ENISA EUVD · EUVD-2022-1575Official EUVD mapping0 linked advisory records.
Official EUVD record ↗BSI · German · WID-SEC-2022-1057Apple macOS: Mehrere SchwachstellenEin entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Apple macOS ausnutzen, um seine Privilegien zu erweitern, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen, vertrauliche Informationen offenzulegen und im schlimmsten Fall das System zu kompromittieren.
Official advisory ↗BSI · German · WID-SEC-2026-0180Dell Data Protection Advisor: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Dell Data Protection Advisor ausnutzen, um beliebigen Code auszuführen, einen Denial-of-Service-Zustand zu erzeugen, Sicherheitsmaßnahmen zu umgehen und nicht näher spezifizierte Angriffe zu starten.
Official advisory ↗BSI · German · WID-SEC-2024-2086SAP Patchday September 2024Ein Angreifer kann mehrere Schwachstellen in SAP Software ausnutzen, um seine Privilegien zu erhöhen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand zu erzeugen oder einen Cross-Site-Scripting-Angriff durchzuführen.
Official advisory ↗BSI · German · WID-SEC-2024-1186IBM DB2 REST: Mehrere SchwachstellenEin entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM DB2 REST ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen oder einen Denial-of-Service-Zustand zu verursachen.
Official advisory ↗BSI · German · WID-SEC-2024-0794Dell ECS: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Dell ECS ausnutzen, um seine Privilegien zu erweitern, beliebigen Programmcode mit Administratorrechten auszuführen, Informationen offenzulegen, Dateien zu manipulieren, einen Cross-Site-Scripting-Angriff durchzuführen, Sicherheitsvorkehrungen zu umgehen oder einen Denial of Service Zustand herbeizuführen.
Official advisory ↗BSI · German · WID-SEC-2023-1969HPE Fabric OS: Mehrere Schwachstellen ermöglichen PrivilegieneskalationEin entfernter, anonymer Angreifer kann mehrere Schwachstellen in HPE Fabric OS für HPE Fibre Channel und SAN Switches ausnutzen, um seine Privilegien zu erhöhen, Informationen offenzulegen oder einen Denial of Service Zustand herbeizuführen.
Official advisory ↗BSI · German · WID-SEC-2022-1335Xerox FreeFlow Print Server: Mehrere SchwachstellenEin entfernter, anonymer Angreifer kann mehrere Schwachstellen in Xerox FreeFlow Print Server ausnutzen, um die Vertraulichkeit, Verfügbarkeit und Integrität des Systems zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2022-0551Kyocera Drucker: Mehrere SchwachstellenEin entfernter, anonymer Angreifer kann mehrere Schwachstellen in Kyocera Druckern ausnutzen, um beliebigen Programmcode auszuführen, einen Cross-Site-Scritping Angriff durchzuführen und einen Denial of Service Zustand herbeizuführen.
Official advisory ↗BSI · German · WID-SEC-2022-0515IBM Spectrum Protect: Mehrere SchwachstellenEin entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in IBM Spectrum Protect ausnutzen, um einen Denial-of-Service-Zustand herbeizuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, beliebigen Code auszuführen, seine Rechte zu erweitern oder beliebigen Code mit Root-Rechten auszuführen.
Official advisory ↗BSI · German · WID-SEC-2022-0432Xerox FreeFlow Print Server: Mehrere SchwachstellenEin entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Xerox FreeFlow Print Server ausnutzen, um die Vertraulichkeit, Verfügbarkeit und Integrität zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2022-0302Xerox FreeFlow Print Server: Mehrere Schwachstellen ermöglichen Ausführen von beliebigem Programmcode mit AdministratorrechtenEin entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Xerox FreeFlow Print Server ausnutzen, um beliebigen Programmcode auszuführen, einen Cross-Site-Scripting-Angriff durchzuführen, Informationen offenzulegen, einen Denial-of-Service-Zustand zu verursachen oder Dateien zu manipulieren.
Official advisory ↗BSI · German · WID-SEC-2022-0169Oracle MySQL: Mehrere SchwachstellenEin entfernter, anonymer Angreifer kann mehrere Schwachstellen in Oracle MySQL ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2022-0200Oracle Java SE und OpenJDK: Mehrere SchwachstellenEin entfernter, anonymer Angreifer kann mehrere Schwachstellen in Oracle Java SE und OpenJDK ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2022-0065OpenSSL: Schwachstelle ermöglicht Denial of ServiceEin entfernter, anonymer Angreifer kann eine Schwachstelle in OpenSSL ausnutzen, um einen Denial of Service Angriff durchzuführen.
Official advisory ↗Canadian Centre for Cyber Security · English · AV22-175Fortinet security advisory (AV22-175)On 1 April 2022 Fortinet published PSIRT Advisories to address vulnerabilities affecting multiple products:
Spring4Shell and CVE-2022-22963 vulnerabilities
Official advisory ↗Cyber Security Agency of Singapore · English · CSA-SB-20220316Security Bulletin 16 Mar 2022The Cyber Security Agency of Singapore included this CVE in its official Security Bulletin 16 Mar 2022, published on 16 March 2022. Open the linked bulletin for the product, severity and reference information published in that issue.
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0432Multiples vulnérabilités dans les produits SiemensDe multiples vulnérabilités ont été découvertes dans les produits Siemens. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0199Multiples vulnérabilités dans les produits VMwareord?id=CVE-2021-42385
Référence CVE CVE-2021-42386
https://www.cve.org/CVERecord?id=CVE-2021-42386
Référence CVE CVE-2021-42836
https://www.cve.org/CVERecord?id=CVE-2021-42836
Référence CVE CVE-2021-43565
https://www.cve.org/CVERecord?id=CVE-2021-43565
Référence CVE CVE-2021-43816
https://www.cve.org/CVERecord?id=CVE-2021-43816
Référence CVE CVE-2021-44716
https://www.cve.org/CVERecord?id=CVE-2021-44716
Référence CVE CVE-2021-44717
https://www.cve.org/CVERecord?id=CVE-2021-44717
Référence CVE CVE-2021-46848
https://www.cve.org/CVERecord?id=CVE-2021-46848
Référence CVE CVE-2022-0563
https://www.cve.org/CVERecord?id=CVE-2022-0563
Référence CVE CVE-2022-0778
https://www.cve.org/CVERecord?id=CVE-2022-0778
Référence CVE CVE-2022-1271
https://www.cve.org/CVERecord?id=CVE-2022-1271
Référence CVE CVE-2022-1292
https://www.cve.org/CVERecord?id=CVE-2022-1292
Référence CVE CVE-2022-1343
https://www.cve.org/CVERecord?id=CVE-2022-1343
Référence CVE CVE-2022-1434
https://www.cve.org/CVERecord?id=CVE-2022-1434
Référence CVE CVE-2022-1471
https://www.cve.org/CVERecord?id=CVE-2022-1471
Référence CVE CVE-2022-1473
https://www.cve.org/CVERecord?id=CVE-2022-1473
Référence CVE CVE-2022-1705
https://www.cve.org/CVERecord?id=CVE-2022-1705
Référence CVE CVE-2022-1962
https://www.cve.org/CVERecord?id=CVE-2022-1962
Ré
Official advisory ↗CERT-FR · French · CERTFR-2024-AVI-0754Multiples vulnérabilités dans les produits SAPté
Résumé
De multiples vulnérabilités ont été découvertes dans les produits SAP. Certaines d'entre elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, une injection de code indirecte à distance (XSS) et un contournement de la politique de sécurité.
Solutions
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).
Documentation
Bulletin de sécurité SAP du 09 septembre 2024
https://support.sap.com/en/my-support/knowledge-base/security-notes-news/september-2024.html
Référence CVE CVE-2013-3587
https://www.cve.org/CVERecord?id=CVE-2013-3587
Référence CVE CVE-2022-0778
https://www.cve.org/CVERecord?id=CVE-2022-0778
Référence CVE CVE-2023-0215
https://www.cve.org/CVERecord?id=CVE-2023-0215
Référence CVE CVE-2023-0286
https://www.cve.org/CVERecord?id=CVE-2023-0286
Référence CVE CVE-2024-33003
https://www.cve.org/CVERecord?id=CVE-2024-33003
Référence CVE CVE-2024-41728
https://www.cve.org/CVERecord?id=CVE-2024-41728
Référence CVE CVE-2024-41729
https://www.cve.org/CVERecord?id=CVE-2024-41729
Référence CVE CVE-2024-41730
https://www.cve.org/CVERecord?id=CVE-2024-41730
Référence CVE CVE-2024-42371
https://www.cve.org/CVERecord?id=CVE-2024-42371
Référence CVE CVE-2024-42378
https://www.cve.org/CVERecord?id=CVE-2
Official advisory ↗CERT-FR · French · CERTFR-2024-AVI-0671Multiples vulnérabilités dans les produits SAPIS-PS-CA 617, 618, 802, 803, 804, 805, 806, 807 et 808 sans le dernier correctif de sécurité
Résumé
De multiples vulnérabilités ont été découvertes dans les produits SAP. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.
Solutions
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).
Documentation
Bulletin de sécurité SAP august-2024 du 13 août 2024
https://support.sap.com/en/my-support/knowledge-base/security-notes-news/august-2024.html
Référence CVE CVE-2022-0778
https://www.cve.org/CVERecord?id=CVE-2022-0778
Référence CVE CVE-2023-0023
https://www.cve.org/CVERecord?id=CVE-2023-0023
Référence CVE CVE-2023-0215
https://www.cve.org/CVERecord?id=CVE-2023-0215
Référence CVE CVE-2023-0286
https://www.cve.org/CVERecord?id=CVE-2023-0286
Référence CVE CVE-2023-30533
https://www.cve.org/CVERecord?id=CVE-2023-30533
Référence CVE CVE-2024-28166
https://www.cve.org/CVERecord?id=CVE-2024-28166
Référence CVE CVE-2024-29415
https://www.cve.org/CVERecord?id=CVE-2024-29415
Référence CVE CVE-2024-33003
https://www.cve.org/CVERecord?id=CVE-2024-33003
Référence CVE CVE-2024-33005
https://www.cve.org/CVERecord?id=CVE-202
Official advisory ↗CERT-FR · French · CERTFR-2024-AVI-0442Multiples vulnérabilités dans les produits IBMDe multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2024-AVI-0180Multiples vulnérabilités dans les produits IBMCVERecord?id=CVE-2021-35588
Référence CVE CVE-2021-35603
https://www.cve.org/CVERecord?id=CVE-2021-35603
Référence CVE CVE-2021-3572
https://www.cve.org/CVERecord?id=CVE-2021-3572
Référence CVE CVE-2021-3711
https://www.cve.org/CVERecord?id=CVE-2021-3711
Référence CVE CVE-2021-3712
https://www.cve.org/CVERecord?id=CVE-2021-3712
Référence CVE CVE-2021-41035
https://www.cve.org/CVERecord?id=CVE-2021-41035
Référence CVE CVE-2021-4160
https://www.cve.org/CVERecord?id=CVE-2021-4160
Référence CVE CVE-2021-43138
https://www.cve.org/CVERecord?id=CVE-2021-43138
Référence CVE CVE-2021-44906
https://www.cve.org/CVERecord?id=CVE-2021-44906
Référence CVE CVE-2022-0778
https://www.cve.org/CVERecord?id=CVE-2022-0778
Référence CVE CVE-2022-1471
https://www.cve.org/CVERecord?id=CVE-2022-1471
Référence CVE CVE-2022-2097
https://www.cve.org/CVERecord?id=CVE-2022-2097
Référence CVE CVE-2022-21299
https://www.cve.org/CVERecord?id=CVE-2022-21299
Référence CVE CVE-2022-21426
https://www.cve.org/CVERecord?id=CVE-2022-21426
Référence CVE CVE-2022-21434
https://www.cve.org/CVERecord?id=CVE-2022-21434
Référence CVE CVE-2022-21443
https://www.cve.org/CVERecord?id=CVE-2022-21443
Référence CVE CVE-2022-21496
https://www.cve.org/CVERecord?id=CVE-2022-21496
Référence CVE CVE-2022-34165
https://www.cve.org/CVERecord?id=CVE-2
Official advisory ↗CERT-FR · French · CERTFR-2024-AVI-0145Multiples vulnérabilités dans les produits IBMRecord?id=CVE-2021-3711
Référence CVE CVE-2021-3712
https://www.cve.org/CVERecord?id=CVE-2021-3712
Référence CVE CVE-2021-38297
https://www.cve.org/CVERecord?id=CVE-2021-38297
Référence CVE CVE-2021-39293
https://www.cve.org/CVERecord?id=CVE-2021-39293
Référence CVE CVE-2021-41190
https://www.cve.org/CVERecord?id=CVE-2021-41190
Référence CVE CVE-2021-4160
https://www.cve.org/CVERecord?id=CVE-2021-4160
Référence CVE CVE-2021-41771
https://www.cve.org/CVERecord?id=CVE-2021-41771
Référence CVE CVE-2021-41772
https://www.cve.org/CVERecord?id=CVE-2021-41772
Référence CVE CVE-2021-44716
https://www.cve.org/CVERecord?id=CVE-2021-44716
Référence CVE CVE-2022-0778
https://www.cve.org/CVERecord?id=CVE-2022-0778
Référence CVE CVE-2022-1292
https://www.cve.org/CVERecord?id=CVE-2022-1292
Référence CVE CVE-2022-1705
https://www.cve.org/CVERecord?id=CVE-2022-1705
Référence CVE CVE-2022-1962
https://www.cve.org/CVERecord?id=CVE-2022-1962
Référence CVE CVE-2022-2068
https://www.cve.org/CVERecord?id=CVE-2022-2068
Référence CVE CVE-2022-2097
https://www.cve.org/CVERecord?id=CVE-2022-2097
Référence CVE CVE-2022-22576
https://www.cve.org/CVERecord?id=CVE-2022-22576
Référence CVE CVE-2022-23529
https://www.cve.org/CVERecord?id=CVE-2022-23529
Référence CVE CVE-2022-23539
https://www.cve.org/CVERecord?id=CVE-2022-23
Official advisory ↗CERT-FR · French · CERTFR-2024-AVI-0119Multiples vulnérabilités dans les produits Siemensg/CVERecord?id=CVE-2020-11896
Référence CVE CVE-2020-1967
https://www.cve.org/CVERecord?id=CVE-2020-1967
Référence CVE CVE-2020-1971
https://www.cve.org/CVERecord?id=CVE-2020-1971
Référence CVE CVE-2021-3445
https://www.cve.org/CVERecord?id=CVE-2021-3445
Référence CVE CVE-2021-36369
https://www.cve.org/CVERecord?id=CVE-2021-36369
Référence CVE CVE-2021-3638
https://www.cve.org/CVERecord?id=CVE-2021-3638
Référence CVE CVE-2021-4037
https://www.cve.org/CVERecord?id=CVE-2021-4037
Référence CVE CVE-2021-43666
https://www.cve.org/CVERecord?id=CVE-2021-43666
Référence CVE CVE-2021-45451
https://www.cve.org/CVERecord?id=CVE-2021-45451
Référence CVE CVE-2022-0778
https://www.cve.org/CVERecord?id=CVE-2022-0778
Référence CVE CVE-2022-1015
https://www.cve.org/CVERecord?id=CVE-2022-1015
Référence CVE CVE-2022-1348
https://www.cve.org/CVERecord?id=CVE-2022-1348
Référence CVE CVE-2022-23471
https://www.cve.org/CVERecord?id=CVE-2022-23471
Référence CVE CVE-2022-23521
https://www.cve.org/CVERecord?id=CVE-2022-23521
Référence CVE CVE-2022-24834
https://www.cve.org/CVERecord?id=CVE-2022-24834
Référence CVE CVE-2022-2586
https://www.cve.org/CVERecord?id=CVE-2022-2586
Référence CVE CVE-2022-26691
https://www.cve.org/CVERecord?id=CVE-2022-26691
Référence CVE CVE-2022-28737
https://www.cve.org/CVERecord?id=CVE-202
Official advisory ↗CERT-FR · French · CERTFR-2023-AVI-1015Multiples vulnérabilités dans les produits Siemensecord?id=CVE-2021-43396
Référence CVE CVE-2021-43618
https://www.cve.org/CVERecord?id=CVE-2021-43618
Référence CVE CVE-2021-45960
https://www.cve.org/CVERecord?id=CVE-2021-45960
Référence CVE CVE-2021-46143
https://www.cve.org/CVERecord?id=CVE-2021-46143
Référence CVE CVE-2021-46195
https://www.cve.org/CVERecord?id=CVE-2021-46195
Référence CVE CVE-2021-46828
https://www.cve.org/CVERecord?id=CVE-2021-46828
Référence CVE CVE-2021-46848
https://www.cve.org/CVERecord?id=CVE-2021-46848
Référence CVE CVE-2022-0391
https://www.cve.org/CVERecord?id=CVE-2022-0391
Référence CVE CVE-2022-0563
https://www.cve.org/CVERecord?id=CVE-2022-0563
Référence CVE CVE-2022-0778
https://www.cve.org/CVERecord?id=CVE-2022-0778
Référence CVE CVE-2022-1271
https://www.cve.org/CVERecord?id=CVE-2022-1271
Référence CVE CVE-2022-1292
https://www.cve.org/CVERecord?id=CVE-2022-1292
Référence CVE CVE-2022-1304
https://www.cve.org/CVERecord?id=CVE-2022-1304
Référence CVE CVE-2022-1343
https://www.cve.org/CVERecord?id=CVE-2022-1343
Référence CVE CVE-2022-1434
https://www.cve.org/CVERecord?id=CVE-2022-1434
Référence CVE CVE-2022-1473
https://www.cve.org/CVERecord?id=CVE-2022-1473
Référence CVE CVE-2022-2068
https://www.cve.org/CVERecord?id=CVE-2022-2068
Référence CVE CVE-2022-2097
https://www.cve.org/CVERecord?id=CVE-2022-2097
Ré
Official advisory ↗CERT-FR · French · CERTFR-2023-AVI-0051Multiples vulnérabilités dans les produits Junipericle/2022-10-Security-Bulletin-Contrail-Networking-Multiple-Vulnerabilities-have-been-resolved-in-Contrail-Networking-R22-3?language=en_US
Bulletin de sécurité Juniper JSA70179 du 11 janvier 2023
https://supportportal.juniper.net/s/article/2023-01-Security-Bulletin-Northstar-Controller-Pivotal-RabbitMQ-contains-a-web-management-plugin-that-is-vulnerable-to-a-Denial-of-Service-DoS-attack-CVE-2019-11287?language=en_US
Bulletin de sécurité Juniper JSA70180 du 11 janvier 2023
https://supportportal.juniper.net/s/article/2023-01-Security-Bulletin-Junos-OS-and-Junos-OS-Evolved-OpenSSL-Infinite-loop-in-BN-mod-sqrt-reachable-when-parsing-certificates-CVE-2022-0778?language=en_US
Bulletin de sécurité Juniper JSA70181 du 11 janvier 2023
https://supportportal.juniper.net/s/article/2023-01-Security-Bulletin-Junos-OS-and-Junos-OS-Evolved-RPD-might-crash-when-MPLS-ping-is-performed-on-BGP-LSPs-CVE-2023-22398?language=en_US
Bulletin de sécurité Juniper JSA70182 du 11 janvier 2023
https://supportportal.juniper.net/s/article/2023-01-Security-Bulletin-Contrail-Service-Orchestration-Multiple-vulnerabilities-resolved-in-CSO-6-3-0?language=en_US
Bulletin de sécurité Juniper JSA70183 du 11 janvier 2023
https://supportportal.juniper.net/s/article/2023-01-Security-Bulletin-Contrail-Cloud-Multiple-Vulnerabilities-have
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-916Multiples vulnérabilités dans les produits Juniperecord?id=CVE-2021-42550
Référence CVE CVE-2021-42574
https://www.cve.org/CVERecord?id=CVE-2021-42574
Référence CVE CVE-2021-42771
https://www.cve.org/CVERecord?id=CVE-2021-42771
Référence CVE CVE-2021-43527
https://www.cve.org/CVERecord?id=CVE-2021-43527
Référence CVE CVE-2021-45417
https://www.cve.org/CVERecord?id=CVE-2021-45417
Référence CVE CVE-2021-45960
https://www.cve.org/CVERecord?id=CVE-2021-45960
Référence CVE CVE-2021-46143
https://www.cve.org/CVERecord?id=CVE-2021-46143
Référence CVE CVE-2022-0330
https://www.cve.org/CVERecord?id=CVE-2022-0330
Référence CVE CVE-2022-0492
https://www.cve.org/CVERecord?id=CVE-2022-0492
Référence CVE CVE-2022-0778
https://www.cve.org/CVERecord?id=CVE-2022-0778
Référence CVE CVE-2022-0847
https://www.cve.org/CVERecord?id=CVE-2022-0847
Référence CVE CVE-2022-1271
https://www.cve.org/CVERecord?id=CVE-2022-1271
Référence CVE CVE-2022-1292
https://www.cve.org/CVERecord?id=CVE-2022-1292
Référence CVE CVE-2022-1343
https://www.cve.org/CVERecord?id=CVE-2022-1343
Référence CVE CVE-2022-1434
https://www.cve.org/CVERecord?id=CVE-2022-1434
Référence CVE CVE-2022-1473
https://www.cve.org/CVERecord?id=CVE-2022-1473
Référence CVE CVE-2022-22192
https://www.cve.org/CVERecord?id=CVE-2022-22192
Référence CVE CVE-2022-22199
https://www.cve.org/CVERecord?id=CVE-2022-2219
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-850Multiples vulnérabilités dans les produits IBMDe multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquant de provoquer une
exécution de code arbitraire à distance, un déni de service à distance
et un contournement de la politique de sécurité.
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-683Multiples vulnérabilités dans IBM QRadar SIEMg/CVERecord?id=CVE-2021-31566
Référence CVE CVE-2021-39088
https://www.cve.org/CVERecord?id=CVE-2021-39088
Référence CVE CVE-2021-3999
https://www.cve.org/CVERecord?id=CVE-2021-3999
Référence CVE CVE-2021-45960
https://www.cve.org/CVERecord?id=CVE-2021-45960
Référence CVE CVE-2021-46143
https://www.cve.org/CVERecord?id=CVE-2021-46143
Référence CVE CVE-2022-0261
https://www.cve.org/CVERecord?id=CVE-2022-0261
Référence CVE CVE-2022-0359
https://www.cve.org/CVERecord?id=CVE-2022-0359
Référence CVE CVE-2022-0361
https://www.cve.org/CVERecord?id=CVE-2022-0361
Référence CVE CVE-2022-0392
https://www.cve.org/CVERecord?id=CVE-2022-0392
Référence CVE CVE-2022-0778
https://www.cve.org/CVERecord?id=CVE-2022-0778
Référence CVE CVE-2022-22822
https://www.cve.org/CVERecord?id=CVE-2022-22822
Référence CVE CVE-2022-22823
https://www.cve.org/CVERecord?id=CVE-2022-22823
Référence CVE CVE-2022-22824
https://www.cve.org/CVERecord?id=CVE-2022-22824
Référence CVE CVE-2022-22825
https://www.cve.org/CVERecord?id=CVE-2022-22825
Référence CVE CVE-2022-22826
https://www.cve.org/CVERecord?id=CVE-2022-22826
Référence CVE CVE-2022-22827
https://www.cve.org/CVERecord?id=CVE-2022-22827
Référence CVE CVE-2022-23218
https://www.cve.org/CVERecord?id=CVE-2022-23218
Référence CVE CVE-2022-23219
https://www.cve.org/CVERecord?id=C
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-619Multiples vulnérabilités dans IBM QRadarDe multiples vulnérabilités ont été découvertes dans IBM QRadar.
Certaines d'entre elles permettent à un attaquant de provoquer un déni
de service à distance, une atteinte à l'intégrité des données et une
atteinte à la confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-611Multiples vulnérabilités dans IBM QRadarDe multiples vulnérabilités ont été découvertes dans IBM QRadar. Elles
permettent à un attaquant de provoquer une exécution de code arbitraire
à distance, un déni de service à distance et une élévation de
privilèges.
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-605Vulnérabilité dans CheckPoint Quantum Smart-1Une vulnérabilité a été découverte dans CheckPoint Quantum Smart-1. Elle
permet à un attaquant de provoquer un déni de service à distance.
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-597Multiples vulnérabilités dans IBM Spectrum Protect PlusDe multiples vulnérabilités ont été découvertes dans IBM Spectrum
Protect Plus. Certaines d'entre elles permettent à un attaquant de
provoquer une exécution de code arbitraire à distance, un déni de
service à distance et un contournement de la politique de sécurité.
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-591Multiples vulnérabilités dans les produits IBMERecord?id=CVE-2021-43784
Référence CVE CVE-2021-44716
https://www.cve.org/CVERecord?id=CVE-2021-44716
Référence CVE CVE-2021-44733
https://www.cve.org/CVERecord?id=CVE-2021-44733
Référence CVE CVE-2021-44907
https://www.cve.org/CVERecord?id=CVE-2021-44907
Référence CVE CVE-2021-45485
https://www.cve.org/CVERecord?id=CVE-2021-45485
Référence CVE CVE-2021-45486
https://www.cve.org/CVERecord?id=CVE-2021-45486
Référence CVE CVE-2022-0185
https://www.cve.org/CVERecord?id=CVE-2022-0185
Référence CVE CVE-2022-0286
https://www.cve.org/CVERecord?id=CVE-2022-0286
Référence CVE CVE-2022-0492
https://www.cve.org/CVERecord?id=CVE-2022-0492
Référence CVE CVE-2022-0778
https://www.cve.org/CVERecord?id=CVE-2022-0778
Référence CVE CVE-2022-0847
https://www.cve.org/CVERecord?id=CVE-2022-0847
Référence CVE CVE-2022-0850
https://www.cve.org/CVERecord?id=CVE-2022-0850
Référence CVE CVE-2022-1011
https://www.cve.org/CVERecord?id=CVE-2022-1011
Référence CVE CVE-2022-22942
https://www.cve.org/CVERecord?id=CVE-2022-22942
Référence CVE CVE-2022-27191
https://www.cve.org/CVERecord?id=CVE-2022-27191
Gestion détaillée du document
le 30 juin 2022
Version initiale
Alertes
Avis
Bulletins d’actualités
Mentions légales
Conditions générales
À propos
Contact
cyber.gouv.fr
service-public.fr
legifrance.gouv.fr
info.gouv.fr
franc
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-570Multiples vulnérabilités dans les produits IBMcord?id=CVE-2019-0210
Référence CVE CVE-2020-13949
https://www.cve.org/CVERecord?id=CVE-2020-13949
Référence CVE CVE-2021-22945
https://www.cve.org/CVERecord?id=CVE-2021-22945
Référence CVE CVE-2021-22946
https://www.cve.org/CVERecord?id=CVE-2021-22946
Référence CVE CVE-2021-22947
https://www.cve.org/CVERecord?id=CVE-2021-22947
Référence CVE CVE-2021-3712
https://www.cve.org/CVERecord?id=CVE-2021-3712
Référence CVE CVE-2021-44228
https://www.cve.org/CVERecord?id=CVE-2021-44228
Référence CVE CVE-2021-45046
https://www.cve.org/CVERecord?id=CVE-2021-45046
Référence CVE CVE-2021-45105
https://www.cve.org/CVERecord?id=CVE-2021-45105
Référence CVE CVE-2022-0778
https://www.cve.org/CVERecord?id=CVE-2022-0778
Référence CVE CVE-2022-1292
https://www.cve.org/CVERecord?id=CVE-2022-1292
Référence CVE CVE-2022-1343
https://www.cve.org/CVERecord?id=CVE-2022-1343
Référence CVE CVE-2022-1434
https://www.cve.org/CVERecord?id=CVE-2022-1434
Référence CVE CVE-2022-1473
https://www.cve.org/CVERecord?id=CVE-2022-1473
Référence CVE CVE-2022-22576
https://www.cve.org/CVERecord?id=CVE-2022-22576
Référence CVE CVE-2022-27774
https://www.cve.org/CVERecord?id=CVE-2022-27774
Référence CVE CVE-2022-27775
https://www.cve.org/CVERecord?id=CVE-2022-27775
Référence CVE CVE-2022-27776
https://www.cve.org/CVERecord?id=CVE-2022-
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-551Multiples vulnérabilités dans ZimbraDe multiples vulnérabilités ont été découvertes dans Zimbra. Certaines
d'entre elles permettent à un attaquant de provoquer un déni de service
à distance, un contournement de la politique de sécurité et une atteinte
à l'intégrité des données.
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-547Multiples vulnérabilités dans les produits Siemensord?id=CVE-2021-39293
Référence CVE CVE-2021-4034
https://www.cve.org/CVERecord?id=CVE-2021-4034
Référence CVE CVE-2021-40438
https://www.cve.org/CVERecord?id=CVE-2021-40438
Référence CVE CVE-2021-41089
https://www.cve.org/CVERecord?id=CVE-2021-41089
Référence CVE CVE-2021-41091
https://www.cve.org/CVERecord?id=CVE-2021-41091
Référence CVE CVE-2021-41092
https://www.cve.org/CVERecord?id=CVE-2021-41092
Référence CVE CVE-2021-41103
https://www.cve.org/CVERecord?id=CVE-2021-41103
Référence CVE CVE-2021-45960
https://www.cve.org/CVERecord?id=CVE-2021-45960
Référence CVE CVE-2021-46143
https://www.cve.org/CVERecord?id=CVE-2021-46143
Référence CVE CVE-2022-0778
https://www.cve.org/CVERecord?id=CVE-2022-0778
Référence CVE CVE-2022-0847
https://www.cve.org/CVERecord?id=CVE-2022-0847
Référence CVE CVE-2022-22822
https://www.cve.org/CVERecord?id=CVE-2022-22822
Référence CVE CVE-2022-22823
https://www.cve.org/CVERecord?id=CVE-2022-22823
Référence CVE CVE-2022-22824
https://www.cve.org/CVERecord?id=CVE-2022-22824
Référence CVE CVE-2022-22825
https://www.cve.org/CVERecord?id=CVE-2022-22825
Référence CVE CVE-2022-22826
https://www.cve.org/CVERecord?id=CVE-2022-22826
Référence CVE CVE-2022-22827
https://www.cve.org/CVERecord?id=CVE-2022-22827
Référence CVE CVE-2022-23852
https://www.cve.org/CVERecord?id=CVE
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-523Multiples vulnérabilités dans les produits IBMDe multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquant de provoquer une
exécution de code arbitraire à distance, un déni de service à distance
et un contournement de la politique de sécurité.
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-467Multiples vulnérabilités dans le noyau Linux de SUSE/CVERecord?id=CVE-2021-4187
Référence CVE CVE-2021-4192
https://www.cve.org/CVERecord?id=CVE-2021-4192
Référence CVE CVE-2021-4193
https://www.cve.org/CVERecord?id=CVE-2021-4193
Référence CVE CVE-2021-44224
https://www.cve.org/CVERecord?id=CVE-2021-44224
Référence CVE CVE-2021-44790
https://www.cve.org/CVERecord?id=CVE-2021-44790
Référence CVE CVE-2021-45444
https://www.cve.org/CVERecord?id=CVE-2021-45444
Référence CVE CVE-2021-46059
https://www.cve.org/CVERecord?id=CVE-2021-46059
Référence CVE CVE-2022-0128
https://www.cve.org/CVERecord?id=CVE-2022-0128
Référence CVE CVE-2022-0530
https://www.cve.org/CVERecord?id=CVE-2022-0530
Référence CVE CVE-2022-0778
https://www.cve.org/CVERecord?id=CVE-2022-0778
Référence CVE CVE-2022-22589
https://www.cve.org/CVERecord?id=CVE-2022-22589
Référence CVE CVE-2022-22663
https://www.cve.org/CVERecord?id=CVE-2022-22663
Référence CVE CVE-2022-22665
https://www.cve.org/CVERecord?id=CVE-2022-22665
Référence CVE CVE-2022-22673
https://www.cve.org/CVERecord?id=CVE-2022-22673
Référence CVE CVE-2022-22674
https://www.cve.org/CVERecord?id=CVE-2022-22674
Référence CVE CVE-2022-22675
https://www.cve.org/CVERecord?id=CVE-2022-22675
Référence CVE CVE-2022-22677
https://www.cve.org/CVERecord?id=CVE-2022-22677
Référence CVE CVE-2022-22719
https://www.cve.org/CVERecord?id=C
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-466Multiples vulnérabilités dans les produits Apple/CVERecord?id=CVE-2021-4187
Référence CVE CVE-2021-4192
https://www.cve.org/CVERecord?id=CVE-2021-4192
Référence CVE CVE-2021-4193
https://www.cve.org/CVERecord?id=CVE-2021-4193
Référence CVE CVE-2021-44224
https://www.cve.org/CVERecord?id=CVE-2021-44224
Référence CVE CVE-2021-44790
https://www.cve.org/CVERecord?id=CVE-2021-44790
Référence CVE CVE-2021-45444
https://www.cve.org/CVERecord?id=CVE-2021-45444
Référence CVE CVE-2021-46059
https://www.cve.org/CVERecord?id=CVE-2021-46059
Référence CVE CVE-2022-0128
https://www.cve.org/CVERecord?id=CVE-2022-0128
Référence CVE CVE-2022-0530
https://www.cve.org/CVERecord?id=CVE-2022-0530
Référence CVE CVE-2022-0778
https://www.cve.org/CVERecord?id=CVE-2022-0778
Référence CVE CVE-2022-22589
https://www.cve.org/CVERecord?id=CVE-2022-22589
Référence CVE CVE-2022-22663
https://www.cve.org/CVERecord?id=CVE-2022-22663
Référence CVE CVE-2022-22665
https://www.cve.org/CVERecord?id=CVE-2022-22665
Référence CVE CVE-2022-22673
https://www.cve.org/CVERecord?id=CVE-2022-22673
Référence CVE CVE-2022-22674
https://www.cve.org/CVERecord?id=CVE-2022-22674
Référence CVE CVE-2022-22675
https://www.cve.org/CVERecord?id=CVE-2022-22675
Référence CVE CVE-2022-22677
https://www.cve.org/CVERecord?id=CVE-2022-22677
Référence CVE CVE-2022-22719
https://www.cve.org/CVERecord?id=C
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-459Multiples vulnérabilités dans les produits IBMDe multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquant de provoquer une
exécution de code arbitraire à distance, un déni de service à distance
et une atteinte à l'intégrité des données.
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-429Multiples vulnérabilités dans Nessus Network MonitorDe multiples vulnérabilités ont été découvertes dans Nessus Network
Monitor. Certaines d'entre elles permettent à un attaquant de provoquer
une exécution de code arbitraire à distance, un déni de service à
distance et une atteinte à l'intégrité des données.
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-417Multiples vulnérabilités dans les produits Arubaalité des données.
Solution
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des
correctifs (cf. section Documentation).
Documentation
Bulletin de sécurité Aruba ARUBA-PSA-2022-007 du 04 mai 2022
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-007.txt
Bulletin de sécurité Aruba ARUBA-PSA-2022-009 du 04 mai 2022
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-009.txt
Référence CVE CVE-2021-21419
https://www.cve.org/CVERecord?id=CVE-2021-21419
Référence CVE CVE-2021-23665
https://www.cve.org/CVERecord?id=CVE-2021-23665
Référence CVE CVE-2021-33503
https://www.cve.org/CVERecord?id=CVE-2021-33503
Référence CVE CVE-2022-0778
https://www.cve.org/CVERecord?id=CVE-2022-0778
Référence CVE CVE-2022-23657
https://www.cve.org/CVERecord?id=CVE-2022-23657
Référence CVE CVE-2022-23658
https://www.cve.org/CVERecord?id=CVE-2022-23658
Référence CVE CVE-2022-23659
https://www.cve.org/CVERecord?id=CVE-2022-23659
Référence CVE CVE-2022-23660
https://www.cve.org/CVERecord?id=CVE-2022-23660
Référence CVE CVE-2022-23661
https://www.cve.org/CVERecord?id=CVE-2022-23661
Référence CVE CVE-2022-23662
https://www.cve.org/CVERecord?id=CVE-2022-23662
Référence CVE CVE-2022-23663
https://www.cve.org/CVERecord?id=CVE-2022-23663
Référence CVE CVE-2022-23664
https://www.cve.org/CVERecord?id=C
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-379Multiples vulnérabilités dans Stormshield Network VPN ClientDe multiples vulnérabilités ont été découvertes dans Stormshield Network
VPN Client. Elles permettent à un attaquant de provoquer une exécution
de code arbitraire à distance et un déni de service à distance.
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-373Vulnérabilité dans les produits Palo Alto NetworksUne vulnérabilité a été découverte dans les produits Palo Alto Networks.
Elle permet à un attaquant de provoquer un déni de service à distance.
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-370Multiples vulnérabilités dans Tenable.scDe multiples vulnérabilités ont été découvertes dans Tenable.sc.
Certaines d'entre elles permettent à un attaquant de provoquer une
exécution de code arbitraire à distance, un déni de service à distance
et une atteinte à l'intégrité des données.
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-364Multiples vulnérabilités dans Oracle Java SEDe multiples vulnérabilités ont été découvertes dans Oracle Java SE.
Certaines d'entre elles permettent à un attaquant de provoquer un déni
de service à distance, un contournement de la politique de sécurité et
une atteinte à l'intégrité des données.
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-352Multiples vulnérabilités dans les produits TheGreenBowDe multiples vulnérabilités ont été découvertes dans les produits
TheGreenBow. Elles permettent à un attaquant de provoquer une exécution
de code arbitraire à distance et un déni de service à distance.
La première vulnérabilité ne dispose pas d'identifiant CVE.
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-330Multiples vulnérabilités dans Stormshield Network Security.cve.org/CVERecord?id=CVE-2022-0361
Référence CVE CVE-2022-0368
https://www.cve.org/CVERecord?id=CVE-2022-0368
Référence CVE CVE-2022-0392
https://www.cve.org/CVERecord?id=CVE-2022-0392
Référence CVE CVE-2022-0393
https://www.cve.org/CVERecord?id=CVE-2022-0393
Référence CVE CVE-2022-0407
https://www.cve.org/CVERecord?id=CVE-2022-0407
Référence CVE CVE-2022-0408
https://www.cve.org/CVERecord?id=CVE-2022-0408
Référence CVE CVE-2022-0413
https://www.cve.org/CVERecord?id=CVE-2022-0413
Référence CVE CVE-2022-0417
https://www.cve.org/CVERecord?id=CVE-2022-0417
Référence CVE CVE-2022-0443
https://www.cve.org/CVERecord?id=CVE-2022-0443
Référence CVE CVE-2022-0778
https://www.cve.org/CVERecord?id=CVE-2022-0778
Référence CVE CVE-2022-20698
https://www.cve.org/CVERecord?id=CVE-2022-20698
Gestion détaillée du document
le 13 avril 2022
Version initiale
Alertes
Avis
Bulletins d’actualités
Mentions légales
Conditions générales
À propos
Contact
cyber.gouv.fr
service-public.fr
legifrance.gouv.fr
info.gouv.fr
france.fr
info.gouv.fr/risques
Premier Ministre / Secrétariat Général de la Défense et de la Sécurité Nationale / Agence nationale de la
sécurité des systèmes d'information
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-319Vulnérabilité dans Stormshield Endpoint SecurityUne vulnérabilité a été découverte dans Stormshield Endpoint Security.
Elle permet à un attaquant de provoquer un déni de service à distance.
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-320Multiples vulnérabilités dans Tenable Tenable.scDe multiples vulnérabilités ont été découvertes dans Tenable Tenable.sc.
Elles permettent à un attaquant de provoquer une exécution de code
arbitraire à distance et un déni de service à distance.
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-303Vulnérabilité dans Tenable Nessus AgentUne vulnérabilité a été découverte dans Tenable Nessus Agent. Elle
permet à un attaquant de provoquer un déni de service à distance.
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-300Vulnérabilité dans les produits Pulse SecureUne vulnérabilité a été découverte dans les produits Pulse Secure. Elle
permet à un attaquant de provoquer un déni de service à distance.
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-296Vulnérabilité dans Stormshield Management CenterUne vulnérabilité a été découverte dans Stormshield Management Center.
Elle permet à un attaquant de provoquer un déni de service à distance.
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-292Vulnérabilité dans Tenable NessusUne vulnérabilité a été découverte dans Tenable Nessus. Elle permet à un
attaquant de provoquer un déni de service à distance.
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-258Vulnérabilité dans les produits SophosUne vulnérabilité a été découverte dans les produits Sophos. Elle permet
à un attaquant de provoquer un déni de service à distance.
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-255Vulnérabilité dans les produits Check PointUne vulnérabilité a été découverte dans les produits Check Point. Elle
permet à un attaquant de provoquer un déni de service à distance.
Official advisory ↗CERT-FR · French · CERTFR-2022-AVI-250Vulnérabilité dans OpenSSLUne vulnérabilité a été découverte dans OpenSSL. Elle permet à un
attaquant de provoquer un déni de service à distance.
Official advisory ↗JVN iPedia · Japanese · JVNDB-2022-001476OpenSSL の BN_mod_sqrt() における法が非素数のときに無限ループを引き起こす問題OpenSSL Project より、 OpenSSL Security Advisory [15 March 2022] が公開されました。 深刻度 − 高(Severity: High) OpenSSL の BN_mod_sqrt() は有限体における平方根を計算します。BN_mod_sqrt() には、法が非素数の場合、無限ループを引き起こす問題があります。 BN_mod_sqrt() は圧縮形式の楕円曲線暗号の公開鍵を含む証明書、もしくは圧縮形式でエンコードされた基準点(Base Point)を持つ楕円曲線パラメータを含む証明書をパースする際に使用されます。また、OpenSSL は証明書の署名を検証する前に証明書をパースするため、外部から受け取った証明書をパースする際、無限ループを引き起こされる可能性があります。同様に、秘密鍵に楕円曲線パラメータを含んでいる場合にも細工された秘密鍵をパースすることで無限ループを引き起こされる可能性があります。 この問題は次の状況で起こる可能性があります。 * TLS クライアントがサーバ証明書を処理する * TLS サーバがクライアント証明書を処理する * ホスティングサービス事業者が顧客から受け取った証明書や秘密鍵を処理する * 認証局が契約者から受け取った CSR (証明書署名要求) データを処理する * その他、ASN.1 形式の楕円曲線パラメータを処理する場合
Official advisory ↗JVN iPedia · Japanese · JVNDB-2026-011246Siemens製品に対するアップデート(2026年4月)新規:8件 SSA-019200: Multiple Vulnerabilities in SCALANCE W-700 IEEE 802.11n Devices Before V6.6.0
SSA-225816: Memory Corruption Vulnerability in RUGGEDCOM CROSSBOW Station Access Controller Before V5.8
SSA-605717: Authorization Bypass Vulnerability in SINEC NMS Before V4.0 SP3
SSA-609469: Authorization Bypass Vulnerability in Industrial Edge Management
SSA-628843: Out of Bound Read Vulnerability in TPM 2.0
SSA-741509: Privilege Escalation Vulnerability in RUGGEDCOM CROSSBOW Secure Access Manager Primary Before V5.8
SSA-801704: Authentication Bypass Vulnerability in SINEC NMS
SSA-981622: Improper Certificate Validation Vulnerability in Siemens Analytics Toolkit
更新:13件 SSA-186293: XML External Entity (XXE) Injection Vulnerability in SIMOTION SCOUT, SIMOTION SCOUT TIA and SINAMICS STARTER
SSA-216014: Vulnerabilities in EFI variable of SIMATIC IPCs, SIMATIC Tablet PCs, and SIMATIC Field PGs
SSA-244969: OpenSSL Vulnerability in Industrial Products
SSA-311973: Multiple Local Privilege Escalation Vulnerabilities in SINEC NMS and User Management Component (UMC)
SSA-408105: Buffer Overflow Vulnerabilities in OpenSSL 3.0 Affecting Siemens Products
SSA-552702: Privilege Escalation Vulnerability in the Web Interface of SCALANCE and RUGGEDCOM Products
SSA-599968: Denial of Service Vulnerability in Profinet Devices
SSA-710008: Multiple Web Vulnerabilities in SCALANCE Products
SSA-712929: Denial of Service Vulnerability in OpenSSL (CVE-2022-0778) Affecting Industrial Products
SSA-726617: Incorrect Privilege Assignment Vulnerability in Mendix OIDC SSO Module
SSA-726834: Denial of Service Vulnerability in the RADIUS Client of SIPROTEC 5 Devices
SSA-827968: Vulnerability in Nozomi Guardian/CMC on RUGGEDCOM APE1808 Devices
SSA-913875: Frame Aggregation and Fragmentation Vulnerabilities in 802.11
Official advisory ↗KISA KrCERT/CC · Korean · KNVD-5576HP Teradici PCoIP 보안 업데이트 권고HP Teradici PCoIP에서 발생하는 OpenSSL 관련 취약점 (CVE-2022-0778) 등 2개 [1]
Official advisory ↗KISA KrCERT/CC · Korean · KNVD-5533OpenSSL 취약점 보안 업데이트 권고o OpenSSL에서 발생하는 취약점을 해결한 보안 업데이트 발표
o 낮은 버전 사용자는 서비스 거부 공격에 취약하므로, 최신 버전으로 업데이트 권고
##### □ 설명 [1]
o OpenSSL 내 BN_mod_sqrt() 함수에서 연산 시 무한 루프로 인해 발생하는 서비스 거부 취약점(CVE-2022-0778)
Official advisory ↗NCSC-NL · Dutch · NCSC-2024-0333Kwetsbaarheden verholpen in SAP productenEen kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade:
- Server Side Request Forgery (SSRF)
- Cross-Site Scripting (XSS)
- Omzeilen van authenticatie
- Omzeilen van beveiligingsmaatregel
- Manipulatie van gegevens
- Toegang tot gevoelige gegevens
Official advisory ↗NCSC-NL · Dutch · NCSC-2024-0239Kwetsbaarheden verholpen in Solarwinds PlatformEen kwaadwillende kan de kwetsbaarheden misbruiken om een Denial-of-Service te veroorzaken, een command-injection uit te voeren, of om een Cross-Site-Scripting-aanval uit te voeren. Een dergelijke aanval kan leiden tot uitvoer van willekeurige code in de browser van het slachtoffer.
Voor succesvol misbruik moet de kwaadwillende voorafgaande authenticatie hebben.
Official advisory ↗NCSC-NL · Dutch · NCSC-2026-0112Kwetsbaarheden verholpen in Siemens productenA critical vulnerability in OpenSSL's BN_mod_sqrt() function causes infinite loops when parsing crafted certificates with invalid elliptic curve parameters, leading to denial of service across multiple OpenSSL versions and affecting various products including Node.js, Oracle, SAP, and NetApp.
Official advisory ↗