buffer Overflow", "title": "CWE-122" }, { "category": "general", "text": "Stack-based Buffer Overflow", "title": "CWE-121" }, { "category": "general", "text": "Buffer Copy without Checking Size of Input (\u0027Classic Buffer Overflow\u0027)", "title": "CWE-120" }, { "category": "general", "text": "External Control of File Name or Path", "title": "CWE-73" }, { "category": "general", "text": "Improper Input Validation", "title": "CWE-20" }, { "category": "general", "text": "Incorrect Authorization", "title": "CWE-863" }, { "category": "general", "text": "Incorrect Default Permissions", "title": "CWE-276" } ], "publisher": { "category": "coordinator", "contact_details": "cert@ncsc.nl", "name": "Nationaal Cyber Security Centrum", "namespace": "https://www.ncsc.nl/" }, "references": [ { "category": "external", "summary": "Reference - ncscclear", "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-082556.pdf" }, { "category": "external", "summary": "Reference - ncscclear", "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-345750.pdf" }, { "category": "external", "summary": "Reference - ncscclear", "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-486186.pdf" }, { "category": "external", "summary": "Reference - ncscclear", "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-513708.pdf" }, { "category": "external", "summary": "Reference - ncscclear", "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-633269.pdf" }, { "category": "external", "summary": "Reference - ncscclear", "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-693776.pdf" } ], "title": "Kwetsbaarheden verholpen in Siemens producten", "tracking": { "current_release_date": "2025-06-10T13:11:56.672768Z", "generator": { "date": "2025-06-05T14:45:00Z", "engine": { "name": "V.A.", "version": "1.1" } }, "id": "NCSC-2025-0187", "initial_release_date": "2025-06-10T13:11:56.672768Z", "revision_history": [ { "date": "2025-06-10T13:11:56.672768Z", "number": "1.0.0", "summary": "Initiele versie" } ], "status": "final", "version": "1.0.0" } }, "product_tree": { "branches": [ { "branches": [ { "branches": [ { "branches": [ { "category": "product_version_range", "name": "vers:unknown/none", "product": { "name": "vers:unknown/none", "product_id": "CSAFPID-1211853" } } ], "category": "product_name", "name": "SIMATIC S7-1500" }, { "branches": [ { "category": "product_version_range", "name": "vers:siemens/3.1.0", "product": { "name": "vers:siemens/3.1.0", "product_id": "CSAFPID-1195553" } } ], "category": "product_name", "name": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP Firmware" }, { "branches": [ { "category": "product_version_range", "name": "vers:unknown/1.0", "product": { "name": "vers:unknown/1.0", "product_id": "CSAFPID-1211202" } } ], "category": "product_name", "name": "Simatic S7-1500 Tm Mfp Firmware" }, { "branches": [ { "category": "product_version_range", "name": "vers:siemens/7.4.3", "product": { "name": "vers:siemens/7.4.3", "product_id": "CSAFPID-2849543" } }, { "category": "product_version_range", "name": "vers:unknown/none", "product": { "name": "vers:unknown/none", "product_id": "CSAFPID-1756091" } } ], "category": "product_name", "name": "RUGGEDCOM APE1808 Firmware" }, { "branches": [ { "category": "product_version_range", "name": "vers:unknown/none", "product": { "name": "vers:unknown/none", "product_id": "CSAFPID-2619544" } } ], "category": "product_name", "name": "Ruggedcom Ape1808" }, { "branches": [ { "category": "product_version_range", "name": "vers:siemens/3.0.0", "product": { "name": "vers:siemens/3.0.0", "product_id": "CSAFPID-2082475" } } ], "category": "product_name", "name": "Scalance W700 Ieee 802.11Ax Firmware" } ], "category": "product_family", "name": "Siemens" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/\u003e=v3.1.0", "product": { "name": "vers:all/\u003e=v3.1.0", "product_id": "CSAFPID-1266669" } } ], "category": "product_name", "name": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/\u003e=v3.1.0", "product": { "name": "vers:all/\u003e=v3.1.0", "product_id": "CSAFPID-1266670" } } ], "category": "product_name", "name": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/\u003e=v3.1.0", "product": { "name": "vers:all/\u003e=v3.1.0", "product_id": "CSAFPID-1266671" } } ], "category": "product_name", "name": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/\u003e=v3.1.0", "product": { "name": "vers:all/\u003e=v3.1.0", "product_id": "CSAFPID-1266672" } } ], "category": "product_name", "name": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "vers:all/*", "product_id": "CSAFPID-2460438" } }, { "category": "product_version_range", "name": "vers:unknown/\u003cv1.3.0", "product": { "name": "vers:unknown/\u003cv1.3.0", "product_id": "CSAFPID-1270701" } } ], "category": "product_name", "name": "SIMATIC S7-1500 TM MFP - BIOS" }, { "branches": [ { "category": "product_version_range", "name": "vers:unknown/\u003cv1.1", "product": { "name": "vers:unknown/\u003cv1.1", "product_id": "CSAFPID-1270700" } } ], "category": "product_name", "name": "SIMATIC S7-1500 TM MFP -\u00a0GNU/Linux subsystem" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/\u003e=v3.1.0", "product": { "name": "vers:all/\u003e=v3.1.0", "product_id": "CSAFPID-1266673" } } ], "category": "product_name", "name": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "vers:all/*", "product_id": "CSAFPID-1272525" } } ], "category": "product_name", "name": "RUGGEDCOM APE1808" }, { "branches": [ { "category": "product_version_range", "name": "vers:unknown/*", "product": { "name": "vers:unknown/*", "product_id": "CSAFPID-126262", "product_identification_helper": { "cpe": "cpe:2.3:a:siemens:ruggedcom_ape1808:*:*:*:*:*:*:*:*" } } } ], "category": "product_name", "name": "ruggedcom_ape1808" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/*", "product": { "name": "vers:all/*", "product_id": "CSAFPID-2905706" } } ], "category": "product_name", "name": "Energy Services" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/\u003cv2404.0013", "product": { "name": "vers:all/\u003cv2404.0013", "product_id": "CSAFPID-2905742" } } ], "category": "product_name", "name": "Tecnomatix Plant Simulation V2404" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/\u003cv3.1", "product": { "name": "vers:all/\u003cv3.1", "product_id": "CSAFPID-2905748" } }, { "category": "product_version_range", "name": "vers:all/\u003cv3.2", "product": { "name": "vers:all/\u003cv3.2", "product_id": "CSAFPID-2905793" } } ], "category": "product_name", "name": "SCALANCE XC316-8 (6GK5324-8TS00-2AC2)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/\u003cv3.1", "product": { "name": "vers:all/\u003cv3.1", "product_id": "CSAFPID-2905749" } }, { "category": "product_version_range", "name": "vers:all/\u003cv3.2", "product": { "name": "vers:all/\u003cv3.2", "product_id": "CSAFPID-2905794" } } ], "category": "product_name", "name": "SCALANCE XC324-4 (6GK5328-4TS00-2AC2)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/\u003cv3.1", "product": { "name": "vers:all/\u003cv3.1", "product_id": "CSAFPID-2905750" } }, { "category": "product_version_range", "name": "vers:all/\u003cv3.2", "product": { "name": "vers:all/\u003cv3.2", "product_id": "CSAFPID-2905795" } } ], "category": "product_name", "name": "SCALANCE XC324-4 EEC (6GK5328-4TS00-2EC2)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/\u003cv3.1", "product": { "name": "vers:all/\u003cv3.1", "product_id": "CSAFPID-2905751" } }, { "category": "product_version_range", "name": "vers:all/\u003cv3.2", "product": { "name": "vers:all/\u003cv3.2", "product_id": "CSAFPID-2905796" } } ], "category": "product_name", "name": "SCALANCE XC332 (6GK5332-0GA00-2AC2)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/\u003cv3.1", "product": { "name": "vers:all/\u003cv3.1", "product_id": "CSAFPID-2905752" } }, { "category": "product_version_range", "name": "vers:all/\u003cv3.2", "product": { "name": "vers:all/\u003cv3.2", "product_id": "CSAFPID-2905797" } } ], "category": "product_name", "name": "SCALANCE XC416-8 (6GK5424-8TR00-2AC2)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/\u003cv3.1", "product": { "name": "vers:all/\u003cv3.1", "product_id": "CSAFPID-2905753" } }, { "category": "product_version_range", "name": "vers:all/\u003cv3.2", "product": { "name": "vers:all/\u003cv3.2", "product_id": "CSAFPID-2905798" } } ], "category": "product_name", "name": "SCALANCE XC424-4 (6GK5428-4TR00-2AC2)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/\u003cv3.1", "product": { "name": "vers:all/\u003cv3.1", "product_id": "CSAFPID-2905754" } }, { "category": "product_version_range", "name": "vers:all/\u003cv3.2", "product": { "name": "vers:all/\u003cv3.2", "product_id": "CSAFPID-2905799" } } ], "category": "product_name", "name": "SCALANCE XC432 (6GK5432-0GR00-2AC2)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/\u003cv3.1", "product": { "name": "vers:all/\u003cv3.1", "product_id": "CSAFPID-2905755" } }, { "category": "product_version_range", "name": "vers:all/\u003cv3.2", "product": { "name": "vers:all/\u003cv3.2", "product_id": "CSAFPID-2905800" } } ], "category": "product_name", "name": "SCALANCE XCH328 (6GK5328-4TS01-2EC2)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/\u003cv3.1", "product": { "name": "vers:all/\u003cv3.1", "product_id": "CSAFPID-2905756" } }, { "category": "product_version_range", "name": "vers:all/\u003cv3.2", "product": { "name": "vers:all/\u003cv3.2", "product_id": "CSAFPID-2905801" } } ], "category": "product_name", "name": "SCALANCE XCM324 (6GK5324-8TS01-2AC2)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/\u003cv3.1", "product": { "name": "vers:all/\u003cv3.1", "product_id": "CSAFPID-2905757" } }, { "category": "product_version_range", "name": "vers:all/\u003cv3.2", "product": { "name": "vers:all/\u003cv3.2", "product_id": "CSAFPID-2905802" } } ], "category": "product_name", "name": "SCALANCE XCM328 (6GK5328-4TS01-2AC2)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/\u003cv3.1", "product": { "name": "vers:all/\u003cv3.1", "product_id": "CSAFPID-2905758" } }, { "category": "product_version_range", "name": "vers:all/\u003cv3.2", "product": { "name": "vers:all/\u003cv3.2", "product_id": "CSAFPID-2905803" } } ], "category": "product_name", "name": "SCALANCE XCM332 (6GK5332-0GA01-2AC2)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/\u003cv3.1", "product": { "name": "vers:all/\u003cv3.1", "product_id": "CSAFPID-2905759" } }, { "category": "product_version_range", "name": "vers:all/\u003cv3.2", "product": { "name": "vers:all/\u003cv3.2", "product_id": "CSAFPID-2905804" } } ], "category": "product_name", "name": "SCALANCE XR302-32 (6GK5334-5TS00-2AR3)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/\u003cv3.1", "product": { "name": "vers:all/\u003cv3.1", "product_id": "CSAFPID-2905760" } }, { "category": "product_version_range", "name": "vers:all/\u003cv3.2", "product": { "name": "vers:all/\u003cv3.2", "product_id": "CSAFPID-2905805" } } ], "category": "product_name", "name": "SCALANCE XR302-32 (6GK5334-5TS00-3AR3)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/\u003cv3.1", "product": { "name": "vers:all/\u003cv3.1", "product_id": "CSAFPID-2905761" } }, { "category": "product_version_range", "name": "vers:all/\u003cv3.2", "product": { "name": "vers:all/\u003cv3.2", "product_id": "CSAFPID-2905806" } } ], "category": "product_name", "name": "SCALANCE XR302-32 (6GK5334-5TS00-4AR3)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/\u003cv3.1", "product": { "name": "vers:all/\u003cv3.1", "product_id": "CSAFPID-2905762" } }, { "category": "product_version_range", "name": "vers:all/\u003cv3.2", "product": { "name": "vers:all/\u003cv3.2", "product_id": "CSAFPID-2905807" } } ], "category": "product_name", "name": "SCALANCE XR322-12 (6GK5334-3TS00-2AR3)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/\u003cv3.1", "product": { "name": "vers:all/\u003cv3.1", "product_id": "CSAFPID-2905763" } }, { "category": "product_version_range", "name": "vers:all/\u003cv3.2", "product": { "name": "vers:all/\u003cv3.2", "product_id": "CSAFPID-2905808" } } ], "category": "product_name", "name": "SCALANCE XR322-12 (6GK5334-3TS00-3AR3)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/\u003cv3.1", "product": { "name": "vers:all/\u003cv3.1", "product_id": "CSAFPID-2905764" } }, { "category": "product_version_range", "name": "vers:all/\u003cv3.2", "product": { "name": "vers:all/\u003cv3.2", "product_id": "CSAFPID-2905809" } } ], "category": "product_name", "name": "SCALANCE XR322-12 (6GK5334-3TS00-4AR3)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/\u003cv3.1", "product": { "name": "vers:all/\u003cv3.1", "product_id": "CSAFPID-2905765" } }, { "category": "product_version_range", "name": "vers:all/\u003cv3.2", "product": { "name": "vers:all/\u003cv3.2", "product_id": "CSAFPID-2905810" } } ], "category": "product_name", "name": "SCALANCE XR326-8 (6GK5334-2TS00-2AR3)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/\u003cv3.1", "product": { "name": "vers:all/\u003cv3.1", "product_id": "CSAFPID-2905766" } }, { "category": "product_version_range", "name": "vers:all/\u003cv3.2", "product": { "name": "vers:all/\u003cv3.2", "product_id": "CSAFPID-2905811" } } ], "category": "product_name", "name": "SCALANCE XR326-8 (6GK5334-2TS00-3AR3)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/\u003cv3.1", "product": { "name": "vers:all/\u003cv3.1", "product_id": "CSAFPID-2905767" } }, { "category": "product_version_range", "name": "vers:all/\u003cv3.2", "product": { "name": "vers:all/\u003cv3.2", "product_id": "CSAFPID-2905812" } } ], "category": "product_name", "name": "SCALANCE XR326-8 (6GK5334-2TS00-4AR3)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/\u003cv3.1", "product": { "name": "vers:all/\u003cv3.1", "product_id": "CSAFPID-2905768" } }, { "category": "product_version_range", "name": "vers:all/\u003cv3.2", "product": { "name": "vers:all/\u003cv3.2", "product_id": "CSAFPID-2905813" } } ], "category": "product_name", "name": "SCALANCE XR326-8 EEC (6GK5334-2TS00-2ER3)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/\u003cv3.1", "product": { "name": "vers:all/\u003cv3.1", "product_id": "CSAFPID-2905769" } }, { "category": "product_version_range", "name": "vers:all/\u003cv3.2", "product": { "name": "vers:all/\u003cv3.2", "product_id": "CSAFPID-2905814" } } ], "category": "product_name", "name": "SCALANCE XR502-32 (6GK5534-5TR00-2AR3)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/\u003cv3.1", "product": { "name": "vers:all/\u003cv3.1", "product_id": "CSAFPID-2905770" } }, { "category": "product_version_range", "name": "vers:all/\u003cv3.2", "product": { "name": "vers:all/\u003cv3.2", "product_id": "CSAFPID-2905815" } } ], "category": "product_name", "name": "SCALANCE XR502-32 (6GK5534-5TR00-3AR3)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/\u003cv3.1", "product": { "name": "vers:all/\u003cv3.1", "product_id": "CSAFPID-2905771" } }, { "category": "product_version_range", "name": "vers:all/\u003cv3.2", "product": { "name": "vers:all/\u003cv3.2", "product_id": "CSAFPID-2905816" } } ], "category": "product_name", "name": "SCALANCE XR502-32 (6GK5534-5TR00-4AR3)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/\u003cv3.1", "product": { "name": "vers:all/\u003cv3.1", "product_id": "CSAFPID-2905772" } }, { "category": "product_version_range", "name": "vers:all/\u003cv3.2", "product": { "name": "vers:all/\u003cv3.2", "product_id": "CSAFPID-2905817" } } ], "category": "product_name", "name": "SCALANCE XR522-12 (6GK5534-3TR00-2AR3)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/\u003cv3.1", "product": { "name": "vers:all/\u003cv3.1", "product_id": "CSAFPID-2905773" } }, { "category": "product_version_range", "name": "vers:all/\u003cv3.2", "product": { "name": "vers:all/\u003cv3.2", "product_id": "CSAFPID-2905818" } } ], "category": "product_name", "name": "SCALANCE XR522-12 (6GK5534-3TR00-3AR3)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/\u003cv3.1", "product": { "name": "vers:all/\u003cv3.1", "product_id": "CSAFPID-2905774" } }, { "category": "product_version_range", "name": "vers:all/\u003cv3.2", "product": { "name": "vers:all/\u003cv3.2", "product_id": "CSAFPID-2905819" } } ], "category": "product_name", "name": "SCALANCE XR522-12 (6GK5534-3TR00-4AR3)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/\u003cv3.1", "product": { "name": "vers:all/\u003cv3.1", "product_id": "CSAFPID-2905775" } }, { "category": "product_version_range", "name": "vers:all/\u003cv3.2", "product": { "name": "vers:all/\u003cv3.2", "product_id": "CSAFPID-2905820" } } ], "category": "product_name", "name": "SCALANCE XR526-8 (6GK5534-2TR00-2AR3)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/\u003cv3.1", "product": { "name": "vers:all/\u003cv3.1", "product_id": "CSAFPID-2905776" } }, { "category": "product_version_range", "name": "vers:all/\u003cv3.2", "product": { "name": "vers:all/\u003cv3.2", "product_id": "CSAFPID-2905821" } } ], "category": "product_name", "name": "SCALANCE XR526-8 (6GK5534-2TR00-3AR3)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/\u003cv3.1", "product": { "name": "vers:all/\u003cv3.1", "product_id": "CSAFPID-2905777" } }, { "category": "product_version_range", "name": "vers:all/\u003cv3.2", "product": { "name": "vers:all/\u003cv3.2", "product_id": "CSAFPID-2905822" } } ], "category": "product_name", "name": "SCALANCE XR526-8 (6GK5534-2TR00-4AR3)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/\u003cv3.1", "product": { "name": "vers:all/\u003cv3.1", "product_id": "CSAFPID-2905778" } }, { "category": "product_version_range", "name": "vers:all/\u003cv3.2", "product": { "name": "vers:all/\u003cv3.2", "product_id": "CSAFPID-2905823" } } ], "category": "product_name", "name": "SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/\u003cv3.1", "product": { "name": "vers:all/\u003cv3.1", "product_id": "CSAFPID-2905786" } }, { "category": "product_version_range", "name": "vers:all/\u003cv3.2", "product": { "name": "vers:all/\u003cv3.2", "product_id": "CSAFPID-2905831" } } ], "category": "product_name", "name": "SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/\u003cv3.1", "product": { "name": "vers:all/\u003cv3.1", "product_id": "CSAFPID-2905785" } }, { "category": "product_version_range", "name": "vers:all/\u003cv3.2", "product": { "name": "vers:all/\u003cv3.2", "product_id": "CSAFPID-2905830" } } ], "category": "product_name", "name": "SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/\u003cv3.1", "product": { "name": "vers:all/\u003cv3.1", "product_id": "CSAFPID-2905787" } }, { "category": "product_version_range", "name": "vers:all/\u003cv3.2", "product": { "name": "vers:all/\u003cv3.2", "product_id": "CSAFPID-2905832" } } ], "category": "product_name", "name": "SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/\u003cv3.1", "product": { "name": "vers:all/\u003cv3.1", "product_id": "CSAFPID-2905783" } }, { "category": "product_version_range", "name": "vers:all/\u003cv3.2", "product": { "name": "vers:all/\u003cv3.2", "product_id": "CSAFPID-2905828" } } ], "category": "product_name", "name": "SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/\u003cv3.1", "product": { "name": "vers:all/\u003cv3.1", "product_id": "CSAFPID-2905782" } }, { "category": "product_version_range", "name": "vers:all/\u003cv3.2", "product": { "name": "vers:all/\u003cv3.2", "product_id": "CSAFPID-2905827" } } ], "category": "product_name", "name": "SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/\u003cv3.1", "product": { "name": "vers:all/\u003cv3.1", "product_id": "CSAFPID-2905784" } }, { "category": "product_version_range", "name": "vers:all/\u003cv3.2", "product": { "name": "vers:all/\u003cv3.2", "product_id": "CSAFPID-2905829" } } ], "category": "product_name", "name": "SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/\u003cv3.1", "product": { "name": "vers:all/\u003cv3.1", "product_id": "CSAFPID-2905780" } }, { "category": "product_version_range", "name": "vers:all/\u003cv3.2", "product": { "name": "vers:all/\u003cv3.2", "product_id": "CSAFPID-2905825" } } ], "category": "product_name", "name": "SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/\u003cv3.1", "product": { "name": "vers:all/\u003cv3.1", "product_id": "CSAFPID-2905779" } }, { "category": "product_version_range", "name": "vers:all/\u003cv3.2", "product": { "name": "vers:all/\u003cv3.2", "product_id": "CSAFPID-2905824" } } ], "category": "product_name", "name": "SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3)" }, { "branches": [ { "category": "product_version_range", "name": "vers:all/\u003cv3.1", "product": { "name": "vers:all/\u003cv3.1", "product_id": "CSAFPID-2905781" } }, { "category": "product_version_range", "name": "vers:all/\u003cv3.2", "product": { "name": "vers:all/\u003cv3.2", "product_id": "CSAFPID-2905826" } } ], "category": "product_name", "name": "SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)" } ], "category": "vendor", "name": "Siemens" } ] }, "vulnerabilities": [ { "cve": "CVE-2021-41617", "cwe": { "id": "CWE-311", "name": "Missing Encryption of Sensitive Data" }, "notes": [ { "category": "other", "text": "Missing Encryption of Sensitive Data", "title": "CWE-311" }, { "category": "other", "text": "Improper Check for Dropped Privileges", "title": "CWE-273" }, { "category": "other", "text": "Improper Access Control", "title": "CWE-284" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2021-41617 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2021/cve-2021-41617.json" } ], "title": "CVE-2021-41617" }, { "cve": "CVE-2023-4527", "cwe": { "id": "CWE-125", "name": "Out-of-bounds Read" }, "notes": [ { "category": "other", "text": "Out-of-bounds Read", "title": "CWE-125" }, { "category": "other", "text": "Exposure of Sensitive Information to an Unauthorized Actor", "title": "CWE-200" }, { "category": "other", "text": "Stack-based Buffer Overflow", "title": "CWE-121" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2023-4527 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2023/cve-2023-4527.json" } ], "scores": [ { "cvss_v3": { "baseScore": 7.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2023-4527" }, { "cve": "CVE-2023-4806", "cwe": { "id": "CWE-416", "name": "Use After Free" }, "notes": [ { "category": "other", "text": "Use After Free", "title": "CWE-416" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2023-4806 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2023/cve-2023-4806.json" } ], "scores": [ { "cvss_v3": { "baseScore": 7.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2023-4806" }, { "cve": "CVE-2023-4911", "cwe": { "id": "CWE-122", "name": "Heap-based Buffer Overflow" }, "notes": [ { "category": "other", "text": "Heap-based Buffer Overflow", "title": "CWE-122" }, { "category": "other", "text": "Stack-based Buffer Overflow", "title": "CWE-121" }, { "category": "other", "text": "Out-of-bounds Write", "title": "CWE-787" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2023-4911 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2023/cve-2023-4911.json" } ], "scores": [ { "cvss_v3": { "baseScore": 7.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2023-4911" }, { "cve": "CVE-2023-5363", "cwe": { "id": "CWE-325", "name": "Missing Cryptographic Step" }, "notes": [ { "category": "other", "text": "Missing Cryptographic Step", "title": "CWE-325" }, { "category": "other", "text": "Improper Input Validation", "title": "CWE-20" }, { "category": "other", "text": "Incorrect Provision of Specified Functionality", "title": "CWE-684" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2023-5363 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2023/cve-2023-5363.json" } ], "scores": [ { "cvss_v3": { "baseScore": 7.5, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2023-5363" }, { "cve": "CVE-2023-6246", "cwe": { "id": "CWE-122", "name": "Heap-based Buffer Overflow" }, "notes": [ { "category": "other", "text": "Heap-based Buffer Overflow", "title": "CWE-122" }, { "category": "other", "text": "Out-of-bounds Write", "title": "CWE-787" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2023-6246 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2023/cve-2023-6246.json" } ], "scores": [ { "cvss_v3": { "baseScore": 8.4, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2023-6246" }, { "cve": "CVE-2023-6779", "cwe": { "id": "CWE-122", "name": "Heap-based Buffer Overflow" }, "notes": [ { "category": "other", "text": "Heap-based Buffer Overflow", "title": "CWE-122" }, { "category": "other", "text": "Out-of-bounds Write", "title": "CWE-787" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2023-6779 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2023/cve-2023-6779.json" } ], "scores": [ { "cvss_v3": { "baseScore": 8.2, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2023-6779" }, { "cve": "CVE-2023-6780", "cwe": { "id": "CWE-190", "name": "Integer Overflow or Wraparound" }, "notes": [ { "category": "other", "text": "Integer Overflow or Wraparound", "title": "CWE-190" }, { "category": "other", "text": "Incorrect Calculation of Buffer Size", "title": "CWE-131" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2023-6780 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2023/cve-2023-6780.json" } ], "scores": [ { "cvss_v3": { "baseScore": 7.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2023-6780" }, { "cve": "CVE-2023-28531", "cwe": { "id": "CWE-311", "name": "Missing Encryption of Sensitive Data" }, "notes": [ { "category": "other", "text": "Missing Encryption of Sensitive Data", "title": "CWE-311" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2023-28531 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2023/cve-2023-28531.json" } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2023-28531" }, { "cve": "CVE-2023-38545", "cwe": { "id": "CWE-122", "name": "Heap-based Buffer Overflow" }, "notes": [ { "category": "other", "text": "Heap-based Buffer Overflow", "title": "CWE-122" }, { "category": "other", "text": "Improper Restriction of Operations within the Bounds of a Memory Buffer", "title": "CWE-119" }, { "category": "other", "text": "Out-of-bounds Write", "title": "CWE-787" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2023-38545 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2023/cve-2023-38545.json" } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2023-38545" }, { "cve": "CVE-2023-38546", "cwe": { "id": "CWE-73", "name": "External Control of File Name or Path" }, "notes": [ { "category": "other", "text": "External Control of File Name or Path", "title": "CWE-73" }, { "category": "other", "text": "Missing Encryption of Sensitive Data", "title": "CWE-311" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2023-38546 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2023/cve-2023-38546.json" } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2023-38546" }, { "cve": "CVE-2023-44487", "cwe": { "id": "CWE-400", "name": "Uncontrolled Resource Consumption" }, "notes": [ { "category": "other", "text": "Uncontrolled Resource Consumption", "title": "CWE-400" }, { "category": "general", "text": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N", "title": "CVSSV4" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2023-44487 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2023/cve-2023-44487.json" } ], "scores": [ { "cvss_v3": { "baseScore": 7.5, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2023-44487" }, { "cve": "CVE-2023-46218", "cwe": { "id": "CWE-201", "name": "Insertion of Sensitive Information Into Sent Data" }, "notes": [ { "category": "other", "text": "Insertion of Sensitive Information Into Sent Data", "title": "CWE-201" }, { "category": "other", "text": "Improper Input Validation", "title": "CWE-20" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2023-46218 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2023/cve-2023-46218.json" } ], "scores": [ { "cvss_v3": { "baseScore": 6.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2023-46218" }, { "cve": "CVE-2023-46219", "cwe": { "id": "CWE-311", "name": "Missing Encryption of Sensitive Data" }, "notes": [ { "category": "other", "text": "Missing Encryption of Sensitive Data", "title": "CWE-311" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2023-46219 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2023/cve-2023-46219.json" } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2023-46219" }, { "cve": "CVE-2023-48795", "cwe": { "id": "CWE-222", "name": "Truncation of Security-relevant Information" }, "notes": [ { "category": "other", "text": "Truncation of Security-relevant Information", "title": "CWE-222" }, { "category": "other", "text": "Selection of Less-Secure Algorithm During Negotiation (\u0027Algorithm Downgrade\u0027)", "title": "CWE-757" }, { "category": "other", "text": "Improper Validation of Integrity Check Value", "title": "CWE-354" }, { "category": "general", "text": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/AU:N/R:A/V:D/RE:L/U:Amber", "title": "CVSSV4" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2023-48795 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2023/cve-2023-48795.json" } ], "scores": [ { "cvss_v3": { "baseScore": 7.5, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2023-48795" }, { "cve": "CVE-2023-51384", "cwe": { "id": "CWE-304", "name": "Missing Critical Step in Authentication" }, "notes": [ { "category": "other", "text": "Missing Critical Step in Authentication", "title": "CWE-304" }, { "category": "other", "text": "Improper Input Validation", "title": "CWE-20" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2023-51384 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2023/cve-2023-51384.json" } ], "scores": [ { "cvss_v3": { "baseScore": 5.9, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2023-51384" }, { "cve": "CVE-2023-51385", "cwe": { "id": "CWE-78", "name": "Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)" }, "notes": [ { "category": "other", "text": "Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)", "title": "CWE-78" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2023-51385 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2023/cve-2023-51385.json" } ], "scores": [ { "cvss_v3": { "baseScore": 6.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2023-51385" }, { "cve": "CVE-2023-52927", "cwe": { "id": "CWE-20", "name": "Improper Input Validation" }, "notes": [ { "category": "other", "text": "Improper Input Validation", "title": "CWE-20" }, { "category": "general", "text": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N", "title": "CVSSV4" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2023-52927 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2023/cve-2023-52927.json" } ], "title": "CVE-2023-52927" }, { "cve": "CVE-2024-2961", "cwe": { "id": "CWE-787", "name": "Out-of-bounds Write" }, "notes": [ { "category": "other", "text": "Out-of-bounds Write", "title": "CWE-787" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2024-2961 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2024/cve-2024-2961.json" } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2024-2961" }, { "cve": "CVE-2024-6119", "cwe": { "id": "CWE-843", "name": "Access of Resource Using Incompatible Type (\u0027Type Confusion\u0027)" }, "notes": [ { "category": "other", "text": "Access of Resource Using Incompatible Type (\u0027Type Confusion\u0027)", "title": "CWE-843" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2024-6119 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2024/cve-2024-6119.json" } ], "scores": [ { "cvss_v3": { "baseScore": 9.1, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2024-6119" }, { "cve": "CVE-2024-6387", "cwe": { "id": "CWE-362", "name": "Concurrent Execution using Shared Resource with Improper Synchronization (\u0027Race Condition\u0027)" }, "notes": [ { "category": "other", "text": "Concurrent Execution using Shared Resource with Improper Synchronization (\u0027Race Condition\u0027)", "title": "CWE-362" }, { "category": "other", "text": "Signal Handler Race Condition", "title": "CWE-364" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2024-6387 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2024/cve-2024-6387.json" } ], "title": "CVE-2024-6387" }, { "cve": "CVE-2024-12133", "cwe": { "id": "CWE-404", "name": "Improper Resource Shutdown or Release" }, "notes": [ { "category": "other", "text": "Improper Resource Shutdown or Release", "title": "CWE-404" }, { "category": "other", "text": "Inefficient Algorithmic Complexity", "title": "CWE-407" }, { "category": "general", "text": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N", "title": "CVSSV4" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2024-12133 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2024/cve-2024-12133.json" } ], "title": "CVE-2024-12133" }, { "cve": "CVE-2024-12243", "cwe": { "id": "CWE-404", "name": "Improper Resource Shutdown or Release" }, "notes": [ { "category": "other", "text": "Improper Resource Shutdown or Release", "title": "CWE-404" }, { "category": "other", "text": "Inefficient Algorithmic Complexity", "title": "CWE-407" }, { "category": "general", "text": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N", "title": "CVSSV4" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2024-12243 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2024/cve-2024-12243.json" } ], "title": "CVE-2024-12243" }, { "cve": "CVE-2024-24855", "cwe": { "id": "CWE-367", "name": "Time-of-check Time-of-use (TOCTOU) Race Condition" }, "notes": [ { "category": "other", "text": "Time-of-check Time-of-use (TOCTOU) Race Condition", "title": "CWE-367" }, { "category": "other", "text": "Concurrent Execution using Shared Resource with Improper Synchronization (\u0027Race Condition\u0027)", "title": "CWE-362" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2024-24855 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2024/cve-2024-24855.json" } ], "scores": [ { "cvss_v3": { "baseScore": 5.1, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2024-24855" }, { "cve": "CVE-2024-26596", "cwe": { "id": "CWE-476", "name": "NULL Pointer Dereference" }, "notes": [ { "category": "other", "text": "NULL Pointer Dereference", "title": "CWE-476" }, { "category": "other", "text": "Improper Input Validation", "title": "CWE-20" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2024-26596 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2024/cve-2024-26596.json" } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2024-26596" }, { "cve": "CVE-2024-28085", "cwe": { "id": "CWE-268", "name": "Privilege Chaining" }, "notes": [ { "category": "other", "text": "Privilege Chaining", "title": "CWE-268" }, { "category": "other", "text": "Improper Input Validation", "title": "CWE-20" }, { "category": "other", "text": "Improper Neutralization of Escape, Meta, or Control Sequences", "title": "CWE-150" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2024-28085 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2024/cve-2024-28085.json" } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2024-28085" }, { "cve": "CVE-2024-33599", "cwe": { "id": "CWE-119", "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer" }, "notes": [ { "category": "other", "text": "Improper Restriction of Operations within the Bounds of a Memory Buffer", "title": "CWE-119" }, { "category": "other", "text": "Stack-based Buffer Overflow", "title": "CWE-121" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2024-33599 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2024/cve-2024-33599.json" } ], "scores": [ { "cvss_v3": { "baseScore": 8.6, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2024-33599" }, { "cve": "CVE-2024-33600", "cwe": { "id": "CWE-476", "name": "NULL Pointer Dereference" }, "notes": [ { "category": "other", "text": "NULL Pointer Dereference", "title": "CWE-476" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2024-33600 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2024/cve-2024-33600.json" } ], "scores": [ { "cvss_v3": { "baseScore": 8.6, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2024-33600" }, { "cve": "CVE-2024-33601", "cwe": { "id": "CWE-703", "name": "Improper Check or Handling of Exceptional Conditions" }, "notes": [ { "category": "other", "text": "Improper Check or Handling of Exceptional Conditions", "title": "CWE-703" }, { "category": "other", "text": "Reachable Assertion", "title": "CWE-617" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2024-33601 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2024/cve-2024-33601.json" } ], "scores": [ { "cvss_v3": { "baseScore": 8.6, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2024-33601" }, { "cve": "CVE-2024-33602", "cwe": { "id": "CWE-466", "name": "Return of Pointer Value Outside of Expected Range" }, "notes": [ { "category": "other", "text": "Return of Pointer Value Outside of Expected Range", "title": "CWE-466" }, { "category": "other", "text": "Improper Check or Handling of Exceptional Conditions", "title": "CWE-703" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2024-33602 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2024/cve-2024-33602.json" } ], "scores": [ { "cvss_v3": { "baseScore": 8.6, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2024-33602" }, { "cve": "CVE-2024-34397", "cwe": { "id": "CWE-940", "name": "Improper Verification of Source of a Communication Channel" }, "notes": [ { "category": "other", "text": "Improper Verification of Source of a Communication Channel", "title": "CWE-940" }, { "category": "other", "text": "Authentication Bypass by Spoofing", "title": "CWE-290" }, { "category": "other", "text": "Improper Input Validation", "title": "CWE-20" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2024-34397 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2024/cve-2024-34397.json" } ], "scores": [ { "cvss_v3": { "baseScore": 7.5, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2024-34397" }, { "cve": "CVE-2024-37370", "cwe": { "id": "CWE-130", "name": "Improper Handling of Length Parameter Inconsistency" }, "notes": [ { "category": "other", "text": "Improper Handling of Length Parameter Inconsistency", "title": "CWE-130" }, { "category": "other", "text": "Insufficient Verification of Data Authenticity", "title": "CWE-345" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2024-37370 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2024/cve-2024-37370.json" } ], "scores": [ { "cvss_v3": { "baseScore": 9.1, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2024-37370" }, { "cve": "CVE-2024-37371", "cwe": { "id": "CWE-130", "name": "Improper Handling of Length Parameter Inconsistency" }, "notes": [ { "category": "other", "text": "Improper Handling of Length Parameter Inconsistency", "title": "CWE-130" }, { "category": "other", "text": "Out-of-bounds Read", "title": "CWE-125" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2024-37371 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2024/cve-2024-37371.json" } ], "scores": [ { "cvss_v3": { "baseScore": 9.1, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2024-37371" }, { "cve": "CVE-2024-41797", "cwe": { "id": "CWE-269", "name": "Improper Privilege Management" }, "notes": [ { "category": "other", "text": "Improper Privilege Management", "title": "CWE-269" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2024-41797 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2024/cve-2024-41797.json" } ], "scores": [ { "cvss_v3": { "baseScore": 4.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2024-41797" }, { "cve": "CVE-2024-45490", "cwe": { "id": "CWE-190", "name": "Integer Overflow or Wraparound" }, "notes": [ { "category": "other", "text": "Integer Overflow or Wraparound", "title": "CWE-190" }, { "category": "other", "text": "Incorrect Calculation of Buffer Size", "title": "CWE-131" }, { "category": "other", "text": "Improper Restriction of XML External Entity Reference", "title": "CWE-611" }, { "category": "general", "text": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N", "title": "CVSSV4" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2024-45490 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2024/cve-2024-45490.json" } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2024-45490" }, { "cve": "CVE-2024-45491", "cwe": { "id": "CWE-190", "name": "Integer Overflow or Wraparound" }, "notes": [ { "category": "other", "text": "Integer Overflow or Wraparound", "title": "CWE-190" }, { "category": "general", "text": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N", "title": "CVSSV4" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2024-45491 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2024/cve-2024-45491.json" } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2024-45491" }, { "cve": "CVE-2024-45492", "cwe": { "id": "CWE-190", "name": "Integer Overflow or Wraparound" }, "notes": [ { "category": "other", "text": "Integer Overflow or Wraparound", "title": "CWE-190" }, { "category": "general", "text": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N", "title": "CVSSV4" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2024-45492 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2024/cve-2024-45492.json" } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2024-45492" }, { "cve": "CVE-2024-50246", "cwe": { "id": "CWE-20", "name": "Improper Input Validation" }, "notes": [ { "category": "other", "text": "Improper Input Validation", "title": "CWE-20" }, { "category": "general", "text": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N", "title": "CVSSV4" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2024-50246 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2024/cve-2024-50246.json" } ], "title": "CVE-2024-50246" }, { "cve": "CVE-2024-53166", "cwe": { "id": "CWE-416", "name": "Use After Free" }, "notes": [ { "category": "other", "text": "Use After Free", "title": "CWE-416" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2024-53166 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2024/cve-2024-53166.json" } ], "scores": [ { "cvss_v3": { "baseScore": 7.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2024-53166" }, { "cve": "CVE-2024-57977", "cwe": { "id": "CWE-667", "name": "Improper Locking" }, "notes": [ { "category": "other", "text": "Improper Locking", "title": "CWE-667" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2024-57977 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2024/cve-2024-57977.json" } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2024-57977" }, { "cve": "CVE-2024-57996", "cwe": { "id": "CWE-129", "name": "Improper Validation of Array Index" }, "notes": [ { "category": "other", "text": "Improper Validation of Array Index", "title": "CWE-129" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2024-57996 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2024/cve-2024-57996.json" } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2024-57996" }, { "cve": "CVE-2024-58005", "cwe": { "id": "CWE-20", "name": "Improper Input Validation" }, "notes": [ { "category": "other", "text": "Improper Input Validation", "title": "CWE-20" }, { "category": "other", "text": "Improper Control of Resource Identifiers (\u0027Resource Injection\u0027)", "title": "CWE-99" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2024-58005 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2024/cve-2024-58005.json" } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2024-58005" }, { "cve": "CVE-2025-0133", "cwe": { "id": "CWE-79", "name": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)" }, "notes": [ { "category": "other", "text": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)", "title": "CWE-79" }, { "category": "general", "text": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/S:N/AU:N/R:U/V:D/RE:M/U:Amber", "title": "CVSSV4" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2025-0133 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2025/cve-2025-0133.json" } ], "scores": [ { "cvss_v3": { "baseScore": 4.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2025-0133" }, { "cve": "CVE-2025-4373", "cwe": { "id": "CWE-120", "name": "Buffer Copy without Checking Size of Input (\u0027Classic Buffer Overflow\u0027)" }, "notes": [ { "category": "other", "text": "Buffer Copy without Checking Size of Input (\u0027Classic Buffer Overflow\u0027)", "title": "CWE-120" }, { "category": "other", "text": "Buffer Underwrite (\u0027Buffer Underflow\u0027)", "title": "CWE-124" }, { "category": "general", "text": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N", "title": "CVSSV4" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2025-4373 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2025/cve-2025-4373.json" } ], "title": "CVE-2025-4373" }, { "cve": "CVE-2025-4598", "cwe": { "id": "CWE-362", "name": "Concurrent Execution using Shared Resource with Improper Synchronization (\u0027Race Condition\u0027)" }, "notes": [ { "category": "other", "text": "Concurrent Execution using Shared Resource with Improper Synchronization (\u0027Race Condition\u0027)", "title": "CWE-362" }, { "category": "other", "text": "Signal Handler Race Condition", "title": "CWE-364" }, { "category": "general", "text": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N", "title": "CVSSV4" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2025-4598 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2025/cve-2025-4598.json" } ], "scores": [ { "cvss_v3": { "baseScore": 4.7, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2025-4598" }, { "cve": "CVE-2025-21701", "cwe": { "id": "CWE-200", "name": "Exposure of Sensitive Information to an Unauthorized Actor" }, "notes": [ { "category": "other", "text": "Exposure of Sensitive Information to an Unauthorized Actor", "title": "CWE-200" }, { "category": "other", "text": "Concurrent Execution using Shared Resource with Improper Synchronization (\u0027Race Condition\u0027)", "title": "CWE-362" }, { "category": "general", "text": "CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N", "title": "CVSSV4" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2025-21701 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2025/cve-2025-21701.json" } ], "title": "CVE-2025-21701" }, { "cve": "CVE-2025-21702", "cwe": { "id": "CWE-20", "name": "Improper Input Validation" }, "notes": [ { "category": "other", "text": "Improper Input Validation", "title": "CWE-20" }, { "category": "general", "text": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N", "title": "CVSSV4" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2025-21702 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2025/cve-2025-21702.json" } ], "scores": [ { "cvss_v3": { "baseScore": 7.0, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2025-21702" }, { "cve": "CVE-2025-21712", "cwe": { "id": "CWE-20", "name": "Improper Input Validation" }, "notes": [ { "category": "other", "text": "Improper Input Validation", "title": "CWE-20" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2025-21712 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2025/cve-2025-21712.json" } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2025-21712" }, { "cve": "CVE-2025-21724", "cwe": { "id": "CWE-20", "name": "Improper Input Validation" }, "notes": [ { "category": "other", "text": "Improper Input Validation", "title": "CWE-20" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2025-21724 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2025/cve-2025-21724.json" } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2025-21724" }, { "cve": "CVE-2025-21728", "cwe": { "id": "CWE-20", "name": "Improper Input Validation" }, "notes": [ { "category": "other", "text": "Improper Input Validation", "title": "CWE-20" }, { "category": "general", "text": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N", "title": "CVSSV4" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2025-21728 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2025/cve-2025-21728.json" } ], "title": "CVE-2025-21728" }, { "cve": "CVE-2025-21745", "cwe": { "id": "CWE-911", "name": "Improper Update of Reference Count" }, "notes": [ { "category": "other", "text": "Improper Update of Reference Count", "title": "CWE-911" }, { "category": "other", "text": "Improper Input Validation", "title": "CWE-20" }, { "category": "general", "text": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", "title": "CVSSV4" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2025-21745 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2025/cve-2025-21745.json" } ], "title": "CVE-2025-21745" }, { "cve": "CVE-2025-21756", "cwe": { "id": "CWE-416", "name": "Use After Free" }, "notes": [ { "category": "other", "text": "Use After Free", "title": "CWE-416" }, { "category": "other", "text": "Improper Input Validation", "title": "CWE-20" }, { "category": "general", "text": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", "title": "CVSSV4" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2025-21756 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2025/cve-2025-21756.json" } ], "title": "CVE-2025-21756" }, { "cve": "CVE-2025-21758", "cwe": { "id": "CWE-770", "name": "Allocation of Resources Without Limits or Throttling" }, "notes": [ { "category": "other", "text": "Allocation of Resources Without Limits or Throttling", "title": "CWE-770" }, { "category": "other", "text": "Improper Input Validation", "title": "CWE-20" }, { "category": "general", "text": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N", "title": "CVSSV4" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2025-21758 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2025/cve-2025-21758.json" } ], "title": "CVE-2025-21758" }, { "cve": "CVE-2025-21765", "cwe": { "id": "CWE-20", "name": "Improper Input Validation" }, "notes": [ { "category": "other", "text": "Improper Input Validation", "title": "CWE-20" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2025-21765 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2025/cve-2025-21765.json" } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2025-21765" }, { "cve": "CVE-2025-21766", "cwe": { "id": "CWE-20", "name": "Improper Input Validation" }, "notes": [ { "category": "other", "text": "Improper Input Validation", "title": "CWE-20" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2025-21766 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2025/cve-2025-21766.json" } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2025-21766" }, { "cve": "CVE-2025-21767", "cwe": { "id": "CWE-332", "name": "Insufficient Entropy in PRNG" }, "notes": [ { "category": "other", "text": "Insufficient Entropy in PRNG", "title": "CWE-332" }, { "category": "other", "text": "Improper Input Validation", "title": "CWE-20" }, { "category": "general", "text": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N", "title": "CVSSV4" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2025-21767 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2025/cve-2025-21767.json" } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2025-21767" }, { "cve": "CVE-2025-21795", "cwe": { "id": "CWE-371", "name": "-" }, "notes": [ { "category": "other", "text": "CWE-371", "title": "CWE-371" }, { "category": "other", "text": "Improper Input Validation", "title": "CWE-20" }, { "category": "general", "text": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", "title": "CVSSV4" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2025-21795 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2025/cve-2025-21795.json" } ], "title": "CVE-2025-21795" }, { "cve": "CVE-2025-21796", "cwe": { "id": "CWE-416", "name": "Use After Free" }, "notes": [ { "category": "other", "text": "Use After Free", "title": "CWE-416" }, { "category": "other", "text": "Improper Input Validation", "title": "CWE-20" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2025-21796 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2025/cve-2025-21796.json" } ], "title": "CVE-2025-21796" }, { "cve": "CVE-2025-21848", "cwe": { "id": "CWE-476", "name": "NULL Pointer Dereference" }, "notes": [ { "category": "other", "text": "NULL Pointer Dereference", "title": "CWE-476" }, { "category": "other", "text": "Use of NullPointerException Catch to Detect NULL Pointer Dereference", "title": "CWE-395" }, { "category": "general", "text": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", "title": "CVSSV4" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2025-21848 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2025/cve-2025-21848.json" } ], "title": "CVE-2025-21848" }, { "cve": "CVE-2025-21862", "cwe": { "id": "CWE-665", "name": "Improper Initialization" }, "notes": [ { "category": "other", "text": "Improper Initialization", "title": "CWE-665" }, { "category": "other", "text": "Use of Uninitialized Resource", "title": "CWE-908" }, { "category": "general", "text": "CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N", "title": "CVSSV4" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2025-21862 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2025/cve-2025-21862.json" } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2025-21862" }, { "cve": "CVE-2025-21864", "cwe": { "id": "CWE-371", "name": "-" }, "notes": [ { "category": "other", "text": "CWE-371", "title": "CWE-371" }, { "category": "other", "text": "NULL Pointer Dereference", "title": "CWE-476" }, { "category": "general", "text": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N", "title": "CVSSV4" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2025-21864 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2025/cve-2025-21864.json" } ], "title": "CVE-2025-21864" }, { "cve": "CVE-2025-21865", "cwe": { "id": "CWE-121", "name": "Stack-based Buffer Overflow" }, "notes": [ { "category": "other", "text": "Stack-based Buffer Overflow", "title": "CWE-121" }, { "category": "other", "text": "Out-of-bounds Write", "title": "CWE-787" }, { "category": "general", "text": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", "title": "CVSSV4" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2025-21865 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2025/cve-2025-21865.json" } ], "title": "CVE-2025-21865" }, { "cve": "CVE-2025-26465", "cwe": { "id": "CWE-310", "name": "-" }, "notes": [ { "category": "other", "text": "CWE-310", "title": "CWE-310" }, { "category": "other", "text": "Detection of Error Condition Without Action", "title": "CWE-390" }, { "category": "general", "text": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N", "title": "CVSSV4" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2025-26465 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2025/cve-2025-26465.json" } ], "scores": [ { "cvss_v3": { "baseScore": 6.8, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2025-26465" }, { "cve": "CVE-2025-31115", "cwe": { "id": "CWE-366", "name": "Race Condition within a Thread" }, "notes": [ { "category": "other", "text": "Race Condition within a Thread", "title": "CWE-366" }, { "category": "other", "text": "NULL Pointer Dereference", "title": "CWE-476" }, { "category": "other", "text": "Use After Free", "title": "CWE-416" }, { "category": "other", "text": "Premature Release of Resource During Expected Lifetime", "title": "CWE-826" }, { "category": "general", "text": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X", "title": "CVSSV4" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2025-31115 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2025/cve-2025-31115.json" } ], "scores": [ { "cvss_v3": { "baseScore": 7.5, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2025-31115" }, { "cve": "CVE-2025-32454", "cwe": { "id": "CWE-125", "name": "Out-of-bounds Read" }, "notes": [ { "category": "other", "text": "Out-of-bounds Read", "title": "CWE-125" }, { "category": "general", "text": "CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X", "title": "CVSSV4" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2025-32454 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2025/cve-2025-32454.json" } ], "scores": [ { "cvss_v3": { "baseScore": 7.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2025-32454" }, { "cve": "CVE-2025-40567", "cwe": { "id": "CWE-863", "name": "Incorrect Authorization" }, "notes": [ { "category": "other", "text": "Incorrect Authorization", "title": "CWE-863" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2025-40567 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2025/cve-2025-40567.json" } ], "scores": [ { "cvss_v3": { "baseScore": 6.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2025-40567" }, { "cve": "CVE-2025-40568", "cwe": { "id": "CWE-863", "name": "Incorrect Authorization" }, "notes": [ { "category": "other", "text": "Incorrect Authorization", "title": "CWE-863" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2025-40568 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2025/cve-2025-40568.json" } ], "scores": [ { "cvss_v3": { "baseScore": 4.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2025-40568" }, { "cve": "CVE-2025-40569", "cwe": { "id": "CWE-362", "name": "Concurrent Execution using Shared Resource with Improper Synchronization (\u0027Race Condition\u0027)" }, "notes": [ { "category": "other", "text": "Concurrent Execution using Shared Resource with Improper Synchronization (\u0027Race Condition\u0027)", "title": "CWE-362" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2025-40569 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2025/cve-2025-40569.json" } ], "scores": [ { "cvss_v3": { "baseScore": 4.8, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2025-40569" }, { "cve": "CVE-2025-40585", "cwe": { "id": "CWE-276", "name": "Incorrect Default Permissions" }, "notes": [ { "category": "other", "text": "Incorrect Default Permissions", "title": "CWE-276" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2025-40585 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2025/cve-2025-40585.json" } ], "scores": [ { "cvss_v3": { "baseScore": 9.9, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2025-40585" }, { "cve": "CVE-2025-46836", "cwe": { "id": "CWE-20", "name": "Improper Input Validation" }, "notes": [ { "category": "other", "text": "Improper Input Validation", "title": "CWE-20" }, { "category": "other", "text": "Stack-based Buffer Overflow", "title": "CWE-121" } ], "product_status": { "known_affected": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] }, "references": [ { "category": "self", "summary": "CVE-2025-46836 | NCSC-NL Website", "url": "https://vulnerabilities.ncsc.nl/csaf/v2/2025/cve-2025-46836.json" } ], "scores": [ { "cvss_v3": { "baseScore": 6.6, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H", "version": "3.1" }, "products": [ "CSAFPID-1211853", "CSAFPID-1266669", "CSAFPID-1266670", "CSAFPID-1195553", "CSAFPID-1266671", "CSAFPID-1266672", "CSAFPID-2460438", "CSAFPID-1270701", "CSAFPID-1270700", "CSAFPID-1266673", "CSAFPID-1211202", "CSAFPID-1272525", "CSAFPID-2849543", "CSAFPID-1756091", "CSAFPID-2619544", "CSAFPID-126262", "CSAFPID-2082475", "CSAFPID-2905706", "CSAFPID-2905742", "CSAFPID-2905748", "CSAFPID-2905793", "CSAFPID-2905749", "CSAFPID-2905794", "CSAFPID-2905750", "CSAFPID-2905795", "CSAFPID-2905751", "CSAFPID-2905796", "CSAFPID-2905752", "CSAFPID-2905797", "CSAFPID-2905753", "CSAFPID-2905798", "CSAFPID-2905754", "CSAFPID-2905799", "CSAFPID-2905755", "CSAFPID-2905800", "CSAFPID-2905756", "CSAFPID-2905801", "CSAFPID-2905757", "CSAFPID-2905802", "CSAFPID-2905758", "CSAFPID-2905803", "CSAFPID-2905759", "CSAFPID-2905804", "CSAFPID-2905760", "CSAFPID-2905805", "CSAFPID-2905761", "CSAFPID-2905806", "CSAFPID-2905762", "CSAFPID-2905807", "CSAFPID-2905763", "CSAFPID-2905808", "CSAFPID-2905764", "CSAFPID-2905809", "CSAFPID-2905765", "CSAFPID-2905810", "CSAFPID-2905766", "CSAFPID-2905811", "CSAFPID-2905767", "CSAFPID-2905812", "CSAFPID-2905768", "CSAFPID-2905813", "CSAFPID-2905769", "CSAFPID-2905814", "CSAFPID-2905770", "CSAFPID-2905815", "CSAFPID-2905771", "CSAFPID-2905816", "CSAFPID-2905772", "CSAFPID-2905817", "CSAFPID-2905773", "CSAFPID-2905818", "CSAFPID-2905774", "CSAFPID-2905819", "CSAFPID-2905775", "CSAFPID-2905820", "CSAFPID-2905776", "CSAFPID-2905821", "CSAFPID-2905777", "CSAFPID-2905822", "CSAFPID-2905778", "CSAFPID-2905823", "CSAFPID-2905786", "CSAFPID-2905831", "CSAFPID-2905785", "CSAFPID-2905830", "CSAFPID-2905787", "CSAFPID-2905832", "CSAFPID-2905783", "CSAFPID-2905828", "CSAFPID-2905782", "CSAFPID-2905827", "CSAFPID-2905784", "CSAFPID-2905829", "CSAFPID-2905780", "CSAFPID-2905825", "CSAFPID-2905779", "CSAFPID-2905824", "CSAFPID-2905781", "CSAFPID-2905826" ] } ], "title": "CVE-2025-46836" } ] }
ssa-082556
Vulnerability from csaf_siemens
Published
2025-06-10 00:00
Modified
2025-08-12 00:00
Summary
SSA-082556: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.5
Notes
Summary
Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.5 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).
Siemens is preparing fix versions and recommends countermeasures for products where fixes are not, or not yet available.
General Recommendations
As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download:
https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals.
Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity
Additional Resources
For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories
Terms of Use
The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.
{ "document": { "category": "csaf_security_advisory", "csaf_version": "2.0", "distribution": { "text": "Disclosure is not limited. (TLPv2: TLP:CLEAR)", "tlp": { "label": "WHITE" } }, "lang": "en", "notes": [ { "category": "summary", "text": "Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.5 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).\n\nSiemens is preparing fix versions and recommends countermeasures for products where fixes are not, or not yet available.", "title": "Summary" }, { "category": "general", "text": "As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens\u0027 operational guidelines for Industrial Security (Download: \nhttps://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals.\nAdditional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity", "title": "General Recommendations" }, { "category": "general", "text": "For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories", "title": "Additional Resources" }, { "category": "legal_disclaimer", "text": "The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.", "title": "Terms of Use" } ], "publisher": { "category": "vendor", "contact_details": "productcert@siemens.com", "name": "Siemens ProductCERT", "namespace": "https://www.siemens.com" }, "references": [ { "category": "self", "summary": "SSA-082556: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.5 - HTML Version", "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html" }, { "category": "self", "summary": "SSA-082556: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.5 - CSAF Version", "url": "https://cert-portal.siemens.com/productcert/csaf/ssa-082556.json" } ], "title": "SSA-082556: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.5", "tracking": { "current_release_date": "2025-08-12T00:00:00Z", "generator": { "engine": { "name": "Siemens ProductCERT CSAF Generator", "version": "1" } }, "id": "SSA-082556", "initial_release_date": "2025-06-10T00:00:00Z", "revision_history": [ { "date": "2025-06-10T00:00:00Z", "legacy_version": "1.0", "number": "1", "summary": "Publication Date" }, { "date": "2025-08-12T00:00:00Z", "legacy_version": "1.1", "number": "2", "summary": "Added CVE-2025-6395, CVE-2025-32988, CVE-2025-32989, CVE-2025-32990" } ], "status": "interim", "version": "2" } }, "product_tree": { "branches": [ { "branches": [ { "branches": [ { "category": "product_version_range", "name": "vers:intdot/\u003e=3.1.5", "product": { "name": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0)", "product_id": "1", "product_identification_helper": { "model_numbers": [ "6ES7518-4AX00-1AB0" ] } } } ], "category": "product_name", "name": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0)" }, { "branches": [ { "category": "product_version_range", "name": "vers:intdot/\u003e=3.1.5", "product": { "name": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0)", "product_id": "2", "product_identification_helper": { "model_numbers": [ "6ES7518-4AX00-1AC0" ] } } } ], "category": "product_name", "name": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0)" }, { "branches": [ { "category": "product_version_range", "name": "vers:intdot/\u003e=3.1.5", "product": { "name": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0)", "product_id": "3", "product_identification_helper": { "model_numbers": [ "6ES7518-4FX00-1AB0" ] } } } ], "category": "product_name", "name": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0)" }, { "branches": [ { "category": "product_version_range", "name": "vers:intdot/\u003e=3.1.5", "product": { "name": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0)", "product_id": "4", "product_identification_helper": { "model_numbers": [ "6ES7518-4FX00-1AC0" ] } } } ], "category": "product_name", "name": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0)" }, { "branches": [ { "category": "product_version_range", "name": "vers:intdot/\u003e=3.1.5", "product": { "name": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0)", "product_id": "5", "product_identification_helper": { "model_numbers": [ "6AG1518-4AX00-4AC0" ] } } } ], "category": "product_name", "name": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0)" } ], "category": "vendor", "name": "Siemens" } ] }, "vulnerabilities": [ { "cve": "CVE-2021-41617", "cwe": { "id": "CWE-311", "name": "Missing Encryption of Sensitive Data" }, "notes": [ { "category": "summary", "text": "sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of the sshd process, if the configuration specifies running the command as a different user.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.0, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2021-41617" }, { "cve": "CVE-2023-4527", "cwe": { "id": "CWE-125", "name": "Out-of-bounds Read" }, "notes": [ { "category": "summary", "text": "A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents through the function returned address data, and may cause a crash.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2023-4527" }, { "cve": "CVE-2023-4806", "cwe": { "id": "CWE-416", "name": "Use After Free" }, "notes": [ { "category": "summary", "text": "A flaw was found in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an application crash. This issue is only exploitable when a NSS module implements only the _nss_*_gethostbyname2_r and _nss_*_getcanonname_r hooks without implementing the _nss_*_gethostbyname3_r hook. The resolved name should return a large number of IPv6 and IPv4, and the call to the getaddrinfo function should have the AF_INET6 address family with AI_CANONNAME, AI_ALL and AI_V4MAPPED as flags.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.9, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2023-4806" }, { "cve": "CVE-2023-4911", "cwe": { "id": "CWE-121", "name": "Stack-based Buffer Overflow" }, "notes": [ { "category": "summary", "text": "A buffer overflow was discovered in the GNU C Library\u0027s dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2023-4911" }, { "cve": "CVE-2023-5363", "cwe": { "id": "CWE-684", "name": "Incorrect Provision of Specified Functionality" }, "notes": [ { "category": "summary", "text": "Issue summary: A bug has been identified in the processing of key and initialisation vector (IV) lengths. This can lead to potential truncation or overruns during the initialisation of some symmetric ciphers. Impact summary: A truncation in the IV can result in non-uniqueness, which could result in loss of confidentiality for some cipher modes. When calling EVP_EncryptInit_ex2(), EVP_DecryptInit_ex2() or EVP_CipherInit_ex2() the provided OSSL_PARAM array is processed after the key and IV have been established. Any alterations to the key length, via the \"keylen\" parameter or the IV length, via the \"ivlen\" parameter, within the OSSL_PARAM array will not take effect as intended, potentially causing truncation or overreading of these values. The following ciphers and cipher modes are impacted: RC2, RC4, RC5, CCM, GCM and OCB. For the CCM, GCM and OCB cipher modes, truncation of the IV can result in loss of confidentiality. For example, when following NIST\u0027s SP 800-38D section 8.2.1 guidance for constructing a deterministic IV for AES in GCM mode, truncation of the counter portion could lead to IV reuse. Both truncations and overruns of the key and overruns of the IV will produce incorrect results and could, in some cases, trigger a memory exception. However, these issues are not currently assessed as security critical. Changing the key and/or IV lengths is not considered to be a common operation and the vulnerable API was recently introduced. Furthermore it is likely that application developers will have spotted this problem during testing since decryption would fail unless both peers in the communication were similarly vulnerable. For these reasons we expect the probability of an application being vulnerable to this to be quite low. However if an application is vulnerable then this issue is considered very serious. For these reasons we have assessed this issue as Moderate severity overall. The OpenSSL SSL/TLS implementation is not affected by this issue. The OpenSSL 3.0 and 3.1 FIPS providers are not affected by this because the issue lies outside of the FIPS provider boundary. OpenSSL 3.1 and 3.0 are vulnerable to this issue.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.5, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2023-5363" }, { "cve": "CVE-2023-6246", "cwe": { "id": "CWE-787", "name": "Out-of-bounds Write" }, "notes": [ { "category": "summary", "text": "A heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when the openlog function was not called, or called with the ident argument set to NULL, and the program name (the basename of argv[0]) is bigger than 1024 bytes, resulting in an application crash or local privilege escalation. This issue affects glibc 2.36 and newer.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2023-6246" }, { "cve": "CVE-2023-6779", "cwe": { "id": "CWE-787", "name": "Out-of-bounds Write" }, "notes": [ { "category": "summary", "text": "An off-by-one heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when these functions are called with a message bigger than INT_MAX bytes, leading to an incorrect calculation of the buffer size to store the message, resulting in an application crash. This issue affects glibc 2.37 and newer.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.5, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2023-6779" }, { "cve": "CVE-2023-6780", "cwe": { "id": "CWE-131", "name": "Incorrect Calculation of Buffer Size" }, "notes": [ { "category": "summary", "text": "An integer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when these functions are called with a very long message, leading to an incorrect calculation of the buffer size to store the message, resulting in undefined behavior. This issue affects glibc 2.37 and newer.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2023-6780" }, { "cve": "CVE-2023-28531", "cwe": { "id": "CWE-311", "name": "Missing Encryption of Sensitive Data" }, "notes": [ { "category": "summary", "text": "ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2023-28531" }, { "cve": "CVE-2023-38545", "cwe": { "id": "CWE-122", "name": "Heap-based Buffer Overflow" }, "notes": [ { "category": "summary", "text": "This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake.\r\n\r\nWhen curl is asked to pass along the hostname to the SOCKS5 proxy to allow that to resolve the address instead of it getting done by curl itself, the maximum length that hostname can be is 255 bytes.\r\n\r\nIf the hostname is detected to be longer than 255 bytes, curl switches to local name resolving and instead passes on the resolved address only to the proxy. Due to a bug, the local variable that means \"let the host resolve the name\" could get the wrong value during a slow SOCKS5 handshake, and contrary to the intention, copy the too long hostname to the target buffer instead of copying just the resolved address there.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2023-38545" }, { "cve": "CVE-2023-38546", "cwe": { "id": "CWE-73", "name": "External Control of File Name or Path" }, "notes": [ { "category": "summary", "text": "This flaw allows an attacker to insert cookies at will into a running program\r\nusing libcurl, if the specific series of conditions are met.\r\n\r\nlibcurl performs transfers. In its API, an application creates \"easy handles\"\r\nthat are the individual handles for single transfers.\r\n\r\nlibcurl provides a function call that duplicates en easy handle called\r\n[curl_easy_duphandle](https://curl.se/libcurl/c/curl_easy_duphandle.html).\r\n\r\nIf a transfer has cookies enabled when the handle is duplicated, the\r\ncookie-enable state is also cloned - but without cloning the actual\r\ncookies. If the source handle did not read any cookies from a specific file on\r\ndisk, the cloned version of the handle would instead store the file name as\r\n`none` (using the four ASCII letters, no quotes).\r\n\r\nSubsequent use of the cloned handle that does not explicitly set a source to\r\nload cookies from would then inadvertently load cookies from a file named\r\n`none` - if such a file exists and is readable in the current directory of the\r\nprogram using libcurl. And if using the correct file format of course.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 3.7, "baseSeverity": "LOW", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2023-38546" }, { "cve": "CVE-2023-44487", "cwe": { "id": "CWE-400", "name": "Uncontrolled Resource Consumption" }, "notes": [ { "category": "summary", "text": "The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.5, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2023-44487" }, { "cve": "CVE-2023-46218", "cwe": { "id": "CWE-20", "name": "Improper Input Validation" }, "notes": [ { "category": "summary", "text": "This flaw allows a malicious HTTP server to set \"super cookies\" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains. It could do this by exploiting a mixed case flaw in curl\u0027s function that verifies a given cookie domain against the Public Suffix List (PSL). For example a cookie could be set with `domain=co.UK` when the URL used a lower case hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2023-46218" }, { "cve": "CVE-2023-46219", "cwe": { "id": "CWE-311", "name": "Missing Encryption of Sensitive Data" }, "notes": [ { "category": "summary", "text": "When saving HSTS data to an excessively long file name, curl could end up removing all contents, making subsequent requests using that file unaware of the HSTS status they should otherwise use.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2023-46219" }, { "cve": "CVE-2023-48795", "cwe": { "id": "CWE-222", "name": "Truncation of Security-relevant Information" }, "notes": [ { "category": "summary", "text": "The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack. This occurs because the SSH Binary Packet Protocol (BPP), implemented by these extensions, mishandles the handshake phase and mishandles use of sequence numbers. For example, there is an effective attack against SSH\u0027s use of ChaCha20-Poly1305 (and CBC with Encrypt-then-MAC). The bypass occurs in chacha20-poly1305@openssh.com and (if CBC is used) the -etm@openssh.com MAC algorithms. This also affects Maverick Synergy Java SSH API before 3.1.0-SNAPSHOT, Dropbear through 2022.83, Ssh before 5.1.1 in Erlang/OTP, PuTTY before 0.80, AsyncSSH before 2.14.2, golang.org/x/crypto before 0.17.0, libssh before 0.10.6, libssh2 through 1.11.0, Thorn Tech SFTP Gateway before 3.4.6, Tera Term before 5.1, Paramiko before 3.4.0, jsch before 0.2.15, SFTPGo before 2.5.6, Netgate pfSense Plus through 23.09.1, Netgate pfSense CE through 2.7.2, HPN-SSH through 18.2.0, ProFTPD before 1.3.8b (and before1.3.9rc2), ORYX CycloneSSH before 2.3.4, NetSarang XShell 7 before Build 0144, CrushFTP before 10.6.0, ConnectBot SSH library before 2.2.22, Apache MINA sshd through 2.11.0, sshj through 0.37.0, TinySSH through 20230101, trilead-ssh2 6401, the net-ssh gem 7.2.0 for Ruby, the mscdex ssh2 module before 1.15.0 for Node.js, the thrussh library before 0.35.1 for Rust, and the Russh crate before 0.40.2 for Rust; and there could be effects on Bitvise SSH through 9.31.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.9, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2023-48795" }, { "cve": "CVE-2023-51384", "cwe": { "id": "CWE-304", "name": "Missing Critical Step in Authentication" }, "notes": [ { "category": "summary", "text": "In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only applied to the first key, even if a PKCS#11 token returns multiple keys.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2023-51384" }, { "cve": "CVE-2023-51385", "cwe": { "id": "CWE-78", "name": "Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)" }, "notes": [ { "category": "summary", "text": "In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and this name is referenced by an expansion token in certain situations. For example, an untrusted Git repository can have a submodule with shell metacharacters in a user name or host name.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2023-51385" }, { "cve": "CVE-2023-52927", "cwe": { "id": "CWE-20", "name": "Improper Input Validation" }, "notes": [ { "category": "summary", "text": "netfilter: allow exp not to be removed in nf_ct_find_expectation Currently nf_conntrack_in() calling nf_ct_find_expectation() will remove the exp from the hash table. However, in some scenario, we expect the exp not to be removed when the created ct will not be confirmed, like in OVS and TC conntrack in the following patches. This patch allows exp not to be removed by setting IPS_CONFIRMED in the status of the tmpl.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.7, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2023-52927" }, { "cve": "CVE-2024-2961", "cwe": { "id": "CWE-787", "name": "Out-of-bounds Write" }, "notes": [ { "category": "summary", "text": "The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2024-2961" }, { "cve": "CVE-2024-6119", "cwe": { "id": "CWE-843", "name": "Access of Resource Using Incompatible Type (\u0027Type Confusion\u0027)" }, "notes": [ { "category": "summary", "text": "Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process. Impact summary: Abnormal termination of an application can a cause a denial of service. Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address when comparing the expected name with an `otherName` subject alternative name of an X.509 certificate. This may result in an exception that terminates the application program. Note that basic certificate chain validation (signatures, dates, ...) is not affected, the denial of service can occur only when the application also specifies an expected DNS name, Email address or IP address. TLS servers rarely solicit client certificates, and even when they do, they generally don\u0027t perform a name check against a reference identifier (expected identity), but rather extract the presented identity after checking the certificate chain. So TLS servers are generally not affected and the severity of the issue is Moderate. The FIPS modules in 3.3, 3.2, 3.1 and 3.0 are not affected by this issue.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.5, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2024-6119" }, { "cve": "CVE-2024-6387", "cwe": { "id": "CWE-364", "name": "Signal Handler Race Condition" }, "notes": [ { "category": "summary", "text": "A security regression (CVE-2006-5051) was discovered in OpenSSH\u0027s server (sshd). There is a race condition which can lead to sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.1, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2024-6387" }, { "cve": "CVE-2024-12133", "cwe": { "id": "CWE-407", "name": "Inefficient Algorithmic Complexity" }, "notes": [ { "category": "summary", "text": "A flaw in libtasn1 causes inefficient handling of specific certificate data. When processing a large number of elements in a certificate, libtasn1 takes much longer than expected, which can slow down or even crash the system. This flaw allows an attacker to send a specially crafted certificate, causing a denial of service attack.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2024-12133" }, { "cve": "CVE-2024-12243", "cwe": { "id": "CWE-407", "name": "Inefficient Algorithmic Complexity" }, "notes": [ { "category": "summary", "text": "A flaw was found in GnuTLS, which relies on libtasn1 for ASN.1 data processing. Due to an inefficient algorithm in libtasn1, decoding certain DER-encoded certificate data can take excessive time, leading to increased resource consumption. This flaw allows a remote attacker to send a specially crafted certificate, causing GnuTLS to become unresponsive or slow, resulting in a denial-of-service condition.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2024-12243" }, { "cve": "CVE-2024-24855", "cwe": { "id": "CWE-362", "name": "Concurrent Execution using Shared Resource with Improper Synchronization (\u0027Race Condition\u0027)" }, "notes": [ { "category": "summary", "text": "A race condition was found in the Linux kernel\u0027s scsi device driver in lpfc_unregister_fcf_rescan() function. This can result in a null pointer dereference issue, possibly leading to a kernel panic or denial of service issue.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.0, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:H", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2024-24855" }, { "cve": "CVE-2024-26596", "cwe": { "id": "CWE-20", "name": "Improper Input Validation" }, "notes": [ { "category": "summary", "text": "net: dsa: netdev_priv() dereference before check on non-DSA netdevice events.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2024-26596" }, { "cve": "CVE-2024-28085", "cwe": { "id": "CWE-20", "name": "Improper Input Validation" }, "notes": [ { "category": "summary", "text": "wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users\u0027 terminals through argv. (Specifically, escape sequences received from stdin are blocked, but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2024-28085" }, { "cve": "CVE-2024-33599", "cwe": { "id": "CWE-121", "name": "Stack-based Buffer Overflow" }, "notes": [ { "category": "summary", "text": "nscd: Stack-based buffer overflow in netgroup cache\r\n\r\nIf the Name Service Cache Daemon\u0027s (nscd) fixed size cache is exhausted\r\nby client requests then a subsequent client request for netgroup data\r\nmay result in a stack-based buffer overflow. This flaw was introduced\r\nin glibc 2.15 when the cache was added to nscd.\r\n\r\nThis vulnerability is only present in the nscd binary.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.6, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2024-33599" }, { "cve": "CVE-2024-33600", "cwe": { "id": "CWE-476", "name": "NULL Pointer Dereference" }, "notes": [ { "category": "summary", "text": "nscd: Null pointer crashes after notfound response\r\n\r\nIf the Name Service Cache Daemon\u0027s (nscd) cache fails to add a not-found\r\nnetgroup response to the cache, the client request can result in a null\r\npointer dereference. This flaw was introduced in glibc 2.15 when the\r\ncache was added to nscd.\r\n\r\nThis vulnerability is only present in the nscd binary.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2024-33600" }, { "cve": "CVE-2024-33601", "cwe": { "id": "CWE-617", "name": "Reachable Assertion" }, "notes": [ { "category": "summary", "text": "nscd: netgroup cache may terminate daemon on memory allocation failure\r\n\r\nThe Name Service Cache Daemon\u0027s (nscd) netgroup cache uses xmalloc or\r\nxrealloc and these functions may terminate the process due to a memory\r\nallocation failure resulting in a denial of service to the clients. The\r\nflaw was introduced in glibc 2.15 when the cache was added to nscd.\r\n\r\nThis vulnerability is only present in the nscd binary.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.0, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2024-33601" }, { "cve": "CVE-2024-33602", "cwe": { "id": "CWE-466", "name": "Return of Pointer Value Outside of Expected Range" }, "notes": [ { "category": "summary", "text": "nscd: netgroup cache assumes NSS callback uses in-buffer strings\r\n\r\nThe Name Service Cache Daemon\u0027s (nscd) netgroup cache can corrupt memory\r\nwhen the NSS callback does not store all strings in the provided buffer.\r\nThe flaw was introduced in glibc 2.15 when the cache was added to nscd.\r\n\r\nThis vulnerability is only present in the nscd binary.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.0, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2024-33602" }, { "cve": "CVE-2024-34397", "cwe": { "id": "CWE-20", "name": "Improper Input Validation" }, "notes": [ { "category": "summary", "text": "An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly interpret as having been sent by the trusted system service. This could lead to the GDBus-based client behaving incorrectly, with an application-dependent impact.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.2, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2024-34397" }, { "cve": "CVE-2024-37370", "cwe": { "id": "CWE-130", "name": "Improper Handling of Length Parameter Inconsistency" }, "notes": [ { "category": "summary", "text": "In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing the unwrapped token to appear truncated to the application.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.4, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2024-37370" }, { "cve": "CVE-2024-37371", "cwe": { "id": "CWE-130", "name": "Improper Handling of Length Parameter Inconsistency" }, "notes": [ { "category": "summary", "text": "In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling by sending message tokens with invalid length fields.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2024-37371" }, { "cve": "CVE-2024-45490", "cwe": { "id": "CWE-131", "name": "Incorrect Calculation of Buffer Size" }, "notes": [ { "category": "summary", "text": "An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2024-45490" }, { "cve": "CVE-2024-45491", "cwe": { "id": "CWE-190", "name": "Integer Overflow or Wraparound" }, "notes": [ { "category": "summary", "text": "An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX equals SIZE_MAX).", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.3, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2024-45491" }, { "cve": "CVE-2024-45492", "cwe": { "id": "CWE-190", "name": "Integer Overflow or Wraparound" }, "notes": [ { "category": "summary", "text": "An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where UINT_MAX equals SIZE_MAX).", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.3, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2024-45492" }, { "cve": "CVE-2024-50246", "cwe": { "id": "CWE-20", "name": "Improper Input Validation" }, "notes": [ { "category": "summary", "text": "In the Linux kernel, the following vulnerability has been resolved:\r\n\r\nfs/ntfs3: Add rough attr alloc_size check", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2024-50246" }, { "cve": "CVE-2024-53166", "cwe": { "id": "CWE-416", "name": "Use After Free" }, "notes": [ { "category": "summary", "text": "block, bfq: bfqq uaf in bfq_limit_depth() Set new allocated bfqq to bic or remove freed bfqq from bic are both protected by bfqd-\u003elock, however bfq_limit_depth() is deferencing bfqq from bic without the lock, this can lead to UAF if the io_context is shared by multiple tasks.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2024-53166" }, { "cve": "CVE-2024-57977", "cwe": { "id": "CWE-667", "name": "Improper Locking" }, "notes": [ { "category": "summary", "text": "memcg: A soft lockup vulnerability in the product with about 56,000 tasks were in the OOM cgroup, it was traversing them when the soft lockup was triggered.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2024-57977" }, { "cve": "CVE-2024-57996", "cwe": { "id": "CWE-129", "name": "Improper Validation of Array Index" }, "notes": [ { "category": "summary", "text": "net_sched: sch_sfq: vulnerability caused by incorrectly handling a packet limit of 1, leading to an array-index-out-of-bounds error and subsequent crash when the queue length is decremented for an empty slot.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2024-57996" }, { "cve": "CVE-2024-58005", "cwe": { "id": "CWE-20", "name": "Improper Input Validation" }, "notes": [ { "category": "summary", "text": "tpm: Change to kvalloc() in eventlog/acpi.c.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2024-58005" }, { "cve": "CVE-2025-4373", "cwe": { "id": "CWE-124", "name": "Buffer Underwrite (\u0027Buffer Underflow\u0027)" }, "notes": [ { "category": "summary", "text": "GLib is vulnerable to an integer overflow in the g_string_insert_unichar() function. When the position at which to insert the character is large, the position will overflow, leading to a buffer underwrite.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.8, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2025-4373" }, { "cve": "CVE-2025-4598", "cwe": { "id": "CWE-364", "name": "Signal Handler Race Condition" }, "notes": [ { "category": "summary", "text": "A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original\u0027s privileged process coredump, allowing the attacker to read sensitive data, such as /etc/shadow content, loaded by the original process.\r\n\r\nA SUID binary or process has a special type of permission, which allows the process to run with the file owner\u0027s permissions, regardless of the user executing the binary. This allows the process to access more restricted data than unprivileged users or processes would be able to. An attacker can leverage this flaw by forcing a SUID process to crash and force the Linux kernel to recycle the process PID before systemd-coredump can analyze the /proc/pid/auxv file. If the attacker wins the race condition, they gain access to the original\u0027s SUID process coredump file. They can read sensitive content loaded into memory by the original binary, affecting data confidentiality.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.7, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2025-4598" }, { "cve": "CVE-2025-6395", "cwe": { "id": "CWE-476", "name": "NULL Pointer Dereference" }, "notes": [ { "category": "summary", "text": "A NULL pointer dereference flaw was found in the GnuTLS software in _gnutls_figure_common_ciphersuite().", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2025-6395" }, { "cve": "CVE-2025-21701", "cwe": { "id": "CWE-362", "name": "Concurrent Execution using Shared Resource with Improper Synchronization (\u0027Race Condition\u0027)" }, "notes": [ { "category": "summary", "text": "net: vulnerability arises because unregister_netdevice_many_notify might run before the rtnl lock section of ethnl operations, leading to potential use of destroyed locks, which is fixed by denying operations on devices being unregistered.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.7, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2025-21701" }, { "cve": "CVE-2025-21702", "cwe": { "id": "CWE-20", "name": "Improper Input Validation" }, "notes": [ { "category": "summary", "text": "pfifo_tail_enqueue: Drop new packet when sch-\u003elimit == 0.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.0, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2025-21702" }, { "cve": "CVE-2025-21712", "cwe": { "id": "CWE-20", "name": "Improper Input Validation" }, "notes": [ { "category": "summary", "text": "md/md-bitmap: vulnerability caused by bitmap_get_stats() can be called even if the bitmap is destroyed or not fully initialized, leading to a kernel crash, which is fixed by synchronizing bitmap_get_stats() with bitmap_info.mutex.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2025-21712" }, { "cve": "CVE-2025-21724", "cwe": { "id": "CWE-20", "name": "Improper Input Validation" }, "notes": [ { "category": "summary", "text": "iommufd/iova_bitmap: Fix shift-out-of-bounds in iova_bitmap_offset_to_index(). Resolve a UBSAN shift-out-of-bounds issue in iova_bitmap_offset_to_index() where shifting the constant \"1\" (of type int) by bitmap-\u003emapped.pgshift (an unsigned long value) could result in undefined behavior. The constant \"1\" defaults to a 32-bit \"int\", and when \"pgshift\" exceeds 31 (e.g., pgshift = 63) the shift operation overflows, as the result cannot be represented in a 32-bit type.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2025-21724" }, { "cve": "CVE-2025-21728", "cwe": { "id": "CWE-20", "name": "Improper Input Validation" }, "notes": [ { "category": "summary", "text": "bpf: Send signals asynchronously if !preemptible BPF programs can execute in all kinds of contexts and when a program running in a non-preemptible context uses the bpf_send_signal() kfunc, it will cause issues because this kfunc can sleep.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2025-21728" }, { "cve": "CVE-2025-21745", "cwe": { "id": "CWE-20", "name": "Improper Input Validation" }, "notes": [ { "category": "summary", "text": "In the Linux kernel, the following vulnerability has been resolved:\r\n\r\nblk-cgroup: Fix class @block_class\u0027s subsystem refcount leakage\r\n\r\nblkcg_fill_root_iostats() iterates over @block_class\u0027s devices by\r\nclass_dev_iter_(init|next)(), but does not end iterating with\r\nclass_dev_iter_exit(), so causes the class\u0027s subsystem refcount leakage.\r\n\r\nFix by ending the iterating with class_dev_iter_exit().", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2025-21745" }, { "cve": "CVE-2025-21756", "cwe": { "id": "CWE-20", "name": "Improper Input Validation" }, "notes": [ { "category": "summary", "text": "vsock: Keep the binding until socket destruction Preserve sockets bindings; this includes both resulting from an explicit bind() and those implicitly bound through autobind during connect().", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2025-21756" }, { "cve": "CVE-2025-21758", "cwe": { "id": "CWE-20", "name": "Improper Input Validation" }, "notes": [ { "category": "summary", "text": "ipv6: mcast: add RCU protection to mld_newpack() mld_newpack() can be called without RTNL or RCU being held.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2025-21758" }, { "cve": "CVE-2025-21765", "cwe": { "id": "CWE-20", "name": "Improper Input Validation" }, "notes": [ { "category": "summary", "text": "ipv6: use RCU protection in ip6_default_advmss() ip6_default_advmss() needs rcu protection to make sure the net structure it reads does not disappear.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2025-21765" }, { "cve": "CVE-2025-21766", "cwe": { "id": "CWE-20", "name": "Improper Input Validation" }, "notes": [ { "category": "summary", "text": "ipv4: use RCU protection in __ip_rt_update_pmtu(). __ip_rt_update_pmtu() must use RCU protection to make sure the net structure it reads does not disappear.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2025-21766" }, { "cve": "CVE-2025-21767", "cwe": { "id": "CWE-20", "name": "Improper Input Validation" }, "notes": [ { "category": "summary", "text": "In the Linux kernel, the following vulnerability has been resolved: clocksource: Use migrate_disable() to avoid calling get_random_u32() in atomic context The following bug report happened with a PREEMPT_RT kernel: BUG: sleeping function called from invalid context at kernel/locking/spinlock_rt.c:48 in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 2012, name: kwatchdog preempt_count: 1, expected: 0 RCU nest depth: 0, expected: 0 get_random_u32+0x4f/0x110 clocksource_verify_choose_cpus+0xab/0x1a0 clocksource_verify_percpu.part.0+0x6b/0x330 clocksource_watchdog_kthread+0x193/0x1a0 It is due to the fact that clocksource_verify_choose_cpus() is invoked with preemption disabled. This function invokes get_random_u32() to obtain random numbers for choosing CPUs. The batched_entropy_32 local lock and/or the base_crng.lock spinlock in driver/char/random.c will be acquired during the call. In PREEMPT_RT kernel, they are both sleeping locks and so cannot be acquired in atomic context. Fix this problem by using migrate_disable() to allow smp_processor_id() to be reliably used without introducing atomic context. preempt_disable() is then called after clocksource_verify_choose_cpus() but before the clocksource measurement is being run to avoid introducing unexpected latency.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2025-21767" }, { "cve": "CVE-2025-21795", "cwe": { "id": "CWE-20", "name": "Improper Input Validation" }, "notes": [ { "category": "summary", "text": "NFSD: hang in nfsd4_shutdown_callback. If nfs4_client is in courtesy state then there is no point to send the callback. This causes nfsd4_shutdown_callback to hang since cl_cb_inflight is not 0. This hang lasts about 15 minutes until TCP notifies NFSD that the connection was dropped.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2025-21795" }, { "cve": "CVE-2025-21796", "cwe": { "id": "CWE-20", "name": "Improper Input Validation" }, "notes": [ { "category": "summary", "text": "nfsd: clear acl_access/acl_default after releasing them If getting acl_default fails, acl_access and acl_default will be released simultaneously.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2025-21796" }, { "cve": "CVE-2025-21848", "cwe": { "id": "CWE-476", "name": "NULL Pointer Dereference" }, "notes": [ { "category": "summary", "text": "In the Linux kernel, the following vulnerability has been resolved:\r\n\r\nnfp: bpf: Add check for nfp_app_ctrl_msg_alloc()\r\n\r\nAdd check for the return value of nfp_app_ctrl_msg_alloc() in\r\nnfp_bpf_cmsg_alloc() to prevent null pointer dereference.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2025-21848" }, { "cve": "CVE-2025-21862", "cwe": { "id": "CWE-908", "name": "Use of Uninitialized Resource" }, "notes": [ { "category": "summary", "text": "drop_monitor: incorrect initialization order. If drop_monitor is built as a kernel module, syzkaller may have time to send a netlink NET_DM_CMD_START message during the module loading. This will call the net_dm_monitor_start() function that uses a spinlock that has not yet been initialized.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2025-21862" }, { "cve": "CVE-2025-21864", "cwe": { "id": "CWE-476", "name": "NULL Pointer Dereference" }, "notes": [ { "category": "summary", "text": "In the Linux kernel, the following vulnerability has been resolved:\r\n\r\ntcp: drop secpath at the same time as we currently drop dst\r\n\r\nXiumei reported hitting the WARN in xfrm6_tunnel_net_exit while\r\nrunning tests that boil down to:\r\n - create a pair of netns\r\n - run a basic TCP test over ipcomp6\r\n - delete the pair of netns\r\n\r\nThe xfrm_state found on spi_byaddr was not deleted at the time we\r\ndelete the netns, because we still have a reference on it. This\r\nlingering reference comes from a secpath (which holds a ref on the\r\nxfrm_state), which is still attached to an skb. This skb is not\r\nleaked, it ends up on sk_receive_queue and then gets defer-free\u0027d by\r\nskb_attempt_defer_free.\r\n\r\nThe problem happens when we defer freeing an skb (push it on one CPU\u0027s\r\ndefer_list), and don\u0027t flush that list before the netns is deleted. In\r\nthat case, we still have a reference on the xfrm_state that we don\u0027t\r\nexpect at this point.\r\n\r\nWe already drop the skb\u0027s dst in the TCP receive path when it\u0027s no\r\nlonger needed, so let\u0027s also drop the secpath. At this point,\r\ntcp_filter has already called into the LSM hooks that may require the\r\nsecpath, so it should not be needed anymore. However, in some of those\r\nplaces, the MPTCP extension has just been attached to the skb, so we\r\ncannot simply drop all extensions.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2025-21864" }, { "cve": "CVE-2025-21865", "cwe": { "id": "CWE-787", "name": "Out-of-bounds Write" }, "notes": [ { "category": "summary", "text": "gtp: Suppress list corruption splat in gtp_net_exit_batch_rtnl(). Commit eb28fd76c0a0 (\"gtp: Destroy device along with udp socket\u0027s netns dismantle.\") added the for_each_netdev() loop in gtp_net_exit_batch_rtnl() to destroy devices in each netns as done in geneve and ip tunnels. However, this could trigger -\u003edellink() twice for the same device during -\u003eexit_batch_rtnl().", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2025-21865" }, { "cve": "CVE-2025-26465", "cwe": { "id": "CWE-390", "name": "Detection of Error Condition Without Action" }, "notes": [ { "category": "summary", "text": "A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be considered successful, the attacker needs to manage to exhaust the client\u0027s memory resource first, turning the attack complexity high.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.8, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2025-26465" }, { "cve": "CVE-2025-31115", "cwe": { "id": "CWE-826", "name": "Premature Release of Resource During Expected Lifetime" }, "notes": [ { "category": "summary", "text": "The threaded .xz decoder in liblzma has a vulnerability that can at least result in a crash (denial of service). The effects include heap use after free and writing to an address based on the null pointer plus an offset.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.5, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2025-31115" }, { "cve": "CVE-2025-32988", "cwe": { "id": "CWE-415", "name": "Double Free" }, "notes": [ { "category": "summary", "text": "A flaw was found in GnuTLS. A double-free vulnerability exists in GnuTLS due to incorrect ownership handling in the export logic of Subject Alternative Name (SAN) entries containing an otherName. If the type-id OID is invalid or malformed, GnuTLS will call asn1_delete_structure() on an ASN.1 node it does not own, leading to a double-free condition when the parent function or caller later attempts to free the same structure. This vulnerability can be triggered using only public GnuTLS APIs and may result in denial of service or memory corruption, depending on allocator behavior.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2025-32988" }, { "cve": "CVE-2025-32989", "cwe": { "id": "CWE-295", "name": "Improper Certificate Validation" }, "notes": [ { "category": "summary", "text": "A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate Transparency (CT) Signed Certificate Timestamp (SCT) extension during X.509 certificate parsing. This flaw allows a malicious user to create a certificate containing a malformed SCT extension (OID 1.3.6.1.4.1.11129.2.4.2) that contains sensitive data. This issue leads to the exposure of confidential information when GnuTLS verifies certificates from certain websites when the certificate (SCT) is not checked correctly.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2025-32989" }, { "cve": "CVE-2025-46836", "cwe": { "id": "CWE-20", "name": "Improper Input Validation" }, "notes": [ { "category": "summary", "text": "net-tools is a collection of programs that form the base set of the NET-3 networking distribution for the Linux operating system. Inn versions up to and including 2.10, the Linux network utilities (like ifconfig) from the net-tools package do not properly validate the structure of /proc files when showing interfaces. `get_name()` in `interface.c` copies interface labels from `/proc/net/dev` into a fixed 16-byte stack buffer without bounds checking, leading to possible arbitrary code execution or crash. The known attack path does not require privilege but also does not provide privilege escalation in this scenario. A patch is available and expected to be part of version 2.20.", "title": "Summary" } ], "product_status": { "known_affected": [ "1", "2", "3", "4", "5" ] }, "remediations": [ { "category": "none_available", "details": "Currently no fix is available", "product_ids": [ "1", "2", "3", "4", "5" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.6, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H", "version": "3.1" }, "products": [ "1", "2", "3", "4", "5" ] } ], "title": "CVE-2025-46836" } ] }
Loading…
Loading…
Sightings
Author | Source | Type | Date |
---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…