BlackTreeCVE Intelligence
← Back to the CVE catalogue
Full vulnerability report · 2024
CVE-2024-6119High confidence

Possible denial of service in X.509 name checks

OpenSSL · OpenSSL

7.5HighCVSS 3.1
Recommended action
Patch only the product branches with a verified fix

High technical severity; prioritise exposed affected systems while verifying vendor guidance. Verified remediation exists for at least one product or source, but 26 structured product or package states remain unresolved. Apply remediation only to the exact product branch confirmed by its source.

Fix availability varies by product
R
Operational reassessment

Published severity in operational context

Open reassessment dashboard →
Published severityHighOperational priority:Critical, raised one band.upgradedsince 5 Oct 2026

Evidence used

  • No CISA KEV confirmation is currently recorded.
  • The selected CVSS metric records a network-reachable, unauthenticated path with no user interaction.
  • EPSS is 66.58% for the current model date.

Compensating controls

  • Validate the affected product branch and deploy the verified fixed release.
  • Restrict the affected network interface to trusted sources where business-safe.
  • Monitor vendor guidance and exploitation sources for a material change.

Verification

  1. Confirm that the asset runs OpenSSL OpenSSL and falls inside the recorded affected range.
  2. Verify the installed build against the product-specific fixed version after deployment.
  3. Validate exposure, authentication requirements and compensating controls in the actual environment.
  4. Reopen this reassessment when CVSS, KEV, EPSS, exploit evidence or remediation changes.
Mitigation target: Within 3 daysRemediation target: Within 90 days

This automated reassessment organises public evidence. It does not know asset exposure, business impact or control effectiveness and does not replace CVSS or a human risk decision.

Cross-source reconciliation

Remediation availability differs by product scope

Verified remediation exists for at least one product or source, but 26 structured product or package states remain unresolved. Apply remediation only to the exact product branch confirmed by its source.

Distribution package intelligence

Release-specific package status

Alpine, Debian, ubuntu findings are scoped to the named distribution, release and source package. An absent finding does not mean a package is unaffected.

9 package states
Repository candidate not checked

A published vendor fix does not prove that a matching update is enabled and installable on a particular asset. Confirm the local package candidate before scheduling remediation.

Distribution releaseSource packageVendor stateFixed versionEvidence
Alpine v3.23v3.23 · mainopensslVendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.3.3.2-r0Alpine Security Database ↗Source updated 3 Oct 2026
Alpine v3.22v3.22 · mainopensslVendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.3.3.2-r0Alpine Security Database ↗Source updated 3 Oct 2026
Alpine v3.21v3.21 · mainopensslVendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.3.3.2-r0Alpine Security Database ↗Source updated 3 Oct 2026
Debian trixietrixie · sourceopensslVendor fix publishedDebian records a fixed source-package version for this release.3.3.2-1Debian Security Tracker ↗Source updated 5 Oct 2026
Debian bookwormbookworm · sourceopensslVendor fix publishedDebian records a fixed source-package version for this release.3.0.14-1~deb12u2Debian Security Tracker ↗Source updated 5 Oct 2026
Debian forkyforky · sourceopensslVendor fix publishedDebian records a fixed source-package version for this release.3.3.2-1Debian Security Tracker ↗Source updated 5 Oct 2026
Debian sidsid · sourceopensslVendor fix publishedDebian records a fixed source-package version for this release.3.3.2-1Debian Security Tracker ↗Source updated 5 Oct 2026
Ubuntu 24.04 LTSnoble · standard archiveedk2Vendor fix publishedCanonical reports that a fixed source package version has been published. Repository candidate availability is not checked by BlackTree.2024.02-2ubuntu0.6Canonical Ubuntu Security ↗Source updated 5 Oct 2026
Ubuntu 24.04 LTSnoble · standard archiveopensslVendor fix publishedCanonical reports that a fixed source package version has been published. Repository candidate availability is not checked by BlackTree.3.0.13-0ubuntu3.4Canonical Ubuntu Security ↗Source updated 5 Oct 2026
Direct vendor intelligence

Authoritative vendor CSAF and VEX advisories

Structured product status and remediation from the issuing vendor. Product-state explanations are always visible; large lists can be searched or downloaded.

5 current
CVE-2024-6119 · CSAF 2.0 · revision 57 · interimSUSE Product Security TeamCVE-2024-6119
15 known affected

The vendor explicitly identifies these products as affected by this CVE.

  • SLES 15 SP1 CHOST Images for Amazon EC2
  • SLES 15 SP2 CHOST Images for Amazon EC2
  • SLES 15 SP3 CHOST Images for Amazon EC2
  • SLES 15 SP4 CHOST Images for Amazon EC2
  • SLES 15 SP5 CHOST Images for Amazon EC2
  • SLES 15 SP1 CHOST Images for Google
  • SLES 15 SP2 CHOST Images for Google
  • SLES 15 SP3 CHOST Images for Google
  • SLES 15 SP4 CHOST Images for Google
  • SLES 15 SP5 CHOST Images for Google
  • SLES 15 SP1 CHOST Images for Microsoft Azure
  • SLES 15 SP2 CHOST Images for Microsoft Azure
Summary
Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process. Impact summary: Abnormal termination of an application can a cause a denial of service. Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address when comparing the expected name with an `otherName` subject alternative name of an X.509 certificate. This may result in an exception that terminates the application program. Note that basic certificate chain validation (signatures, dates, ...) is not affected, the denial of service can occur only when the application also specifies an expected DNS name, Email address or IP address. TLS servers rarely solicit client certificates, and even when they do, they generally don't perform a name check against a reference identifier (expected identity), but rather extract the presented identity after checking the certificate chain. So TLS servers are generally not affected and the severity of the issue is Moderate. The FIPS modules in 3.3, 3.2, 3.1 and 3.0 are not affected by this issue.
Remediation
To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
CVE-2024-6119 · CSAF 2.0 · revision 3 · finalRed Hat Product Securityopenssl: Possible denial of service in X.509 name checks
20 known affected

The vendor explicitly identifies these products as affected by this CVE.

  • 3scale-amp-backend-container as a component of Red Hat 3scale API Management Platform 2
  • openssl as a component of Red Hat Enterprise Linux 6
  • openssl-devel as a component of Red Hat Enterprise Linux 6
  • openssl-perl as a component of Red Hat Enterprise Linux 6
  • openssl-static as a component of Red Hat Enterprise Linux 6
  • openssl.src as a component of Red Hat Enterprise Linux 6
  • AAVMF as a component of Red Hat Enterprise Linux 7
  • OVMF as a component of Red Hat Enterprise Linux 7
  • openssl as a component of Red Hat Enterprise Linux 7
  • openssl-devel as a component of Red Hat Enterprise Linux 7
  • openssl-libs as a component of Red Hat Enterprise Linux 7
  • openssl-perl as a component of Red Hat Enterprise Linux 7
Summary
A flaw was found in OpenSSL. Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process.
Remediation
For OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.16/release_notes/ocp-4-16-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:bd78fab2d62370a0a051c4284239c81e97304cf4cc63b97c194b7a9e1ff3235d (For s390x architecture) The image digest is sha256:31016c82002f5facebac2579b5f74d564f05a22f3c1d09fcec7b5271fdc25d41 (For ppc64le architecture) The image digest is sha256:8f5b445a0c6ead7efcc437219a5e0c84bcc39c7845f517079cecf86ba3ce3408 (For aarch64 architecture) The image digest is sha256:a56716b3f6cc89ae530684346c3b47816b11c717bfe51c038af7163f138ccdab All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.16/updating/updating_a_cluster/updating-cluster-cli.html
SSA-082556 · CSAF 2.0 · revision 7 · interimSiemens ProductCERTSSA-082556: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.5
5 known affected

The vendor explicitly identifies these products as affected by this CVE.

  • SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) >= V3.1.5
  • SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) >= V3.1.5
  • SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) >= V3.1.5
  • SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) >= V3.1.5
  • SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) >= V3.1.5
Summary
Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process. Impact summary: Abnormal termination of an application can a cause a denial of service. Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address when comparing the expected name with an `otherName` subject alternative name of an X.509 certificate. This may result in an exception that terminates the application program. Note that basic certificate chain validation (signatures, dates, ...) is not affected, the denial of service can occur only when the application also specifies an expected DNS name, Email address or IP address. TLS servers rarely solicit client certificates, and even when they do, they generally don't perform a name check against a reference identifier (expected identity), but rather extract the presented identity after checking the certificate chain. So TLS servers are generally not affected and the severity of the issue is Moderate. The FIPS modules in 3.3, 3.2, 3.1 and 3.0 are not affected by this issue.
Remediation
Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.
SSA-613116 · CSAF 2.0 · revision 3 · interimSiemens ProductCERTSSA-613116: Multiple Vulnerabilities in Third-Party Components in SINEC OS before V3.1
2 known affected

The vendor explicitly identifies these products as affected by this CVE.

  • RUGGEDCOM RST2428P (6GK6242-6PA00)
  • SCALANCE XCM-/XRM-/XCH-/XRH-300 family
Summary
Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process. Impact summary: Abnormal termination of an application can a cause a denial of service. Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address when comparing the expected name with an `otherName` subject alternative name of an X.509 certificate. This may result in an exception that terminates the application program. Note that basic certificate chain validation (signatures, dates, ...) is not affected, the denial of service can occur only when the application also specifies an expected DNS name, Email address or IP address. TLS servers rarely solicit client certificates, and even when they do, they generally don't perform a name check against a reference identifier (expected identity), but rather extract the presented identity after checking the certificate chain. So TLS servers are generally not affected and the severity of the issue is Moderate. The FIPS modules in 3.3, 3.2, 3.1 and 3.0 are not affected by this issue.
Remediation
Update to V3.1 or later version
SSA-769027 · CSAF 2.0 · revision 1 · interimSiemens ProductCERTSSA-769027: Multiple Vulnerabilities fixed in SCALANCE W700 IEEE 802.11ax devices before V3.0.0
19 known affected

The vendor explicitly identifies these products as affected by this CVE.

  • SCALANCE WAB762-1 (6GK5762-1AJ00-6AA0)
  • SCALANCE WAM763-1 (6GK5763-1AL00-7DA0)
  • SCALANCE WAM763-1 (ME) (6GK5763-1AL00-7DC0)
  • SCALANCE WAM763-1 (US) (6GK5763-1AL00-7DB0)
  • SCALANCE WAM766-1 (6GK5766-1GE00-7DA0)
  • SCALANCE WAM766-1 (ME) (6GK5766-1GE00-7DC0)
  • SCALANCE WAM766-1 (US) (6GK5766-1GE00-7DB0)
  • SCALANCE WAM766-1 EEC (6GK5766-1GE00-7TA0)
  • SCALANCE WAM766-1 EEC (ME) (6GK5766-1GE00-7TC0)
  • SCALANCE WAM766-1 EEC (US) (6GK5766-1GE00-7TB0)
  • SCALANCE WUB762-1 (6GK5762-1AJ00-1AA0)
  • SCALANCE WUB762-1 iFeatures (6GK5762-1AJ00-2AA0)
Summary
Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process. Impact summary: Abnormal termination of an application can a cause a denial of service. Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address when comparing the expected name with an `otherName` subject alternative name of an X.509 certificate. This may result in an exception that terminates the application program. Note that basic certificate chain validation (signatures, dates, ...) is not affected, the denial of service can occur only when the application also specifies an expected DNS name, Email address or IP address. TLS servers rarely solicit client certificates, and even when they do, they generally don't perform a name check against a reference identifier (expected identity), but rather extract the presented identity after checking the certificate chain. So TLS servers are generally not affected and the severity of the issue is Moderate. The FIPS modules in 3.3, 3.2, 3.1 and 3.0 are not affected by this issue.
Remediation
Update to V3.0.0 or later version
Optional official sources

National CERT insights
?CERT means Computer Emergency Response Team; CSIRT is the closely related term Computer Security Incident Response Team.

Choose official national sources for this report. Each advisory shows its original language. Your selection is remembered on this device and included in shared links.

Official European source

ENISA European Vulnerability Database

Official EUVD identifiers, advisory evidence and known-exploited context. Missing fields are not treated as evidence of low risk.

1 current
ENISA EUVD identifier

EUVD-2024-47266

No EUVD known-exploited evidence

ENISA has published the identifier mapping but no EUVD description has been stored yet.

EUVD state
Present in the current official mapping
Known exploitation
Not present in the current ENISA EUVD known-exploited dataset. This is not proof of no exploitation.
ENISA score
Not supplied in the stored EUVD record
Advisory evidence
No linked advisory details stored yet
Recommended actionPatch only the product branches with a verified fix

High technical severity; prioritise exposed affected systems while verifying vendor guidance. Verified remediation exists for at least one product or source, but 26 structured product or package states remain unresolved. Apply remediation only to the exact product branch confirmed by its source.

Fix availability varies by product
01

What, why and how

Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process. Impact summary: Abnormal termination of an application can a cause a denial of service. Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address when comparing the expected name with an `otherName` subject alternative name of an X.509 certificate. This may result in an exception that terminates the application program. Note that basic certificate chain validation (signatures, dates, ...) is not affected, the denial of service can occur only when the application also specifies an expected DNS name, Email address or IP address. TLS servers rarely solicit client certificates, and even when they do, they generally don't perform a name check against a reference identifier (expected identity), but rather extract the presented identity after checking the certificate chain. So TLS servers are generally not affected and the severity of the issue is Moderate. The FIPS modules in 3.3, 3.2, 3.1 and 3.0 are not affected by this issue.

What

Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process. Impact summary: Abnormal termination of an application can a cause a denial of service. Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address when comparing the expected name with an `otherName` subject alternative name of an X.509 certificate. This may result in an exception that terminates the application program. Note that basic certificate chain validation (signatures, dates, ...) is not affected, the denial of service can occur only when the application also specifies an expected DNS name, Email address or IP address. TLS servers rarely solicit client certificates, and even when they do, they generally don't perform a name check against a reference identifier (expected identity), but rather extract the presented identity after checking the certificate chain. So TLS servers are generally not affected and the severity of the issue is Moderate. The FIPS modules in 3.3, 3.2, 3.1 and 3.0 are not affected by this issue.

Why

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

How

An attacker operating through a network path may attempt exploitation without authentication or user interaction. If successful, the issue may disrupt the affected service.

What

Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process. Impact summary: Abnormal termination of an application can a cause a denial of service. Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address when comparing the expected name with an `otherName` subject alternative name of an X.509 certificate. This may result in an exception that terminates the application program. Note that basic certificate chain validation (signatures, dates, ...) is not affected, the denial of service can occur only when the application also specifies an expected DNS name, Email address or IP address. TLS servers rarely solicit client certificates, and even when they do, they generally don't perform a name check against a reference identifier (expected identity), but rather extract the presented identity after checking the certificate chain. So TLS servers are generally not affected and the severity of the issue is Moderate. The FIPS modules in 3.3, 3.2, 3.1 and 3.0 are not affected by this issue.

Why

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

How

An attacker operating through a network path may attempt exploitation without authentication or user interaction. If successful, the issue may disrupt the affected service.

02

Exploit reality and attack path

CVSS severity, EPSS forecast probability, public exploit material and CISA-confirmed exploitation are separate signals.

Observed exploitation
?Confirmed exploitation and public exploit material are separate signals. Attacks can occur without public proof-of-concept or exploit code.
No confirmed evidence

No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.

Public PoC / exploit material
?Confirmed exploitation and public exploit material are separate signals. Attacks can occur without public proof-of-concept or exploit code.
None recorded

No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.

Likely attack path
a network path → Access of Resource Using Incompatible Type ('Type Confusion') → disrupt the affected service
Attack surface
Network
Privileges required
None: unauthenticated exploitation is possible
User interaction
None
Attack complexity
Low: no specialised conditions are recorded
Security boundary
Unchanged: impact remains within the vulnerable component's security authority
Weakness
?CWE means Common Weakness Enumeration: a standard category for the underlying weakness.
CWE-843 ↗

CWE-843: Access of Resource Using Incompatible Type ('Type Confusion'). The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

CVSS vector
?CVSS means Common Vulnerability Scoring System. The vector records the metric values used to calculate technical severity.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Common Vulnerability Scoring System 3.1: the compact vector below is decoded into plain language.

AVNetworkAttack vector: The vulnerable component can be reached over a network.ACLowAttack complexity: No specialised conditions are required beyond attacker-controlled input.PRNonePrivileges required: The attacker does not need an account or existing privileges.UINoneUser interaction: No action by another user is required.SUnchangedScope: The security impact remains within the vulnerable component's authority.CNoneConfidentiality impact: No direct loss is represented by this metric.INoneIntegrity impact: No direct loss is represented by this metric.AHighAvailability impact: A successful attack can cause a major loss.
Post-exploitation / living off the land
No specific living-off-the-land technique is confirmed in the structured sources. Monitor normal administration tools for activity inconsistent with the affected service's baseline.
NetworkUnauthenticatedDenial of serviceCWE-843
A

Official authority intelligence

Only matched European and national findings are included. Language selectors and unavailable sources are omitted.

BSI · German · WID-SEC-2025-0148Oracle Communications: Mehrere Schwachstellen

Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Communications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.

Official advisory ↗
BSI · German · WID-SEC-2025-0001IBM DB2: Mehrere Schwachstellen

Ein entfernter oder lokaler Angreifer kann mehrere Schwachstellen in IBM DB2 on Cloud Pak for Data ausnutzen, um seine Privilegien zu erhöhen, beliebigen Code auszuführen, vertrauliche Informationen offenzulegen, Sicherheitsmaßnahmen zu umgehen oder einen Denial-of-Service-Zustand zu erzeugen.

Official advisory ↗
BSI · German · WID-SEC-2025-0612IBM Security Guardium: Mehrere Schwachstellen

Ein Angreifer kann mehrere Schwachstellen in IBM Security Guardium ausnutzen, um Sicherheitsbeschränkungen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen, beliebigen Code auszuführen und vertrauliche Informationen preiszugeben.

Official advisory ↗
BSI · German · WID-SEC-2024-3201Oracle Database Server: Mehrere Schwachstellen

Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Database Server ausnutzen, um die Integrität und Verfügbarkeit zu gefährden.

Official advisory ↗
BSI · German · WID-SEC-2024-2040OpenSSL: Schwachstelle ermöglicht Denial of Service

Ein entfernter, anonymer Angreifer kann eine Schwachstelle in OpenSSL ausnutzen, um einen Denial of Service Angriff durchzuführen.

Official advisory ↗
Cyber Security Agency of Singapore · English · CSA-SB-20240904Security Bulletin 04 Sep 2024

The Cyber Security Agency of Singapore included this CVE in its official Security Bulletin 04 Sep 2024, published on 4 September 2024. Open the linked bulletin for the product, severity and reference information published in that issue.

Official advisory ↗
CERT-FR · French · CERTFR-2026-AVI-0556Multiples vulnérabilités dans les produits VMware

ERecord?id=CVE-2024-36114 Référence CVE CVE-2024-3651 https://www.cve.org/CVERecord?id=CVE-2024-3651 Référence CVE CVE-2024-37891 https://www.cve.org/CVERecord?id=CVE-2024-37891 Référence CVE CVE-2024-47081 https://www.cve.org/CVERecord?id=CVE-2024-47081 Référence CVE CVE-2024-47535 https://www.cve.org/CVERecord?id=CVE-2024-47535 Référence CVE CVE-2024-47554 https://www.cve.org/CVERecord?id=CVE-2024-47554 Référence CVE CVE-2024-52012 https://www.cve.org/CVERecord?id=CVE-2024-52012 Référence CVE CVE-2024-5535 https://www.cve.org/CVERecord?id=CVE-2024-5535 Référence CVE CVE-2024-5642 https://www.cve.org/CVERecord?id=CVE-2024-5642 Référence CVE CVE-2024-6119 https://www.cve.org/CVERecord?id=CVE-2024-6119 Référence CVE CVE-2024-6763 https://www.cve.org/CVERecord?id=CVE-2024-6763 Référence CVE CVE-2024-7254 https://www.cve.org/CVERecord?id=CVE-2024-7254 Référence CVE CVE-2024-8184 https://www.cve.org/CVERecord?id=CVE-2024-8184 Référence CVE CVE-2024-9143 https://www.cve.org/CVERecord?id=CVE-2024-9143 Référence CVE CVE-2024-9823 https://www.cve.org/CVERecord?id=CVE-2024-9823 Référence CVE CVE-2025-0938 https://www.cve.org/CVERecord?id=CVE-2025-0938 Référence CVE CVE-2025-10158 https://www.cve.org/CVERecord?id=CVE-2025-10158 Référence CVE CVE-2025-1094 https://www.cve.org/CVERecord?id=CVE-2025-1094

Official advisory ↗
CERT-FR · French · CERTFR-2026-AVI-0326Multiples vulnérabilités dans les produits VMware

d?id=CVE-2024-58095 Référence CVE CVE-2024-58096 https://www.cve.org/CVERecord?id=CVE-2024-58096 Référence CVE CVE-2024-58097 https://www.cve.org/CVERecord?id=CVE-2024-58097 Référence CVE CVE-2024-58098 https://www.cve.org/CVERecord?id=CVE-2024-58098 Référence CVE CVE-2024-58100 https://www.cve.org/CVERecord?id=CVE-2024-58100 Référence CVE CVE-2024-58237 https://www.cve.org/CVERecord?id=CVE-2024-58237 Référence CVE CVE-2024-58238 https://www.cve.org/CVERecord?id=CVE-2024-58238 Référence CVE CVE-2024-58241 https://www.cve.org/CVERecord?id=CVE-2024-58241 Référence CVE CVE-2024-58251 https://www.cve.org/CVERecord?id=CVE-2024-58251 Référence CVE CVE-2024-6119 https://www.cve.org/CVERecord?id=CVE-2024-6119 Référence CVE CVE-2024-6345 https://www.cve.org/CVERecord?id=CVE-2024-6345 Référence CVE CVE-2024-6519 https://www.cve.org/CVERecord?id=CVE-2024-6519 Référence CVE CVE-2024-7883 https://www.cve.org/CVERecord?id=CVE-2024-7883 Référence CVE CVE-2024-8354 https://www.cve.org/CVERecord?id=CVE-2024-8354 Référence CVE CVE-2024-8612 https://www.cve.org/CVERecord?id=CVE-2024-8612 Référence CVE CVE-2024-9143 https://www.cve.org/CVERecord?id=CVE-2024-9143 Référence CVE CVE-2025-0012 https://www.cve.org/CVERecord?id=CVE-2025-0012 Référence CVE CVE-2025-0033 https://www.cve.org/CVERecord?id=CVE-2025-0033 Ré

Official advisory ↗
CERT-FR · French · CERTFR-2026-AVI-0316Multiples vulnérabilités dans les produits VMware

d?id=CVE-2024-58095 Référence CVE CVE-2024-58096 https://www.cve.org/CVERecord?id=CVE-2024-58096 Référence CVE CVE-2024-58097 https://www.cve.org/CVERecord?id=CVE-2024-58097 Référence CVE CVE-2024-58098 https://www.cve.org/CVERecord?id=CVE-2024-58098 Référence CVE CVE-2024-58100 https://www.cve.org/CVERecord?id=CVE-2024-58100 Référence CVE CVE-2024-58237 https://www.cve.org/CVERecord?id=CVE-2024-58237 Référence CVE CVE-2024-58238 https://www.cve.org/CVERecord?id=CVE-2024-58238 Référence CVE CVE-2024-58241 https://www.cve.org/CVERecord?id=CVE-2024-58241 Référence CVE CVE-2024-58251 https://www.cve.org/CVERecord?id=CVE-2024-58251 Référence CVE CVE-2024-6119 https://www.cve.org/CVERecord?id=CVE-2024-6119 Référence CVE CVE-2024-6345 https://www.cve.org/CVERecord?id=CVE-2024-6345 Référence CVE CVE-2024-6519 https://www.cve.org/CVERecord?id=CVE-2024-6519 Référence CVE CVE-2024-7883 https://www.cve.org/CVERecord?id=CVE-2024-7883 Référence CVE CVE-2024-8354 https://www.cve.org/CVERecord?id=CVE-2024-8354 Référence CVE CVE-2024-8612 https://www.cve.org/CVERecord?id=CVE-2024-8612 Référence CVE CVE-2024-9143 https://www.cve.org/CVERecord?id=CVE-2024-9143 Référence CVE CVE-2025-0012 https://www.cve.org/CVERecord?id=CVE-2025-0012 Référence CVE CVE-2025-0033 https://www.cve.org/CVERecord?id=CVE-2025-0033 Ré

Official advisory ↗
CERT-FR · French · CERTFR-2026-AVI-0249Multiples vulnérabilités dans les produits IBM

d?id=CVE-2024-50264 Référence CVE CVE-2024-50302 https://www.cve.org/CVERecord?id=CVE-2024-50302 Référence CVE CVE-2024-51479 https://www.cve.org/CVERecord?id=CVE-2024-51479 Référence CVE CVE-2024-51744 https://www.cve.org/CVERecord?id=CVE-2024-51744 Référence CVE CVE-2024-52798 https://www.cve.org/CVERecord?id=CVE-2024-52798 Référence CVE CVE-2024-53113 https://www.cve.org/CVERecord?id=CVE-2024-53113 Référence CVE CVE-2024-55565 https://www.cve.org/CVERecord?id=CVE-2024-55565 Référence CVE CVE-2024-56332 https://www.cve.org/CVERecord?id=CVE-2024-56332 Référence CVE CVE-2024-57980 https://www.cve.org/CVERecord?id=CVE-2024-57980 Référence CVE CVE-2024-6119 https://www.cve.org/CVERecord?id=CVE-2024-6119 Référence CVE CVE-2024-6531 https://www.cve.org/CVERecord?id=CVE-2024-6531 Référence CVE CVE-2024-7143 https://www.cve.org/CVERecord?id=CVE-2024-7143 Référence CVE CVE-2024-8176 https://www.cve.org/CVERecord?id=CVE-2024-8176 Référence CVE CVE-2024-8184 https://www.cve.org/CVERecord?id=CVE-2024-8184 Référence CVE CVE-2024-9042 https://www.cve.org/CVERecord?id=CVE-2024-9042 Référence CVE CVE-2025-0426 https://www.cve.org/CVERecord?id=CVE-2025-0426 Référence CVE CVE-2025-13465 https://www.cve.org/CVERecord?id=CVE-2025-13465 Référence CVE CVE-2025-13867 https://www.cve.org/CVERecord?id=CVE-2025-1386

Official advisory ↗
CERT-FR · French · CERTFR-2026-AVI-0218Multiples vulnérabilités dans les produits VMware

ord?id=CVE-2024-56171 Référence CVE CVE-2024-56406 https://www.cve.org/CVERecord?id=CVE-2024-56406 Référence CVE CVE-2024-5642 https://www.cve.org/CVERecord?id=CVE-2024-5642 Référence CVE CVE-2024-56433 https://www.cve.org/CVERecord?id=CVE-2024-56433 Référence CVE CVE-2024-56538 https://www.cve.org/CVERecord?id=CVE-2024-56538 Référence CVE CVE-2024-57360 https://www.cve.org/CVERecord?id=CVE-2024-57360 Référence CVE CVE-2024-57970 https://www.cve.org/CVERecord?id=CVE-2024-57970 Référence CVE CVE-2024-58011 https://www.cve.org/CVERecord?id=CVE-2024-58011 Référence CVE CVE-2024-58251 https://www.cve.org/CVERecord?id=CVE-2024-58251 Référence CVE CVE-2024-6119 https://www.cve.org/CVERecord?id=CVE-2024-6119 Référence CVE CVE-2024-6232 https://www.cve.org/CVERecord?id=CVE-2024-6232 Référence CVE CVE-2024-6345 https://www.cve.org/CVERecord?id=CVE-2024-6345 Référence CVE CVE-2024-6763 https://www.cve.org/CVERecord?id=CVE-2024-6763 Référence CVE CVE-2024-7006 https://www.cve.org/CVERecord?id=CVE-2024-7006 Référence CVE CVE-2024-7264 https://www.cve.org/CVERecord?id=CVE-2024-7264 Référence CVE CVE-2024-8088 https://www.cve.org/CVERecord?id=CVE-2024-8088 Référence CVE CVE-2024-8096 https://www.cve.org/CVERecord?id=CVE-2024-8096 Référence CVE CVE-2024-8176 https://www.cve.org/CVERecord?id=CVE-2024-8176 Ré

Official advisory ↗
CERT-FR · French · CERTFR-2026-AVI-0199Multiples vulnérabilités dans les produits VMware

ecord?id=CVE-2024-47561 Référence CVE CVE-2024-51744 https://www.cve.org/CVERecord?id=CVE-2024-51744 Référence CVE CVE-2024-53114 https://www.cve.org/CVERecord?id=CVE-2024-53114 Référence CVE CVE-2024-5535 https://www.cve.org/CVERecord?id=CVE-2024-5535 Référence CVE CVE-2024-5642 https://www.cve.org/CVERecord?id=CVE-2024-5642 Référence CVE CVE-2024-56433 https://www.cve.org/CVERecord?id=CVE-2024-56433 Référence CVE CVE-2024-56538 https://www.cve.org/CVERecord?id=CVE-2024-56538 Référence CVE CVE-2024-58011 https://www.cve.org/CVERecord?id=CVE-2024-58011 Référence CVE CVE-2024-58251 https://www.cve.org/CVERecord?id=CVE-2024-58251 Référence CVE CVE-2024-6119 https://www.cve.org/CVERecord?id=CVE-2024-6119 Référence CVE CVE-2024-7254 https://www.cve.org/CVERecord?id=CVE-2024-7254 Référence CVE CVE-2024-7264 https://www.cve.org/CVERecord?id=CVE-2024-7264 Référence CVE CVE-2024-8096 https://www.cve.org/CVERecord?id=CVE-2024-8096 Référence CVE CVE-2024-9143 https://www.cve.org/CVERecord?id=CVE-2024-9143 Référence CVE CVE-2024-9681 https://www.cve.org/CVERecord?id=CVE-2024-9681 Référence CVE CVE-2025-0167 https://www.cve.org/CVERecord?id=CVE-2025-0167 Référence CVE CVE-2025-0725 https://www.cve.org/CVERecord?id=CVE-2025-0725 Référence CVE CVE-2025-0913 https://www.cve.org/CVERecord?id=CVE-2025-0913 Ré

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-1057Multiples vulnérabilités dans les produits VMware

d?id=CVE-2024-58068 Référence CVE CVE-2024-58070 https://www.cve.org/CVERecord?id=CVE-2024-58070 Référence CVE CVE-2024-58074 https://www.cve.org/CVERecord?id=CVE-2024-58074 Référence CVE CVE-2024-58075 https://www.cve.org/CVERecord?id=CVE-2024-58075 Référence CVE CVE-2024-58077 https://www.cve.org/CVERecord?id=CVE-2024-58077 Référence CVE CVE-2024-58078 https://www.cve.org/CVERecord?id=CVE-2024-58078 Référence CVE CVE-2024-58079 https://www.cve.org/CVERecord?id=CVE-2024-58079 Référence CVE CVE-2024-58084 https://www.cve.org/CVERecord?id=CVE-2024-58084 Référence CVE CVE-2024-58088 https://www.cve.org/CVERecord?id=CVE-2024-58088 Référence CVE CVE-2024-6119 https://www.cve.org/CVERecord?id=CVE-2024-6119 Référence CVE CVE-2024-6197 https://www.cve.org/CVERecord?id=CVE-2024-6197 Référence CVE CVE-2024-6232 https://www.cve.org/CVERecord?id=CVE-2024-6232 Référence CVE CVE-2024-6923 https://www.cve.org/CVERecord?id=CVE-2024-6923 Référence CVE CVE-2024-7264 https://www.cve.org/CVERecord?id=CVE-2024-7264 Référence CVE CVE-2024-7592 https://www.cve.org/CVERecord?id=CVE-2024-7592 Référence CVE CVE-2024-8088 https://www.cve.org/CVERecord?id=CVE-2024-8088 Référence CVE CVE-2024-8096 https://www.cve.org/CVERecord?id=CVE-2024-8096 Référence CVE CVE-2024-8176 https://www.cve.org/CVERecord?id=CVE-2024-8176 Ré

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-1054Multiples vulnérabilités dans les produits VMware

CVERecord?id=CVE-2024-26775 Référence CVE CVE-2024-26896 https://www.cve.org/CVERecord?id=CVE-2024-26896 Référence CVE CVE-2024-4032 https://www.cve.org/CVERecord?id=CVE-2024-4032 Référence CVE CVE-2024-44939 https://www.cve.org/CVERecord?id=CVE-2024-44939 Référence CVE CVE-2024-4603 https://www.cve.org/CVERecord?id=CVE-2024-4603 Référence CVE CVE-2024-4741 https://www.cve.org/CVERecord?id=CVE-2024-4741 Référence CVE CVE-2024-50602 https://www.cve.org/CVERecord?id=CVE-2024-50602 Référence CVE CVE-2024-5535 https://www.cve.org/CVERecord?id=CVE-2024-5535 Référence CVE CVE-2024-57883 https://www.cve.org/CVERecord?id=CVE-2024-57883 Référence CVE CVE-2024-6119 https://www.cve.org/CVERecord?id=CVE-2024-6119 Référence CVE CVE-2024-6232 https://www.cve.org/CVERecord?id=CVE-2024-6232 Référence CVE CVE-2024-6923 https://www.cve.org/CVERecord?id=CVE-2024-6923 Référence CVE CVE-2024-7592 https://www.cve.org/CVERecord?id=CVE-2024-7592 Référence CVE CVE-2024-8088 https://www.cve.org/CVERecord?id=CVE-2024-8088 Référence CVE CVE-2024-9143 https://www.cve.org/CVERecord?id=CVE-2024-9143 Référence CVE CVE-2024-9287 https://www.cve.org/CVERecord?id=CVE-2024-9287 Référence CVE CVE-2025-0938 https://www.cve.org/CVERecord?id=CVE-2025-0938 Référence CVE CVE-2025-12817 https://www.cve.org/CVERecord?id=CVE-2025-12817

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-1036Multiples vulnérabilités dans les produits VMware

ERecord?id=CVE-2024-45336 Référence CVE CVE-2024-45337 https://www.cve.org/CVERecord?id=CVE-2024-45337 Référence CVE CVE-2024-45341 https://www.cve.org/CVERecord?id=CVE-2024-45341 Référence CVE CVE-2024-4603 https://www.cve.org/CVERecord?id=CVE-2024-4603 Référence CVE CVE-2024-47081 https://www.cve.org/CVERecord?id=CVE-2024-47081 Référence CVE CVE-2024-4741 https://www.cve.org/CVERecord?id=CVE-2024-4741 Référence CVE CVE-2024-50602 https://www.cve.org/CVERecord?id=CVE-2024-50602 Référence CVE CVE-2024-51744 https://www.cve.org/CVERecord?id=CVE-2024-51744 Référence CVE CVE-2024-5535 https://www.cve.org/CVERecord?id=CVE-2024-5535 Référence CVE CVE-2024-6119 https://www.cve.org/CVERecord?id=CVE-2024-6119 Référence CVE CVE-2024-6232 https://www.cve.org/CVERecord?id=CVE-2024-6232 Référence CVE CVE-2024-6345 https://www.cve.org/CVERecord?id=CVE-2024-6345 Référence CVE CVE-2024-6923 https://www.cve.org/CVERecord?id=CVE-2024-6923 Référence CVE CVE-2024-7254 https://www.cve.org/CVERecord?id=CVE-2024-7254 Référence CVE CVE-2024-7592 https://www.cve.org/CVERecord?id=CVE-2024-7592 Référence CVE CVE-2024-8088 https://www.cve.org/CVERecord?id=CVE-2024-8088 Référence CVE CVE-2024-9143 https://www.cve.org/CVERecord?id=CVE-2024-9143 Référence CVE CVE-2024-9287 https://www.cve.org/CVERecord?id=CVE-2024-9287 Ré

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0969Multiples vulnérabilités dans les produits VMware

d?id=CVE-2024-58081 Référence CVE CVE-2024-58082 https://www.cve.org/CVERecord?id=CVE-2024-58082 Référence CVE CVE-2024-58083 https://www.cve.org/CVERecord?id=CVE-2024-58083 Référence CVE CVE-2024-58085 https://www.cve.org/CVERecord?id=CVE-2024-58085 Référence CVE CVE-2024-58086 https://www.cve.org/CVERecord?id=CVE-2024-58086 Référence CVE CVE-2024-58088 https://www.cve.org/CVERecord?id=CVE-2024-58088 Référence CVE CVE-2024-58090 https://www.cve.org/CVERecord?id=CVE-2024-58090 Référence CVE CVE-2024-58093 https://www.cve.org/CVERecord?id=CVE-2024-58093 Référence CVE CVE-2024-58266 https://www.cve.org/CVERecord?id=CVE-2024-58266 Référence CVE CVE-2024-6119 https://www.cve.org/CVERecord?id=CVE-2024-6119 Référence CVE CVE-2024-6174 https://www.cve.org/CVERecord?id=CVE-2024-6174 Référence CVE CVE-2024-6232 https://www.cve.org/CVERecord?id=CVE-2024-6232 Référence CVE CVE-2024-6345 https://www.cve.org/CVERecord?id=CVE-2024-6345 Référence CVE CVE-2024-6923 https://www.cve.org/CVERecord?id=CVE-2024-6923 Référence CVE CVE-2024-7254 https://www.cve.org/CVERecord?id=CVE-2024-7254 Référence CVE CVE-2024-7264 https://www.cve.org/CVERecord?id=CVE-2024-7264 Référence CVE CVE-2024-7592 https://www.cve.org/CVERecord?id=CVE-2024-7592 Référence CVE CVE-2024-8088 https://www.cve.org/CVERecord?id=CVE-2024-8088 Ré

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0864Multiples vulnérabilités dans VMware Tanzu

CVERecord?id=CVE-2024-45341 Référence CVE CVE-2024-45490 https://www.cve.org/CVERecord?id=CVE-2024-45490 Référence CVE CVE-2024-45491 https://www.cve.org/CVERecord?id=CVE-2024-45491 Référence CVE CVE-2024-45492 https://www.cve.org/CVERecord?id=CVE-2024-45492 Référence CVE CVE-2024-4603 https://www.cve.org/CVERecord?id=CVE-2024-4603 Référence CVE CVE-2024-4741 https://www.cve.org/CVERecord?id=CVE-2024-4741 Référence CVE CVE-2024-50602 https://www.cve.org/CVERecord?id=CVE-2024-50602 Référence CVE CVE-2024-5535 https://www.cve.org/CVERecord?id=CVE-2024-5535 Référence CVE CVE-2024-5642 https://www.cve.org/CVERecord?id=CVE-2024-5642 Référence CVE CVE-2024-6119 https://www.cve.org/CVERecord?id=CVE-2024-6119 Référence CVE CVE-2024-6232 https://www.cve.org/CVERecord?id=CVE-2024-6232 Référence CVE CVE-2024-6923 https://www.cve.org/CVERecord?id=CVE-2024-6923 Référence CVE CVE-2024-8088 https://www.cve.org/CVERecord?id=CVE-2024-8088 Référence CVE CVE-2024-8096 https://www.cve.org/CVERecord?id=CVE-2024-8096 Référence CVE CVE-2024-9143 https://www.cve.org/CVERecord?id=CVE-2024-9143 Référence CVE CVE-2024-9287 https://www.cve.org/CVERecord?id=CVE-2024-9287 Référence CVE CVE-2025-0395 https://www.cve.org/CVERecord?id=CVE-2025-0395 Référence CVE CVE-2025-0938 https://www.cve.org/CVERecord?id=CVE-2025-0938 Ré

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0789Multiples vulnérabilités dans les produits IBM

5 https://www.ibm.com/support/pages/node/7244264 Bulletin de sécurité IBM 7244494 du 10 septembre 2025 https://www.ibm.com/support/pages/node/7244494 Bulletin de sécurité IBM 7244786 du 12 septembre 2025 https://www.ibm.com/support/pages/node/7244786 Référence CVE CVE-2021-47670 https://www.cve.org/CVERecord?id=CVE-2021-47670 Référence CVE CVE-2023-49083 https://www.cve.org/CVERecord?id=CVE-2023-49083 Référence CVE CVE-2024-12797 https://www.cve.org/CVERecord?id=CVE-2024-12797 Référence CVE CVE-2024-47081 https://www.cve.org/CVERecord?id=CVE-2024-47081 Référence CVE CVE-2024-56644 https://www.cve.org/CVERecord?id=CVE-2024-56644 Référence CVE CVE-2024-6119 https://www.cve.org/CVERecord?id=CVE-2024-6119 Référence CVE CVE-2025-21727 https://www.cve.org/CVERecord?id=CVE-2025-21727 Référence CVE CVE-2025-21759 https://www.cve.org/CVERecord?id=CVE-2025-21759 Référence CVE CVE-2025-22058 https://www.cve.org/CVERecord?id=CVE-2025-22058 Référence CVE CVE-2025-22097 https://www.cve.org/CVERecord?id=CVE-2025-22097 Référence CVE CVE-2025-26791 https://www.cve.org/CVERecord?id=CVE-2025-26791 Référence CVE CVE-2025-37914 https://www.cve.org/CVERecord?id=CVE-2025-37914 Référence CVE CVE-2025-38085 https://www.cve.org/CVERecord?id=CVE-2025-38085 Référence CVE CVE-2025-38159 https://www.cve.org/CVERecord?id=C

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0756Multiples vulnérabilités dans les produits VMware

rd?id=CVE-2024-5535 Référence CVE CVE-2024-55549 https://www.cve.org/CVERecord?id=CVE-2024-55549 Référence CVE CVE-2024-56171 https://www.cve.org/CVERecord?id=CVE-2024-56171 Référence CVE CVE-2024-56406 https://www.cve.org/CVERecord?id=CVE-2024-56406 Référence CVE CVE-2024-56433 https://www.cve.org/CVERecord?id=CVE-2024-56433 Référence CVE CVE-2024-56664 https://www.cve.org/CVERecord?id=CVE-2024-56664 Référence CVE CVE-2024-56751 https://www.cve.org/CVERecord?id=CVE-2024-56751 Référence CVE CVE-2024-58093 https://www.cve.org/CVERecord?id=CVE-2024-58093 Référence CVE CVE-2024-58251 https://www.cve.org/CVERecord?id=CVE-2024-58251 Référence CVE CVE-2024-6119 https://www.cve.org/CVERecord?id=CVE-2024-6119 Référence CVE CVE-2024-6174 https://www.cve.org/CVERecord?id=CVE-2024-6174 Référence CVE CVE-2024-6232 https://www.cve.org/CVERecord?id=CVE-2024-6232 Référence CVE CVE-2024-6345 https://www.cve.org/CVERecord?id=CVE-2024-6345 Référence CVE CVE-2024-6763 https://www.cve.org/CVERecord?id=CVE-2024-6763 Référence CVE CVE-2024-6923 https://www.cve.org/CVERecord?id=CVE-2024-6923 Référence CVE CVE-2024-7012 https://www.cve.org/CVERecord?id=CVE-2024-7012 Référence CVE CVE-2024-7254 https://www.cve.org/CVERecord?id=CVE-2024-7254 Référence CVE CVE-2024-7264 https://www.cve.org/CVERecord?id=CVE-2024-7264 Ré

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0622Multiples vulnérabilités dans les produits VMware

ecord?id=CVE-2024-52587 Référence CVE CVE-2024-53051 https://www.cve.org/CVERecord?id=CVE-2024-53051 Référence CVE CVE-2024-53144 https://www.cve.org/CVERecord?id=CVE-2024-53144 Référence CVE CVE-2024-53427 https://www.cve.org/CVERecord?id=CVE-2024-53427 Référence CVE CVE-2024-5535 https://www.cve.org/CVERecord?id=CVE-2024-5535 Référence CVE CVE-2024-56171 https://www.cve.org/CVERecord?id=CVE-2024-56171 Référence CVE CVE-2024-56664 https://www.cve.org/CVERecord?id=CVE-2024-56664 Référence CVE CVE-2024-58093 https://www.cve.org/CVERecord?id=CVE-2024-58093 Référence CVE CVE-2024-6104 https://www.cve.org/CVERecord?id=CVE-2024-6104 Référence CVE CVE-2024-6119 https://www.cve.org/CVERecord?id=CVE-2024-6119 Référence CVE CVE-2024-6232 https://www.cve.org/CVERecord?id=CVE-2024-6232 Référence CVE CVE-2024-6923 https://www.cve.org/CVERecord?id=CVE-2024-6923 Référence CVE CVE-2024-7264 https://www.cve.org/CVERecord?id=CVE-2024-7264 Référence CVE CVE-2024-7592 https://www.cve.org/CVERecord?id=CVE-2024-7592 Référence CVE CVE-2024-8088 https://www.cve.org/CVERecord?id=CVE-2024-8088 Référence CVE CVE-2024-8096 https://www.cve.org/CVERecord?id=CVE-2024-8096 Référence CVE CVE-2024-8805 https://www.cve.org/CVERecord?id=CVE-2024-8805 Référence CVE CVE-2024-9143 https://www.cve.org/CVERecord?id=CVE-2024-9143 Ré

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0524Multiples vulnérabilités dans VMware Tanzu

ord?id=CVE-2024-53427 Référence CVE CVE-2024-53920 https://www.cve.org/CVERecord?id=CVE-2024-53920 Référence CVE CVE-2024-5535 https://www.cve.org/CVERecord?id=CVE-2024-5535 Référence CVE CVE-2024-55549 https://www.cve.org/CVERecord?id=CVE-2024-55549 Référence CVE CVE-2024-56171 https://www.cve.org/CVERecord?id=CVE-2024-56171 Référence CVE CVE-2024-56378 https://www.cve.org/CVERecord?id=CVE-2024-56378 Référence CVE CVE-2024-56406 https://www.cve.org/CVERecord?id=CVE-2024-56406 Référence CVE CVE-2024-56826 https://www.cve.org/CVERecord?id=CVE-2024-56826 Référence CVE CVE-2024-56827 https://www.cve.org/CVERecord?id=CVE-2024-56827 Référence CVE CVE-2024-6119 https://www.cve.org/CVERecord?id=CVE-2024-6119 Référence CVE CVE-2024-6716 https://www.cve.org/CVERecord?id=CVE-2024-6716 Référence CVE CVE-2024-7348 https://www.cve.org/CVERecord?id=CVE-2024-7348 Référence CVE CVE-2024-8176 https://www.cve.org/CVERecord?id=CVE-2024-8176 Référence CVE CVE-2024-9143 https://www.cve.org/CVERecord?id=CVE-2024-9143 Référence CVE CVE-2024-9287 https://www.cve.org/CVERecord?id=CVE-2024-9287 Référence CVE CVE-2025-0167 https://www.cve.org/CVERecord?id=CVE-2025-0167 Référence CVE CVE-2025-0395 https://www.cve.org/CVERecord?id=CVE-2025-0395 Référence CVE CVE-2025-0938 https://www.cve.org/CVERecord?id=CVE-2025-0938 Ré

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0492Multiples vulnérabilités dans les produits Siemens

XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3) versions antérieures à V3.2 SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3) versions antérieures à V3.1 SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3) versions antérieures à V3.2 SIMATIC S7-1500 versions supérieures ou égales àV3.1.5 pour les vulnérabilités CVE-2021-41617, CVE-2023-4527, CVE-2023-4806, CVE-2023-4911, CVE-2023-5363, CVE-2023-6246, CVE-2023-6779, CVE-2023-6780, CVE-2023-28531, CVE-2023-38545, CVE-2023-38546, CVE-2023-44487, CVE-2023-46218, CVE-2023-46219, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2023-52927, CVE-2024-2961, CVE-2024-6119, CVE-2024-6387, CVE-2024-12133, CVE-2024-12243, CVE-2024-24855, CVE-2024-26596, CVE-2024-28085, CVE-2024-33599, CVE-2024-33600, CVE-2024-33601, CVE-2024-33602, CVE-2024-34397, CVE-2024-37370, CVE-2024-37371, CVE-2024-45490, CVE-2024-45491, CVE-2024-45492, CVE-2024-50246, CVE-2024-53166, CVE-2024-57977, CVE-2024-57996, CVE-2024-58005, CVE-2025-4373, CVE-2025-4598, CVE-2025-21701, CVE-2025-21702, CVE-2025-21712, CVE-2025-21724, CVE-2025-21728, CVE-2025-21745, CVE-2025-21756, CVE-2025-21758, CVE-2025-21765, CVE-2025-21766, CVE-2025-21767, CVE-2025-21795, CVE-2025-21796, CVE-2025-21848, CVE-2025-21862, CVE-2025-21864, CVE-2025-21865, CVE-2025-26

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0337Multiples vulnérabilités dans les produits IBM

d?id=CVE-2024-45813 Référence CVE CVE-2024-47535 https://www.cve.org/CVERecord?id=CVE-2024-47535 Référence CVE CVE-2024-47554 https://www.cve.org/CVERecord?id=CVE-2024-47554 Référence CVE CVE-2024-48948 https://www.cve.org/CVERecord?id=CVE-2024-48948 Référence CVE CVE-2024-52798 https://www.cve.org/CVERecord?id=CVE-2024-52798 Référence CVE CVE-2024-55565 https://www.cve.org/CVERecord?id=CVE-2024-55565 Référence CVE CVE-2024-56201 https://www.cve.org/CVERecord?id=CVE-2024-56201 Référence CVE CVE-2024-56326 https://www.cve.org/CVERecord?id=CVE-2024-56326 Référence CVE CVE-2024-57699 https://www.cve.org/CVERecord?id=CVE-2024-57699 Référence CVE CVE-2024-6119 https://www.cve.org/CVERecord?id=CVE-2024-6119 Référence CVE CVE-2024-6531 https://www.cve.org/CVERecord?id=CVE-2024-6531 Référence CVE CVE-2024-6763 https://www.cve.org/CVERecord?id=CVE-2024-6763 Référence CVE CVE-2024-7254 https://www.cve.org/CVERecord?id=CVE-2024-7254 Référence CVE CVE-2024-8184 https://www.cve.org/CVERecord?id=CVE-2024-8184 Référence CVE CVE-2025-1094 https://www.cve.org/CVERecord?id=CVE-2025-1094 Référence CVE CVE-2025-1302 https://www.cve.org/CVERecord?id=CVE-2025-1302 Référence CVE CVE-2025-21502 https://www.cve.org/CVERecord?id=CVE-2025-21502 Référence CVE CVE-2025-21613 https://www.cve.org/CVERecord?id=CVE-2025-2161

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0279Multiples vulnérabilités dans les produits IBM

d?id=CVE-2024-43398 Référence CVE CVE-2024-45296 https://www.cve.org/CVERecord?id=CVE-2024-45296 Référence CVE CVE-2024-45337 https://www.cve.org/CVERecord?id=CVE-2024-45337 Référence CVE CVE-2024-45338 https://www.cve.org/CVERecord?id=CVE-2024-45338 Référence CVE CVE-2024-45663 https://www.cve.org/CVERecord?id=CVE-2024-45663 Référence CVE CVE-2024-47764 https://www.cve.org/CVERecord?id=CVE-2024-47764 Référence CVE CVE-2024-49761 https://www.cve.org/CVERecord?id=CVE-2024-49761 Référence CVE CVE-2024-51479 https://www.cve.org/CVERecord?id=CVE-2024-51479 Référence CVE CVE-2024-52798 https://www.cve.org/CVERecord?id=CVE-2024-52798 Référence CVE CVE-2024-6119 https://www.cve.org/CVERecord?id=CVE-2024-6119 Référence CVE CVE-2024-6232 https://www.cve.org/CVERecord?id=CVE-2024-6232 Référence CVE CVE-2024-6484 https://www.cve.org/CVERecord?id=CVE-2024-6484 Référence CVE CVE-2024-6485 https://www.cve.org/CVERecord?id=CVE-2024-6485 Référence CVE CVE-2025-23184 https://www.cve.org/CVERecord?id=CVE-2025-23184 Référence CVE CVE-2025-25285 https://www.cve.org/CVERecord?id=CVE-2025-25285 Référence CVE CVE-2025-25288 https://www.cve.org/CVERecord?id=CVE-2025-25288 Référence CVE CVE-2025-25289 https://www.cve.org/CVERecord?id=CVE-2025-25289 Référence CVE CVE-2025-25290 https://www.cve.org/CVERecord?id=CVE-202

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0113Multiples vulnérabilités dans les produits Siemens

Record?id=CVE-2024-4603 Référence CVE CVE-2024-4741 https://www.cve.org/CVERecord?id=CVE-2024-4741 Référence CVE CVE-2024-50560 https://www.cve.org/CVERecord?id=CVE-2024-50560 Référence CVE CVE-2024-50561 https://www.cve.org/CVERecord?id=CVE-2024-50561 Référence CVE CVE-2024-50572 https://www.cve.org/CVERecord?id=CVE-2024-50572 Référence CVE CVE-2024-53648 https://www.cve.org/CVERecord?id=CVE-2024-53648 Référence CVE CVE-2024-53651 https://www.cve.org/CVERecord?id=CVE-2024-53651 Référence CVE CVE-2024-54015 https://www.cve.org/CVERecord?id=CVE-2024-54015 Référence CVE CVE-2024-5535 https://www.cve.org/CVERecord?id=CVE-2024-5535 Référence CVE CVE-2024-6119 https://www.cve.org/CVERecord?id=CVE-2024-6119 Référence CVE CVE-2024-9143 https://www.cve.org/CVERecord?id=CVE-2024-9143 Référence CVE CVE-2025-23403 https://www.cve.org/CVERecord?id=CVE-2025-23403 Référence CVE CVE-2025-24499 https://www.cve.org/CVERecord?id=CVE-2025-24499 Référence CVE CVE-2025-24532 https://www.cve.org/CVERecord?id=CVE-2025-24532 Référence CVE CVE-2025-24811 https://www.cve.org/CVERecord?id=CVE-2025-24811 Référence CVE CVE-2025-24812 https://www.cve.org/CVERecord?id=CVE-2025-24812 Gestion détaillée du document le 11 février 2025 Version initiale Alertes Avis Bulletins d’actualités Mentions légales Conditions générales À

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0055Multiples vulnérabilités dans Oracle PeopleSoft

g/CVERecord?id=CVE-2024-36137 Référence CVE CVE-2024-36138 https://www.cve.org/CVERecord?id=CVE-2024-36138 Référence CVE CVE-2024-37372 https://www.cve.org/CVERecord?id=CVE-2024-37372 Référence CVE CVE-2024-37891 https://www.cve.org/CVERecord?id=CVE-2024-37891 Référence CVE CVE-2024-4030 https://www.cve.org/CVERecord?id=CVE-2024-4030 Référence CVE CVE-2024-4032 https://www.cve.org/CVERecord?id=CVE-2024-4032 Référence CVE CVE-2024-4603 https://www.cve.org/CVERecord?id=CVE-2024-4603 Référence CVE CVE-2024-4741 https://www.cve.org/CVERecord?id=CVE-2024-4741 Référence CVE CVE-2024-5535 https://www.cve.org/CVERecord?id=CVE-2024-5535 Référence CVE CVE-2024-6119 https://www.cve.org/CVERecord?id=CVE-2024-6119 Référence CVE CVE-2024-6232 https://www.cve.org/CVERecord?id=CVE-2024-6232 Référence CVE CVE-2024-7592 https://www.cve.org/CVERecord?id=CVE-2024-7592 Référence CVE CVE-2025-21530 https://www.cve.org/CVERecord?id=CVE-2025-21530 Référence CVE CVE-2025-21537 https://www.cve.org/CVERecord?id=CVE-2025-21537 Référence CVE CVE-2025-21539 https://www.cve.org/CVERecord?id=CVE-2025-21539 Référence CVE CVE-2025-21545 https://www.cve.org/CVERecord?id=CVE-2025-21545 Référence CVE CVE-2025-21561 https://www.cve.org/CVERecord?id=CVE-2025-21561 Référence CVE CVE-2025-21562 https://www.cve.org/CVERecord?id=CVE-2

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0021Multiples vulnérabilités dans les produits IBM

d?id=CVE-2024-43830 Référence CVE CVE-2024-45296 https://www.cve.org/CVERecord?id=CVE-2024-45296 Référence CVE CVE-2024-45590 https://www.cve.org/CVERecord?id=CVE-2024-45590 Référence CVE CVE-2024-47764 https://www.cve.org/CVERecord?id=CVE-2024-47764 Référence CVE CVE-2024-47831 https://www.cve.org/CVERecord?id=CVE-2024-47831 Référence CVE CVE-2024-47874 https://www.cve.org/CVERecord?id=CVE-2024-47874 Référence CVE CVE-2024-49766 https://www.cve.org/CVERecord?id=CVE-2024-49766 Référence CVE CVE-2024-49767 https://www.cve.org/CVERecord?id=CVE-2024-49767 Référence CVE CVE-2024-55565 https://www.cve.org/CVERecord?id=CVE-2024-55565 Référence CVE CVE-2024-6119 https://www.cve.org/CVERecord?id=CVE-2024-6119 Référence CVE CVE-2024-7254 https://www.cve.org/CVERecord?id=CVE-2024-7254 Référence CVE CVE-2024-9355 https://www.cve.org/CVERecord?id=CVE-2024-9355 Gestion détaillée du document le 10 janvier 2025 Version initiale Alertes Avis Bulletins d’actualités Mentions légales Conditions générales À propos Contact cyber.gouv.fr service-public.fr legifrance.gouv.fr info.gouv.fr france.fr info.gouv.fr/risques Premier Ministre / Secrétariat Général de la Défense et de la Sécurité Nationale / Agence nationale de la sécurité des systèmes d'information

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0018Multiples vulnérabilités dans les produits Juniper Networks

d?id=CVE-2024-41073 Référence CVE CVE-2024-41096 https://www.cve.org/CVERecord?id=CVE-2024-41096 Référence CVE CVE-2024-42082 https://www.cve.org/CVERecord?id=CVE-2024-42082 Référence CVE CVE-2024-42096 https://www.cve.org/CVERecord?id=CVE-2024-42096 Référence CVE CVE-2024-42102 https://www.cve.org/CVERecord?id=CVE-2024-42102 Référence CVE CVE-2024-42131 https://www.cve.org/CVERecord?id=CVE-2024-42131 Référence CVE CVE-2024-45490 https://www.cve.org/CVERecord?id=CVE-2024-45490 Référence CVE CVE-2024-45491 https://www.cve.org/CVERecord?id=CVE-2024-45491 Référence CVE CVE-2024-45492 https://www.cve.org/CVERecord?id=CVE-2024-45492 Référence CVE CVE-2024-6119 https://www.cve.org/CVERecord?id=CVE-2024-6119 Référence CVE CVE-2024-6387 https://www.cve.org/CVERecord?id=CVE-2024-6387 Référence CVE CVE-2025-21592 https://www.cve.org/CVERecord?id=CVE-2025-21592 Référence CVE CVE-2025-21593 https://www.cve.org/CVERecord?id=CVE-2025-21593 Référence CVE CVE-2025-21596 https://www.cve.org/CVERecord?id=CVE-2025-21596 Référence CVE CVE-2025-21598 https://www.cve.org/CVERecord?id=CVE-2025-21598 Référence CVE CVE-2025-21599 https://www.cve.org/CVERecord?id=CVE-2025-21599 Référence CVE CVE-2025-21600 https://www.cve.org/CVERecord?id=CVE-2025-21600 Référence CVE CVE-2025-21602 https://www.cve.org/CVERecord?id=CVE

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0003Multiples vulnérabilités dans les produits IBM

rd?id=CVE-2024-4068 Référence CVE CVE-2024-41110 https://www.cve.org/CVERecord?id=CVE-2024-41110 Référence CVE CVE-2024-41123 https://www.cve.org/CVERecord?id=CVE-2024-41123 Référence CVE CVE-2024-41946 https://www.cve.org/CVERecord?id=CVE-2024-41946 Référence CVE CVE-2024-45296 https://www.cve.org/CVERecord?id=CVE-2024-45296 Référence CVE CVE-2024-45491 https://www.cve.org/CVERecord?id=CVE-2024-45491 Référence CVE CVE-2024-45590 https://www.cve.org/CVERecord?id=CVE-2024-45590 Référence CVE CVE-2024-47220 https://www.cve.org/CVERecord?id=CVE-2024-47220 Référence CVE CVE-2024-47554 https://www.cve.org/CVERecord?id=CVE-2024-47554 Référence CVE CVE-2024-6119 https://www.cve.org/CVERecord?id=CVE-2024-6119 Référence CVE CVE-2024-6345 https://www.cve.org/CVERecord?id=CVE-2024-6345 Référence CVE CVE-2024-6387 https://www.cve.org/CVERecord?id=CVE-2024-6387 Gestion détaillée du document le 03 janvier 2025 Version initiale Alertes Avis Bulletins d’actualités Mentions légales Conditions générales À propos Contact cyber.gouv.fr service-public.fr legifrance.gouv.fr info.gouv.fr france.fr info.gouv.fr/risques Premier Ministre / Secrétariat Général de la Défense et de la Sécurité Nationale / Agence nationale de la sécurité des systèmes d'information

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-1105Multiples vulnérabilités dans Tenable Security Center

De multiples vulnérabilités ont été découvertes dans Tenable Security Center. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-1081Multiples vulnérabilités dans les produits IBM

ord?id=CVE-2024-47175 Référence CVE CVE-2024-47554 https://www.cve.org/CVERecord?id=CVE-2024-47554 Référence CVE CVE-2024-47764 https://www.cve.org/CVERecord?id=CVE-2024-47764 Référence CVE CVE-2024-48949 https://www.cve.org/CVERecord?id=CVE-2024-48949 Référence CVE CVE-2024-51504 https://www.cve.org/CVERecord?id=CVE-2024-51504 Référence CVE CVE-2024-52316 https://www.cve.org/CVERecord?id=CVE-2024-52316 Référence CVE CVE-2024-52317 https://www.cve.org/CVERecord?id=CVE-2024-52317 Référence CVE CVE-2024-52318 https://www.cve.org/CVERecord?id=CVE-2024-52318 Référence CVE CVE-2024-5535 https://www.cve.org/CVERecord?id=CVE-2024-5535 Référence CVE CVE-2024-6119 https://www.cve.org/CVERecord?id=CVE-2024-6119 Référence CVE CVE-2024-7006 https://www.cve.org/CVERecord?id=CVE-2024-7006 Référence CVE CVE-2024-7264 https://www.cve.org/CVERecord?id=CVE-2024-7264 Gestion détaillée du document le 13 décembre 2024 Version initiale Alertes Avis Bulletins d’actualités Mentions légales Conditions générales À propos Contact cyber.gouv.fr service-public.fr legifrance.gouv.fr info.gouv.fr france.fr info.gouv.fr/risques Premier Ministre / Secrétariat Général de la Défense et de la Sécurité Nationale / Agence nationale de la sécurité des systèmes d'information

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-1046Multiples vulnérabilités dans Tenable Security Center

De multiples vulnérabilités ont été découvertes dans les produits Tenable. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, un contournement de la politique de sécurité et un déni de service.

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0958Multiples vulnérabilités dans les produits IBM

ord?id=CVE-2024-45491 Référence CVE CVE-2024-45492 https://www.cve.org/CVERecord?id=CVE-2024-45492 Référence CVE CVE-2024-45590 https://www.cve.org/CVERecord?id=CVE-2024-45590 Référence CVE CVE-2024-45801 https://www.cve.org/CVERecord?id=CVE-2024-45801 Référence CVE CVE-2024-46982 https://www.cve.org/CVERecord?id=CVE-2024-46982 Référence CVE CVE-2024-47764 https://www.cve.org/CVERecord?id=CVE-2024-47764 Référence CVE CVE-2024-47874 https://www.cve.org/CVERecord?id=CVE-2024-47874 Référence CVE CVE-2024-47875 https://www.cve.org/CVERecord?id=CVE-2024-47875 Référence CVE CVE-2024-5535 https://www.cve.org/CVERecord?id=CVE-2024-5535 Référence CVE CVE-2024-6119 https://www.cve.org/CVERecord?id=CVE-2024-6119 Référence CVE CVE-2024-6232 https://www.cve.org/CVERecord?id=CVE-2024-6232 Référence CVE CVE-2024-6345 https://www.cve.org/CVERecord?id=CVE-2024-6345 Référence CVE CVE-2024-6923 https://www.cve.org/CVERecord?id=CVE-2024-6923 Référence CVE CVE-2024-7592 https://www.cve.org/CVERecord?id=CVE-2024-7592 Référence CVE CVE-2024-8088 https://www.cve.org/CVERecord?id=CVE-2024-8088 Gestion détaillée du document le 08 novembre 2024 Version initiale Alertes Avis Bulletins d’actualités Mentions légales Conditions générales À propos Contact cyber.gouv.fr service-public.fr legifrance.gouv.fr info.gouv.fr franc

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0935Vulnérabilité dans Tenable Sensor Proxy

Une vulnérabilité a été découverte dans Tenable Sensor Proxy. Elle permet à un attaquant de provoquer un déni de service à distance.

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0923Multiples vulnérabilités dans les produits IBM

ERecord?id=CVE-2024-39908 Référence CVE CVE-2024-4067 https://www.cve.org/CVERecord?id=CVE-2024-4067 Référence CVE CVE-2024-4068 https://www.cve.org/CVERecord?id=CVE-2024-4068 Référence CVE CVE-2024-41123 https://www.cve.org/CVERecord?id=CVE-2024-41123 Référence CVE CVE-2024-41784 https://www.cve.org/CVERecord?id=CVE-2024-41784 Référence CVE CVE-2024-41946 https://www.cve.org/CVERecord?id=CVE-2024-41946 Référence CVE CVE-2024-43398 https://www.cve.org/CVERecord?id=CVE-2024-43398 Référence CVE CVE-2024-45296 https://www.cve.org/CVERecord?id=CVE-2024-45296 Référence CVE CVE-2024-5569 https://www.cve.org/CVERecord?id=CVE-2024-5569 Référence CVE CVE-2024-6119 https://www.cve.org/CVERecord?id=CVE-2024-6119 Référence CVE CVE-2024-6345 https://www.cve.org/CVERecord?id=CVE-2024-6345 Gestion détaillée du document le 25 octobre 2024 Version initiale Alertes Avis Bulletins d’actualités Mentions légales Conditions générales À propos Contact cyber.gouv.fr service-public.fr legifrance.gouv.fr info.gouv.fr france.fr info.gouv.fr/risques Premier Ministre / Secrétariat Général de la Défense et de la Sécurité Nationale / Agence nationale de la sécurité des systèmes d'information

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0884Multiples vulnérabilités dans Oracle MySQL

ord?id=CVE-2024-21243 Référence CVE CVE-2024-21244 https://www.cve.org/CVERecord?id=CVE-2024-21244 Référence CVE CVE-2024-21247 https://www.cve.org/CVERecord?id=CVE-2024-21247 Référence CVE CVE-2024-21262 https://www.cve.org/CVERecord?id=CVE-2024-21262 Référence CVE CVE-2024-21272 https://www.cve.org/CVERecord?id=CVE-2024-21272 Référence CVE CVE-2024-28182 https://www.cve.org/CVERecord?id=CVE-2024-28182 Référence CVE CVE-2024-37370 https://www.cve.org/CVERecord?id=CVE-2024-37370 Référence CVE CVE-2024-37371 https://www.cve.org/CVERecord?id=CVE-2024-37371 Référence CVE CVE-2024-5535 https://www.cve.org/CVERecord?id=CVE-2024-5535 Référence CVE CVE-2024-6119 https://www.cve.org/CVERecord?id=CVE-2024-6119 Référence CVE CVE-2024-7264 https://www.cve.org/CVERecord?id=CVE-2024-7264 Gestion détaillée du document le 16 octobre 2024 Version initiale Alertes Avis Bulletins d’actualités Mentions légales Conditions générales À propos Contact cyber.gouv.fr service-public.fr legifrance.gouv.fr info.gouv.fr france.fr info.gouv.fr/risques Premier Ministre / Secrétariat Général de la Défense et de la Sécurité Nationale / Agence nationale de la sécurité des systèmes d'information

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0882Multiples vulnérabilités dans Oracle Database Server

De multiples vulnérabilités ont été découvertes dans Oracle Database Server. Elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0807Multiples vulnérabilités dans Nessus Network Monitor

De multiples vulnérabilités ont été découvertes dans Nessus Network Monitor. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une injection de code indirecte à distance (XSS) et un problème de sécurité non spécifié par l'éditeur.

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0780Multiples vulnérabilités dans les produits IBM

De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0771Multiples vulnérabilités dans les produits Tenable

De multiples vulnérabilités ont été découvertes dans les produits Tenable. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance et un déni de service à distance.

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0736Vulnérabilité dans OpenSSL

Une vulnérabilité a été découverte dans OpenSSL. Elle permet à un attaquant de provoquer un déni de service à distance.

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2024-007376OpenSSL におけるサービス運用妨害 (DoS) の脆弱性 (Security Advisory [3rd September 2024])

OpenSSL Project より、 OpenSSL Security Advisory [3rd September 2024] ("Possible denial of service in X.509 name checks (CVE-2024-6119)")が公開されました。 深刻度−中 (Severity:Moderate) OpenSSL を用いるアプリケーションにおいて X.509 サーバ証明書の検証を行う際、Subject Alternative Name フィールド内の otherName の検証時に誤ったメモリアドレスを参照してアクセスエラーが生じる問題 (CWE-843、CVE-2024-6119) が報告されています。 なお本脆弱性は、証明書チェーンの検証には影響を与えません。一般的に TLS サーバがクライアント証明書を要求することは少なく、要求する場合においても識別子に対する名前のチェックは行われないため、影響は限定的となります。

Official advisory ↗
NCSC-NL · Dutch · NCSC-2025-0187Kwetsbaarheden verholpen in Siemens producten

De kwetsbaarheden stellen een kwaadwillende mogelijk in staat aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade: - Denial-of-Service (DoS) - Manipulatie van gegevens - Omzeilen van een beveiligingsmaatregel - Omzeilen van authenticatie - (Remote) code execution (root/admin rechten) - (Remote) code execution (Gebruikersrechten) - Toegang tot systeemgegevens - Toegang tot gevoelige gegevens - Spoofing De kwaadwillende heeft hiervoor toegang nodig tot de productieomgeving. Het is goed gebruik een dergelijke omgeving niet publiek toegankelijk te hebben.

Official advisory ↗
NCSC-NL · Dutch · NCSC-2025-0061Kwetsbaarheden verholpen in Siemens producten

De kwetsbaarheden stellen een kwaadwillende mogelijk in staat aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade: - Denial-of-Service (DoS) - Cross-Site-Scripting (XSS) - Cross-Site Request Forgery (CSRF) - Manipulatie van gegevens - Omzeilen van een beveiligingsmaatregel - Omzeilen van authenticatie - (Remote) code execution (root/admin rechten) - (Remote) code execution (Gebruikersrechten) - Toegang tot systeemgegevens - Toegang tot gevoelige gegevens De kwaadwillende heeft hiervoor toegang nodig tot de productieomgeving. Het is goed gebruik een dergelijke omgeving niet publiek toegankelijk te hebben.

Official advisory ↗
NCSC-NL · Dutch · NCSC-2025-0051Kwetsbaarheden verholpen in Siemens producten

De kwetsbaarheden stellen een kwaadwillende mogelijk in staat aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade: - Denial-of-Service (DoS) - Cross-Site-Scripting (XSS) - Cross-Site Request Forgery (CSRF) - Manipulatie van gegevens - Omzeilen van een beveiligingsmaatregel - Omzeilen van authenticatie - (Remote) code execution (root/admin rechten) - (Remote) code execution (Gebruikersrechten) - Toegang tot systeemgegevens - Toegang tot gevoelige gegevens De kwaadwillende heeft hiervoor toegang nodig tot de productieomgeving. Het is goed gebruik een dergelijke omgeving niet publiek toegankelijk te hebben.

Official advisory ↗
NCSC-NL · Dutch · NCSC-2025-0027Kwetsbaarheden verholpen in Oracle Fusion Middleware

De kwetsbaarheden bevinden zich in verschillende Oracle producten, waaronder Oracle WebLogic Server versies 12.2.1.4.0 en 14.1.1.0.0, die het mogelijk maken voor ongeauthenticeerde kwaadwillenden om toegang te krijgen tot kritieke gegevens. Dit kan leiden tot ernstige gevolgen voor de vertrouwelijkheid, integriteit en beschikbaarheid van de systemen. De kwetsbaarheid in Oracle HTTP Server versie 12.2.1.4.0 stelt kwaadwillenden in staat om ongeautoriseerde toegang te verkrijgen, met een CVSS-score van 5.3, terwijl de kwetsbaarheid in WebLogic Server een CVSS-score van 9.8 heeft, wat wijst op een kritieke impact. Kwaadwillenden kunnen ook gebruik maken van kwetsbaarheden in Oracle Fusion Middleware en andere producten om Denial-of-Service (DoS) aanvallen uit te voeren.

Official advisory ↗
NCSC-NL · Dutch · NCSC-2025-0023Kwetsbaarheden verholpen in Oracle PeopleSoft

De kwetsbaarheden in Oracle PeopleSoft stellen geauthenticeerde kwaadwillenden in staat om via HTTP-netwerktoegang ongeautoriseerde toegang te krijgen tot specifieke gegevens, wat kan leiden tot ongeautoriseerde gegevensmanipulatie en -toegang. Kwaadwillenden kunnen ook een Denial-of-Service veroorzaken. Hiervoor heeft de kwaadwillende geen voorafgaande authenticatie nodig.

Official advisory ↗
NCSC-NL · Dutch · NCSC-2025-0021Kwetsbaarheden verholpen in Oracle Communications

De kwetsbaarheden stellen ongeauthenticeerde kwaadwillenden in staat om Denial of Service (DoS) aanvallen uit te voeren of om ongeautoriseerde toegang tot gevoelige gegevens te verkrijgen. Specifieke versies, zoals 24.2.0 en 24.3.0 van de Cloud Native Core Network Function, zijn bijzonder kwetsbaar. Kwaadwillenden kunnen deze kwetsbaarheden misbruiken door speciaal geprepareerde HTTP-verzoeken te sturen naar het kwetsbare systeem.

Official advisory ↗
NCSC-NL · Dutch · NCSC-2024-0411Kwetsbaarheden verholpen in Oracle Database producten

Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade: - Denial-of-Service (DoS) - Manipuleren van data - Toegang tot gevoelige gegevens

Official advisory ↗
03

Patch and workaround

Operational remediation based on structured source evidence.

Status
?Patch availability is based on structured fixed-version fields and authoritative update references. If no fix is verified, check the vendor advisory before making a change.
Fix availability varies by product
Affected
Fixed
An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
Action
Use the product-specific evidence above. Patch only products with a verified fixed release, and keep every affected or under-investigation state without a matching fix in the remediation queue.
Workaround
No verified workaround is recorded. If business-safe, reduce exposure to the affected interface and allow only trusted sources until authoritative guidance is available.
04

Evidence and provenance

Published 3 Sept 2024 · Last source change 14 Jul 2026, 12:37 UTC · CWE-843 · Access of Resource Using Incompatible Type ('Type Confusion')

CVE recordCVE.org · 5.2
CVSS sourceNIST NVD
EPSS source
?The date BlackTree first stored a score for this CVE from the daily FIRST EPSS feed.
FIRST · tracked since 2026-08-14
European sourceENISA EUVD · EUVD-2024-47266
Product sourceVendor CSAF · SUSE Product Security Team
Remediation sourceVendor CSAF · SUSE Product Security Team
CWE sourceCNA
NVD statusNVD modified after enrichment

Core structured fields are present and their contributing authorities are shown above.

Material change intelligence

What changed after publication

View recent updates ↗
  1. Affected versionsThe structured affected or fixed version information changed.
    Before
    3.3.0 < 3.3.2; 3.2.0 < 3.2.3; 3.1.0 < 3.1.7; 3.0.0 < 3.0.15 · Fixed: An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
    After
    3.3.0 < 3.3.2; 3.2.0 < 3.2.3; 3.1.0 < 3.1.7; 3.0.0 < 3.0.15 · Fixed: For OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.16/release_notes/ocp-4-16-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:bd78fab2d62370a0a051c4284239c81e97304cf4cc63b97c194b7a9e1ff3235d (For s390x architecture) The image digest is sha256:31016c82002f5facebac2579b5f74d564f05a22f3c1d09fcec7b5271fdc25d41 (For ppc64le architecture) The image digest is sha256:8f5b445a0c6ead7efcc437219a5e0c84bcc39c7845f517079cecf86ba3ce3408 (For aarch64 architecture) The image digest is sha256:a56716b3f6cc89ae530684346c3b47816b11c717bfe51c038af7163f138ccdab All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.16/updating/updating_a_cluster/updating-cluster-cli.html
    Red Hat Product Security ↗
  2. Affected versionsThe structured affected or fixed version information changed.
    Before
    3scale-amp-backend-container as a component of Red Hat 3scale API Management Platform 2; openssl as a component of Red Hat Enterprise Linux 6; openssl-devel as a component of Red Hat Enterprise Linux 6; openssl-perl as a component of Red Hat Enterprise Linux 6; openssl-static as a component of Red Hat Enterprise Linux 6; openssl.src as a component of Red Hat Enterprise Linux 6; AAVMF as a component of Red Hat Enterprise Linux 7; OVMF as a component of Red Hat Enterprise Linux 7; openssl as a component of Red Hat Enterprise Linux 7; openssl-devel as a component of Red Hat Enterprise Linux 7; openssl-libs as a component of Red Hat Enterprise Linux 7; openssl-perl as a component of Red Hat Enterprise Linux 7; openssl-static as a component of Red Hat Enterprise Linux 7; openssl.src as a component of Red Hat Enterprise Linux 7; ovmf.src as a component of Red Hat Enterprise Linux 7; mingw-openssl.src as a component of Red Hat Enterprise Linux 8; mingw32-openssl as a component of Red Hat Enterprise Linux 8; mingw64-openssl as a component of Red Hat Enterprise Linux 8; openshift/ose-rhel-coreos-9 as a component of Red Hat OpenShift Container Platform 4; rhtpa/rhtpa-trustification-service-rhel9.src as a component of Red Hat Trusted Profile Analyzer · Fixed: rhcos@sha256:7a301deaa9e27ef553cc75f957e4ea9caf68213613e5d53bee330f00d792aa08_aarch64 as a component of Red Hat OpenShift Container Platform 4.16; rhcos@sha256:7a301deaa9e27ef553cc75f957e4ea9caf68213613e5d53bee330f00d792aa08_ppc64le as a component of Red Hat OpenShift Container Platform 4.16; rhcos@sha256:7a301deaa9e27ef553cc75f957e4ea9caf68213613e5d53bee330f00d792aa08_s390x as a component of Red Hat OpenShift Container Platform 4.16; rhcos@sha256:7a301deaa9e27ef553cc75f957e4ea9caf68213613e5d53bee330f00d792aa08_x86_64 as a component of Red Hat OpenShift Container Platform 4.16; rhcos@sha256:8f0c54ffdb883ab023c6f978316b8fb7e11e5888dcb1b136db6d943ddc67b2c1_aarch64 as a component of Red Hat OpenShift Container Platform 4.17; rhcos@sha256:8f0c54ffdb883ab023c6f978316b8fb7e11e5888dcb1b136db6d943ddc67b2c1_ppc64le as a component of Red Hat OpenShift Container Platform 4.17; rhcos@sha256:8f0c54ffdb883ab023c6f978316b8fb7e11e5888dcb1b136db6d943ddc67b2c1_s390x as a component of Red Hat OpenShift Container Platform 4.17; rhcos@sha256:8f0c54ffdb883ab023c6f978316b8fb7e11e5888dcb1b136db6d943ddc67b2c1_x86_64 as a component of Red Hat OpenShift Container Platform 4.17; service-interconnect/skupper-config-sync-rhel9@sha256:025f8c5b4ea63567a49b79945932e877f2279bc149c832283226a8488590ab37_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-config-sync-rhel9@sha256:51c106e22bc98c6678dafc2f42e387f6e6158e686436e6f89747703dd9c1bbbc_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-flow-collector-rhel9@sha256:58ec0e5cb8a9544153410867797e40055928dbd589e652e02bf4cddff083f5f6_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-flow-collector-rhel9@sha256:c338911564f18192114799711b16bc3015da0f53cbc9eb44418b6d1e78864bf9_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-operator-bundle@sha256:32c03556f3eb7f87c0624b105e8d9aac7dcfaea71adf16e4e9825586829880c1_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-operator-bundle@sha256:b6d7798d7fdfd40662f0d479efe7eb35414cbbd3643ea02cd05c71aeea020ffb_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-router-rhel9@sha256:0f7be97ca4fabb79ff77557429f0d08118eb5afc4e7322361493d322ae57cd08_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-router-rhel9@sha256:958ec2e1c85c49252d7b49a7b0073a0e73dffac31e46bad2b0a788114cb13c74_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-service-controller-rhel9@sha256:2da6dba7b2c9a47d0eedd7915a470d1a4e435848962ba39c72b8ea0d2bc9c1d8_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-service-controller-rhel9@sha256:34ce86c11588f0c7b2ba40ff988a8b6ac7ae6d29182e94d3a65e5756c68578f8_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-site-controller-rhel9@sha256:04dd17efae41b6d7e07fd89b8eddca076dfea7cb4e603a83c5c4e27062ef4c90_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-site-controller-rhel9@sha256:cce081bb2d5ae131770dfd095c2e8ad2fcc616d9b3fc487f9252c8f721f1b2ba_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-config-sync-rhel9@sha256:01b7f735b8efd48b3406d116a7885f4545efa21786fd96ea3479573b72181e6c_amd64 as a component of Red Hat Service Interconnect 1; service-interconnect/skupper-config-sync-rhel9@sha256:2dedeeda52b1701d005dee4c2277c949d978214d32fffbdfc63e7c5ead8f1782_ppc64le as a component of Red Hat Service Interconnect 1; service-interconnect/skupper-config-sync-rhel9@sha256:7460ced07d36f6ce528561e92db8f212b2db38ecefa6f28b1c6d336f676f5010_s390x as a component of Red Hat Service Interconnect 1; service-interconnect/skupper-config-sync-rhel9@sha256:7dd1ff26d428fc7b075b0ccd4e19ecce723029e2e3b957c59716ceb48a532f09_arm64 as a component of Red Hat Service Interconnect 1; service-interconnect/skupper-controller-podman-container-rhel9@sha256:03c5da9f3d13f3d5c54072cec23d09e49c18925d389817f3c75ab73e94be9e45_arm64 as a component of Red Hat Service Interconnect 1; service-interconnect/skupper-controller-podman-container-rhel9@sha256:2da92855aa7fc0a5b17909ca2e43950a9785ca3b58b001880caaddfe69bd7c1b_s390x as a component of Red Hat Service Interconnect 1; service-interconnect/skupper-controller-podman-container-rhel9@sha256:bdf007b74711d3bbd1986a29c9702e5b237edc34b2db86c70df7c8fd47e54454_ppc64le as a component of Red Hat Service Interconnect 1; service-interconnect/skupper-controller-podman-container-rhel9@sha256:ef40b43b27d8bd205d01ee1a6e11fbceaa345ab72ee6d39e2d436fa1b99a9aaa_amd64 as a component of Red Hat Service Interconnect 1; service-interconnect/skupper-controller-podman-rhel9@sha256:03c5da9f3d13f3d5c54072cec23d09e49c18925d389817f3c75ab73e94be9e45_arm64 as a component of Red Hat Service Interconnect 1; service-interconnect/skupper-controller-podman-rhel9@sha256:2da92855aa7fc0a5b17909ca2e43950a9785ca3b58b001880caaddfe69bd7c1b_s390x as a component of Red Hat Service Interconnect 1; and 81 more
    After
    3scale-amp-backend-container as a component of Red Hat 3scale API Management Platform 2; openssl as a component of Red Hat Enterprise Linux 6; openssl-devel as a component of Red Hat Enterprise Linux 6; openssl-perl as a component of Red Hat Enterprise Linux 6; openssl-static as a component of Red Hat Enterprise Linux 6; openssl.src as a component of Red Hat Enterprise Linux 6; AAVMF as a component of Red Hat Enterprise Linux 7; OVMF as a component of Red Hat Enterprise Linux 7; openssl as a component of Red Hat Enterprise Linux 7; openssl-devel as a component of Red Hat Enterprise Linux 7; openssl-libs as a component of Red Hat Enterprise Linux 7; openssl-perl as a component of Red Hat Enterprise Linux 7; openssl-static as a component of Red Hat Enterprise Linux 7; openssl.src as a component of Red Hat Enterprise Linux 7; ovmf.src as a component of Red Hat Enterprise Linux 7; mingw-openssl.src as a component of Red Hat Enterprise Linux 8; mingw32-openssl as a component of Red Hat Enterprise Linux 8; mingw64-openssl as a component of Red Hat Enterprise Linux 8; openshift/ose-rhel-coreos-8 as a component of Red Hat OpenShift Container Platform 4; rhtpa/rhtpa-trustification-service-rhel9.src as a component of Red Hat Trusted Profile Analyzer · Fixed: rhcos@sha256:7a301deaa9e27ef553cc75f957e4ea9caf68213613e5d53bee330f00d792aa08_aarch64 as a component of Red Hat OpenShift Container Platform 4.16; rhcos@sha256:7a301deaa9e27ef553cc75f957e4ea9caf68213613e5d53bee330f00d792aa08_ppc64le as a component of Red Hat OpenShift Container Platform 4.16; rhcos@sha256:7a301deaa9e27ef553cc75f957e4ea9caf68213613e5d53bee330f00d792aa08_s390x as a component of Red Hat OpenShift Container Platform 4.16; rhcos@sha256:7a301deaa9e27ef553cc75f957e4ea9caf68213613e5d53bee330f00d792aa08_x86_64 as a component of Red Hat OpenShift Container Platform 4.16; rhcos@sha256:8f0c54ffdb883ab023c6f978316b8fb7e11e5888dcb1b136db6d943ddc67b2c1_aarch64 as a component of Red Hat OpenShift Container Platform 4.17; rhcos@sha256:8f0c54ffdb883ab023c6f978316b8fb7e11e5888dcb1b136db6d943ddc67b2c1_ppc64le as a component of Red Hat OpenShift Container Platform 4.17; rhcos@sha256:8f0c54ffdb883ab023c6f978316b8fb7e11e5888dcb1b136db6d943ddc67b2c1_s390x as a component of Red Hat OpenShift Container Platform 4.17; rhcos@sha256:8f0c54ffdb883ab023c6f978316b8fb7e11e5888dcb1b136db6d943ddc67b2c1_x86_64 as a component of Red Hat OpenShift Container Platform 4.17; service-interconnect/skupper-config-sync-rhel9@sha256:025f8c5b4ea63567a49b79945932e877f2279bc149c832283226a8488590ab37_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-config-sync-rhel9@sha256:51c106e22bc98c6678dafc2f42e387f6e6158e686436e6f89747703dd9c1bbbc_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-flow-collector-rhel9@sha256:58ec0e5cb8a9544153410867797e40055928dbd589e652e02bf4cddff083f5f6_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-flow-collector-rhel9@sha256:c338911564f18192114799711b16bc3015da0f53cbc9eb44418b6d1e78864bf9_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-operator-bundle@sha256:32c03556f3eb7f87c0624b105e8d9aac7dcfaea71adf16e4e9825586829880c1_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-operator-bundle@sha256:b6d7798d7fdfd40662f0d479efe7eb35414cbbd3643ea02cd05c71aeea020ffb_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-router-rhel9@sha256:0f7be97ca4fabb79ff77557429f0d08118eb5afc4e7322361493d322ae57cd08_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-router-rhel9@sha256:958ec2e1c85c49252d7b49a7b0073a0e73dffac31e46bad2b0a788114cb13c74_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-service-controller-rhel9@sha256:2da6dba7b2c9a47d0eedd7915a470d1a4e435848962ba39c72b8ea0d2bc9c1d8_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-service-controller-rhel9@sha256:34ce86c11588f0c7b2ba40ff988a8b6ac7ae6d29182e94d3a65e5756c68578f8_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-site-controller-rhel9@sha256:04dd17efae41b6d7e07fd89b8eddca076dfea7cb4e603a83c5c4e27062ef4c90_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-site-controller-rhel9@sha256:cce081bb2d5ae131770dfd095c2e8ad2fcc616d9b3fc487f9252c8f721f1b2ba_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-config-sync-rhel9@sha256:01b7f735b8efd48b3406d116a7885f4545efa21786fd96ea3479573b72181e6c_amd64 as a component of Red Hat Service Interconnect 1; service-interconnect/skupper-config-sync-rhel9@sha256:2dedeeda52b1701d005dee4c2277c949d978214d32fffbdfc63e7c5ead8f1782_ppc64le as a component of Red Hat Service Interconnect 1; service-interconnect/skupper-config-sync-rhel9@sha256:7460ced07d36f6ce528561e92db8f212b2db38ecefa6f28b1c6d336f676f5010_s390x as a component of Red Hat Service Interconnect 1; service-interconnect/skupper-config-sync-rhel9@sha256:7dd1ff26d428fc7b075b0ccd4e19ecce723029e2e3b957c59716ceb48a532f09_arm64 as a component of Red Hat Service Interconnect 1; service-interconnect/skupper-controller-podman-container-rhel9@sha256:03c5da9f3d13f3d5c54072cec23d09e49c18925d389817f3c75ab73e94be9e45_arm64 as a component of Red Hat Service Interconnect 1; service-interconnect/skupper-controller-podman-container-rhel9@sha256:2da92855aa7fc0a5b17909ca2e43950a9785ca3b58b001880caaddfe69bd7c1b_s390x as a component of Red Hat Service Interconnect 1; service-interconnect/skupper-controller-podman-container-rhel9@sha256:bdf007b74711d3bbd1986a29c9702e5b237edc34b2db86c70df7c8fd47e54454_ppc64le as a component of Red Hat Service Interconnect 1; service-interconnect/skupper-controller-podman-container-rhel9@sha256:ef40b43b27d8bd205d01ee1a6e11fbceaa345ab72ee6d39e2d436fa1b99a9aaa_amd64 as a component of Red Hat Service Interconnect 1; service-interconnect/skupper-controller-podman-rhel9@sha256:03c5da9f3d13f3d5c54072cec23d09e49c18925d389817f3c75ab73e94be9e45_arm64 as a component of Red Hat Service Interconnect 1; service-interconnect/skupper-controller-podman-rhel9@sha256:2da92855aa7fc0a5b17909ca2e43950a9785ca3b58b001880caaddfe69bd7c1b_s390x as a component of Red Hat Service Interconnect 1; and 81 more
    Red Hat Product Security ↗
  3. Affected versionsThe structured affected or fixed version information changed.
    Before
    3scale-amp-backend-container as a component of Red Hat 3scale API Management Platform 2; openssl as a component of Red Hat Enterprise Linux 6; openssl-devel as a component of Red Hat Enterprise Linux 6; openssl-perl as a component of Red Hat Enterprise Linux 6; openssl-static as a component of Red Hat Enterprise Linux 6; openssl.src as a component of Red Hat Enterprise Linux 6; AAVMF as a component of Red Hat Enterprise Linux 7; OVMF as a component of Red Hat Enterprise Linux 7; openssl as a component of Red Hat Enterprise Linux 7; openssl-devel as a component of Red Hat Enterprise Linux 7; openssl-libs as a component of Red Hat Enterprise Linux 7; openssl-perl as a component of Red Hat Enterprise Linux 7; openssl-static as a component of Red Hat Enterprise Linux 7; openssl.src as a component of Red Hat Enterprise Linux 7; ovmf.src as a component of Red Hat Enterprise Linux 7; mingw32-openssl as a component of Red Hat Enterprise Linux 8; mingw64-openssl as a component of Red Hat Enterprise Linux 8; rhtpa/rhtpa-trustification-service-rhel9.src as a component of Red Hat Trusted Profile Analyzer · Fixed: rhcos@sha256:7a301deaa9e27ef553cc75f957e4ea9caf68213613e5d53bee330f00d792aa08_aarch64 as a component of Red Hat OpenShift Container Platform 4.16; rhcos@sha256:7a301deaa9e27ef553cc75f957e4ea9caf68213613e5d53bee330f00d792aa08_ppc64le as a component of Red Hat OpenShift Container Platform 4.16; rhcos@sha256:7a301deaa9e27ef553cc75f957e4ea9caf68213613e5d53bee330f00d792aa08_s390x as a component of Red Hat OpenShift Container Platform 4.16; rhcos@sha256:7a301deaa9e27ef553cc75f957e4ea9caf68213613e5d53bee330f00d792aa08_x86_64 as a component of Red Hat OpenShift Container Platform 4.16; rhcos@sha256:8f0c54ffdb883ab023c6f978316b8fb7e11e5888dcb1b136db6d943ddc67b2c1_aarch64 as a component of Red Hat OpenShift Container Platform 4.17; rhcos@sha256:8f0c54ffdb883ab023c6f978316b8fb7e11e5888dcb1b136db6d943ddc67b2c1_ppc64le as a component of Red Hat OpenShift Container Platform 4.17; rhcos@sha256:8f0c54ffdb883ab023c6f978316b8fb7e11e5888dcb1b136db6d943ddc67b2c1_s390x as a component of Red Hat OpenShift Container Platform 4.17; rhcos@sha256:8f0c54ffdb883ab023c6f978316b8fb7e11e5888dcb1b136db6d943ddc67b2c1_x86_64 as a component of Red Hat OpenShift Container Platform 4.17; service-interconnect/skupper-config-sync-rhel9@sha256:025f8c5b4ea63567a49b79945932e877f2279bc149c832283226a8488590ab37_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-config-sync-rhel9@sha256:51c106e22bc98c6678dafc2f42e387f6e6158e686436e6f89747703dd9c1bbbc_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-flow-collector-rhel9@sha256:58ec0e5cb8a9544153410867797e40055928dbd589e652e02bf4cddff083f5f6_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-flow-collector-rhel9@sha256:c338911564f18192114799711b16bc3015da0f53cbc9eb44418b6d1e78864bf9_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-operator-bundle@sha256:32c03556f3eb7f87c0624b105e8d9aac7dcfaea71adf16e4e9825586829880c1_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-operator-bundle@sha256:b6d7798d7fdfd40662f0d479efe7eb35414cbbd3643ea02cd05c71aeea020ffb_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-router-rhel9@sha256:0f7be97ca4fabb79ff77557429f0d08118eb5afc4e7322361493d322ae57cd08_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-router-rhel9@sha256:958ec2e1c85c49252d7b49a7b0073a0e73dffac31e46bad2b0a788114cb13c74_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-service-controller-rhel9@sha256:2da6dba7b2c9a47d0eedd7915a470d1a4e435848962ba39c72b8ea0d2bc9c1d8_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-service-controller-rhel9@sha256:34ce86c11588f0c7b2ba40ff988a8b6ac7ae6d29182e94d3a65e5756c68578f8_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-site-controller-rhel9@sha256:04dd17efae41b6d7e07fd89b8eddca076dfea7cb4e603a83c5c4e27062ef4c90_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-site-controller-rhel9@sha256:cce081bb2d5ae131770dfd095c2e8ad2fcc616d9b3fc487f9252c8f721f1b2ba_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-config-sync-rhel9@sha256:01b7f735b8efd48b3406d116a7885f4545efa21786fd96ea3479573b72181e6c_amd64 as a component of Red Hat Service Interconnect 1; service-interconnect/skupper-config-sync-rhel9@sha256:2dedeeda52b1701d005dee4c2277c949d978214d32fffbdfc63e7c5ead8f1782_ppc64le as a component of Red Hat Service Interconnect 1; service-interconnect/skupper-config-sync-rhel9@sha256:7460ced07d36f6ce528561e92db8f212b2db38ecefa6f28b1c6d336f676f5010_s390x as a component of Red Hat Service Interconnect 1; service-interconnect/skupper-config-sync-rhel9@sha256:7dd1ff26d428fc7b075b0ccd4e19ecce723029e2e3b957c59716ceb48a532f09_arm64 as a component of Red Hat Service Interconnect 1; service-interconnect/skupper-controller-podman-container-rhel9@sha256:03c5da9f3d13f3d5c54072cec23d09e49c18925d389817f3c75ab73e94be9e45_arm64 as a component of Red Hat Service Interconnect 1; service-interconnect/skupper-controller-podman-container-rhel9@sha256:2da92855aa7fc0a5b17909ca2e43950a9785ca3b58b001880caaddfe69bd7c1b_s390x as a component of Red Hat Service Interconnect 1; service-interconnect/skupper-controller-podman-container-rhel9@sha256:bdf007b74711d3bbd1986a29c9702e5b237edc34b2db86c70df7c8fd47e54454_ppc64le as a component of Red Hat Service Interconnect 1; service-interconnect/skupper-controller-podman-container-rhel9@sha256:ef40b43b27d8bd205d01ee1a6e11fbceaa345ab72ee6d39e2d436fa1b99a9aaa_amd64 as a component of Red Hat Service Interconnect 1; service-interconnect/skupper-controller-podman-rhel9@sha256:03c5da9f3d13f3d5c54072cec23d09e49c18925d389817f3c75ab73e94be9e45_arm64 as a component of Red Hat Service Interconnect 1; service-interconnect/skupper-controller-podman-rhel9@sha256:2da92855aa7fc0a5b17909ca2e43950a9785ca3b58b001880caaddfe69bd7c1b_s390x as a component of Red Hat Service Interconnect 1; and 81 more
    After
    3scale-amp-backend-container as a component of Red Hat 3scale API Management Platform 2; openssl as a component of Red Hat Enterprise Linux 6; openssl-devel as a component of Red Hat Enterprise Linux 6; openssl-perl as a component of Red Hat Enterprise Linux 6; openssl-static as a component of Red Hat Enterprise Linux 6; openssl.src as a component of Red Hat Enterprise Linux 6; AAVMF as a component of Red Hat Enterprise Linux 7; OVMF as a component of Red Hat Enterprise Linux 7; openssl as a component of Red Hat Enterprise Linux 7; openssl-devel as a component of Red Hat Enterprise Linux 7; openssl-libs as a component of Red Hat Enterprise Linux 7; openssl-perl as a component of Red Hat Enterprise Linux 7; openssl-static as a component of Red Hat Enterprise Linux 7; openssl.src as a component of Red Hat Enterprise Linux 7; ovmf.src as a component of Red Hat Enterprise Linux 7; mingw-openssl.src as a component of Red Hat Enterprise Linux 8; mingw32-openssl as a component of Red Hat Enterprise Linux 8; mingw64-openssl as a component of Red Hat Enterprise Linux 8; openshift/ose-rhel-coreos-9 as a component of Red Hat OpenShift Container Platform 4; rhtpa/rhtpa-trustification-service-rhel9.src as a component of Red Hat Trusted Profile Analyzer · Fixed: rhcos@sha256:7a301deaa9e27ef553cc75f957e4ea9caf68213613e5d53bee330f00d792aa08_aarch64 as a component of Red Hat OpenShift Container Platform 4.16; rhcos@sha256:7a301deaa9e27ef553cc75f957e4ea9caf68213613e5d53bee330f00d792aa08_ppc64le as a component of Red Hat OpenShift Container Platform 4.16; rhcos@sha256:7a301deaa9e27ef553cc75f957e4ea9caf68213613e5d53bee330f00d792aa08_s390x as a component of Red Hat OpenShift Container Platform 4.16; rhcos@sha256:7a301deaa9e27ef553cc75f957e4ea9caf68213613e5d53bee330f00d792aa08_x86_64 as a component of Red Hat OpenShift Container Platform 4.16; rhcos@sha256:8f0c54ffdb883ab023c6f978316b8fb7e11e5888dcb1b136db6d943ddc67b2c1_aarch64 as a component of Red Hat OpenShift Container Platform 4.17; rhcos@sha256:8f0c54ffdb883ab023c6f978316b8fb7e11e5888dcb1b136db6d943ddc67b2c1_ppc64le as a component of Red Hat OpenShift Container Platform 4.17; rhcos@sha256:8f0c54ffdb883ab023c6f978316b8fb7e11e5888dcb1b136db6d943ddc67b2c1_s390x as a component of Red Hat OpenShift Container Platform 4.17; rhcos@sha256:8f0c54ffdb883ab023c6f978316b8fb7e11e5888dcb1b136db6d943ddc67b2c1_x86_64 as a component of Red Hat OpenShift Container Platform 4.17; service-interconnect/skupper-config-sync-rhel9@sha256:025f8c5b4ea63567a49b79945932e877f2279bc149c832283226a8488590ab37_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-config-sync-rhel9@sha256:51c106e22bc98c6678dafc2f42e387f6e6158e686436e6f89747703dd9c1bbbc_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-flow-collector-rhel9@sha256:58ec0e5cb8a9544153410867797e40055928dbd589e652e02bf4cddff083f5f6_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-flow-collector-rhel9@sha256:c338911564f18192114799711b16bc3015da0f53cbc9eb44418b6d1e78864bf9_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-operator-bundle@sha256:32c03556f3eb7f87c0624b105e8d9aac7dcfaea71adf16e4e9825586829880c1_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-operator-bundle@sha256:b6d7798d7fdfd40662f0d479efe7eb35414cbbd3643ea02cd05c71aeea020ffb_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-router-rhel9@sha256:0f7be97ca4fabb79ff77557429f0d08118eb5afc4e7322361493d322ae57cd08_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-router-rhel9@sha256:958ec2e1c85c49252d7b49a7b0073a0e73dffac31e46bad2b0a788114cb13c74_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-service-controller-rhel9@sha256:2da6dba7b2c9a47d0eedd7915a470d1a4e435848962ba39c72b8ea0d2bc9c1d8_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-service-controller-rhel9@sha256:34ce86c11588f0c7b2ba40ff988a8b6ac7ae6d29182e94d3a65e5756c68578f8_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-site-controller-rhel9@sha256:04dd17efae41b6d7e07fd89b8eddca076dfea7cb4e603a83c5c4e27062ef4c90_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-site-controller-rhel9@sha256:cce081bb2d5ae131770dfd095c2e8ad2fcc616d9b3fc487f9252c8f721f1b2ba_amd64 as a component of 9Base-Service-Interconnect-1.4; service-interconnect/skupper-config-sync-rhel9@sha256:01b7f735b8efd48b3406d116a7885f4545efa21786fd96ea3479573b72181e6c_amd64 as a component of Red Hat Service Interconnect 1; service-interconnect/skupper-config-sync-rhel9@sha256:2dedeeda52b1701d005dee4c2277c949d978214d32fffbdfc63e7c5ead8f1782_ppc64le as a component of Red Hat Service Interconnect 1; service-interconnect/skupper-config-sync-rhel9@sha256:7460ced07d36f6ce528561e92db8f212b2db38ecefa6f28b1c6d336f676f5010_s390x as a component of Red Hat Service Interconnect 1; service-interconnect/skupper-config-sync-rhel9@sha256:7dd1ff26d428fc7b075b0ccd4e19ecce723029e2e3b957c59716ceb48a532f09_arm64 as a component of Red Hat Service Interconnect 1; service-interconnect/skupper-controller-podman-container-rhel9@sha256:03c5da9f3d13f3d5c54072cec23d09e49c18925d389817f3c75ab73e94be9e45_arm64 as a component of Red Hat Service Interconnect 1; service-interconnect/skupper-controller-podman-container-rhel9@sha256:2da92855aa7fc0a5b17909ca2e43950a9785ca3b58b001880caaddfe69bd7c1b_s390x as a component of Red Hat Service Interconnect 1; service-interconnect/skupper-controller-podman-container-rhel9@sha256:bdf007b74711d3bbd1986a29c9702e5b237edc34b2db86c70df7c8fd47e54454_ppc64le as a component of Red Hat Service Interconnect 1; service-interconnect/skupper-controller-podman-container-rhel9@sha256:ef40b43b27d8bd205d01ee1a6e11fbceaa345ab72ee6d39e2d436fa1b99a9aaa_amd64 as a component of Red Hat Service Interconnect 1; service-interconnect/skupper-controller-podman-rhel9@sha256:03c5da9f3d13f3d5c54072cec23d09e49c18925d389817f3c75ab73e94be9e45_arm64 as a component of Red Hat Service Interconnect 1; service-interconnect/skupper-controller-podman-rhel9@sha256:2da92855aa7fc0a5b17909ca2e43950a9785ca3b58b001880caaddfe69bd7c1b_s390x as a component of Red Hat Service Interconnect 1; and 81 more
    Red Hat Product Security ↗
Material fields only · duplicate refreshes suppressed · history retained for the configured operational retention period
Technical terms and abbreviations used in this report
CVE
Common Vulnerabilities and Exposures: the public identifier for one disclosed vulnerability.
CVSS
Common Vulnerability Scoring System: a technical severity framework; it is not patching priority by itself.
EPSS
Exploit Prediction Scoring System: FIRST's estimate of the probability that exploitation activity will be observed in the next 30 days; it is a forecast, not confirmation.
CWE
Common Weakness Enumeration: the standard category describing the underlying software or hardware weakness.
CNA
CVE Numbering Authority: an organisation authorised to assign and publish CVE records.
CISA ADP
Cybersecurity and Infrastructure Security Agency Authorized Data Publisher: structured enrichment added to a CVE record.
NVD
National Vulnerability Database: NIST's enrichment service for CVE records.
CERT / CSIRT
A computer security incident response team that publishes warnings or coordinates incident response.
PoC
Proof of concept: public material that demonstrates or helps reproduce exploitation.
CSAF
Common Security Advisory Framework: a machine-readable format for security advisories.
LoTL
Living off the land: abuse of legitimate tools or system functions during an attack.
Free version - for non-commercial use only.CVE-2024-6119 · cve.blacktree.nl