ENISA EUVD · EUVD-2023-32201Official EUVD mappingssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.
Official EUVD recordBSI · German · WID-SEC-W-2024-1082Juniper JUNOS: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Juniper JUNOS im Zusammenhang mit OpenSSH ausnutzen, um Sicherheitsmaßnahmen zu umgehen, beliebigen Code auszuführen oder Dateien zu manipulieren.
Official advisoryBSI · German · WID-SEC-W-2023-0670OpenSSH: Mehrere SchwachstellenEin lokaler Angreifer kann mehrere Schwachstellen in OpenSSH ausnutzen, um Sicherheitsvorkehrungen zu umgehen oder einen Denial of Service Zustand herbeizuführen.
Official advisoryCERT-FR · French · CERTFR-2026-AVI-0880Multiples vulnérabilités dans les produits Siemensjuillet 2026
Bulletin de sécurité Siemens SSA-734552 du 14 juillet 2026
Bulletin de sécurité Siemens SSA-828211 du 14 juillet 2026
Une gestion de version détaillée se trouve à la fin de ce document.
Risques
Atteinte à la confidentialité des données
Contournement de la politique de sécurité
Déni de service à distance
Exécution de code arbitraire à distance
Non spécifié par l'éditeur
Élévation de privilèges
Systèmes affectés
Desigo CC toutes versions
Desigo CC toutes versions pour la vulnérabilité CVE-2025-15467
Desigo CC versions antérieures à 9.0.1
SIMATIC S7-1500 versions supérieures ou égales à 3.1.6 pour les vulnérabilités CVE-2021-41617, CVE-2023-28531, CVE-2023-51384, CVE-2023-52927, CVE-2024-26783, CVE-2024-27056, CVE-2024-28956, CVE-2024-36903, CVE-2024-36927, CVE-2024-42079, CVE-2024-46786, CVE-2024-47736, CVE-2024-47809, CVE-2024-49968, CVE-2024-49994, CVE-2024-49998, CVE-2024-50014, CVE-2024-50063, CVE-2024-50164, CVE-2024-50298, CVE-2024-53124, CVE-2024-53170, CVE-2024-54458, CVE-2024-56631, CVE-2024-56703, CVE-2024-56719, CVE-2024-57917, CVE-2024-57924, CVE-2024-57973, CVE-2024-57977, CVE-2024-57979, CVE-2024-58011, CVE-2024-58016, CVE-2024-58020, CVE-2024-58056, CVE-2024-58058, CVE-2024-58061, CVE-2024-58086, CVE-2025-21645, CVE-2025-21648, CVE-2025-21655, CVE-2025-21676, CVE-2025
Official advisoryCERT-FR · French · CERTFR-2025-AVI-0492Multiples vulnérabilités dans les produits SiemensLANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3) versions antérieures à V3.2
SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3) versions antérieures à V3.1
SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3) versions antérieures à V3.2
SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3) versions antérieures à V3.1
SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3) versions antérieures à V3.2
SIMATIC S7-1500 versions supérieures ou égales àV3.1.5 pour les vulnérabilités CVE-2021-41617, CVE-2023-4527, CVE-2023-4806, CVE-2023-4911, CVE-2023-5363, CVE-2023-6246, CVE-2023-6779, CVE-2023-6780, CVE-2023-28531, CVE-2023-38545, CVE-2023-38546, CVE-2023-44487, CVE-2023-46218, CVE-2023-46219, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2023-52927, CVE-2024-2961, CVE-2024-6119, CVE-2024-6387, CVE-2024-12133, CVE-2024-12243, CVE-2024-24855, CVE-2024-26596, CVE-2024-28085, CVE-2024-33599, CVE-2024-33600, CVE-2024-33601, CVE-2024-33602, CVE-2024-34397, CVE-2024-37370, CVE-2024-37371, CVE-2024-45490, CVE-2024-45491, CVE-2024-45492, CVE-2024-50246, CVE-2024-53166, CVE-2024-57977, CVE-2024-57996, CVE-2024-58005, CVE-2025-4373, CVE-2025-4598, CVE-2025-21701, CVE-2025-21702, CVE-2025-21712, CVE-2025-21724, CVE-2025-21728, CVE-2025-21745, CVE-2025-2175
Official advisoryCERT-FR · French · CERTFR-2024-AVI-0585Multiples vulnérabilités dans les produits VMwareorg/CVERecord?id=CVE-2021-41617
Référence CVE CVE-2022-1725
https://www.cve.org/CVERecord?id=CVE-2022-1725
Référence CVE CVE-2022-1771
https://www.cve.org/CVERecord?id=CVE-2022-1771
Référence CVE CVE-2022-1886
https://www.cve.org/CVERecord?id=CVE-2022-1886
Référence CVE CVE-2022-1897
https://www.cve.org/CVERecord?id=CVE-2022-1897
Référence CVE CVE-2022-2000
https://www.cve.org/CVERecord?id=CVE-2022-2000
Référence CVE CVE-2022-2042
https://www.cve.org/CVERecord?id=CVE-2022-2042
Référence CVE CVE-2022-46908
https://www.cve.org/CVERecord?id=CVE-2022-46908
Référence CVE CVE-2022-48624
https://www.cve.org/CVERecord?id=CVE-2022-48624
Référence CVE CVE-2023-28531
https://www.cve.org/CVERecord?id=CVE-2023-28531
Référence CVE CVE-2023-2953
https://www.cve.org/CVERecord?id=CVE-2023-2953
Référence CVE CVE-2023-39804
https://www.cve.org/CVERecord?id=CVE-2023-39804
Référence CVE CVE-2023-46218
https://www.cve.org/CVERecord?id=CVE-2023-46218
Référence CVE CVE-2023-46219
https://www.cve.org/CVERecord?id=CVE-2023-46219
Référence CVE CVE-2023-46246
https://www.cve.org/CVERecord?id=CVE-2023-46246
Référence CVE CVE-2023-4641
https://www.cve.org/CVERecord?id=CVE-2023-4641
Référence CVE CVE-2023-4806
https://www.cve.org/CVERecord?id=CVE-2023-4806
Référence CVE CVE-2023-4813
https://www.cve.org/CVERecord?id=CVE-202
Official advisoryCERT-FR · French · CERTFR-2023-AVI-1015Multiples vulnérabilités dans les produits Siemensd?id=CVE-2023-26604
Référence CVE CVE-2023-27371
https://www.cve.org/CVERecord?id=CVE-2023-27371
Référence CVE CVE-2023-27533
https://www.cve.org/CVERecord?id=CVE-2023-27533
Référence CVE CVE-2023-27534
https://www.cve.org/CVERecord?id=CVE-2023-27534
Référence CVE CVE-2023-27535
https://www.cve.org/CVERecord?id=CVE-2023-27535
Référence CVE CVE-2023-27536
https://www.cve.org/CVERecord?id=CVE-2023-27536
Référence CVE CVE-2023-27537
https://www.cve.org/CVERecord?id=CVE-2023-27537
Référence CVE CVE-2023-27538
https://www.cve.org/CVERecord?id=CVE-2023-27538
Référence CVE CVE-2023-28484
https://www.cve.org/CVERecord?id=CVE-2023-28484
Référence CVE CVE-2023-28531
https://www.cve.org/CVERecord?id=CVE-2023-28531
Référence CVE CVE-2023-28831
https://www.cve.org/CVERecord?id=CVE-2023-28831
Référence CVE CVE-2023-29383
https://www.cve.org/CVERecord?id=CVE-2023-29383
Référence CVE CVE-2023-29469
https://www.cve.org/CVERecord?id=CVE-2023-29469
Référence CVE CVE-2023-29491
https://www.cve.org/CVERecord?id=CVE-2023-29491
Référence CVE CVE-2023-29499
https://www.cve.org/CVERecord?id=CVE-2023-29499
Référence CVE CVE-2023-2953
https://www.cve.org/CVERecord?id=CVE-2023-2953
Référence CVE CVE-2023-30901
https://www.cve.org/CVERecord?id=CVE-2023-30901
Référence CVE CVE-2023-31085
https://www.cve.org/CVERecord?id=CV
Official advisoryNBSZ-NKI · Hungarian · cve-2023-28531CVE-2023-28531Kritikus
Official advisoryNCSC-NL · Dutch · NCSC-2025-0187Kwetsbaarheden verholpen in Siemens productenDe kwetsbaarheden stellen een kwaadwillende mogelijk in staat aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade:
- Denial-of-Service (DoS)
- Manipulatie van gegevens
- Omzeilen van een beveiligingsmaatregel
- Omzeilen van authenticatie
- (Remote) code execution (root/admin rechten)
- (Remote) code execution (Gebruikersrechten)
- Toegang tot systeemgegevens
- Toegang tot gevoelige gegevens
- Spoofing
De kwaadwillende heeft hiervoor toegang nodig tot de productieomgeving. Het is goed gebruik een dergelijke omgeving niet publiek toegankelijk te hebben.
Official advisory