BlackTreeIndependent security intelligence
← Back to the CVE catalogue
Full vulnerability report · 2023
CVE-2023-1380High confidence

This issue could occur when assoc_info->req_len data is bigger than the size of the buffer, defined as WL_EXTRA_BUF_MAX, leading to a denial of service

n/a · Kernel

7.1HighCVSS 3.1
Recommended action
Within 7 days

High technical severity; prioritise exposed affected systems while verifying vendor guidance.

Patch available
Distribution package intelligence

Ubuntu vendor package status

Canonical’s release and source-package findings are shown separately from local repository availability.

1 package state
Repository candidate not checked

A published vendor fix does not prove that a matching update is enabled and installable on a particular asset. Confirm the local package candidate before scheduling remediation.

Ubuntu releaseSource packageVendor stateFixed versionEvidence
Ubuntu 24.04 LTSnoble · standard archivelinux-raspi-realtimeAffected, no fix publishedCanonical OVAL identifies this running kernel flavour as affected and does not publish a fixed package version in this definition.Not published in this feedCanonical record ↗Source updated 9 Sept 2026
Direct vendor intelligence

Authoritative vendor CSAF and VEX advisories

Structured product status and remediation from the issuing vendor. Product-state explanations are always visible; large lists can be searched or downloaded.

2 current
SSA-769027 · CSAF 2.0 · revision 1 · interimSiemens ProductCERTSSA-769027: Multiple Vulnerabilities fixed in SCALANCE W700 IEEE 802.11ax devices before V3.0.0
19 known affected

The vendor explicitly identifies these products as affected by this CVE.

  • SCALANCE WAB762-1 (6GK5762-1AJ00-6AA0)
  • SCALANCE WAM763-1 (6GK5763-1AL00-7DA0)
  • SCALANCE WAM763-1 (ME) (6GK5763-1AL00-7DC0)
  • SCALANCE WAM763-1 (US) (6GK5763-1AL00-7DB0)
  • SCALANCE WAM766-1 (6GK5766-1GE00-7DA0)
  • SCALANCE WAM766-1 (ME) (6GK5766-1GE00-7DC0)
  • SCALANCE WAM766-1 (US) (6GK5766-1GE00-7DB0)
  • SCALANCE WAM766-1 EEC (6GK5766-1GE00-7TA0)
  • SCALANCE WAM766-1 EEC (ME) (6GK5766-1GE00-7TC0)
  • SCALANCE WAM766-1 EEC (US) (6GK5766-1GE00-7TB0)
  • SCALANCE WUB762-1 (6GK5762-1AJ00-1AA0)
  • SCALANCE WUB762-1 iFeatures (6GK5762-1AJ00-2AA0)
Summary
A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux Kernel. This issue could occur when assoc_info->req_len data is bigger than the size of the buffer, defined as WL_EXTRA_BUF_MAX, leading to a denial of service.
Remediation
Update to V3.0.0 or later version
SSA-806742 · CSAF 2.0 · revision 1 · interimSiemens ProductCERTSSA-806742: Multiple Vulnerabilities in SCALANCE XCM-/XRM-300 before V2.4
11 known affected

The vendor explicitly identifies these products as affected by this CVE.

  • SCALANCE XCH328 (6GK5328-4TS01-2EC2)
  • SCALANCE XCM324 (6GK5324-8TS01-2AC2)
  • SCALANCE XCM328 (6GK5328-4TS01-2AC2)
  • SCALANCE XCM332 (6GK5332-0GA01-2AC2)
  • SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3)
  • SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3)
  • SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3)
  • SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3)
  • SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3)
  • SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3)
  • SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3)
Summary
A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux Kernel. This issue could occur when assoc_info->req_len data is bigger than the size of the buffer, defined as WL_EXTRA_BUF_MAX, leading to a denial of service.
Remediation
Update to V2.4 or later version
Optional official sources

National CERT insights
?CERT means Computer Emergency Response Team; CSIRT is the closely related term Computer Security Incident Response Team.

Select the national-authority views to include. The exact source language is shown on each matched advisory. Your choice is remembered on this device and encoded in the shareable URL.

Official European source

ENISA European Vulnerability Database

Official EUVD identifiers, advisory evidence and known-exploited context. Missing fields are not treated as evidence of low risk.

1 current
ENISA EUVD identifier

EUVD-2023-23636

No EUVD known-exploited evidence

ENISA has published the identifier mapping but no EUVD description has been stored yet.

EUVD state
Present in the current official mapping
Known exploitation
Not present in the current ENISA EUVD known-exploited dataset. This is not proof of no exploitation.
ENISA score
Not supplied in the stored EUVD record
Advisory evidence
No linked advisory details stored yet
Recommended actionWithin 7 days

High technical severity; prioritise exposed affected systems while verifying vendor guidance.

Patch available
01

What, why and how

A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux Kernel. This issue could occur when assoc_info->req_len data is bigger than the size of the buffer, defined as WL_EXTRA_BUF_MAX, leading to a denial of service.

What

A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux Kernel. This issue could occur when assoc_info->req_len data is bigger than the size of the buffer, defined as WL_EXTRA_BUF_MAX, leading to a denial of service.

Why

The product reads data past the end, or before the beginning, of the intended buffer.

How

An attacker operating through local access may attempt exploitation with low privileges. If successful, the issue may disrupt the affected service.

What

A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux Kernel. This issue could occur when assoc_info->req_len data is bigger than the size of the buffer, defined as WL_EXTRA_BUF_MAX, leading to a denial of service.

Why

The product reads data past the end, or before the beginning, of the intended buffer.

How

An attacker operating through local access may attempt exploitation with low privileges. If successful, the issue may disrupt the affected service.

02

Exploit reality and attack path

CVSS severity, EPSS forecast probability, public exploit material and CISA-confirmed exploitation are separate signals.

Observed exploitation
?Confirmed exploitation and public exploit material are separate signals. Attacks can occur without public proof-of-concept or exploit code.
No confirmed evidence

No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.

Public PoC / exploit material
?Confirmed exploitation and public exploit material are separate signals. Attacks can occur without public proof-of-concept or exploit code.
None recorded

No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.

Likely attack path
local access → Out-of-bounds Read → disrupt the affected service
Attack surface
Local
Privileges required
Low: a basic authenticated account is required
User interaction
None
Attack complexity
Low: no specialised conditions are recorded
Security boundary
Unchanged: impact remains within the vulnerable component's security authority
Weakness
?CWE means Common Weakness Enumeration: a standard category for the underlying weakness.
CWE-125

CWE-125: Out-of-bounds Read. The product reads data past the end, or before the beginning, of the intended buffer.

CVSS vector
?CVSS means Common Vulnerability Scoring System. The vector records the metric values used to calculate technical severity.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Common Vulnerability Scoring System 3.1: the compact vector below is decoded into plain language.

AVLocalAttack vector: The attacker needs local access to the vulnerable system.ACLowAttack complexity: No specialised conditions are required beyond attacker-controlled input.PRLowPrivileges required: The attacker needs basic user-level privileges.UINoneUser interaction: No action by another user is required.SUnchangedScope: The security impact remains within the vulnerable component's authority.CHighConfidentiality impact: A successful attack can cause a major loss.INoneIntegrity impact: No direct loss is represented by this metric.AHighAvailability impact: A successful attack can cause a major loss.
Post-exploitation / living off the land
The issue can support a local privilege or sandbox boundary transition; normal system utilities may then be available in the gained context.
Denial of serviceCWE-125
A

Official authority intelligence

Only matched European and national findings are included. Language selectors and unavailable sources are omitted.

BSI · German · WID-SEC-W-2024-0794Dell ECS: Mehrere Schwachstellen

Ein Angreifer kann mehrere Schwachstellen in Dell ECS ausnutzen, um seine Privilegien zu erweitern, beliebigen Programmcode mit Administratorrechten auszuführen, Informationen offenzulegen, Dateien zu manipulieren, einen Cross-Site-Scripting-Angriff durchzuführen, Sicherheitsvorkehrungen zu umgehen oder einen Denial of Service Zustand herbeizuführen.

Official advisory
BSI · German · WID-SEC-W-2023-0637Linux Kernel: Schwachstelle ermöglicht Offenlegung von Informationen

Ein lokaler Angreifer kann eine Schwachstelle in Linux Kernel ausnutzen, um Informationen offenzulegen.

Official advisory
CERT-FR · French · CERTFR-2025-AVI-1057Multiples vulnérabilités dans les produits VMware

.cve.org/CVERecord?id=CVE-2023-0216 Référence CVE CVE-2023-0217 https://www.cve.org/CVERecord?id=CVE-2023-0217 Référence CVE CVE-2023-0286 https://www.cve.org/CVERecord?id=CVE-2023-0286 Référence CVE CVE-2023-0401 https://www.cve.org/CVERecord?id=CVE-2023-0401 Référence CVE CVE-2023-0464 https://www.cve.org/CVERecord?id=CVE-2023-0464 Référence CVE CVE-2023-0465 https://www.cve.org/CVERecord?id=CVE-2023-0465 Référence CVE CVE-2023-0466 https://www.cve.org/CVERecord?id=CVE-2023-0466 Référence CVE CVE-2023-1118 https://www.cve.org/CVERecord?id=CVE-2023-1118 Référence CVE CVE-2023-1255 https://www.cve.org/CVERecord?id=CVE-2023-1255 Référence CVE CVE-2023-1380 https://www.cve.org/CVERecord?id=CVE-2023-1380 Référence CVE CVE-2023-1838 https://www.cve.org/CVERecord?id=CVE-2023-1838 Référence CVE CVE-2023-2156 https://www.cve.org/CVERecord?id=CVE-2023-2156 Référence CVE CVE-2023-23914 https://www.cve.org/CVERecord?id=CVE-2023-23914 Référence CVE CVE-2023-23915 https://www.cve.org/CVERecord?id=CVE-2023-23915 Référence CVE CVE-2023-23916 https://www.cve.org/CVERecord?id=CVE-2023-23916 Référence CVE CVE-2023-24329 https://www.cve.org/CVERecord?id=CVE-2023-24329 Référence CVE CVE-2023-2602 https://www.cve.org/CVERecord?id=CVE-2023-2602 Référence CVE CVE-2023-2603 https://www.cve.org/CVERecord?id=CVE-2023

Official advisory
CERT-FR · French · CERTFR-2025-AVI-0921Multiples vulnérabilités dans le noyau Linux de SUSE

d?id=CVE-2022-50456 Référence CVE CVE-2022-50458 https://www.cve.org/CVERecord?id=CVE-2022-50458 Référence CVE CVE-2022-50459 https://www.cve.org/CVERecord?id=CVE-2022-50459 Référence CVE CVE-2022-50460 https://www.cve.org/CVERecord?id=CVE-2022-50460 Référence CVE CVE-2022-50465 https://www.cve.org/CVERecord?id=CVE-2022-50465 Référence CVE CVE-2022-50466 https://www.cve.org/CVERecord?id=CVE-2022-50466 Référence CVE CVE-2022-50467 https://www.cve.org/CVERecord?id=CVE-2022-50467 Référence CVE CVE-2022-50468 https://www.cve.org/CVERecord?id=CVE-2022-50468 Référence CVE CVE-2022-50469 https://www.cve.org/CVERecord?id=CVE-2022-50469 Référence CVE CVE-2023-1380 https://www.cve.org/CVERecord?id=CVE-2023-1380 Référence CVE CVE-2023-28328 https://www.cve.org/CVERecord?id=CVE-2023-28328 Référence CVE CVE-2023-31248 https://www.cve.org/CVERecord?id=CVE-2023-31248 Référence CVE CVE-2023-3772 https://www.cve.org/CVERecord?id=CVE-2023-3772 Référence CVE CVE-2023-3867 https://www.cve.org/CVERecord?id=CVE-2023-3867 Référence CVE CVE-2023-39197 https://www.cve.org/CVERecord?id=CVE-2023-39197 Référence CVE CVE-2023-4130 https://www.cve.org/CVERecord?id=CVE-2023-4130 Référence CVE CVE-2023-42753 https://www.cve.org/CVERecord?id=CVE-2023-42753 Référence CVE CVE-2023-4515 https://www.cve.org/CVERecord?id=CVE-2023

Official advisory
CERT-FR · French · CERTFR-2025-AVI-0895Multiples vulnérabilités dans le noyau Linux de SUSE

d?id=CVE-2022-50458 Référence CVE CVE-2022-50459 https://www.cve.org/CVERecord?id=CVE-2022-50459 Référence CVE CVE-2022-50460 https://www.cve.org/CVERecord?id=CVE-2022-50460 Référence CVE CVE-2022-50464 https://www.cve.org/CVERecord?id=CVE-2022-50464 Référence CVE CVE-2022-50465 https://www.cve.org/CVERecord?id=CVE-2022-50465 Référence CVE CVE-2022-50466 https://www.cve.org/CVERecord?id=CVE-2022-50466 Référence CVE CVE-2022-50467 https://www.cve.org/CVERecord?id=CVE-2022-50467 Référence CVE CVE-2022-50468 https://www.cve.org/CVERecord?id=CVE-2022-50468 Référence CVE CVE-2022-50469 https://www.cve.org/CVERecord?id=CVE-2022-50469 Référence CVE CVE-2023-1380 https://www.cve.org/CVERecord?id=CVE-2023-1380 Référence CVE CVE-2023-28328 https://www.cve.org/CVERecord?id=CVE-2023-28328 Référence CVE CVE-2023-31248 https://www.cve.org/CVERecord?id=CVE-2023-31248 Référence CVE CVE-2023-3772 https://www.cve.org/CVERecord?id=CVE-2023-3772 Référence CVE CVE-2023-3867 https://www.cve.org/CVERecord?id=CVE-2023-3867 Référence CVE CVE-2023-39197 https://www.cve.org/CVERecord?id=CVE-2023-39197 Référence CVE CVE-2023-4130 https://www.cve.org/CVERecord?id=CVE-2023-4130 Référence CVE CVE-2023-42753 https://www.cve.org/CVERecord?id=CVE-2023-42753 Référence CVE CVE-2023-4515 https://www.cve.org/CVERecord?id=CVE-2023

Official advisory
CERT-FR · French · CERTFR-2025-AVI-0113Multiples vulnérabilités dans les produits Siemens

.cve.org/CVERecord?id=CVE-2023-0286 Référence CVE CVE-2023-0464 https://www.cve.org/CVERecord?id=CVE-2023-0464 Référence CVE CVE-2023-0465 https://www.cve.org/CVERecord?id=CVE-2023-0465 Référence CVE CVE-2023-0466 https://www.cve.org/CVERecord?id=CVE-2023-0466 Référence CVE CVE-2023-0590 https://www.cve.org/CVERecord?id=CVE-2023-0590 Référence CVE CVE-2023-1073 https://www.cve.org/CVERecord?id=CVE-2023-1073 Référence CVE CVE-2023-1074 https://www.cve.org/CVERecord?id=CVE-2023-1074 Référence CVE CVE-2023-1118 https://www.cve.org/CVERecord?id=CVE-2023-1118 Référence CVE CVE-2023-1206 https://www.cve.org/CVERecord?id=CVE-2023-1206 Référence CVE CVE-2023-1380 https://www.cve.org/CVERecord?id=CVE-2023-1380 Référence CVE CVE-2023-1670 https://www.cve.org/CVERecord?id=CVE-2023-1670 Référence CVE CVE-2023-2194 https://www.cve.org/CVERecord?id=CVE-2023-2194 Référence CVE CVE-2023-23454 https://www.cve.org/CVERecord?id=CVE-2023-23454 Référence CVE CVE-2023-23455 https://www.cve.org/CVERecord?id=CVE-2023-23455 Référence CVE CVE-2023-23559 https://www.cve.org/CVERecord?id=CVE-2023-23559 Référence CVE CVE-2023-26545 https://www.cve.org/CVERecord?id=CVE-2023-26545 Référence CVE CVE-2023-28484 https://www.cve.org/CVERecord?id=CVE-2023-28484 Référence CVE CVE-2023-28578 https://www.cve.org/CVERecord?id=CVE-2

Official advisory
CERT-FR · French · CERTFR-2024-AVI-0119Multiples vulnérabilités dans les produits Siemens

.cve.org/CVERecord?id=CVE-2023-0361 Référence CVE CVE-2023-0401 https://www.cve.org/CVERecord?id=CVE-2023-0401 Référence CVE CVE-2023-0494 https://www.cve.org/CVERecord?id=CVE-2023-0494 Référence CVE CVE-2023-0567 https://www.cve.org/CVERecord?id=CVE-2023-0567 Référence CVE CVE-2023-0568 https://www.cve.org/CVERecord?id=CVE-2023-0568 Référence CVE CVE-2023-0590 https://www.cve.org/CVERecord?id=CVE-2023-0590 Référence CVE CVE-2023-0662 https://www.cve.org/CVERecord?id=CVE-2023-0662 Référence CVE CVE-2023-1206 https://www.cve.org/CVERecord?id=CVE-2023-1206 Référence CVE CVE-2023-1255 https://www.cve.org/CVERecord?id=CVE-2023-1255 Référence CVE CVE-2023-1380 https://www.cve.org/CVERecord?id=CVE-2023-1380 Référence CVE CVE-2023-1393 https://www.cve.org/CVERecord?id=CVE-2023-1393 Référence CVE CVE-2023-1611 https://www.cve.org/CVERecord?id=CVE-2023-1611 Référence CVE CVE-2023-1670 https://www.cve.org/CVERecord?id=CVE-2023-1670 Référence CVE CVE-2023-1838 https://www.cve.org/CVERecord?id=CVE-2023-1838 Référence CVE CVE-2023-1855 https://www.cve.org/CVERecord?id=CVE-2023-1855 Référence CVE CVE-2023-1859 https://www.cve.org/CVERecord?id=CVE-2023-1859 Référence CVE CVE-2023-1989 https://www.cve.org/CVERecord?id=CVE-2023-1989 Référence CVE CVE-2023-1990 https://www.cve.org/CVERecord?id=CVE-2023-1990 Ré

Official advisory
CERT-FR · French · CERTFR-2023-AVI-0911Multiples vulnérabilités dans le noyau Linux d'Ubuntu

465-2 du 01 novembre 2023 https://ubuntu.com/security/notices/USN-6465-2 Bulletin de sécurité Ubuntu USN-6466-1 du 31 octobre 2023 https://ubuntu.com/security/notices/USN-6466-1 Référence CVE CVE-2022-45886 https://www.cve.org/CVERecord?id=CVE-2022-45886 Référence CVE CVE-2022-45887 https://www.cve.org/CVERecord?id=CVE-2022-45887 Référence CVE CVE-2022-45919 https://www.cve.org/CVERecord?id=CVE-2022-45919 Référence CVE CVE-2022-48425 https://www.cve.org/CVERecord?id=CVE-2022-48425 Référence CVE CVE-2023-0597 https://www.cve.org/CVERecord?id=CVE-2023-0597 Référence CVE CVE-2023-1206 https://www.cve.org/CVERecord?id=CVE-2023-1206 Référence CVE CVE-2023-1380 https://www.cve.org/CVERecord?id=CVE-2023-1380 Référence CVE CVE-2023-20569 https://www.cve.org/CVERecord?id=CVE-2023-20569 Référence CVE CVE-2023-20588 https://www.cve.org/CVERecord?id=CVE-2023-20588 Référence CVE CVE-2023-21264 https://www.cve.org/CVERecord?id=CVE-2023-21264 Référence CVE CVE-2023-2156 https://www.cve.org/CVERecord?id=CVE-2023-2156 Référence CVE CVE-2023-31083 https://www.cve.org/CVERecord?id=CVE-2023-31083 Référence CVE CVE-2023-31085 https://www.cve.org/CVERecord?id=CVE-2023-31085 Référence CVE CVE-2023-31436 https://www.cve.org/CVERecord?id=CVE-2023-31436 Référence CVE CVE-2023-3212 https://www.cve.org/CVERecord?id=CVE-

Official advisory
CERT-FR · French · CERTFR-2023-AVI-0874Multiples vulnérabilités dans le noyau Linux de DebianLTS

e elles permettent à un attaquant de provoquer une exécution de code arbitraire, atteinte à l'intégrité des données et une atteinte à la confidentialité des données. Solution Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation). Documentation Bulletin de sécurité DebianLTS DLA-3623-1 du 19 octobre 2023 https://www.debian.org/lts/security/2023/dla-3623 Référence CVE CVE-2022-39189 https://www.cve.org/CVERecord?id=CVE-2022-39189 Référence CVE CVE-2022-4269 https://www.cve.org/CVERecord?id=CVE-2022-4269 Référence CVE CVE-2023-1206 https://www.cve.org/CVERecord?id=CVE-2023-1206 Référence CVE CVE-2023-1380 https://www.cve.org/CVERecord?id=CVE-2023-1380 Référence CVE CVE-2023-2002 https://www.cve.org/CVERecord?id=CVE-2023-2002 Référence CVE CVE-2023-2007 https://www.cve.org/CVERecord?id=CVE-2023-2007 Référence CVE CVE-2023-20588 https://www.cve.org/CVERecord?id=CVE-2023-20588 Référence CVE CVE-2023-2124 https://www.cve.org/CVERecord?id=CVE-2023-2124 Référence CVE CVE-2023-21255 https://www.cve.org/CVERecord?id=CVE-2023-21255 Référence CVE CVE-2023-21400 https://www.cve.org/CVERecord?id=CVE-2023-21400 Référence CVE CVE-2023-2269 https://www.cve.org/CVERecord?id=CVE-2023-2269 Référence CVE CVE-2023-2898 https://www.cve.org/CVERecord?id=CVE-2023-2

Official advisory
CERT-FR · French · CERTFR-2023-AVI-0775Multiples vulnérabilités dans le noyau Linux d'Ubuntu

m/security/notices/USN-6388-1 Référence CVE CVE-2022-27672 https://www.cve.org/CVERecord?id=CVE-2022-27672 Référence CVE CVE-2022-40982 https://www.cve.org/CVERecord?id=CVE-2022-40982 Référence CVE CVE-2022-4269 https://www.cve.org/CVERecord?id=CVE-2022-4269 Référence CVE CVE-2022-48425 https://www.cve.org/CVERecord?id=CVE-2022-48425 Référence CVE CVE-2023-0458 https://www.cve.org/CVERecord?id=CVE-2023-0458 Référence CVE CVE-2023-1075 https://www.cve.org/CVERecord?id=CVE-2023-1075 Référence CVE CVE-2023-1076 https://www.cve.org/CVERecord?id=CVE-2023-1076 Référence CVE CVE-2023-1206 https://www.cve.org/CVERecord?id=CVE-2023-1206 Référence CVE CVE-2023-1380 https://www.cve.org/CVERecord?id=CVE-2023-1380 Référence CVE CVE-2023-1611 https://www.cve.org/CVERecord?id=CVE-2023-1611 Référence CVE CVE-2023-2002 https://www.cve.org/CVERecord?id=CVE-2023-2002 Référence CVE CVE-2023-20588 https://www.cve.org/CVERecord?id=CVE-2023-20588 Référence CVE CVE-2023-20593 https://www.cve.org/CVERecord?id=CVE-2023-20593 Référence CVE CVE-2023-21255 https://www.cve.org/CVERecord?id=CVE-2023-21255 Référence CVE CVE-2023-21264 https://www.cve.org/CVERecord?id=CVE-2023-21264 Référence CVE CVE-2023-2162 https://www.cve.org/CVERecord?id=CVE-2023-2162 Référence CVE CVE-2023-2163 https://www.cve.org/CVERecord?id=CVE-2023

Official advisory
CERT-FR · French · CERTFR-2023-AVI-0687Multiples vulnérabilités dans le noyau Linux de Debian

Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, une élévation de privilèges et une atteinte à la confidentialité des données. Solution Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation). Documentation Bulletin de sécurité Debian DSA-5480-1 du 18 août 2023 https://www.debian.org/security/2023/dsa-5480 Référence CVE CVE-2022-39189 https://www.cve.org/CVERecord?id=CVE-2022-39189 Référence CVE CVE-2022-4269 https://www.cve.org/CVERecord?id=CVE-2022-4269 Référence CVE CVE-2023-1206 https://www.cve.org/CVERecord?id=CVE-2023-1206 Référence CVE CVE-2023-1380 https://www.cve.org/CVERecord?id=CVE-2023-1380 Référence CVE CVE-2023-2002 https://www.cve.org/CVERecord?id=CVE-2023-2002 Référence CVE CVE-2023-2007 https://www.cve.org/CVERecord?id=CVE-2023-2007 Référence CVE CVE-2023-20588 https://www.cve.org/CVERecord?id=CVE-2023-20588 Référence CVE CVE-2023-2124 https://www.cve.org/CVERecord?id=CVE-2023-2124 Référence CVE CVE-2023-21255 https://www.cve.org/CVERecord?id=CVE-2023-21255 Référence CVE CVE-2023-21400 https://www.cve.org/CVERecord?id=CVE-2023-21400 Référence CVE CVE-2023-2269 https://www.cve.org/CVERecord?id=CVE-2023-2269 Référence CVE CVE-2023-2898 https://www.cve.org/CVERecord?id=CVE-2023-2

Official advisory
CERT-FR · French · CERTFR-2023-AVI-0601Multiples vulnérabilités dans le noyau Linux de Debian

De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité des données.

Official advisory
CERT-FR · French · CERTFR-2023-AVI-0599Multiples vulnérabilités dans le noyau Linux d'Ubuntu

.cve.org/CVERecord?id=CVE-2023-1073 Référence CVE CVE-2023-1074 https://www.cve.org/CVERecord?id=CVE-2023-1074 Référence CVE CVE-2023-1075 https://www.cve.org/CVERecord?id=CVE-2023-1075 Référence CVE CVE-2023-1076 https://www.cve.org/CVERecord?id=CVE-2023-1076 Référence CVE CVE-2023-1077 https://www.cve.org/CVERecord?id=CVE-2023-1077 Référence CVE CVE-2023-1078 https://www.cve.org/CVERecord?id=CVE-2023-1078 Référence CVE CVE-2023-1079 https://www.cve.org/CVERecord?id=CVE-2023-1079 Référence CVE CVE-2023-1118 https://www.cve.org/CVERecord?id=CVE-2023-1118 Référence CVE CVE-2023-1281 https://www.cve.org/CVERecord?id=CVE-2023-1281 Référence CVE CVE-2023-1380 https://www.cve.org/CVERecord?id=CVE-2023-1380 Référence CVE CVE-2023-1513 https://www.cve.org/CVERecord?id=CVE-2023-1513 Référence CVE CVE-2023-1611 https://www.cve.org/CVERecord?id=CVE-2023-1611 Référence CVE CVE-2023-1670 https://www.cve.org/CVERecord?id=CVE-2023-1670 Référence CVE CVE-2023-1829 https://www.cve.org/CVERecord?id=CVE-2023-1829 Référence CVE CVE-2023-1859 https://www.cve.org/CVERecord?id=CVE-2023-1859 Référence CVE CVE-2023-1990 https://www.cve.org/CVERecord?id=CVE-2023-1990 Référence CVE CVE-2023-1998 https://www.cve.org/CVERecord?id=CVE-2023-1998 Référence CVE CVE-2023-21106 https://www.cve.org/CVERecord?id=CVE-2023-21106

Official advisory
CERT-FR · French · CERTFR-2023-AVI-0543Multiples vulnérabilités dans le noyau Linux d'Ubuntu

.cve.org/CVERecord?id=CVE-2023-1073 Référence CVE CVE-2023-1074 https://www.cve.org/CVERecord?id=CVE-2023-1074 Référence CVE CVE-2023-1075 https://www.cve.org/CVERecord?id=CVE-2023-1075 Référence CVE CVE-2023-1076 https://www.cve.org/CVERecord?id=CVE-2023-1076 Référence CVE CVE-2023-1077 https://www.cve.org/CVERecord?id=CVE-2023-1077 Référence CVE CVE-2023-1078 https://www.cve.org/CVERecord?id=CVE-2023-1078 Référence CVE CVE-2023-1079 https://www.cve.org/CVERecord?id=CVE-2023-1079 Référence CVE CVE-2023-1118 https://www.cve.org/CVERecord?id=CVE-2023-1118 Référence CVE CVE-2023-1281 https://www.cve.org/CVERecord?id=CVE-2023-1281 Référence CVE CVE-2023-1380 https://www.cve.org/CVERecord?id=CVE-2023-1380 Référence CVE CVE-2023-1513 https://www.cve.org/CVERecord?id=CVE-2023-1513 Référence CVE CVE-2023-1670 https://www.cve.org/CVERecord?id=CVE-2023-1670 Référence CVE CVE-2023-1829 https://www.cve.org/CVERecord?id=CVE-2023-1829 Référence CVE CVE-2023-1859 https://www.cve.org/CVERecord?id=CVE-2023-1859 Référence CVE CVE-2023-1990 https://www.cve.org/CVERecord?id=CVE-2023-1990 Référence CVE CVE-2023-1998 https://www.cve.org/CVERecord?id=CVE-2023-1998 Référence CVE CVE-2023-2124 https://www.cve.org/CVERecord?id=CVE-2023-2124 Référence CVE CVE-2023-2162 https://www.cve.org/CVERecord?id=CVE-2023-2162 Ré

Official advisory
CERT-FR · French · CERTFR-2023-AVI-0544Multiples vulnérabilités dans le noyau Linux de SUSE

.cve.org/CVERecord?id=CVE-2023-0597 Référence CVE CVE-2023-1075 https://www.cve.org/CVERecord?id=CVE-2023-1075 Référence CVE CVE-2023-1076 https://www.cve.org/CVERecord?id=CVE-2023-1076 Référence CVE CVE-2023-1077 https://www.cve.org/CVERecord?id=CVE-2023-1077 Référence CVE CVE-2023-1078 https://www.cve.org/CVERecord?id=CVE-2023-1078 Référence CVE CVE-2023-1079 https://www.cve.org/CVERecord?id=CVE-2023-1079 Référence CVE CVE-2023-1095 https://www.cve.org/CVERecord?id=CVE-2023-1095 Référence CVE CVE-2023-1118 https://www.cve.org/CVERecord?id=CVE-2023-1118 Référence CVE CVE-2023-1249 https://www.cve.org/CVERecord?id=CVE-2023-1249 Référence CVE CVE-2023-1380 https://www.cve.org/CVERecord?id=CVE-2023-1380 Référence CVE CVE-2023-1382 https://www.cve.org/CVERecord?id=CVE-2023-1382 Référence CVE CVE-2023-1390 https://www.cve.org/CVERecord?id=CVE-2023-1390 Référence CVE CVE-2023-1513 https://www.cve.org/CVERecord?id=CVE-2023-1513 Référence CVE CVE-2023-1582 https://www.cve.org/CVERecord?id=CVE-2023-1582 Référence CVE CVE-2023-1583 https://www.cve.org/CVERecord?id=CVE-2023-1583 Référence CVE CVE-2023-1611 https://www.cve.org/CVERecord?id=CVE-2023-1611 Référence CVE CVE-2023-1637 https://www.cve.org/CVERecord?id=CVE-2023-1637 Référence CVE CVE-2023-1652 https://www.cve.org/CVERecord?id=CVE-2023-1652 Ré

Official advisory
CERT-FR · French · CERTFR-2023-AVI-0517Multiples vulnérabilités dans le noyau Linux de SUSE

CVERecord?id=CVE-2022-45884 Référence CVE CVE-2022-45885 https://www.cve.org/CVERecord?id=CVE-2022-45885 Référence CVE CVE-2022-45886 https://www.cve.org/CVERecord?id=CVE-2022-45886 Référence CVE CVE-2022-45887 https://www.cve.org/CVERecord?id=CVE-2022-45887 Référence CVE CVE-2022-45919 https://www.cve.org/CVERecord?id=CVE-2022-45919 Référence CVE CVE-2022-4744 https://www.cve.org/CVERecord?id=CVE-2022-4744 Référence CVE CVE-2023-1077 https://www.cve.org/CVERecord?id=CVE-2023-1077 Référence CVE CVE-2023-1079 https://www.cve.org/CVERecord?id=CVE-2023-1079 Référence CVE CVE-2023-1249 https://www.cve.org/CVERecord?id=CVE-2023-1249 Référence CVE CVE-2023-1380 https://www.cve.org/CVERecord?id=CVE-2023-1380 Référence CVE CVE-2023-1382 https://www.cve.org/CVERecord?id=CVE-2023-1382 Référence CVE CVE-2023-1390 https://www.cve.org/CVERecord?id=CVE-2023-1390 Référence CVE CVE-2023-2002 https://www.cve.org/CVERecord?id=CVE-2023-2002 Référence CVE CVE-2023-21102 https://www.cve.org/CVERecord?id=CVE-2023-21102 Référence CVE CVE-2023-2124 https://www.cve.org/CVERecord?id=CVE-2023-2124 Référence CVE CVE-2023-2156 https://www.cve.org/CVERecord?id=CVE-2023-2156 Référence CVE CVE-2023-2162 https://www.cve.org/CVERecord?id=CVE-2023-2162 Référence CVE CVE-2023-2269 https://www.cve.org/CVERecord?id=CVE-2023-2269

Official advisory
CERT-FR · French · CERTFR-2023-AVI-0507Multiples vulnérabilités dans le noyau Linux de SUSE

VERecord?id=CVE-2022-3566 Référence CVE CVE-2022-4269 https://www.cve.org/CVERecord?id=CVE-2022-4269 Référence CVE CVE-2022-45884 https://www.cve.org/CVERecord?id=CVE-2022-45884 Référence CVE CVE-2022-45885 https://www.cve.org/CVERecord?id=CVE-2022-45885 Référence CVE CVE-2022-45886 https://www.cve.org/CVERecord?id=CVE-2022-45886 Référence CVE CVE-2022-45887 https://www.cve.org/CVERecord?id=CVE-2022-45887 Référence CVE CVE-2022-45919 https://www.cve.org/CVERecord?id=CVE-2022-45919 Référence CVE CVE-2022-4744 https://www.cve.org/CVERecord?id=CVE-2022-4744 Référence CVE CVE-2023-1079 https://www.cve.org/CVERecord?id=CVE-2023-1079 Référence CVE CVE-2023-1380 https://www.cve.org/CVERecord?id=CVE-2023-1380 Référence CVE CVE-2023-1382 https://www.cve.org/CVERecord?id=CVE-2023-1382 Référence CVE CVE-2023-1390 https://www.cve.org/CVERecord?id=CVE-2023-1390 Référence CVE CVE-2023-1637 https://www.cve.org/CVERecord?id=CVE-2023-1637 Référence CVE CVE-2023-2002 https://www.cve.org/CVERecord?id=CVE-2023-2002 Référence CVE CVE-2023-2124 https://www.cve.org/CVERecord?id=CVE-2023-2124 Référence CVE CVE-2023-2156 https://www.cve.org/CVERecord?id=CVE-2023-2156 Référence CVE CVE-2023-2162 https://www.cve.org/CVERecord?id=CVE-2023-2162 Référence CVE CVE-2023-2194 https://www.cve.org/CVERecord?id=CVE-2023-2194 Ré

Official advisory
CERT-FR · French · CERTFR-2023-AVI-0489Multiples vulnérabilités dans le noyau Linux de SUSE

VERecord?id=CVE-2022-3566 Référence CVE CVE-2022-4269 https://www.cve.org/CVERecord?id=CVE-2022-4269 Référence CVE CVE-2022-45884 https://www.cve.org/CVERecord?id=CVE-2022-45884 Référence CVE CVE-2022-45885 https://www.cve.org/CVERecord?id=CVE-2022-45885 Référence CVE CVE-2022-45886 https://www.cve.org/CVERecord?id=CVE-2022-45886 Référence CVE CVE-2022-45887 https://www.cve.org/CVERecord?id=CVE-2022-45887 Référence CVE CVE-2022-45919 https://www.cve.org/CVERecord?id=CVE-2022-45919 Référence CVE CVE-2023-1077 https://www.cve.org/CVERecord?id=CVE-2023-1077 Référence CVE CVE-2023-1079 https://www.cve.org/CVERecord?id=CVE-2023-1079 Référence CVE CVE-2023-1380 https://www.cve.org/CVERecord?id=CVE-2023-1380 Référence CVE CVE-2023-1637 https://www.cve.org/CVERecord?id=CVE-2023-1637 Référence CVE CVE-2023-2156 https://www.cve.org/CVERecord?id=CVE-2023-2156 Référence CVE CVE-2023-2176 https://www.cve.org/CVERecord?id=CVE-2023-2176 Référence CVE CVE-2023-2194 https://www.cve.org/CVERecord?id=CVE-2023-2194 Référence CVE CVE-2023-2269 https://www.cve.org/CVERecord?id=CVE-2023-2269 Référence CVE CVE-2023-23586 https://www.cve.org/CVERecord?id=CVE-2023-23586 Référence CVE CVE-2023-2483 https://www.cve.org/CVERecord?id=CVE-2023-2483 Référence CVE CVE-2023-2513 https://www.cve.org/CVERecord?id=CVE-2023-2513

Official advisory
CERT-FR · French · CERTFR-2023-AVI-0488Multiples vulnérabilités dans le noyau Linux d'Ubuntu

N-6186-1 Bulletin de sécurité Ubuntu USN-6187-1 du 22 juin 2023 https://ubuntu.com/security/notices/USN-6187-1 Référence CVE CVE-2022-4269 https://www.cve.org/CVERecord?id=CVE-2022-4269 Référence CVE CVE-2023-0386 https://www.cve.org/CVERecord?id=CVE-2023-0386 Référence CVE CVE-2023-0459 https://www.cve.org/CVERecord?id=CVE-2023-0459 Référence CVE CVE-2023-1073 https://www.cve.org/CVERecord?id=CVE-2023-1073 Référence CVE CVE-2023-1076 https://www.cve.org/CVERecord?id=CVE-2023-1076 Référence CVE CVE-2023-1077 https://www.cve.org/CVERecord?id=CVE-2023-1077 Référence CVE CVE-2023-1079 https://www.cve.org/CVERecord?id=CVE-2023-1079 Référence CVE CVE-2023-1380 https://www.cve.org/CVERecord?id=CVE-2023-1380 Référence CVE CVE-2023-1583 https://www.cve.org/CVERecord?id=CVE-2023-1583 Référence CVE CVE-2023-1611 https://www.cve.org/CVERecord?id=CVE-2023-1611 Référence CVE CVE-2023-1670 https://www.cve.org/CVERecord?id=CVE-2023-1670 Référence CVE CVE-2023-1855 https://www.cve.org/CVERecord?id=CVE-2023-1855 Référence CVE CVE-2023-1859 https://www.cve.org/CVERecord?id=CVE-2023-1859 Référence CVE CVE-2023-1872 https://www.cve.org/CVERecord?id=CVE-2023-1872 Référence CVE CVE-2023-1989 https://www.cve.org/CVERecord?id=CVE-2023-1989 Référence CVE CVE-2023-1990 https://www.cve.org/CVERecord?id=CVE-2023-1990 Ré

Official advisory
CERT-FR · French · CERTFR-2023-AVI-0473Multiples vulnérabilités dans le noyau Linux d'Ubuntu

De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Elles permettent à un attaquant de provoquer une exécution de code arbitraire, un déni de service à distance et une atteinte à la confidentialité des données.

Official advisory
CERT-FR · French · CERTFR-2023-AVI-0474Multiples vulnérabilités dans le noyau Linux de SUSE

VERecord?id=CVE-2022-4269 Référence CVE CVE-2022-45884 https://www.cve.org/CVERecord?id=CVE-2022-45884 Référence CVE CVE-2022-45885 https://www.cve.org/CVERecord?id=CVE-2022-45885 Référence CVE CVE-2022-45886 https://www.cve.org/CVERecord?id=CVE-2022-45886 Référence CVE CVE-2022-45887 https://www.cve.org/CVERecord?id=CVE-2022-45887 Référence CVE CVE-2022-45919 https://www.cve.org/CVERecord?id=CVE-2022-45919 Référence CVE CVE-2023-0590 https://www.cve.org/CVERecord?id=CVE-2023-0590 Référence CVE CVE-2023-1079 https://www.cve.org/CVERecord?id=CVE-2023-1079 Référence CVE CVE-2023-1118 https://www.cve.org/CVERecord?id=CVE-2023-1118 Référence CVE CVE-2023-1380 https://www.cve.org/CVERecord?id=CVE-2023-1380 Référence CVE CVE-2023-1382 https://www.cve.org/CVERecord?id=CVE-2023-1382 Référence CVE CVE-2023-1513 https://www.cve.org/CVERecord?id=CVE-2023-1513 Référence CVE CVE-2023-1637 https://www.cve.org/CVERecord?id=CVE-2023-1637 Référence CVE CVE-2023-1670 https://www.cve.org/CVERecord?id=CVE-2023-1670 Référence CVE CVE-2023-1989 https://www.cve.org/CVERecord?id=CVE-2023-1989 Référence CVE CVE-2023-2002 https://www.cve.org/CVERecord?id=CVE-2023-2002 Référence CVE CVE-2023-2124 https://www.cve.org/CVERecord?id=CVE-2023-2124 Référence CVE CVE-2023-2156 https://www.cve.org/CVERecord?id=CVE-2023-2156 Ré

Official advisory
CERT-FR · French · CERTFR-2023-AVI-0448Multiples vulnérabilités dans le noyau Linux d'Ubuntu

De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu . Certaines d'entre elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, une atteinte à l'intégrité des données et une exécution de code arbitraire.

Official advisory
CERT-FR · French · CERTFR-2023-AVI-0429Multiples vulnérabilités dans le noyau Linux d'Ubuntu

.cve.org/CVERecord?id=CVE-2023-0394 Référence CVE CVE-2023-0458 https://www.cve.org/CVERecord?id=CVE-2023-0458 Référence CVE CVE-2023-0459 https://www.cve.org/CVERecord?id=CVE-2023-0459 Référence CVE CVE-2023-1073 https://www.cve.org/CVERecord?id=CVE-2023-1073 Référence CVE CVE-2023-1074 https://www.cve.org/CVERecord?id=CVE-2023-1074 Référence CVE CVE-2023-1075 https://www.cve.org/CVERecord?id=CVE-2023-1075 Référence CVE CVE-2023-1078 https://www.cve.org/CVERecord?id=CVE-2023-1078 Référence CVE CVE-2023-1118 https://www.cve.org/CVERecord?id=CVE-2023-1118 Référence CVE CVE-2023-1281 https://www.cve.org/CVERecord?id=CVE-2023-1281 Référence CVE CVE-2023-1380 https://www.cve.org/CVERecord?id=CVE-2023-1380 Référence CVE CVE-2023-1513 https://www.cve.org/CVERecord?id=CVE-2023-1513 Référence CVE CVE-2023-1652 https://www.cve.org/CVERecord?id=CVE-2023-1652 Référence CVE CVE-2023-1670 https://www.cve.org/CVERecord?id=CVE-2023-1670 Référence CVE CVE-2023-1829 https://www.cve.org/CVERecord?id=CVE-2023-1829 Référence CVE CVE-2023-1872 https://www.cve.org/CVERecord?id=CVE-2023-1872 Référence CVE CVE-2023-20938 https://www.cve.org/CVERecord?id=CVE-2023-20938 Référence CVE CVE-2023-21102 https://www.cve.org/CVERecord?id=CVE-2023-21102 Référence CVE CVE-2023-2162 https://www.cve.org/CVERecord?id=CVE-2023-216

Official advisory
NCSC-NL · Dutch · NCSC-2025-0051Kwetsbaarheden verholpen in Siemens producten

De kwetsbaarheden stellen een kwaadwillende mogelijk in staat aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade: - Denial-of-Service (DoS) - Cross-Site-Scripting (XSS) - Cross-Site Request Forgery (CSRF) - Manipulatie van gegevens - Omzeilen van een beveiligingsmaatregel - Omzeilen van authenticatie - (Remote) code execution (root/admin rechten) - (Remote) code execution (Gebruikersrechten) - Toegang tot systeemgegevens - Toegang tot gevoelige gegevens De kwaadwillende heeft hiervoor toegang nodig tot de productieomgeving. Het is goed gebruik een dergelijke omgeving niet publiek toegankelijk te hebben.

Official advisory
NCSC-NL · Dutch · NCSC-2025-0061Kwetsbaarheden verholpen in Siemens producten

De kwetsbaarheden stellen een kwaadwillende mogelijk in staat aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade: - Denial-of-Service (DoS) - Cross-Site-Scripting (XSS) - Cross-Site Request Forgery (CSRF) - Manipulatie van gegevens - Omzeilen van een beveiligingsmaatregel - Omzeilen van authenticatie - (Remote) code execution (root/admin rechten) - (Remote) code execution (Gebruikersrechten) - Toegang tot systeemgegevens - Toegang tot gevoelige gegevens De kwaadwillende heeft hiervoor toegang nodig tot de productieomgeving. Het is goed gebruik een dergelijke omgeving niet publiek toegankelijk te hebben.

Official advisory
03

Patch and workaround

Operational remediation based on structured source evidence.

Status
?Patch availability is based on structured fixed-version fields and authoritative update references. If no fix is verified, check the vendor advisory before making a change.
Patch available
Affected
SCALANCE WAB762-1 (6GK5762-1AJ00-6AA0); SCALANCE WAM763-1 (6GK5763-1AL00-7DA0); SCALANCE WAM763-1 (ME) (6GK5763-1AL00-7DC0); SCALANCE WAM763-1 (US) (6GK5763-1AL00-7DB0); SCALANCE WAM766-1 (6GK5766-1GE00-7DA0); SCALANCE WAM766-1 (ME) (6GK5766-1GE00-7DC0); SCALANCE WAM766-1 (US) (6GK5766-1GE00-7DB0); SCALANCE WAM766-1 EEC (6GK5766-1GE00-7TA0); SCALANCE WAM766-1 EEC (ME) (6GK5766-1GE00-7TC0); SCALANCE WAM766-1 EEC (US) (6GK5766-1GE00-7TB0); SCALANCE WUB762-1 (6GK5762-1AJ00-1AA0); SCALANCE WUB762-1 iFeatures (6GK5762-1AJ00-2AA0); SCALANCE WUM763-1 (6GK5763-1AL00-3AA0); SCALANCE WUM763-1 (6GK5763-1AL00-3DA0); SCALANCE WUM763-1 (US) (6GK5763-1AL00-3AB0); SCALANCE WUM763-1 (US) (6GK5763-1AL00-3DB0); SCALANCE WUM766-1 (6GK5766-1GE00-3DA0); SCALANCE WUM766-1 (ME) (6GK5766-1GE00-3DC0); SCALANCE WUM766-1 (USA) (6GK5766-1GE00-3DB0)
Fixed
An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
Action
Update to V3.0.0 or later version
Workaround
A mitigation or workaround reference is available from the source linked below; validate it against the affected product and version.
04

Evidence and provenance

Published 27 Mar 2023 · Last source change 2 Aug 2024, 05:49 UTC · CWE-125 · Out-of-bounds Read

CVE recordCVE.org · 5.1
CVSS sourceNIST NVD
EPSS source
?The date BlackTree first stored a score for this CVE from the daily FIRST EPSS feed.
FIRST · tracked since 2026-08-14
European sourceENISA EUVD · EUVD-2023-23636
Product sourceVendor CSAF · Siemens ProductCERT
Remediation sourceVendor CSAF · Siemens ProductCERT
CWE sourceCNA
NVD statusNVD modified after enrichment

Core structured fields are present and their contributing authorities are shown above.

Material change intelligence

What changed after publication

View recent updates →

No material field changes have been recorded since change tracking began. Routine source refreshes and cosmetic edits are intentionally excluded.

Material fields only · duplicate refreshes suppressed · history retained for the configured operational retention period
Technical terms and abbreviations used in this report
CVE
Common Vulnerabilities and Exposures: the public identifier for one disclosed vulnerability.
CVSS
Common Vulnerability Scoring System: a technical severity framework; it is not patching priority by itself.
EPSS
Exploit Prediction Scoring System: FIRST's estimate of the probability that exploitation activity will be observed in the next 30 days; it is a forecast, not confirmation.
CWE
Common Weakness Enumeration: the standard category describing the underlying software or hardware weakness.
CNA
CVE Numbering Authority: an organisation authorised to assign and publish CVE records.
CISA ADP
Cybersecurity and Infrastructure Security Agency Authorized Data Publisher: structured enrichment added to a CVE record.
NVD
National Vulnerability Database: NIST's enrichment service for CVE records.
CERT / CSIRT
A computer security incident response team that publishes warnings or coordinates incident response.
PoC
Proof of concept: public material that demonstrates or helps reproduce exploitation.
CSAF
Common Security Advisory Framework: a machine-readable format for security advisories.
LoTL
Living off the land: abuse of legitimate tools or system functions during an attack.
Free version - for non-commercial use only.CVE-2023-1380 · cve.blacktree.nl