ENISA EUVD · EUVD-2021-28630Official EUVD mappingsshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of the sshd process, if the configuration specifies running the command as a different user.
Official EUVD record ↗BSI · German · WID-SEC-2024-1082Juniper JUNOS: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Juniper JUNOS im Zusammenhang mit OpenSSH ausnutzen, um Sicherheitsmaßnahmen zu umgehen, beliebigen Code auszuführen oder Dateien zu manipulieren.
Official advisory ↗BSI · German · WID-SEC-2023-1969HPE Fabric OS: Mehrere Schwachstellen ermöglichen PrivilegieneskalationEin entfernter, anonymer Angreifer kann mehrere Schwachstellen in HPE Fabric OS für HPE Fibre Channel und SAN Switches ausnutzen, um seine Privilegien zu erhöhen, Informationen offenzulegen oder einen Denial of Service Zustand herbeizuführen.
Official advisory ↗BSI · German · WID-SEC-2022-0676Juniper Junos Space: Mehrere SchwachstellenEin entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Juniper Junos Space ausnutzen, um einen Denial-of-Service-Zustand herbeizuführen, vertrauliche Informationen offenzulegen, Daten zu manipulieren oder zu verändern, seine Privilegien zu erweitern und Sicherheitsmaßnahmen zu umgehen.
Official advisory ↗BSI · German · WID-SEC-2023-0426IBM Spectrum Protect: Mehrere SchwachstellenEin entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in IBM Spectrum Protect ausnutzen, um einen 'Denial of Service'-Zustand herbeizuführen, Sicherheitsmaßnahmen zu umgehen, einen 'Cross-Site-Scripting'-Angriff durchzuführen, beliebigen Code auszuführen, sensible Informationen offenzulegen und seine Privilegien zu erweitern.
Official advisory ↗BSI · German · WID-SEC-2022-0534OpenSSH: Schwachstelle ermöglicht PrivilegieneskalationEin lokaler Angreifer kann eine Schwachstelle in OpenSSH ausnutzen, um seine Privilegien zu erhöhen.
Official advisory ↗Cyber Security Agency of Singapore · English · CSA-SB-20210929Security Bulletin 29 Sep 2021The Cyber Security Agency of Singapore included this CVE in its official Security Bulletin 29 Sep 2021, published on 29 September 2021. Open the linked bulletin for the product, severity and reference information published in that issue.
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0880Multiples vulnérabilités dans les produits SiemensSA-019113 du 14 juillet 2026
Bulletin de sécurité Siemens SSA-734552 du 14 juillet 2026
Bulletin de sécurité Siemens SSA-828211 du 14 juillet 2026
Une gestion de version détaillée se trouve à la fin de ce document.
Risques
Atteinte à la confidentialité des données
Contournement de la politique de sécurité
Déni de service à distance
Exécution de code arbitraire à distance
Non spécifié par l'éditeur
Élévation de privilèges
Systèmes affectés
Desigo CC toutes versions
Desigo CC toutes versions pour la vulnérabilité CVE-2025-15467
Desigo CC versions antérieures à 9.0.1
SIMATIC S7-1500 versions supérieures ou égales à 3.1.6 pour les vulnérabilités CVE-2021-41617, CVE-2023-28531, CVE-2023-51384, CVE-2023-52927, CVE-2024-26783, CVE-2024-27056, CVE-2024-28956, CVE-2024-36903, CVE-2024-36927, CVE-2024-42079, CVE-2024-46786, CVE-2024-47736, CVE-2024-47809, CVE-2024-49968, CVE-2024-49994, CVE-2024-49998, CVE-2024-50014, CVE-2024-50063, CVE-2024-50164, CVE-2024-50298, CVE-2024-53124, CVE-2024-53170, CVE-2024-54458, CVE-2024-56631, CVE-2024-56703, CVE-2024-56719, CVE-2024-57917, CVE-2024-57924, CVE-2024-57973, CVE-2024-57977, CVE-2024-57979, CVE-2024-58011, CVE-2024-58016, CVE-2024-58020, CVE-2024-58056, CVE-2024-58058, CVE-2024-58061, CVE-2024-58086, CVE-2025-21645, CVE-2025-21648, CVE-2025-21655, CVE-2025
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0492Multiples vulnérabilités dans les produits SiemensAR3) versions antérieures à V3.2
SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3) versions antérieures à V3.1
SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3) versions antérieures à V3.2
SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3) versions antérieures à V3.1
SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3) versions antérieures à V3.2
SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3) versions antérieures à V3.1
SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3) versions antérieures à V3.2
SIMATIC S7-1500 versions supérieures ou égales àV3.1.5 pour les vulnérabilités CVE-2021-41617, CVE-2023-4527, CVE-2023-4806, CVE-2023-4911, CVE-2023-5363, CVE-2023-6246, CVE-2023-6779, CVE-2023-6780, CVE-2023-28531, CVE-2023-38545, CVE-2023-38546, CVE-2023-44487, CVE-2023-46218, CVE-2023-46219, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2023-52927, CVE-2024-2961, CVE-2024-6119, CVE-2024-6387, CVE-2024-12133, CVE-2024-12243, CVE-2024-24855, CVE-2024-26596, CVE-2024-28085, CVE-2024-33599, CVE-2024-33600, CVE-2024-33601, CVE-2024-33602, CVE-2024-34397, CVE-2024-37370, CVE-2024-37371, CVE-2024-45490, CVE-2024-45491, CVE-2024-45492, CVE-2024-50246, CVE-2024-53166, CVE-2024-57977, CVE-2024-57996, CVE-2024-58005, CVE-2025-4373, CVE
Official advisory ↗CERT-FR · French · CERTFR-2024-AVI-1018Multiples vulnérabilités dans les produits Qnapadvisory/qsa-24-39
Bulletin de sécurité Qnap QSA-24-40 du 23 novembre 2024
https://www.qnap.com/go/security-advisory/qsa-24-40
Bulletin de sécurité Qnap QSA-24-43 du 23 novembre 2024
https://www.qnap.com/go/security-advisory/qsa-24-43
Bulletin de sécurité Qnap QSA-24-44 du 23 novembre 2024
https://www.qnap.com/go/security-advisory/qsa-24-44
Bulletin de sécurité Qnap QSA-24-46 du 23 novembre 2024
https://www.qnap.com/go/security-advisory/qsa-24-46
Bulletin de sécurité Qnap QSA-24-47 du 23 novembre 2024
https://www.qnap.com/go/security-advisory/qsa-24-47
Référence CVE CVE-2020-14145
https://www.cve.org/CVERecord?id=CVE-2020-14145
Référence CVE CVE-2021-41617
https://www.cve.org/CVERecord?id=CVE-2021-41617
Référence CVE CVE-2023-38408
https://www.cve.org/CVERecord?id=CVE-2023-38408
Référence CVE CVE-2024-32767
https://www.cve.org/CVERecord?id=CVE-2024-32767
Référence CVE CVE-2024-32768
https://www.cve.org/CVERecord?id=CVE-2024-32768
Référence CVE CVE-2024-32769
https://www.cve.org/CVERecord?id=CVE-2024-32769
Référence CVE CVE-2024-32770
https://www.cve.org/CVERecord?id=CVE-2024-32770
Référence CVE CVE-2024-37041
https://www.cve.org/CVERecord?id=CVE-2024-37041
Référence CVE CVE-2024-37042
https://www.cve.org/CVERecord?id=CVE-2024-37042
Référence CVE CVE-2024-37043
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2024-AVI-0585Multiples vulnérabilités dans les produits VMwaretent-notification/-/external/content/SecurityAdvisories/0/24676
Bulletin de sécurité VMware 24679 du 15 juillet 2024
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24679
Bulletin de sécurité VMware 24680 du 15 juillet 2024
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24680
Bulletin de sécurité VMware 24681 du 15 juillet 2024
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24681
Référence CVE CVE-2020-28493
https://www.cve.org/CVERecord?id=CVE-2020-28493
Référence CVE CVE-2021-41617
https://www.cve.org/CVERecord?id=CVE-2021-41617
Référence CVE CVE-2022-1725
https://www.cve.org/CVERecord?id=CVE-2022-1725
Référence CVE CVE-2022-1771
https://www.cve.org/CVERecord?id=CVE-2022-1771
Référence CVE CVE-2022-1886
https://www.cve.org/CVERecord?id=CVE-2022-1886
Référence CVE CVE-2022-1897
https://www.cve.org/CVERecord?id=CVE-2022-1897
Référence CVE CVE-2022-2000
https://www.cve.org/CVERecord?id=CVE-2022-2000
Référence CVE CVE-2022-2042
https://www.cve.org/CVERecord?id=CVE-2022-2042
Référence CVE CVE-2022-46908
https://www.cve.org/CVERecord?id=CVE-2022-46908
Référence CVE CVE-2022-48624
https://www.cve.org/CVERecord?id=CVE-2022-486
Official advisory ↗CERT-FR · French · CERTFR-2024-AVI-0378Multiples vulnérabilités dans Juniper Junos OSDe multiples vulnérabilités ont été découvertes dans Juniper Junos OS.
Certaines d'entre elles permettent à un attaquant de provoquer un
problème de sécurité non spécifié par l'éditeur, une exécution de code
arbitraire à distance et un déni de service à distance.
Official advisory ↗CERT-FR · French · CERTFR-2023-AVI-1015Multiples vulnérabilités dans les produits Siemensrg/CVERecord?id=CVE-2021-3737
Référence CVE CVE-2021-37600
https://www.cve.org/CVERecord?id=CVE-2021-37600
Référence CVE CVE-2021-37750
https://www.cve.org/CVERecord?id=CVE-2021-37750
Référence CVE CVE-2021-3826
https://www.cve.org/CVERecord?id=CVE-2021-3826
Référence CVE CVE-2021-38604
https://www.cve.org/CVERecord?id=CVE-2021-38604
Référence CVE CVE-2021-3997
https://www.cve.org/CVERecord?id=CVE-2021-3997
Référence CVE CVE-2021-3998
https://www.cve.org/CVERecord?id=CVE-2021-3998
Référence CVE CVE-2021-3999
https://www.cve.org/CVERecord?id=CVE-2021-3999
Référence CVE CVE-2021-4122
https://www.cve.org/CVERecord?id=CVE-2021-4122
Référence CVE CVE-2021-41617
https://www.cve.org/CVERecord?id=CVE-2021-41617
Référence CVE CVE-2021-4189
https://www.cve.org/CVERecord?id=CVE-2021-4189
Référence CVE CVE-2021-4209
https://www.cve.org/CVERecord?id=CVE-2021-4209
Référence CVE CVE-2021-43396
https://www.cve.org/CVERecord?id=CVE-2021-43396
Référence CVE CVE-2021-43618
https://www.cve.org/CVERecord?id=CVE-2021-43618
Référence CVE CVE-2021-45960
https://www.cve.org/CVERecord?id=CVE-2021-45960
Référence CVE CVE-2021-46143
https://www.cve.org/CVERecord?id=CVE-2021-46143
Référence CVE CVE-2021-46195
https://www.cve.org/CVERecord?id=CVE-2021-46195
Référence CVE CVE-2021-46828
https://www.cve.org/CVERecord?id=CVE-
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-916Multiples vulnérabilités dans les produits Juniper.org/CVERecord?id=CVE-2021-3712
Référence CVE CVE-2021-3715
https://www.cve.org/CVERecord?id=CVE-2021-3715
Référence CVE CVE-2021-3752
https://www.cve.org/CVERecord?id=CVE-2021-3752
Référence CVE CVE-2021-37576
https://www.cve.org/CVERecord?id=CVE-2021-37576
Référence CVE CVE-2021-3765
https://www.cve.org/CVERecord?id=CVE-2021-3765
Référence CVE CVE-2021-37750
https://www.cve.org/CVERecord?id=CVE-2021-37750
Référence CVE CVE-2021-4034
https://www.cve.org/CVERecord?id=CVE-2021-4034
Référence CVE CVE-2021-4155
https://www.cve.org/CVERecord?id=CVE-2021-4155
Référence CVE CVE-2021-4160
https://www.cve.org/CVERecord?id=CVE-2021-4160
Référence CVE CVE-2021-41617
https://www.cve.org/CVERecord?id=CVE-2021-41617
Référence CVE CVE-2021-42550
https://www.cve.org/CVERecord?id=CVE-2021-42550
Référence CVE CVE-2021-42574
https://www.cve.org/CVERecord?id=CVE-2021-42574
Référence CVE CVE-2021-42771
https://www.cve.org/CVERecord?id=CVE-2021-42771
Référence CVE CVE-2021-43527
https://www.cve.org/CVERecord?id=CVE-2021-43527
Référence CVE CVE-2021-45417
https://www.cve.org/CVERecord?id=CVE-2021-45417
Référence CVE CVE-2021-45960
https://www.cve.org/CVERecord?id=CVE-2021-45960
Référence CVE CVE-2021-46143
https://www.cve.org/CVERecord?id=CVE-2021-46143
Référence CVE CVE-2022-0330
https://www.cve.org/CVERecord?id=C
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-650Multiples vulnérabilités dans les produits Juniperord?id=CVE-2021-35565
Référence CVE CVE-2021-35567
https://www.cve.org/CVERecord?id=CVE-2021-35567
Référence CVE CVE-2021-35578
https://www.cve.org/CVERecord?id=CVE-2021-35578
Référence CVE CVE-2021-35586
https://www.cve.org/CVERecord?id=CVE-2021-35586
Référence CVE CVE-2021-35588
https://www.cve.org/CVERecord?id=CVE-2021-35588
Référence CVE CVE-2021-35603
https://www.cve.org/CVERecord?id=CVE-2021-35603
Référence CVE CVE-2021-36690
https://www.cve.org/CVERecord?id=CVE-2021-36690
Référence CVE CVE-2021-3712
https://www.cve.org/CVERecord?id=CVE-2021-3712
Référence CVE CVE-2021-37750
https://www.cve.org/CVERecord?id=CVE-2021-37750
Référence CVE CVE-2021-41617
https://www.cve.org/CVERecord?id=CVE-2021-41617
Référence CVE CVE-2021-42574
https://www.cve.org/CVERecord?id=CVE-2021-42574
Référence CVE CVE-2021-42739
https://www.cve.org/CVERecord?id=CVE-2021-42739
Référence CVE CVE-2022-21245
https://www.cve.org/CVERecord?id=CVE-2022-21245
Référence CVE CVE-2022-21270
https://www.cve.org/CVERecord?id=CVE-2022-21270
Référence CVE CVE-2022-21303
https://www.cve.org/CVERecord?id=CVE-2022-21303
Référence CVE CVE-2022-21304
https://www.cve.org/CVERecord?id=CVE-2022-21304
Référence CVE CVE-2022-21344
https://www.cve.org/CVERecord?id=CVE-2022-21344
Référence CVE CVE-2022-21367
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-619Multiples vulnérabilités dans IBM QRadarDe multiples vulnérabilités ont été découvertes dans IBM QRadar.
Certaines d'entre elles permettent à un attaquant de provoquer un déni
de service à distance, une atteinte à l'intégrité des données et une
atteinte à la confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-239Multiples vulnérabilités dans les produits IBMcord?id=CVE-2021-3712
Référence CVE CVE-2021-38926
https://www.cve.org/CVERecord?id=CVE-2021-38926
Référence CVE CVE-2021-38931
https://www.cve.org/CVERecord?id=CVE-2021-38931
Référence CVE CVE-2021-38951
https://www.cve.org/CVERecord?id=CVE-2021-38951
Référence CVE CVE-2021-39002
https://www.cve.org/CVERecord?id=CVE-2021-39002
Référence CVE CVE-2021-4034
https://www.cve.org/CVERecord?id=CVE-2021-4034
Référence CVE CVE-2021-41182
https://www.cve.org/CVERecord?id=CVE-2021-41182
Référence CVE CVE-2021-41183
https://www.cve.org/CVERecord?id=CVE-2021-41183
Référence CVE CVE-2021-41184
https://www.cve.org/CVERecord?id=CVE-2021-41184
Référence CVE CVE-2021-41617
https://www.cve.org/CVERecord?id=CVE-2021-41617
Référence CVE CVE-2021-44716
https://www.cve.org/CVERecord?id=CVE-2021-44716
Référence CVE CVE-2021-44717
https://www.cve.org/CVERecord?id=CVE-2021-44717
Référence CVE CVE-2022-0235
https://www.cve.org/CVERecord?id=CVE-2022-0235
Référence CVE CVE-2022-0391
https://www.cve.org/CVERecord?id=CVE-2022-0391
Référence CVE CVE-2022-21680
https://www.cve.org/CVERecord?id=CVE-2022-21680
Référence CVE CVE-2022-21681
https://www.cve.org/CVERecord?id=CVE-2022-21681
Référence CVE CVE-2022-23772
https://www.cve.org/CVERecord?id=CVE-2022-23772
Référence CVE CVE-2022-23773
https://www.cve.org/CVERecord?id=CVE-
Official advisory ↗JVN iPedia · Japanese · JVNDB-2021-012423OpenSSH における脆弱性OpenSSH には、不特定の脆弱性が存在します。
Official advisory ↗NCSC-NL · Dutch · NCSC-2025-0187Kwetsbaarheden verholpen in Siemens productenDe kwetsbaarheden stellen een kwaadwillende mogelijk in staat aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade:
- Denial-of-Service (DoS)
- Manipulatie van gegevens
- Omzeilen van een beveiligingsmaatregel
- Omzeilen van authenticatie
- (Remote) code execution (root/admin rechten)
- (Remote) code execution (Gebruikersrechten)
- Toegang tot systeemgegevens
- Toegang tot gevoelige gegevens
- Spoofing
De kwaadwillende heeft hiervoor toegang nodig tot de productieomgeving. Het is goed gebruik een dergelijke omgeving niet publiek toegankelijk te hebben.
Official advisory ↗