ENISA EUVD · EUVD-2023-56106Official EUVD mapping0 linked advisory records.
Official EUVD recordBSI · German · WID-SEC-W-2024-3140Juniper JUNOS: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Juniper JUNOS ausnutzen, um Denial-of-Service-Zustände herbeizuführen, Informationen preiszugeben, Code auszuführen, Privilegien zu erweitern und Sicherheitsmechanismen zu umgehen.
Official advisoryBSI · German · WID-SEC-W-2024-1248Xerox FreeFlow Print Server: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Xerox FreeFlow Print Server ausnutzen, um die Vertraulichkeit, Verfügbarkeit und Integrität des Systems zu gefährden
Official advisoryBSI · German · WID-SEC-W-2024-1082Juniper JUNOS: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Juniper JUNOS im Zusammenhang mit OpenSSH ausnutzen, um Sicherheitsmaßnahmen zu umgehen, beliebigen Code auszuführen oder Dateien zu manipulieren.
Official advisoryBSI · German · WID-SEC-W-2024-0578Apple macOS: Mehrere SchwachstellenEin entfernter anonymer Angreifer kann mehrere Schwachstellen in Apple macOS ausnutzen, um vertrauliche Informationen offenzulegen, Dateien zu manipulieren, einen Denial-of-Service-Zustand zu verursachen, beliebigen Code auszuführen, seine Privilegien zu erweitern oder Sicherheitsmaßnahmen zu umgehen.
Official advisoryBSI · German · WID-SEC-W-2024-1781Aruba ArubaOS: Mehrere Schwachstellen ermöglichen Codeausführung und DOSEin entfernter, anonymer Angreifer kann mehrere Schwachstellen in Aruba ArubaOS ausnutzen, um beliebigen Programmcode auszuführen und einen Denial-of-Service-Zustand zu erzeugen.
Official advisoryBSI · German · WID-SEC-W-2024-1701Aruba EdgeConnect: Mehrere SchwachstellenEin entfernter Angreifer kann mehrere Schwachstellen in Aruba EdgeConnect ausnutzen, um beliebigen Code auszuführen oder um Sicherheitsmaßnahmen zu umgehen.
Official advisoryBSI · German · WID-SEC-W-2023-3182OpenSSH: Mehrere Schwachstellen ermöglichen Offenlegung von InformationenEin Angreifer kann mehrere Schwachstellen in OpenSSH ausnutzen, um Informationen offenzulegen.
Official advisoryCERT-FR · French · CERTFR-2025-AVI-0969Multiples vulnérabilités dans les produits VMwareord?id=CVE-2023-48795
Référence CVE CVE-2023-49083
https://www.cve.org/CVERecord?id=CVE-2023-49083
Référence CVE CVE-2023-4911
https://www.cve.org/CVERecord?id=CVE-2023-4911
Référence CVE CVE-2023-49582
https://www.cve.org/CVERecord?id=CVE-2023-49582
Référence CVE CVE-2023-50495
https://www.cve.org/CVERecord?id=CVE-2023-50495
Référence CVE CVE-2023-50782
https://www.cve.org/CVERecord?id=CVE-2023-50782
Référence CVE CVE-2023-50868
https://www.cve.org/CVERecord?id=CVE-2023-50868
Référence CVE CVE-2023-51074
https://www.cve.org/CVERecord?id=CVE-2023-51074
Référence CVE CVE-2023-51384
https://www.cve.org/CVERecord?id=CVE-2023-51384
Référence CVE CVE-2023-51385
https://www.cve.org/CVERecord?id=CVE-2023-51385
Référence CVE CVE-2023-5156
https://www.cve.org/CVERecord?id=CVE-2023-5156
Référence CVE CVE-2023-51767
https://www.cve.org/CVERecord?id=CVE-2023-51767
Référence CVE CVE-2023-51792
https://www.cve.org/CVERecord?id=CVE-2023-51792
Référence CVE CVE-2023-52425
https://www.cve.org/CVERecord?id=CVE-2023-52425
Référence CVE CVE-2023-52426
https://www.cve.org/CVERecord?id=CVE-2023-52426
Référence CVE CVE-2023-52593
https://www.cve.org/CVERecord?id=CVE-2023-52593
Référence CVE CVE-2023-52969
https://www.cve.org/CVERecord?id=CVE-2023-52969
Référence CVE CVE-2023-52970
https://www.cve.org/CVERecord?id=CV
Official advisoryCERT-FR · French · CERTFR-2025-AVI-0492Multiples vulnérabilités dans les produits SiemensS01-4AR3) versions antérieures à V3.1
SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3) versions antérieures à V3.2
SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3) versions antérieures à V3.1
SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3) versions antérieures à V3.2
SIMATIC S7-1500 versions supérieures ou égales àV3.1.5 pour les vulnérabilités CVE-2021-41617, CVE-2023-4527, CVE-2023-4806, CVE-2023-4911, CVE-2023-5363, CVE-2023-6246, CVE-2023-6779, CVE-2023-6780, CVE-2023-28531, CVE-2023-38545, CVE-2023-38546, CVE-2023-44487, CVE-2023-46218, CVE-2023-46219, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2023-52927, CVE-2024-2961, CVE-2024-6119, CVE-2024-6387, CVE-2024-12133, CVE-2024-12243, CVE-2024-24855, CVE-2024-26596, CVE-2024-28085, CVE-2024-33599, CVE-2024-33600, CVE-2024-33601, CVE-2024-33602, CVE-2024-34397, CVE-2024-37370, CVE-2024-37371, CVE-2024-45490, CVE-2024-45491, CVE-2024-45492, CVE-2024-50246, CVE-2024-53166, CVE-2024-57977, CVE-2024-57996, CVE-2024-58005, CVE-2025-4373, CVE-2025-4598, CVE-2025-21701, CVE-2025-21702, CVE-2025-21712, CVE-2025-21724, CVE-2025-21728, CVE-2025-21745, CVE-2025-21756, CVE-2025-21758, CVE-2025-21765, CVE-2025-21766, CVE-2025-21767, CVE-2025-21795, CVE-2025-21796, CVE-2025-21848, CVE-2025-2186
Official advisoryCERT-FR · French · CERTFR-2025-AVI-0113Multiples vulnérabilités dans les produits Siemensecord?id=CVE-2023-43522
Référence CVE CVE-2023-44320
https://www.cve.org/CVERecord?id=CVE-2023-44320
Référence CVE CVE-2023-44322
https://www.cve.org/CVERecord?id=CVE-2023-44322
Référence CVE CVE-2023-45853
https://www.cve.org/CVERecord?id=CVE-2023-45853
Référence CVE CVE-2023-45863
https://www.cve.org/CVERecord?id=CVE-2023-45863
Référence CVE CVE-2023-4623
https://www.cve.org/CVERecord?id=CVE-2023-4623
Référence CVE CVE-2023-48795
https://www.cve.org/CVERecord?id=CVE-2023-48795
Référence CVE CVE-2023-4921
https://www.cve.org/CVERecord?id=CVE-2023-4921
Référence CVE CVE-2023-51384
https://www.cve.org/CVERecord?id=CVE-2023-51384
Référence CVE CVE-2023-51385
https://www.cve.org/CVERecord?id=CVE-2023-51385
Référence CVE CVE-2023-5363
https://www.cve.org/CVERecord?id=CVE-2023-5363
Référence CVE CVE-2023-5678
https://www.cve.org/CVERecord?id=CVE-2023-5678
Référence CVE CVE-2023-5717
https://www.cve.org/CVERecord?id=CVE-2023-5717
Référence CVE CVE-2023-6129
https://www.cve.org/CVERecord?id=CVE-2023-6129
Référence CVE CVE-2023-6237
https://www.cve.org/CVERecord?id=CVE-2023-6237
Référence CVE CVE-2023-7250
https://www.cve.org/CVERecord?id=CVE-2023-7250
Référence CVE CVE-2024-0727
https://www.cve.org/CVERecord?id=CVE-2024-0727
Référence CVE CVE-2024-23814
https://www.cve.org/CVERecord?id=CVE-2024-23814
Official advisoryCERT-FR · French · CERTFR-2024-AVI-0866Multiples vulnérabilités dans les produits Juniper Networks4.4R1, 22.2R3-S5-EVO, 22.3R3-S4-EVO, 24.2R2-EVO et 24.4R1-EVO
Résumé
De multiples vulnérabilités ont été découvertes dans les produits Juniper Networks. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
Solutions
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).
Documentation
Bulletin de sécurité Juniper Networks JSA88097 du 09 octobre 2024
https://supportportal.juniper.net/s/article/2024-10-Security-Bulletin-Junos-Space-OS-command-injection-vulnerability-in-OpenSSH-CVE-2023-51385
Bulletin de sécurité Juniper Networks JSA88099 du 09 octobre 2024
https://supportportal.juniper.net/s/article/2024-10-Security-Bulletin-Junos-OS-and-Junos-OS-Evolved-With-BGP-traceoptions-enabled-receipt-of-specially-crafted-BGP-update-causes-RPD-crash-CVE-2024-39515
Bulletin de sécurité Juniper Networks JSA88102 du 09 octobre 2024
https://supportportal.juniper.net/s/article/2024-10-Security-Bulletin-Junos-OS-and-Junos-OS-Evolved-When-BGP-nexthop-traceoptions-is-enabled-receipt-of-specially-crafted-BGP-packet-causes-RPD-crash-CVE-2024-39525
Bulletin de sécurité Juniper Networks JSA88103 du 09 octobre 2024
https://supportportal.juniper.net/s/
Official advisoryCERT-FR · French · CERTFR-2024-AVI-0657Multiples vulnérabilités dans les produits HPE Aruba NetworkingDe multiples vulnérabilités ont été découvertes dans les produits HPE Aruba Networking. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et un contournement de la politique de sécurité.
Official advisoryCERT-FR · French · CERTFR-2024-AVI-0630Multiples vulnérabilités dans IBM QRadarRecord?id=CVE-2023-3817
Référence CVE CVE-2023-38546
https://www.cve.org/CVERecord?id=CVE-2023-38546
Référence CVE CVE-2023-39615
https://www.cve.org/CVERecord?id=CVE-2023-39615
Référence CVE CVE-2023-40217
https://www.cve.org/CVERecord?id=CVE-2023-40217
Référence CVE CVE-2023-42282
https://www.cve.org/CVERecord?id=CVE-2023-42282
Référence CVE CVE-2023-45133
https://www.cve.org/CVERecord?id=CVE-2023-45133
Référence CVE CVE-2023-4806
https://www.cve.org/CVERecord?id=CVE-2023-4806
Référence CVE CVE-2023-4813
https://www.cve.org/CVERecord?id=CVE-2023-4813
Référence CVE CVE-2023-48795
https://www.cve.org/CVERecord?id=CVE-2023-48795
Référence CVE CVE-2023-51385
https://www.cve.org/CVERecord?id=CVE-2023-51385
Référence CVE CVE-2023-5156
https://www.cve.org/CVERecord?id=CVE-2023-5156
Référence CVE CVE-2023-5678
https://www.cve.org/CVERecord?id=CVE-2023-5678
Référence CVE CVE-2023-5981
https://www.cve.org/CVERecord?id=CVE-2023-5981
Référence CVE CVE-2023-6129
https://www.cve.org/CVERecord?id=CVE-2023-6129
Référence CVE CVE-2024-0553
https://www.cve.org/CVERecord?id=CVE-2024-0553
Référence CVE CVE-2024-0567
https://www.cve.org/CVERecord?id=CVE-2024-0567
Référence CVE CVE-2024-27088
https://www.cve.org/CVERecord?id=CVE-2024-27088
Référence CVE CVE-2024-27982
https://www.cve.org/CVERecord?id=CVE-2024-279
Official advisoryCERT-FR · French · CERTFR-2024-AVI-0620Multiples vulnérabilités dans les produits HPE Aruba NetworkingDe multiples vulnérabilités ont été découvertes dans les produits HPE Aruba Networking. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une atteinte à la confidentialité des données et une injection de code indirecte à distance (XSS).
Official advisoryCERT-FR · French · CERTFR-2024-AVI-0585Multiples vulnérabilités dans les produits VMwared?id=CVE-2023-48233
Référence CVE CVE-2023-48234
https://www.cve.org/CVERecord?id=CVE-2023-48234
Référence CVE CVE-2023-48235
https://www.cve.org/CVERecord?id=CVE-2023-48235
Référence CVE CVE-2023-48236
https://www.cve.org/CVERecord?id=CVE-2023-48236
Référence CVE CVE-2023-48237
https://www.cve.org/CVERecord?id=CVE-2023-48237
Référence CVE CVE-2023-48706
https://www.cve.org/CVERecord?id=CVE-2023-48706
Référence CVE CVE-2023-48795
https://www.cve.org/CVERecord?id=CVE-2023-48795
Référence CVE CVE-2023-50495
https://www.cve.org/CVERecord?id=CVE-2023-50495
Référence CVE CVE-2023-51384
https://www.cve.org/CVERecord?id=CVE-2023-51384
Référence CVE CVE-2023-51385
https://www.cve.org/CVERecord?id=CVE-2023-51385
Référence CVE CVE-2023-5156
https://www.cve.org/CVERecord?id=CVE-2023-5156
Référence CVE CVE-2023-52425
https://www.cve.org/CVERecord?id=CVE-2023-52425
Référence CVE CVE-2023-5341
https://www.cve.org/CVERecord?id=CVE-2023-5341
Référence CVE CVE-2023-5678
https://www.cve.org/CVERecord?id=CVE-2023-5678
Référence CVE CVE-2023-5981
https://www.cve.org/CVERecord?id=CVE-2023-5981
Référence CVE CVE-2023-6004
https://www.cve.org/CVERecord?id=CVE-2023-6004
Référence CVE CVE-2023-6129
https://www.cve.org/CVERecord?id=CVE-2023-6129
Référence CVE CVE-2023-6237
https://www.cve.org/CVERecord?id=CVE-2023-6237
Official advisoryCERT-FR · French · CERTFR-2024-AVI-0506Multiples vulnérabilités dans Juniper Secure Analyticscord?id=CVE-2023-4732
Référence CVE CVE-2023-48795
https://www.cve.org/CVERecord?id=CVE-2023-48795
Référence CVE CVE-2023-4921
https://www.cve.org/CVERecord?id=CVE-2023-4921
Référence CVE CVE-2023-50387
https://www.cve.org/CVERecord?id=CVE-2023-50387
Référence CVE CVE-2023-50868
https://www.cve.org/CVERecord?id=CVE-2023-50868
Référence CVE CVE-2023-50960
https://www.cve.org/CVERecord?id=CVE-2023-50960
Référence CVE CVE-2023-50961
https://www.cve.org/CVERecord?id=CVE-2023-50961
Référence CVE CVE-2023-51042
https://www.cve.org/CVERecord?id=CVE-2023-51042
Référence CVE CVE-2023-51043
https://www.cve.org/CVERecord?id=CVE-2023-51043
Référence CVE CVE-2023-51385
https://www.cve.org/CVERecord?id=CVE-2023-51385
Référence CVE CVE-2023-51779
https://www.cve.org/CVERecord?id=CVE-2023-51779
Référence CVE CVE-2023-5178
https://www.cve.org/CVERecord?id=CVE-2023-5178
Référence CVE CVE-2023-51780
https://www.cve.org/CVERecord?id=CVE-2023-51780
Référence CVE CVE-2023-52340
https://www.cve.org/CVERecord?id=CVE-2023-52340
Référence CVE CVE-2023-52425
https://www.cve.org/CVERecord?id=CVE-2023-52425
Référence CVE CVE-2023-52434
https://www.cve.org/CVERecord?id=CVE-2023-52434
Référence CVE CVE-2023-52448
https://www.cve.org/CVERecord?id=CVE-2023-52448
Référence CVE CVE-2023-52489
https://www.cve.org/CVERecord?id=CV
Official advisoryCERT-FR · French · CERTFR-2024-AVI-0479Multiples vulnérabilités dans HPE Aruba Networking AirWave Management PlatformDe multiples vulnérabilités ont été découvertes dans HPE Aruba Networking AirWave Management Platform. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.
Official advisoryCERT-FR · French · CERTFR-2024-AVI-0305Multiples vulnérabilités dans les produits IBMd?id=CVE-2023-45648
Référence CVE CVE-2023-45803
https://www.cve.org/CVERecord?id=CVE-2023-45803
Référence CVE CVE-2023-45857
https://www.cve.org/CVERecord?id=CVE-2023-45857
Référence CVE CVE-2023-46218
https://www.cve.org/CVERecord?id=CVE-2023-46218
Référence CVE CVE-2023-46234
https://www.cve.org/CVERecord?id=CVE-2023-46234
Référence CVE CVE-2023-46589
https://www.cve.org/CVERecord?id=CVE-2023-46589
Référence CVE CVE-2023-48795
https://www.cve.org/CVERecord?id=CVE-2023-48795
Référence CVE CVE-2023-49083
https://www.cve.org/CVERecord?id=CVE-2023-49083
Référence CVE CVE-2023-50782
https://www.cve.org/CVERecord?id=CVE-2023-50782
Référence CVE CVE-2023-51385
https://www.cve.org/CVERecord?id=CVE-2023-51385
Référence CVE CVE-2023-52426
https://www.cve.org/CVERecord?id=CVE-2023-52426
Référence CVE CVE-2023-5388
https://www.cve.org/CVERecord?id=CVE-2023-5388
Référence CVE CVE-2023-5676
https://www.cve.org/CVERecord?id=CVE-2023-5676
Référence CVE CVE-2023-6135
https://www.cve.org/CVERecord?id=CVE-2023-6135
Référence CVE CVE-2023-6597
https://www.cve.org/CVERecord?id=CVE-2023-6597
Référence CVE CVE-2024-0553
https://www.cve.org/CVERecord?id=CVE-2024-0553
Référence CVE CVE-2024-1597
https://www.cve.org/CVERecord?id=CVE-2024-1597
Référence CVE CVE-2024-20918
https://www.cve.org/CVERecord?id=CVE-2024-209
Official advisoryCERT-FR · French · CERTFR-2024-AVI-0240Multiples vulnérabilités dans les produits IBMERecord?id=CVE-2023-45862
Référence CVE CVE-2023-45871
https://www.cve.org/CVERecord?id=CVE-2023-45871
Référence CVE CVE-2023-4622
https://www.cve.org/CVERecord?id=CVE-2023-4622
Référence CVE CVE-2023-4623
https://www.cve.org/CVERecord?id=CVE-2023-4623
Référence CVE CVE-2023-46813
https://www.cve.org/CVERecord?id=CVE-2023-46813
Référence CVE CVE-2023-47715
https://www.cve.org/CVERecord?id=CVE-2023-47715
Référence CVE CVE-2023-48795
https://www.cve.org/CVERecord?id=CVE-2023-48795
Référence CVE CVE-2023-4921
https://www.cve.org/CVERecord?id=CVE-2023-4921
Référence CVE CVE-2023-51042
https://www.cve.org/CVERecord?id=CVE-2023-51042
Référence CVE CVE-2023-51385
https://www.cve.org/CVERecord?id=CVE-2023-51385
Référence CVE CVE-2023-51780
https://www.cve.org/CVERecord?id=CVE-2023-51780
Référence CVE CVE-2023-52071
https://www.cve.org/CVERecord?id=CVE-2023-52071
Référence CVE CVE-2023-5633
https://www.cve.org/CVERecord?id=CVE-2023-5633
Référence CVE CVE-2023-5717
https://www.cve.org/CVERecord?id=CVE-2023-5717
Référence CVE CVE-2023-6535
https://www.cve.org/CVERecord?id=CVE-2023-6535
Référence CVE CVE-2023-6536
https://www.cve.org/CVERecord?id=CVE-2023-6536
Référence CVE CVE-2023-6606
https://www.cve.org/CVERecord?id=CVE-2023-6606
Référence CVE CVE-2023-6610
https://www.cve.org/CVERecord?id=CVE-2023-66
Official advisoryCERT-FR · French · CERTFR-2024-AVI-0194Multiples vulnérabilités dans les produits Applesécurité Apple HT214085 du 07 mars 2024
https://support.apple.com/en-us/HT214085
Bulletin de sécurité Apple HT214089 du 07 mars 2024
https://support.apple.com/en-us/HT214089
Référence CVE CVE-2022-42816
https://www.cve.org/CVERecord?id=CVE-2022-42816
Référence CVE CVE-2022-48554
https://www.cve.org/CVERecord?id=CVE-2022-48554
Référence CVE CVE-2023-28826
https://www.cve.org/CVERecord?id=CVE-2023-28826
Référence CVE CVE-2023-42853
https://www.cve.org/CVERecord?id=CVE-2023-42853
Référence CVE CVE-2023-48795
https://www.cve.org/CVERecord?id=CVE-2023-48795
Référence CVE CVE-2023-51384
https://www.cve.org/CVERecord?id=CVE-2023-51384
Référence CVE CVE-2023-51385
https://www.cve.org/CVERecord?id=CVE-2023-51385
Référence CVE CVE-2024-0258
https://www.cve.org/CVERecord?id=CVE-2024-0258
Référence CVE CVE-2024-23201
https://www.cve.org/CVERecord?id=CVE-2024-23201
Référence CVE CVE-2024-23203
https://www.cve.org/CVERecord?id=CVE-2024-23203
Référence CVE CVE-2024-23204
https://www.cve.org/CVERecord?id=CVE-2024-23204
Référence CVE CVE-2024-23205
https://www.cve.org/CVERecord?id=CVE-2024-23205
Référence CVE CVE-2024-23216
https://www.cve.org/CVERecord?id=CVE-2024-23216
Référence CVE CVE-2024-23217
https://www.cve.org/CVERecord?id=CVE-2024-23217
Référence CVE CVE-2024-23218
https://www.cve.org/CVERecord?id=CV
Official advisoryCERT-FR · French · CERTFR-2024-AVI-0180Multiples vulnérabilités dans les produits IBMd?id=CVE-2023-44487
Référence CVE CVE-2023-45133
https://www.cve.org/CVERecord?id=CVE-2023-45133
Référence CVE CVE-2023-45857
https://www.cve.org/CVERecord?id=CVE-2023-45857
Référence CVE CVE-2023-46158
https://www.cve.org/CVERecord?id=CVE-2023-46158
Référence CVE CVE-2023-46234
https://www.cve.org/CVERecord?id=CVE-2023-46234
Référence CVE CVE-2023-46604
https://www.cve.org/CVERecord?id=CVE-2023-46604
Référence CVE CVE-2023-48795
https://www.cve.org/CVERecord?id=CVE-2023-48795
Référence CVE CVE-2023-50324
https://www.cve.org/CVERecord?id=CVE-2023-50324
Référence CVE CVE-2023-51384
https://www.cve.org/CVERecord?id=CVE-2023-51384
Référence CVE CVE-2023-51385
https://www.cve.org/CVERecord?id=CVE-2023-51385
Référence CVE CVE-2023-5676
https://www.cve.org/CVERecord?id=CVE-2023-5676
Gestion détaillée du document
le 01 mars 2024
Version initiale
Alertes
Avis
Bulletins d’actualités
Mentions légales
Conditions générales
À propos
Contact
cyber.gouv.fr
service-public.fr
legifrance.gouv.fr
info.gouv.fr
france.fr
info.gouv.fr/risques
Premier Ministre / Secrétariat Général de la Défense et de la Sécurité Nationale / Agence nationale de la
sécurité des systèmes d'information
Official advisoryCERT-FR · French · CERTFR-2024-AVI-0001Vulnérabilité dans StormShield Network SecurityUne vulnérabilité a été découverte dans StormShield Stormshield Network
Security. Elle permet à un attaquant de provoquer un contournement de la
politique de sécurité.
Official advisoryCERT-FR · French · CERTFR-2023-AVI-1044Multiples vulnérabilités dans OpenSSHDe multiples vulnérabilités ont été découvertes dans OpenSSH. Elles
permettent à un attaquant de provoquer une exécution de code arbitraire
à distance, une atteinte à l'intégrité des données, un déni de service à
distance et un contournement de la politique de sécurité.
Official advisoryNBSZ-NKI · Hungarian · cve-2023-51385CVE-2023-51385Kritikus
Official advisoryNCSC-NL · Dutch · NCSC-2024-0325Kwetsbaarheden verholpen in Aruba Networks ArubaOS en InstantOSEen kwaadwillende kan de kwetsbaarheden misbruiken om een Denial-of-Service te veroorzaken, of om willekeurige code uit te voeren op het kwetsbare systeem.
Succesvol misbruik vereist dat de kwaadwillende toegang heeft tot de PAPI-poort, of de SSH-poort. Beide poorten zijn onder normale omstandigheden niet publiek toegankelijk.
Official advisoryNCSC-NL · Dutch · NCSC-2025-0187Kwetsbaarheden verholpen in Siemens productenDe kwetsbaarheden stellen een kwaadwillende mogelijk in staat aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade:
- Denial-of-Service (DoS)
- Manipulatie van gegevens
- Omzeilen van een beveiligingsmaatregel
- Omzeilen van authenticatie
- (Remote) code execution (root/admin rechten)
- (Remote) code execution (Gebruikersrechten)
- Toegang tot systeemgegevens
- Toegang tot gevoelige gegevens
- Spoofing
De kwaadwillende heeft hiervoor toegang nodig tot de productieomgeving. Het is goed gebruik een dergelijke omgeving niet publiek toegankelijk te hebben.
Official advisoryNCSC-NL · Dutch · NCSC-2025-0061Kwetsbaarheden verholpen in Siemens productenDe kwetsbaarheden stellen een kwaadwillende mogelijk in staat aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade:
- Denial-of-Service (DoS)
- Cross-Site-Scripting (XSS)
- Cross-Site Request Forgery (CSRF)
- Manipulatie van gegevens
- Omzeilen van een beveiligingsmaatregel
- Omzeilen van authenticatie
- (Remote) code execution (root/admin rechten)
- (Remote) code execution (Gebruikersrechten)
- Toegang tot systeemgegevens
- Toegang tot gevoelige gegevens
De kwaadwillende heeft hiervoor toegang nodig tot de productieomgeving. Het is goed gebruik een dergelijke omgeving niet publiek toegankelijk te hebben.
Official advisoryNCSC-NL · Dutch · NCSC-2025-0051Kwetsbaarheden verholpen in Siemens productenDe kwetsbaarheden stellen een kwaadwillende mogelijk in staat aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade:
- Denial-of-Service (DoS)
- Cross-Site-Scripting (XSS)
- Cross-Site Request Forgery (CSRF)
- Manipulatie van gegevens
- Omzeilen van een beveiligingsmaatregel
- Omzeilen van authenticatie
- (Remote) code execution (root/admin rechten)
- (Remote) code execution (Gebruikersrechten)
- Toegang tot systeemgegevens
- Toegang tot gevoelige gegevens
De kwaadwillende heeft hiervoor toegang nodig tot de productieomgeving. Het is goed gebruik een dergelijke omgeving niet publiek toegankelijk te hebben.
Official advisoryNCSC-NL · Dutch · NCSC-2024-0411Kwetsbaarheden verholpen in Oracle Database productenEen kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade:
- Denial-of-Service (DoS)
- Manipuleren van data
- Toegang tot gevoelige gegevens
Official advisory