ENISA EUVD · EUVD-2022-2673Official EUVD mapping0 linked advisory records.
Official EUVD record ↗BSI · German · WID-SEC-2025-1459Dell Data Protection Advisor: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Dell Data Protection Advisor ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, und um weitere nicht näher spezifizierte Angriffe durchzuführen.
Official advisory ↗BSI · German · WID-SEC-2024-1186IBM DB2 REST: Mehrere SchwachstellenEin entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM DB2 REST ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen oder einen Denial-of-Service-Zustand zu verursachen.
Official advisory ↗BSI · German · WID-SEC-2024-0794Dell ECS: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Dell ECS ausnutzen, um seine Privilegien zu erweitern, beliebigen Programmcode mit Administratorrechten auszuführen, Informationen offenzulegen, Dateien zu manipulieren, einen Cross-Site-Scripting-Angriff durchzuführen, Sicherheitsvorkehrungen zu umgehen oder einen Denial of Service Zustand herbeizuführen.
Official advisory ↗BSI · German · WID-SEC-2022-0432Xerox FreeFlow Print Server: Mehrere SchwachstellenEin entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Xerox FreeFlow Print Server ausnutzen, um die Vertraulichkeit, Verfügbarkeit und Integrität zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2022-0302Xerox FreeFlow Print Server: Mehrere Schwachstellen ermöglichen Ausführen von beliebigem Programmcode mit AdministratorrechtenEin entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Xerox FreeFlow Print Server ausnutzen, um beliebigen Programmcode auszuführen, einen Cross-Site-Scripting-Angriff durchzuführen, Informationen offenzulegen, einen Denial-of-Service-Zustand zu verursachen oder Dateien zu manipulieren.
Official advisory ↗BSI · German · WID-SEC-2022-0400OpenSSL: Mehrere Schwachstellen ermöglichen Denial of ServiceEin entfernter, anonymer Angreifer kann mehrere Schwachstellen in OpenSSL ausnutzen, um einen Denial of Service Angriff durchzuführen oder Informationen offenzulegen.
Official advisory ↗Canadian Centre for Cyber Security · English · AV21-627IBM security advisoryBetween 6 and 12 December 2021 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:
IBM App Connect Enterprise
https://www.ibm.com/blogs/psirt/security-bulletin-ibm-app-connect-enterprise-v11-is-affected-by-vulnerabilities-in-node-js-cve-2021-23358-3/
Official advisory ↗Canadian Centre for Cyber Security · English · AV21-594IBM security advisoryBetween 15 and 21 November 2021 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:
IBM Cloud Pak System
https://www.ibm.com/blogs/psirt/security-bulletin-vulnerability-in-ibm-sdk-java-affects-ibm-cloud-pak-system-cve-2020-27221/
Official advisory ↗Canadian Centre for Cyber Security · English · AV21-585IBM security advisoryBetween 8 and 14 November 2021 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:
IBM Cloud Object Storage Systems
https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-affect-ibm-cloud-object-storage-systems-nov-2021-v1/
Official advisory ↗Canadian Centre for Cyber Security · English · AV21-569IBM security advisoryBetween 1 and 7 November 2021 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:
IBM WIoTP MessageGateway
Official advisory ↗Canadian Centre for Cyber Security · English · AV21-535IBM security advisoryBetween 18 and 24 October 2021 IBM published Security Bulletins to address vulnerabilities in multiple products. Included were critical updates for the following:
IBM Watson Explorer Deep Analytics Edition Foundational Components
https://www.ibm.com/blogs/psirt/security-bulletin-vulnerabilities-affect-watson-explorer-foundational-components-cve-2021-3712-cve-2021-3711/
Official advisory ↗Cyber Security Agency of Singapore · English · CSA-SB-20210825Security Bulletin 25 Aug 2021The Cyber Security Agency of Singapore included this CVE in its official Security Bulletin 25 Aug 2021, published on 25 August 2021. Open the linked bulletin for the product, severity and reference information published in that issue.
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0199Multiples vulnérabilités dans les produits VMwareord?id=CVE-2021-22922
Référence CVE CVE-2021-22923
https://www.cve.org/CVERecord?id=CVE-2021-22923
Référence CVE CVE-2021-22925
https://www.cve.org/CVERecord?id=CVE-2021-22925
Référence CVE CVE-2021-22926
https://www.cve.org/CVERecord?id=CVE-2021-22926
Référence CVE CVE-2021-22946
https://www.cve.org/CVERecord?id=CVE-2021-22946
Référence CVE CVE-2021-22947
https://www.cve.org/CVERecord?id=CVE-2021-22947
Référence CVE CVE-2021-23840
https://www.cve.org/CVERecord?id=CVE-2021-23840
Référence CVE CVE-2021-23841
https://www.cve.org/CVERecord?id=CVE-2021-23841
Référence CVE CVE-2021-3449
https://www.cve.org/CVERecord?id=CVE-2021-3449
Référence CVE CVE-2021-3711
https://www.cve.org/CVERecord?id=CVE-2021-3711
Référence CVE CVE-2021-3712
https://www.cve.org/CVERecord?id=CVE-2021-3712
Référence CVE CVE-2021-37600
https://www.cve.org/CVERecord?id=CVE-2021-37600
Référence CVE CVE-2021-38297
https://www.cve.org/CVERecord?id=CVE-2021-38297
Référence CVE CVE-2021-38561
https://www.cve.org/CVERecord?id=CVE-2021-38561
Référence CVE CVE-2021-39293
https://www.cve.org/CVERecord?id=CVE-2021-39293
Référence CVE CVE-2021-3995
https://www.cve.org/CVERecord?id=CVE-2021-3995
Référence CVE CVE-2021-3996
https://www.cve.org/CVERecord?id=CVE-2021-3996
Référence CVE CVE-2021-41089
https://www.cve.org/CVERecord?id=CVE-202
Official advisory ↗CERT-FR · French · CERTFR-2024-AVI-0442Multiples vulnérabilités dans les produits IBMDe multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2024-AVI-0180Multiples vulnérabilités dans les produits IBMord?id=CVE-2021-35559
Référence CVE CVE-2021-35560
https://www.cve.org/CVERecord?id=CVE-2021-35560
Référence CVE CVE-2021-35564
https://www.cve.org/CVERecord?id=CVE-2021-35564
Référence CVE CVE-2021-35565
https://www.cve.org/CVERecord?id=CVE-2021-35565
Référence CVE CVE-2021-35578
https://www.cve.org/CVERecord?id=CVE-2021-35578
Référence CVE CVE-2021-35586
https://www.cve.org/CVERecord?id=CVE-2021-35586
Référence CVE CVE-2021-35588
https://www.cve.org/CVERecord?id=CVE-2021-35588
Référence CVE CVE-2021-35603
https://www.cve.org/CVERecord?id=CVE-2021-35603
Référence CVE CVE-2021-3572
https://www.cve.org/CVERecord?id=CVE-2021-3572
Référence CVE CVE-2021-3711
https://www.cve.org/CVERecord?id=CVE-2021-3711
Référence CVE CVE-2021-3712
https://www.cve.org/CVERecord?id=CVE-2021-3712
Référence CVE CVE-2021-41035
https://www.cve.org/CVERecord?id=CVE-2021-41035
Référence CVE CVE-2021-4160
https://www.cve.org/CVERecord?id=CVE-2021-4160
Référence CVE CVE-2021-43138
https://www.cve.org/CVERecord?id=CVE-2021-43138
Référence CVE CVE-2021-44906
https://www.cve.org/CVERecord?id=CVE-2021-44906
Référence CVE CVE-2022-0778
https://www.cve.org/CVERecord?id=CVE-2022-0778
Référence CVE CVE-2022-1471
https://www.cve.org/CVERecord?id=CVE-2022-1471
Référence CVE CVE-2022-2097
https://www.cve.org/CVERecord?id=CVE-2022-2
Official advisory ↗CERT-FR · French · CERTFR-2024-AVI-0145Multiples vulnérabilités dans les produits IBMrd?id=CVE-2021-3114
Référence CVE CVE-2021-31525
https://www.cve.org/CVERecord?id=CVE-2021-31525
Référence CVE CVE-2021-33194
https://www.cve.org/CVERecord?id=CVE-2021-33194
Référence CVE CVE-2021-33195
https://www.cve.org/CVERecord?id=CVE-2021-33195
Référence CVE CVE-2021-33196
https://www.cve.org/CVERecord?id=CVE-2021-33196
Référence CVE CVE-2021-33197
https://www.cve.org/CVERecord?id=CVE-2021-33197
Référence CVE CVE-2021-33198
https://www.cve.org/CVERecord?id=CVE-2021-33198
Référence CVE CVE-2021-34558
https://www.cve.org/CVERecord?id=CVE-2021-34558
Référence CVE CVE-2021-36221
https://www.cve.org/CVERecord?id=CVE-2021-36221
Référence CVE CVE-2021-3711
https://www.cve.org/CVERecord?id=CVE-2021-3711
Référence CVE CVE-2021-3712
https://www.cve.org/CVERecord?id=CVE-2021-3712
Référence CVE CVE-2021-38297
https://www.cve.org/CVERecord?id=CVE-2021-38297
Référence CVE CVE-2021-39293
https://www.cve.org/CVERecord?id=CVE-2021-39293
Référence CVE CVE-2021-41190
https://www.cve.org/CVERecord?id=CVE-2021-41190
Référence CVE CVE-2021-4160
https://www.cve.org/CVERecord?id=CVE-2021-4160
Référence CVE CVE-2021-41771
https://www.cve.org/CVERecord?id=CVE-2021-41771
Référence CVE CVE-2021-41772
https://www.cve.org/CVERecord?id=CVE-2021-41772
Référence CVE CVE-2021-44716
https://www.cve.org/CVERecord?id=CVE-2
Official advisory ↗CERT-FR · French · CERTFR-2023-AVI-0363Multiples vulnérabilités dans les produits SchneiderDe multiples vulnérabilités ont été découvertes dans les produits
Schneider. Certaines d'entre elles permettent à un attaquant de
provoquer un problème de sécurité non spécifié par l'éditeur, une
exécution de code arbitraire à distance et un déni de service à
distance.
Official advisory ↗CERT-FR · French · CERTFR-2023-AVI-0214Multiples vulnérabilités dans les produits IBMre à distance et une atteinte à
la confidentialité des données.
Solution
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des
correctifs (cf. section Documentation).
Documentation
Bulletin de sécurité IBM 6828527 du 10 mars 2023
https://www.ibm.com/support/pages/node/6828527
Bulletin de sécurité IBM 6962773 du 10 mars 2023
https://www.ibm.com/support/pages/node/6962773
Bulletin de sécurité IBM 6962775 du 10 mars 2023
https://www.ibm.com/support/pages/node/6962775
Référence CVE CVE-2020-4051
https://www.cve.org/CVERecord?id=CVE-2020-4051
Référence CVE CVE-2021-29425
https://www.cve.org/CVERecord?id=CVE-2021-29425
Référence CVE CVE-2021-3711
https://www.cve.org/CVERecord?id=CVE-2021-3711
Référence CVE CVE-2021-3712
https://www.cve.org/CVERecord?id=CVE-2021-3712
Référence CVE CVE-2021-3733
https://www.cve.org/CVERecord?id=CVE-2021-3733
Référence CVE CVE-2021-3737
https://www.cve.org/CVERecord?id=CVE-2021-3737
Référence CVE CVE-2021-4160
https://www.cve.org/CVERecord?id=CVE-2021-4160
Référence CVE CVE-2021-43138
https://www.cve.org/CVERecord?id=CVE-2021-43138
Référence CVE CVE-2022-0391
https://www.cve.org/CVERecord?id=CVE-2022-0391
Référence CVE CVE-2022-24758
https://www.cve.org/CVERecord?id=CVE-2022-24758
Référence CVE CVE-2022-25881
https://www.cve.org/CVERecord?id=CVE-2022-25
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-928Multiples vulnérabilités dans les produits IBMord?id=CVE-2021-22960
Référence CVE CVE-2021-23337
https://www.cve.org/CVERecord?id=CVE-2021-23337
Référence CVE CVE-2021-23450
https://www.cve.org/CVERecord?id=CVE-2021-23450
Référence CVE CVE-2021-29425
https://www.cve.org/CVERecord?id=CVE-2021-29425
Référence CVE CVE-2021-3177
https://www.cve.org/CVERecord?id=CVE-2021-3177
Référence CVE CVE-2021-32803
https://www.cve.org/CVERecord?id=CVE-2021-32803
Référence CVE CVE-2021-32804
https://www.cve.org/CVERecord?id=CVE-2021-32804
Référence CVE CVE-2021-33502
https://www.cve.org/CVERecord?id=CVE-2021-33502
Référence CVE CVE-2021-34538
https://www.cve.org/CVERecord?id=CVE-2021-34538
Référence CVE CVE-2021-3711
https://www.cve.org/CVERecord?id=CVE-2021-3711
Référence CVE CVE-2021-3712
https://www.cve.org/CVERecord?id=CVE-2021-3712
Référence CVE CVE-2021-3733
https://www.cve.org/CVERecord?id=CVE-2021-3733
Référence CVE CVE-2021-3737
https://www.cve.org/CVERecord?id=CVE-2021-3737
Référence CVE CVE-2021-3765
https://www.cve.org/CVERecord?id=CVE-2021-3765
Référence CVE CVE-2021-37701
https://www.cve.org/CVERecord?id=CVE-2021-37701
Référence CVE CVE-2021-37712
https://www.cve.org/CVERecord?id=CVE-2021-37712
Référence CVE CVE-2021-37713
https://www.cve.org/CVERecord?id=CVE-2021-37713
Référence CVE CVE-2021-3807
https://www.cve.org/CVERecord?id=CVE-2021-3
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-916Multiples vulnérabilités dans les produits JuniperCVERecord?id=CVE-2021-35567
Référence CVE CVE-2021-35578
https://www.cve.org/CVERecord?id=CVE-2021-35578
Référence CVE CVE-2021-35586
https://www.cve.org/CVERecord?id=CVE-2021-35586
Référence CVE CVE-2021-35588
https://www.cve.org/CVERecord?id=CVE-2021-35588
Référence CVE CVE-2021-35603
https://www.cve.org/CVERecord?id=CVE-2021-35603
Référence CVE CVE-2021-3564
https://www.cve.org/CVERecord?id=CVE-2021-3564
Référence CVE CVE-2021-3573
https://www.cve.org/CVERecord?id=CVE-2021-3573
Référence CVE CVE-2021-3653
https://www.cve.org/CVERecord?id=CVE-2021-3653
Référence CVE CVE-2021-3656
https://www.cve.org/CVERecord?id=CVE-2021-3656
Référence CVE CVE-2021-3711
https://www.cve.org/CVERecord?id=CVE-2021-3711
Référence CVE CVE-2021-3712
https://www.cve.org/CVERecord?id=CVE-2021-3712
Référence CVE CVE-2021-3715
https://www.cve.org/CVERecord?id=CVE-2021-3715
Référence CVE CVE-2021-3752
https://www.cve.org/CVERecord?id=CVE-2021-3752
Référence CVE CVE-2021-37576
https://www.cve.org/CVERecord?id=CVE-2021-37576
Référence CVE CVE-2021-3765
https://www.cve.org/CVERecord?id=CVE-2021-3765
Référence CVE CVE-2021-37750
https://www.cve.org/CVERecord?id=CVE-2021-37750
Référence CVE CVE-2021-4034
https://www.cve.org/CVERecord?id=CVE-2021-4034
Référence CVE CVE-2021-4155
https://www.cve.org/CVERecord?id=CVE-2021-415
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-429Multiples vulnérabilités dans Nessus Network MonitorDe multiples vulnérabilités ont été découvertes dans Nessus Network
Monitor. Certaines d'entre elles permettent à un attaquant de provoquer
une exécution de code arbitraire à distance, un déni de service à
distance et une atteinte à l'intégrité des données.
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-216Multiples vulnérabilités dans les produits SiemensERecord?id=CVE-2021-32940
Référence CVE CVE-2021-32944
https://www.cve.org/CVERecord?id=CVE-2021-32944
Référence CVE CVE-2021-32946
https://www.cve.org/CVERecord?id=CVE-2021-32946
Référence CVE CVE-2021-32948
https://www.cve.org/CVERecord?id=CVE-2021-32948
Référence CVE CVE-2021-32950
https://www.cve.org/CVERecord?id=CVE-2021-32950
Référence CVE CVE-2021-32952
https://www.cve.org/CVERecord?id=CVE-2021-32952
Référence CVE CVE-2021-3449
https://www.cve.org/CVERecord?id=CVE-2021-3449
Référence CVE CVE-2021-3450
https://www.cve.org/CVERecord?id=CVE-2021-3450
Référence CVE CVE-2021-3672
https://www.cve.org/CVERecord?id=CVE-2021-3672
Référence CVE CVE-2021-3711
https://www.cve.org/CVERecord?id=CVE-2021-3711
Référence CVE CVE-2021-3712
https://www.cve.org/CVERecord?id=CVE-2021-3712
Référence CVE CVE-2021-37208
https://www.cve.org/CVERecord?id=CVE-2021-37208
Référence CVE CVE-2021-37209
https://www.cve.org/CVERecord?id=CVE-2021-37209
Référence CVE CVE-2021-37701
https://www.cve.org/CVERecord?id=CVE-2021-37701
Référence CVE CVE-2021-37712
https://www.cve.org/CVERecord?id=CVE-2021-37712
Référence CVE CVE-2021-37713
https://www.cve.org/CVERecord?id=CVE-2021-37713
Référence CVE CVE-2021-39134
https://www.cve.org/CVERecord?id=CVE-2021-39134
Référence CVE CVE-2021-39135
https://www.cve.org/CVERecord?id=CVE
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-006Multiples vulnérabilités dans les produits TenableDe multiples vulnérabilités ont été découvertes dans les produits
Tenable. Elles permettent à un attaquant de provoquer une atteinte à
l'intégrité des données et une atteinte à la confidentialité des
données.
Official advisory ↗CERT-FR · French · CERTFR-2021-AVI-943Multiples vulnérabilités dans les produits IBMd?id=CVE-2021-33502
Référence CVE CVE-2021-33909
https://www.cve.org/CVERecord?id=CVE-2021-33909
Référence CVE CVE-2021-34558
https://www.cve.org/CVERecord?id=CVE-2021-34558
Référence CVE CVE-2021-35065
https://www.cve.org/CVERecord?id=CVE-2021-35065
Référence CVE CVE-2021-35515
https://www.cve.org/CVERecord?id=CVE-2021-35515
Référence CVE CVE-2021-35516
https://www.cve.org/CVERecord?id=CVE-2021-35516
Référence CVE CVE-2021-35517
https://www.cve.org/CVERecord?id=CVE-2021-35517
Référence CVE CVE-2021-36090
https://www.cve.org/CVERecord?id=CVE-2021-36090
Référence CVE CVE-2021-36221
https://www.cve.org/CVERecord?id=CVE-2021-36221
Référence CVE CVE-2021-3711
https://www.cve.org/CVERecord?id=CVE-2021-3711
Référence CVE CVE-2021-3712
https://www.cve.org/CVERecord?id=CVE-2021-3712
Référence CVE CVE-2021-3715
https://www.cve.org/CVERecord?id=CVE-2021-3715
Référence CVE CVE-2021-37712
https://www.cve.org/CVERecord?id=CVE-2021-37712
Référence CVE CVE-2021-37713
https://www.cve.org/CVERecord?id=CVE-2021-37713
Référence CVE CVE-2021-38947
https://www.cve.org/CVERecord?id=CVE-2021-38947
Référence CVE CVE-2021-39052
https://www.cve.org/CVERecord?id=CVE-2021-39052
Référence CVE CVE-2021-39053
https://www.cve.org/CVERecord?id=CVE-2021-39053
Référence CVE CVE-2021-39054
https://www.cve.org/CVERecord?id=CVE-2
Official advisory ↗CERT-FR · French · CERTFR-2021-AVI-863Multiples vulnérabilités dans les produits Microsoftsual Studio Code
Résumé
De multiples vulnérabilités ont été corrigées dans les produits Microsoft . Elles permettent à un
attaquant de provoquer une usurpation d'identité, une atteinte à la
confidentialité des données, une exécution de code à distance, une
élévation de privilèges et un contournement de la fonctionnalité de
sécurité.
Solution
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des
correctifs (cf. section Documentation).
Documentation
Bulletin de sécurité Microsoft du 09 novembre 2021
https://msrc.microsoft.com/update-guide/
Référence CVE CVE-2021-26444
https://www.cve.org/CVERecord?id=CVE-2021-26444
Référence CVE CVE-2021-3711
https://www.cve.org/CVERecord?id=CVE-2021-3711
Référence CVE CVE-2021-40442
https://www.cve.org/CVERecord?id=CVE-2021-40442
Référence CVE CVE-2021-41349
https://www.cve.org/CVERecord?id=CVE-2021-41349
Référence CVE CVE-2021-41368
https://www.cve.org/CVERecord?id=CVE-2021-41368
Référence CVE CVE-2021-41372
https://www.cve.org/CVERecord?id=CVE-2021-41372
Référence CVE CVE-2021-41373
https://www.cve.org/CVERecord?id=CVE-2021-41373
Référence CVE CVE-2021-41374
https://www.cve.org/CVERecord?id=CVE-2021-41374
Référence CVE CVE-2021-41375
https://www.cve.org/CVERecord?id=CVE-2021-41375
Référence CVE CVE-2021-41376
https://www.cve.org/CVERecord?id=C
Official advisory ↗CERT-FR · French · CERTFR-2021-AVI-801Multiples vulnérabilités dans Oracle MySQLd?id=CVE-2021-35641
Référence CVE CVE-2021-35642
https://www.cve.org/CVERecord?id=CVE-2021-35642
Référence CVE CVE-2021-35643
https://www.cve.org/CVERecord?id=CVE-2021-35643
Référence CVE CVE-2021-35644
https://www.cve.org/CVERecord?id=CVE-2021-35644
Référence CVE CVE-2021-35645
https://www.cve.org/CVERecord?id=CVE-2021-35645
Référence CVE CVE-2021-35646
https://www.cve.org/CVERecord?id=CVE-2021-35646
Référence CVE CVE-2021-35647
https://www.cve.org/CVERecord?id=CVE-2021-35647
Référence CVE CVE-2021-35648
https://www.cve.org/CVERecord?id=CVE-2021-35648
Référence CVE CVE-2021-36222
https://www.cve.org/CVERecord?id=CVE-2021-36222
Référence CVE CVE-2021-3711
https://www.cve.org/CVERecord?id=CVE-2021-3711
Référence CVE CVE-2021-3712
https://www.cve.org/CVERecord?id=CVE-2021-3712
Gestion détaillée du document
le 20 octobre 2021
Version initiale
Alertes
Avis
Bulletins d’actualités
Mentions légales
Conditions générales
À propos
Contact
cyber.gouv.fr
service-public.fr
legifrance.gouv.fr
info.gouv.fr
france.fr
info.gouv.fr/risques
Premier Ministre / Secrétariat Général de la Défense et de la Sécurité Nationale / Agence nationale de la
sécurité des systèmes d'information
Official advisory ↗CERT-FR · French · CERTFR-2021-AVI-760Vulnérabilité dans Stormshield Network SecurityUne vulnérabilité a été découverte dans Stormshield Network Security.
Elle permet à un attaquant de provoquer un déni de service à distance et
une atteinte à la confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2021-AVI-747Multiples vulnérabilités dans les produits SynologyDe multiples vulnérabilités ont été découvertes dans les produits
Synology. Elles permettent à un attaquant de provoquer une exécution de
code arbitraire à distance et un déni de service à distance.
A la date de rédaction de l'avis, les vulnérabilités affectant le
produit DiskStation Manager ne disposent pas encore d'un identifiant
CVE.
Official advisory ↗CERT-FR · French · CERTFR-2021-AVI-729Multiples vulnérabilités dans TenableDe multiples vulnérabilités ont été découvertes dans Tenable. Elles
permettent à un attaquant de provoquer un problème de sécurité non
spécifié par l'éditeur.
Official advisory ↗CERT-FR · French · CERTFR-2021-AVI-656Multiples vulnérabilités dans OpenSSLDe multiples vulnérabilités ont été découvertes dans OpenSSL. Elles
permettent à un attaquant de provoquer un déni de service à distance, un
contournement de la politique de sécurité et une atteinte à la
confidentialité des données.
Official advisory ↗JVN iPedia · Japanese · JVNDB-2021-002326OpenSSL に複数の脆弱性OpenSSL Project より、 OpenSSL Security Advisory [24 August 2021] が公開されました。 OpenSSL には、次の脆弱性が存在します。 深刻度 - 高(Severity: High) * SM2 暗号データの復号処理におけるバッファオーバーフロー (CWE-120)- CVE-2021-3711 * SM2 暗号データの復号処理を行うアプリケーションは、EVP_PKEY_decrypt() 関数を通常 2 回呼び出すが、1 回目の呼び出しで計算されるバッファサイズが 2 回目の呼び出しで必要なサイズより小さくなるような SM2 データがアプリケーションに渡された場合、バッファオーバーフローが発生する可能性がある 深刻度 - 中(Severity: Moderate) * ASN.1 文字列処理におけるバッファエラー (CWE-119)- CVE-2021-3712 * OpenSSL において、ASN.1 形式の文字列は ASN1_STRING 構造で表され、その構造では NULL 終端が必須とはされていない。しかし、OpenSSL 内には NULL 終端を前提として処理を行う関数が複数存在するため、アプリケーション内で直接生成されるなどした NULL 終端を持たない ASN1_STRING 構造文字列を処理させられた場合、バッファエラーが発生する可能性がある
Official advisory ↗KISA KrCERT/CC · Korean · KNVD-5524MS 3월 보안 위협에 따른 정기 보안 업데이트 권고지점 간 터널링 프로토콜 서비스 거부 취약성
Microsoft Windows Codecs Library
CVE-2022-22010
미디어 파운데이션 정보 유출 취약성
Microsoft Windows Codecs Library
CVE-2022-22007
HEVC 비디오 확장 원격 코드 실행 취약성
Microsoft Windows Codecs Library
CVE-2022-22006
HEVC 비디오 확장 원격 코드 실행 취약성
Windows Remote Desktop
CVE-2022-21990
원격 데스크톱 클라이언트 원격 코드 실행 취약성
Microsoft Windows Codecs Library
CVE-2022-21977
미디어 파운데이션 정보 유출 취약성
Role: Windows Hyper-V
CVE-2022-21975
Windows Hyper-V 서비스 거부 취약성
Windows Media
CVE-2022-21973
Windows Media Center 업데이트 서비스 거부 취약성
XBox
CVE-2022-21967
Windows용 Xbox Live 인증 관리자 권한 상승 취약성
Microsoft Dynamics
CVE-2022-21957
Microsoft Dynamics 365(온-프레미스) 원격 코드 실행 취약성
Visual Studio
CVE-2021-3711
OpenSSL: CVE-2021-3711 SM2 Decryption Buffer Overflow
Windows Media
CVE-2021-36927
Windows 디지털 TV 튜너 장치 등록 응용 프로그램 권한 상승 취약성
.NET and Visual Studio
CVE-2020-8927
Brotli 라이브러리 버퍼 오버플로 취약성
Servicing Stack Updates
ADV990001
최신 서비스 스택 업데이트
##### □ 작성 : 침해사고분석단 취약점분석팀
Official advisory ↗KISA KrCERT/CC · Korean · KNVD-5435MS 11월 보안 위협에 따른 정기 보안 업데이트 권고rosoft Office Excel
CVE-2021-42292
Microsoft Excel 보안 기능 우회 취약성
Microsoft Office Excel
CVE-2021-40442
Microsoft Excel 원격 코드 실행 취약성
Microsoft Office Word
CVE-2021-42296
Microsoft Word 원격 코드 실행 취약성
Microsoft Windows
CVE-2021-41356
Windows 암호화 서비스 거부 취약성
Microsoft Windows Codecs Library
CVE-2021-42276
Windows 미디어 파운데이션 원격 코드 실행 취약성
Power BI
CVE-2021-41372
Power BI Report Server Spoofing Vulnerability
Role: Windows Hyper-V
CVE-2021-42284
Windows Hyper-V 서비스 거부 취약성
Role: Windows Hyper-V
CVE-2021-42274
Windows Hyper-V Discrete Device Assignment (DDA) Denial of Service Vulnerability
Visual Studio
CVE-2021-42319
Visual Studio 권한 상승 취약성
Visual Studio
CVE-2021-3711
OpenSSL: CVE-2021-3711 SM2 Decryption Buffer Overflow
Visual Studio Code
CVE-2021-42322
Visual Studio Code 권한 상승 취약성
Windows Active Directory
CVE-2021-42291
Active Directory Domain Services Elevation of Privilege Vulnerability
Windows Active Directory
CVE-2021-42287
Active Directory Domain Services Elevation of Privilege Vulnerability
Windows Active Directory
CVE-2021-42282
Active Directory Domain Services Elevation of Privilege Vulnerability
Windows Active Directory
CVE-2021-42278
Active Directory Domain Services Elevation of Privilege Vulnerability
Windows COM
CVE-2021-42275
Windows용 Microsoft COM 원격 코드 실행 취약성
Windows Core Shell
CVE-2021-4
Official advisory ↗KISA KrCERT/CC · Korean · KNVD-5361OpenSSL 취약점 보안 업데이트 권고#### OpenSSL 취약점 보안 업데이트 권고 2021.08.25
##### □ 개요
o OpenSSL에서 발생하는 취약점을 해결한 보안 업데이트 발표
o 낮은 버전 사용자는 서비스 거부 공격에 취약하므로, 최신 버전으로 업데이트 권고
##### □ 설명 [1]
o OpenSSL에서 버퍼오버플로우로 인해 발생하는 서비스거부 취약점(CVE-2021-3711)
o OpenSSL에서 발생하는 정보노출 및 서비스거부 취약점(CVE-2021-3712)
##### □ 영향받는 버전
o OpenSSL 1.1.1k 및 이전 버전
##### □ 해결 방안
o 취약점이 해결된 버전(OpenSSL 1.1.1l 이상)으로 업데이트 적용
##### □ 기타 문의사항
o 한국인터넷진흥원 사이버민원센터: 국번없이 118
[참고사이트]
[1]
https://www.openssl.org/news/secadv/20210824.txt
##### □ 작성 : 침해사고분석단 취약점분석팀
Official advisory ↗