BlackTreeCVE Intelligence
← Back to the CVE catalogue
Full vulnerability report · 2023
CVE-2023-44487High confidence

HTTP/2 Rapid Reset Attack Vulnerability

IETF · HTTP/2

Official source article: Siemens SSA-082556 ↗. Check the applicable product and release in the original source.

7.5HighCVSS 3.1
Recommended action
Patch only the product branches with a verified fix

CISA confirms exploitation in the wild and lists 2023-10-31 as the remediation due date. Verified remediation exists for at least one product or source, but 17 structured product or package states remain unresolved. Apply remediation only to the exact product branch confirmed by its source.

Fix availability varies by product
R
Operational reassessment

Published severity in operational context

Open reassessment dashboard →
Published severityHighOperational priority:Critical, raised one band.upgradedsince 10 Oct 2023

Evidence used

  • CISA confirms exploitation in the wild.
  • A structured source references public exploit or proof-of-concept material.
  • The selected CVSS metric records a network-reachable, unauthenticated path with no user interaction.
  • EPSS is 100.00% for the current model date.

Compensating controls

  • Validate the affected product branch and deploy the verified fixed release.
  • Restrict the affected network interface to trusted sources where business-safe.
  • Increase monitoring for the attack path and post-exploitation behaviour described in the report.

Verification

  1. Confirm that the asset runs IETF HTTP/2 and falls inside the recorded affected range.
  2. Verify the installed build against the product-specific fixed version after deployment.
  3. Validate exposure, authentication requirements and compensating controls in the actual environment.
  4. Reopen this reassessment when CVSS, KEV, EPSS, exploit evidence or remediation changes.
Mitigation target: Within 3 daysRemediation target: Within 90 days

This automated reassessment organises public evidence. It does not know asset exposure, business impact or control effectiveness and does not replace CVSS or a human risk decision.

Cross-source reconciliation

Remediation availability differs by product scope

Verified remediation exists for at least one product or source, but 17 structured product or package states remain unresolved. Apply remediation only to the exact product branch confirmed by its source.

Distribution package intelligence

Release-specific package status

Alpine, Debian, ubuntu findings are scoped to the named distribution, release and source package. An absent finding does not mean a package is unaffected.

71 package states
Package result overrides the generic status

BlackTree has verified remediation for at least one product or source, but the relevant distribution still reports no fixed package for 8 affected package states shown here. Treat those rows as affected with no fix until that distribution publishes a fixed version.

Repository candidate not checked

A published vendor fix does not prove that a matching update is enabled and installable on a particular asset. Confirm the local package candidate before scheduling remediation.

Distribution releaseSource packageVendor stateFixed versionEvidence
Alpine v3.23v3.23 · communitygoVendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.1.21.3-r0Alpine Security Database ↗Source updated 8 Oct 2026
Alpine v3.23v3.23 · communitygrpcVendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.1.59.3-r0Alpine Security Database ↗Source updated 8 Oct 2026
Alpine v3.23v3.23 · communityjetty-runnerVendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.9.4.53.20231009-r0Alpine Security Database ↗Source updated 8 Oct 2026
Alpine v3.23v3.23 · communitynetdataVendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.1.43.2-r1Alpine Security Database ↗Source updated 8 Oct 2026
Alpine v3.23v3.23 · communitynodejs-currentVendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.0Alpine Security Database ↗Source updated 8 Oct 2026
Alpine v3.23v3.23 · communityopenjdk21Vendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.21.0.2_p13-r0Alpine Security Database ↗Source updated 8 Oct 2026
Alpine v3.23v3.23 · communitytrafficserver9Vendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.9.2.3-r0Alpine Security Database ↗Source updated 8 Oct 2026
Alpine v3.23v3.23 · mainnghttp2Vendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.1.57.0-r0Alpine Security Database ↗Source updated 8 Oct 2026
Alpine v3.23v3.23 · mainnginxVendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.1.24.0-r12Alpine Security Database ↗Source updated 8 Oct 2026
Alpine v3.23v3.23 · mainnodejsVendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.0Alpine Security Database ↗Source updated 8 Oct 2026
Alpine v3.22v3.22 · communitygoVendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.1.21.3-r0Alpine Security Database ↗Source updated 11 Sep 2026
Alpine v3.22v3.22 · communitygrpcVendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.1.59.3-r0Alpine Security Database ↗Source updated 11 Sep 2026
Alpine v3.22v3.22 · communityjetty-runnerVendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.9.4.53.20231009-r0Alpine Security Database ↗Source updated 11 Sep 2026
Alpine v3.22v3.22 · communitynetdataVendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.1.43.2-r1Alpine Security Database ↗Source updated 11 Sep 2026
Alpine v3.22v3.22 · communitynodejs-currentVendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.0Alpine Security Database ↗Source updated 11 Sep 2026
Alpine v3.22v3.22 · communityopenjdk21Vendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.21.0.2_p13-r0Alpine Security Database ↗Source updated 11 Sep 2026
Alpine v3.22v3.22 · communitytrafficserver9Vendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.9.2.3-r0Alpine Security Database ↗Source updated 11 Sep 2026
Alpine v3.22v3.22 · mainnghttp2Vendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.1.57.0-r0Alpine Security Database ↗Source updated 8 Oct 2026
Alpine v3.22v3.22 · mainnginxVendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.1.24.0-r12Alpine Security Database ↗Source updated 8 Oct 2026
Alpine v3.22v3.22 · mainnodejsVendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.0Alpine Security Database ↗Source updated 8 Oct 2026
Alpine v3.21v3.21 · communitygoVendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.1.21.3-r0Alpine Security Database ↗Source updated 19 Aug 2026
Alpine v3.21v3.21 · communitygrpcVendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.1.59.3-r0Alpine Security Database ↗Source updated 19 Aug 2026
Alpine v3.21v3.21 · communityjetty-runnerVendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.9.4.53.20231009-r0Alpine Security Database ↗Source updated 19 Aug 2026
Alpine v3.21v3.21 · communitynetdataVendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.1.43.2-r1Alpine Security Database ↗Source updated 19 Aug 2026
Alpine v3.21v3.21 · communitynodejs-currentVendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.0Alpine Security Database ↗Source updated 19 Aug 2026
Alpine v3.21v3.21 · communityopenjdk21Vendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.21.0.2_p13-r0Alpine Security Database ↗Source updated 19 Aug 2026
Alpine v3.21v3.21 · communitytrafficserver9Vendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.9.2.3-r0Alpine Security Database ↗Source updated 19 Aug 2026
Alpine v3.21v3.21 · mainnghttp2Vendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.1.57.0-r0Alpine Security Database ↗Source updated 8 Oct 2026
Alpine v3.21v3.21 · mainnginxVendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.1.24.0-r12Alpine Security Database ↗Source updated 8 Oct 2026
Alpine v3.21v3.21 · mainnodejsVendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.0Alpine Security Database ↗Source updated 8 Oct 2026
Debian trixietrixie · sourcednsdistVendor fix publishedDebian records a fixed source-package version for this release.1.8.2-2Debian Security Tracker ↗Source updated 8 Oct 2026
Debian trixietrixie · sourcegrpcAffected, no fix publishedDebian currently tracks this release as open.Not published in this feedDebian Security Tracker ↗Source updated 8 Oct 2026
Debian trixietrixie · sourcehaproxyVendor fix publishedDebian records a fixed source-package version for this release.1.8.13-1Debian Security Tracker ↗Source updated 8 Oct 2026
Debian trixietrixie · sourcejetty9Vendor fix publishedDebian records a fixed source-package version for this release.9.4.53-1Debian Security Tracker ↗Source updated 8 Oct 2026
Debian trixietrixie · sourcenettyVendor fix publishedDebian records a fixed source-package version for this release.1:4.1.48-8Debian Security Tracker ↗Source updated 8 Oct 2026
Debian trixietrixie · sourcenghttp2Vendor fix publishedDebian records a fixed source-package version for this release.1.57.0-1Debian Security Tracker ↗Source updated 8 Oct 2026
Debian trixietrixie · sourcenginxVendor fix publishedDebian records a fixed source-package version for this release.1.24.0-2Debian Security Tracker ↗Source updated 8 Oct 2026
Debian trixietrixie · sourcetomcat10Vendor fix publishedDebian records a fixed source-package version for this release.10.1.14-1Debian Security Tracker ↗Source updated 8 Oct 2026
Debian trixietrixie · sourcetomcat9Vendor fix publishedDebian records a fixed source-package version for this release.9.0.70-2Debian Security Tracker ↗Source updated 8 Oct 2026
Debian trixietrixie · sourcevarnishVendor fix publishedDebian records a fixed source-package version for this release.7.5.0-1Debian Security Tracker ↗Source updated 8 Oct 2026
Debian bookwormbookworm · sourcednsdistAffected, no fix publishedDebian currently tracks this release as open.Not published in this feedDebian Security Tracker ↗Source updated 8 Oct 2026
Debian bookwormbookworm · sourcegrpcAffected, no fix publishedDebian currently tracks this release as open.Not published in this feedDebian Security Tracker ↗Source updated 8 Oct 2026
Debian bookwormbookworm · sourceh2oAffected, no fix publishedDebian currently tracks this release as open.Not published in this feedDebian Security Tracker ↗Source updated 8 Oct 2026
Debian bookwormbookworm · sourcehaproxyVendor fix publishedDebian records a fixed source-package version for this release.1.8.13-1Debian Security Tracker ↗Source updated 8 Oct 2026
Debian bookwormbookworm · sourcejetty9Vendor fix publishedDebian records a fixed source-package version for this release.9.4.50-4+deb12u2Debian Security Tracker ↗Source updated 8 Oct 2026
Debian bookwormbookworm · sourcenettyVendor fix publishedDebian records a fixed source-package version for this release.1:4.1.48-7+deb12u1Debian Security Tracker ↗Source updated 8 Oct 2026
Debian bookwormbookworm · sourcenghttp2Vendor fix publishedDebian records a fixed source-package version for this release.1.52.0-1+deb12u1Debian Security Tracker ↗Source updated 8 Oct 2026
Debian bookwormbookworm · sourcenginxAffected, no fix publishedDebian currently tracks this release as open.Not published in this feedDebian Security Tracker ↗Source updated 8 Oct 2026
Debian bookwormbookworm · sourcetomcat10Vendor fix publishedDebian records a fixed source-package version for this release.10.1.6-1+deb12u1Debian Security Tracker ↗Source updated 8 Oct 2026
Debian bookwormbookworm · sourcetomcat9Vendor fix publishedDebian records a fixed source-package version for this release.9.0.70-2Debian Security Tracker ↗Source updated 8 Oct 2026
Debian bookwormbookworm · sourcetrafficserverVendor fix publishedDebian records a fixed source-package version for this release.9.2.3+ds-1+deb12u1Debian Security Tracker ↗Source updated 8 Oct 2026
Debian bookwormbookworm · sourcevarnishAffected, no fix publishedDebian currently tracks this release as open.Not published in this feedDebian Security Tracker ↗Source updated 8 Oct 2026
Debian forkyforky · sourcednsdistVendor fix publishedDebian records a fixed source-package version for this release.1.8.2-2Debian Security Tracker ↗Source updated 8 Oct 2026
Debian forkyforky · sourcegrpcAffected, no fix publishedDebian currently tracks this release as open.Not published in this feedDebian Security Tracker ↗Source updated 8 Oct 2026
Debian forkyforky · sourcehaproxyVendor fix publishedDebian records a fixed source-package version for this release.1.8.13-1Debian Security Tracker ↗Source updated 8 Oct 2026
Debian forkyforky · sourcejetty9Vendor fix publishedDebian records a fixed source-package version for this release.9.4.53-1Debian Security Tracker ↗Source updated 8 Oct 2026
Debian forkyforky · sourcenettyVendor fix publishedDebian records a fixed source-package version for this release.1:4.1.48-8Debian Security Tracker ↗Source updated 8 Oct 2026
Debian forkyforky · sourcenghttp2Vendor fix publishedDebian records a fixed source-package version for this release.1.57.0-1Debian Security Tracker ↗Source updated 8 Oct 2026
Debian forkyforky · sourcenginxVendor fix publishedDebian records a fixed source-package version for this release.1.24.0-2Debian Security Tracker ↗Source updated 8 Oct 2026
Debian forkyforky · sourcetomcat10Vendor fix publishedDebian records a fixed source-package version for this release.10.1.14-1Debian Security Tracker ↗Source updated 8 Oct 2026
Debian forkyforky · sourcetomcat9Vendor fix publishedDebian records a fixed source-package version for this release.9.0.70-2Debian Security Tracker ↗Source updated 8 Oct 2026
Debian sidsid · sourcednsdistVendor fix publishedDebian records a fixed source-package version for this release.1.8.2-2Debian Security Tracker ↗Source updated 8 Oct 2026
Debian sidsid · sourcegrpcAffected, no fix publishedDebian currently tracks this release as open.Not published in this feedDebian Security Tracker ↗Source updated 8 Oct 2026
Debian sidsid · sourcehaproxyVendor fix publishedDebian records a fixed source-package version for this release.1.8.13-1Debian Security Tracker ↗Source updated 8 Oct 2026
Debian sidsid · sourcejetty9Vendor fix publishedDebian records a fixed source-package version for this release.9.4.53-1Debian Security Tracker ↗Source updated 8 Oct 2026
Debian sidsid · sourcenettyVendor fix publishedDebian records a fixed source-package version for this release.1:4.1.48-8Debian Security Tracker ↗Source updated 8 Oct 2026
Debian sidsid · sourcenghttp2Vendor fix publishedDebian records a fixed source-package version for this release.1.57.0-1Debian Security Tracker ↗Source updated 8 Oct 2026
Debian sidsid · sourcenginxVendor fix publishedDebian records a fixed source-package version for this release.1.24.0-2Debian Security Tracker ↗Source updated 8 Oct 2026
Debian sidsid · sourcetomcat10Vendor fix publishedDebian records a fixed source-package version for this release.10.1.14-1Debian Security Tracker ↗Source updated 8 Oct 2026
Debian sidsid · sourcetomcat9Vendor fix publishedDebian records a fixed source-package version for this release.9.0.70-2Debian Security Tracker ↗Source updated 8 Oct 2026
Ubuntu 24.04 LTSnoble · standard archivedotnet8Vendor fix publishedCanonical reports that a fixed source package version has been published. Repository candidate availability is not checked by BlackTree.8.0.100-8.0.0-0ubuntu1Canonical Ubuntu Security ↗Source updated 7 Oct 2026
Open-source package ranges44 source-attributed ranges

These OSV and GitHub advisory ranges apply only to the named package and ecosystem. A listed fixed version is not a universal product patch or proof that an update is installed.

Ecosystem and packageAffected rangeFirst fixed versionEvidence
Gogolang.org/x/netSEMVER: introduced 0; fixed 0.17.00.17.0OSV record ↗aggregator derived · 10 Sep 2026
Mavencom.typesafe.akka:akka-http-coreECOSYSTEM: introduced 0; fixed 10.5.310.5.3OSV record ↗aggregator derived · 10 Sep 2026
Mavencom.typesafe.akka:akka-http-core_2.11ECOSYSTEM: introduced 0; last affected 10.1.15Not statedOSV record ↗aggregator derived · 10 Sep 2026
Mavencom.typesafe.akka:akka-http-core_2.12ECOSYSTEM: introduced 0; fixed 10.5.310.5.3OSV record ↗aggregator derived · 10 Sep 2026
Mavencom.typesafe.akka:akka-http-core_2.13ECOSYSTEM: introduced 0; fixed 10.5.310.5.3OSV record ↗aggregator derived · 10 Sep 2026
Mavenorg.apache.tomcat.embed:tomcat-embed-coreECOSYSTEM: introduced 11.0.0-M1; fixed 11.0.0-M1211.0.0-M12OSV record ↗aggregator derived · 10 Sep 2026
Mavenorg.apache.tomcat.embed:tomcat-embed-coreECOSYSTEM: introduced 10.0.0; fixed 10.1.1410.1.14OSV record ↗aggregator derived · 10 Sep 2026
Mavenorg.apache.tomcat.embed:tomcat-embed-coreECOSYSTEM: introduced 9.0.0; fixed 9.0.819.0.81OSV record ↗aggregator derived · 10 Sep 2026
Mavenorg.apache.tomcat.embed:tomcat-embed-coreECOSYSTEM: introduced 8.5.0; fixed 8.5.948.5.94OSV record ↗aggregator derived · 10 Sep 2026
Mavenorg.apache.tomcat:tomcat-coyoteECOSYSTEM: introduced 11.0.0-M1; fixed 11.0.0-M1211.0.0-M12OSV record ↗aggregator derived · 10 Sep 2026
Mavenorg.apache.tomcat:tomcat-coyoteECOSYSTEM: introduced 10.0.0; fixed 10.1.1410.1.14OSV record ↗aggregator derived · 10 Sep 2026
Mavenorg.apache.tomcat:tomcat-coyoteECOSYSTEM: introduced 9.0.0; fixed 9.0.819.0.81OSV record ↗aggregator derived · 10 Sep 2026
Mavenorg.apache.tomcat:tomcat-coyoteECOSYSTEM: introduced 8.5.0; fixed 8.5.948.5.94OSV record ↗aggregator derived · 10 Sep 2026
Mavenorg.eclipse.jetty.http2:http2-commonECOSYSTEM: introduced 9.3.0; fixed 9.4.539.4.53OSV record ↗aggregator derived · 10 Sep 2026
Mavenorg.eclipse.jetty.http2:http2-commonECOSYSTEM: introduced 10.0.0; fixed 10.0.1710.0.17OSV record ↗aggregator derived · 10 Sep 2026
Mavenorg.eclipse.jetty.http2:http2-commonECOSYSTEM: introduced 11.0.0; fixed 11.0.1711.0.17OSV record ↗aggregator derived · 10 Sep 2026
Mavenorg.eclipse.jetty.http2:http2-serverECOSYSTEM: introduced 9.3.0; fixed 9.4.539.4.53OSV record ↗aggregator derived · 10 Sep 2026
Mavenorg.eclipse.jetty.http2:http2-serverECOSYSTEM: introduced 10.0.0; fixed 10.0.1710.0.17OSV record ↗aggregator derived · 10 Sep 2026
Mavenorg.eclipse.jetty.http2:http2-serverECOSYSTEM: introduced 11.0.0; fixed 11.0.1711.0.17OSV record ↗aggregator derived · 10 Sep 2026
Mavenorg.eclipse.jetty.http2:jetty-http2-commonECOSYSTEM: introduced 12.0.0; fixed 12.0.212.0.2OSV record ↗aggregator derived · 10 Sep 2026
Mavenorg.eclipse.jetty.http2:jetty-http2-serverECOSYSTEM: introduced 12.0.0; fixed 12.0.212.0.2OSV record ↗aggregator derived · 10 Sep 2026
SwiftURLgithub.com/apple/swift-nio-http2SEMVER: introduced 0; fixed 1.28.01.28.0OSV record ↗aggregator derived · 10 Sep 2026
gogolang.org/x/net< 0.17.00.17.0GitHub advisory ↗upstream repository advisory · 13 May 2026
mavencom.typesafe.akka:akka-http-core< 10.5.310.5.3GitHub advisory ↗upstream repository advisory · 13 May 2026
mavencom.typesafe.akka:akka-http-core_2.11<= 10.1.15Not statedGitHub advisory ↗upstream repository advisory · 13 May 2026
mavencom.typesafe.akka:akka-http-core_2.12< 10.5.310.5.3GitHub advisory ↗upstream repository advisory · 13 May 2026
mavencom.typesafe.akka:akka-http-core_2.13< 10.5.310.5.3GitHub advisory ↗upstream repository advisory · 13 May 2026
mavenorg.apache.tomcat.embed:tomcat-embed-core>= 11.0.0-M1, < 11.0.0-M1211.0.0-M12GitHub advisory ↗upstream repository advisory · 13 May 2026
mavenorg.apache.tomcat.embed:tomcat-embed-core>= 10.0.0, < 10.1.1410.1.14GitHub advisory ↗upstream repository advisory · 13 May 2026
mavenorg.apache.tomcat.embed:tomcat-embed-core>= 9.0.0, < 9.0.819.0.81GitHub advisory ↗upstream repository advisory · 13 May 2026
mavenorg.apache.tomcat.embed:tomcat-embed-core>= 8.5.0, < 8.5.948.5.94GitHub advisory ↗upstream repository advisory · 13 May 2026
mavenorg.apache.tomcat:tomcat-coyote>= 11.0.0-M1, < 11.0.0-M1211.0.0-M12GitHub advisory ↗upstream repository advisory · 13 May 2026
mavenorg.apache.tomcat:tomcat-coyote>= 10.0.0, < 10.1.1410.1.14GitHub advisory ↗upstream repository advisory · 13 May 2026
mavenorg.apache.tomcat:tomcat-coyote>= 9.0.0, < 9.0.819.0.81GitHub advisory ↗upstream repository advisory · 13 May 2026
mavenorg.apache.tomcat:tomcat-coyote>= 8.5.0, < 8.5.948.5.94GitHub advisory ↗upstream repository advisory · 13 May 2026
mavenorg.eclipse.jetty.http2:http2-common>= 9.3.0, < 9.4.539.4.53GitHub advisory ↗upstream repository advisory · 13 May 2026
mavenorg.eclipse.jetty.http2:http2-common>= 10.0.0, < 10.0.1710.0.17GitHub advisory ↗upstream repository advisory · 13 May 2026
mavenorg.eclipse.jetty.http2:http2-common>= 11.0.0, < 11.0.1711.0.17GitHub advisory ↗upstream repository advisory · 13 May 2026
mavenorg.eclipse.jetty.http2:http2-server>= 9.3.0, < 9.4.539.4.53GitHub advisory ↗upstream repository advisory · 13 May 2026
mavenorg.eclipse.jetty.http2:http2-server>= 10.0.0, < 10.0.1710.0.17GitHub advisory ↗upstream repository advisory · 13 May 2026
mavenorg.eclipse.jetty.http2:http2-server>= 11.0.0, < 11.0.1711.0.17GitHub advisory ↗upstream repository advisory · 13 May 2026
mavenorg.eclipse.jetty.http2:jetty-http2-common>= 12.0.0, < 12.0.212.0.2GitHub advisory ↗upstream repository advisory · 13 May 2026
mavenorg.eclipse.jetty.http2:jetty-http2-server>= 12.0.0, < 12.0.212.0.2GitHub advisory ↗upstream repository advisory · 13 May 2026
swiftgithub.com/apple/swift-nio-http2< 1.28.01.28.0GitHub advisory ↗upstream repository advisory · 13 May 2026
Direct vendor intelligence

Authoritative vendor CSAF and VEX advisories

Structured product status and remediation from the issuing vendor. Product-state explanations are always visible; large lists can be searched or downloaded.

8 current
SSA-082556 · CSAF 2.0 · revision 7 · interimSiemens ProductCERTSSA-082556: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.5
5 known affected

The vendor explicitly identifies these products as affected by this CVE.

  • SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AB0) >= V3.1.5
  • SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (6ES7518-4AX00-1AC0) >= V3.1.5
  • SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AB0) >= V3.1.5
  • SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (6ES7518-4FX00-1AC0) >= V3.1.5
  • SIPLUS S7-1500 CPU 1518-4 PN/DP MFP (6AG1518-4AX00-4AC0) >= V3.1.5
Summary
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Remediation
Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.
SEVD-2025-189-03 · CSAF 2.0 · revision 2.0.0 · finalSchneider Electric CPCERTEcoStruxure™ Power Operation
2 known affected

The vendor explicitly identifies these products as affected by this CVE.

  • EcoStruxure™ Power Operation (EPO) 2022 CU6 and prior
  • EcoStruxure™ Power Operation (EPO) 2024 CU1 and prior
Summary
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Remediation
The CVE’s listed above affect the PostgresSQL pgadmin tool. If you have installed this tool, not required by EcoStruxure™ Power Operation 2024, we recommend you uninstall it from your EPO server and client machines.We strongly recommend customers take the following actions:• If waveform analysis and ETAP simulation features are not used, uninstall PostgreSQLOR• For those customers using waveform analysis and ETAP simulation features, we recommend all deployments of EPO only accept connections from localhost in PostgresSQL. Contact customer care for information on how to modify PostgreSQL. Further, we recommend you manually uninstall PostgreSQL 14.10 and update to PostgreSQL 14.17 or higher. EcoStruxure™ Power Operation 2024 CU2 includes an updated version of PostgreSQL and is available for download here: https://community.se.com/t5/EcoStruxure-Power-Operation/v2024-Release-amp-Updates-Install-Procedure/m-p/478928/thread-id/6997#M6997
SSA-832273 · CSAF 2.0 · revision 12 · finalSiemens ProductCERTSSA-832273: Multiple Vulnerabilities in Fortigate NGFW Before V7.4.3 on RUGGEDCOM APE1808 Devices
1 known affected

The vendor explicitly identifies these products as affected by this CVE.

  • RUGGEDCOM APE1808
Summary
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Remediation
Update Fortigate NGFW to V7.4.3. Contact customer support to receive patch and update information.
SCA-2025-0011 · CSAF 2.0 · revision 1.0.0 · finalSICK PSIRTVulnerabilities affecting Endress+Hauser SSG-E210GC
1 known not affected

The vendor explicitly states that these products are not affected by this CVE.

  • Endress+Hauser SSG-E210GC all Firmware versions
Summary
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Remediation
No remediation text is recorded.
SCA-2025-0009 · CSAF 2.0 · revision 1 · finalSICK PSIRTVulnerabilities affecting SICK TDC-E210GC
1 known not affected

The vendor explicitly states that these products are not affected by this CVE.

  • SICK TDC-E210GC all Firmware versions
Summary
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Remediation
No remediation text is recorded.
SSA-915275 · CSAF 2.0 · revision 1 · interimSiemens ProductCERTSSA-915275: Multiple Vulnerabilities in SINEC INS Before V1.0 SP2 Update 3
1 known affected

The vendor explicitly identifies these products as affected by this CVE.

  • SINEC INS
Summary
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Remediation
Update to V1.0 SP2 Update 3 or later version
SSA-784301 · CSAF 2.0 · revision 1 · interimSiemens ProductCERTSSA-784301: Multiple Vulnerabilities in SINEC NMS Before V3.0
1 known affected

The vendor explicitly identifies these products as affected by this CVE.

  • SINEC NMS
Summary
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Remediation
Update to V3.0 or later version
SSA-341067 · CSAF 2.0 · revision 1 · interimSiemens ProductCERTSSA-341067: Multiple vulnerabilities in third-party components in ST7 ScadaConnect before V1.1
1 known affected

The vendor explicitly identifies these products as affected by this CVE.

  • ST7 ScadaConnect (6NH7997-5DA10-0AA0)
Summary
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Remediation
Update to V1.1 or later version
Optional official sources

National CERT insights
?CERT means Computer Emergency Response Team; CSIRT is the closely related term Computer Security Incident Response Team.

Choose official national sources for this report. Each advisory shows its original language. Your selection is remembered on this device and included in shared links.

Official European source

ENISA European Vulnerability Database

Official EUVD identifiers, advisory evidence and known-exploited context. Missing fields are not treated as evidence of low risk.

1 current
ENISA EUVD identifier

EUVD-2023-2795

CISA KEV mirrored by ENISA

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

EUVD state
Present in the current official mapping
Known exploitation
Recorded by ENISA since 10 Oct 2023. Evidence sources: cisa_kev.
ENISA score
7.5 · CVSS 3.1
Advisory evidence
328 linked advisory records
Explicit mitigation evidence

Only statements that explicitly mention a fix, patch, update, workaround or mitigation are shown here.

  • csaf_redhat · RHSA-2023:7205Red Hat Security Advisory: nodejs:20 security update
  • csaf_redhat · RHBA-2023:5806Red Hat Bug Fix Advisory: Red Hat Ansible Automation Platform 2.4 Container Release Update
  • csaf_redhat · RHSA-2023:6837Red Hat Security Advisory: OpenShift Container Platform 4.14.2 bug fix and security update
  • csaf_redhat · RHSA-2023:5980Red Hat Security Advisory: Satellite 6.11.5.6 async security update
  • csaf_redhat · RHSA-2023:7699Red Hat Security Advisory: Red Hat OpenShift Pipelines Client tkn for 1.10.6 release and security update
  • csaf_redhat · RHSA-2023:6115Red Hat Security Advisory: OpenShift API for Data Protection security update
  • csaf_redhat · RHSA-2023:5784Red Hat Security Advisory: Red Hat JBoss Web Server 5.7.5 release and security update
  • csaf_redhat · RHSA-2023:6286Red Hat Security Advisory: Red Hat Data Grid 7.3.11 security update
  • csaf_redhat · RHSA-2023:7288Red Hat Security Advisory: Red Hat Product OCP Tools 4.14 Openshift Jenkins security update
  • csaf_redhat · RHSA-2023:5783Red Hat Security Advisory: Red Hat JBoss Web Server 5.7.5 release and security update
  • csaf_opensuse · openSUSE-SU-2023:0360-1Security update for go1.21
  • csaf_redhat · RHSA-2023:7704Red Hat Security Advisory: OpenShift Virtualization 4.14.1 security and bug fix update
  • csaf_redhat · RHSA-2023:6305Red Hat Security Advisory: Migration Toolkit for Applications security update
  • csaf_redhat · RHSA-2023:6120Red Hat Security Advisory: nginx:1.22 security update
  • csaf_redhat · RHSA-2023:5675Red Hat Security Advisory: OpenShift Container Platform 4.13.17 packages and security update
  • csaf_redhat · RHSA-2023:5721Red Hat Security Advisory: go-toolset:rhel8 security update
  • csaf_redhat · RHSA-2023:5965Red Hat Security Advisory: Red Hat OpenStack Platform 16.2.5 (collectd-libpod-stats, etcd) security update
  • csaf_redhat · RHSA-2023:5920Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.4 security update
  • csaf_redhat · RHSA-2023:7486Red Hat Security Advisory: Red Hat Single Sign-On 7.6.6 for OpenShift image enhancement and security update
  • csaf_redhat · RHSA-2023:5850Red Hat Security Advisory: nodejs:16 security update
  • csaf_redhat · RHSA-2023:6165Red Hat Security Advisory: skupper-cli and skupper-router security update
  • csaf_redhat · RHSA-2023:5724Red Hat Security Advisory: Red Hat build of Quarkus security update
  • csaf_redhat · RHSA-2023:6788Red Hat Security Advisory: Red Hat OpenShift GitOps security update
  • csaf_redhat · RHSA-2023:6248Red Hat Security Advisory: OpenShift Virtualization 4.12.8 Images security update
  • csaf_suse · SUSE-SU-2024:3341-1Security update for kubernetes1.23
  • csaf_suse · SUSE-SU-2024:3344-1Security update for kubernetes1.25
  • csaf_suse · SUSE-SU-2023:4472-1Security update for go1.20-openssl
  • csaf_ncscnl · NCSC-2024-0246Kwetsbaarheden verholpen in Siemens producten
  • csaf_redhat · RHSA-2023:6023Red Hat Security Advisory: varnish:6 security update
  • csaf_redhat · RHSA-2023:5929Red Hat Security Advisory: tomcat security update
  • csaf_redhat · RHSA-2023:6020Red Hat Security Advisory: varnish:6 security update
  • csaf_redhat · RHSA-2024:1770Red Hat Security Advisory: OpenShift Container Platform 4.15.9 bug fix and security update
  • csaf_redhat · RHSA-2023:7639Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.4.14 on RHEL 9 security update
  • csaf_redhat · RHSA-2023:6077Red Hat Security Advisory: toolbox security update
  • csaf_ncscnl · NCSC-2024-0411Kwetsbaarheden verholpen in Oracle Database producten
  • csaf_redhat · RHSA-2023:7522Red Hat Security Advisory: OpenShift Virtualization 4.13.6 security and bug fix update
  • csaf_redhat · RHSA-2023:5706Red Hat Security Advisory: dotnet6.0 security update
  • csaf_redhat · RHBA-2024:0815Red Hat Bug Fix Advisory: OpenShift sandboxed containers 1.5.2 update
  • csaf_redhat · RHBA-2023:5949Red Hat Bug Fix Advisory: Red Hat Integration - Service Registry 2.4.4 SP1 OpenShift images
  • csaf_redhat · RHSA-2023:6839Red Hat Security Advisory: OpenShift Container Platform 4.14.2 security update
  • csaf_redhat · RHSA-2023:6200Red Hat Security Advisory: Multicluster Engine for Kubernetes 2.1.9 security updates and bug fixes
  • csaf_redhat · RHSA-2023:5714Red Hat Security Advisory: nginx security update
  • csaf_redhat · RHSA-2023:6129Red Hat Security Advisory: OpenShift Container Platform 4.13.19 security and extras update
  • csaf_redhat · RHSA-2023:6144Red Hat Security Advisory: Custom Metric Autoscaler operator for Red Hat OpenShift security update
  • csaf_redhat · RHSA-2023:5713Red Hat Security Advisory: nginx:1.22 security update
  • csaf_redhat · RHSA-2023:5679Red Hat Security Advisory: OpenShift Container Platform 4.12.39 packages and security update
  • csaf_redhat · RHEA-2023:6741Red Hat Enhancement Advisory: .NET 8.0 bugfix update
  • csaf_redhat · RHSA-2023:5709Red Hat Security Advisory: dotnet7.0 security update
  • csaf_redhat · RHSA-2023:5935Red Hat Security Advisory: Red Hat OpenStack Platform 16.2.5 security update
  • csaf_redhat · RHSA-2023:7641Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.4.14 security update
  • csaf_redhat · RHSA-2023:6122Red Hat Security Advisory: Red Hat Advanced Cluster Management 2.8.3 security and bug fix updates
  • csaf_redhat · RHBA-2023:7492Red Hat Bug Fix Advisory: RHODS 2.4 - Red Hat OpenShift Data Science
  • csaf_redhat · RHSA-2023:6817Red Hat Security Advisory: OpenShift Virtualization 4.14.0 Images security and bug fix update
  • csaf_redhat · RHSA-2023:6084Red Hat Security Advisory: RHACS 3.74 enhancement and security update
  • csaf_redhat · RHSA-2023:5716Red Hat Security Advisory: Red Hat Data Grid 8.4.5 security update
  • csaf_redhat · RHSA-2023:7587Red Hat Security Advisory: Updated IBM Business Automation Manager Open Editions 8.0.4 SP1 Images
  • csaf_redhat · RHSA-2025:23528Red Hat Security Advisory: multicluster engine for Kubernetes 2.6 security update
  • csaf_suse · SUSE-SU-2023:4469-1Security update for go1.21-openssl
  • csaf_redhat · RHSA-2023:5009Red Hat Security Advisory: OpenShift Container Platform 4.14.0 security update
  • csaf_redhat · RHSA-2023:7637Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.4.14 on RHEL 7 security update
  • csaf_redhat · RHSA-2023:7488Red Hat Security Advisory: Red Hat Single Sign-On 7.6.6 security update
  • csaf_redhat · RHSA-2023:6041Red Hat Security Advisory: Self Node Remediation Operator 0.7.1 security update
  • csaf_redhat · RHSA-2023:6031Red Hat Security Advisory: Cryostat security update
  • csaf_redhat · RHSA-2023:6044Red Hat Security Advisory: Cost Management security update
  • csaf_redhat · RHSA-2023:6217Red Hat Security Advisory: Red Hat OpenShift Enterprise security update
  • csaf_redhat · RHSA-2024:4118Red Hat Security Advisory: Red Hat Ceph Storage 5.3 security, bug fix, and enhancement update
  • csaf_ncscnl · NCSC-2024-0306 Kwetsbaarheden verholpen in Oracle Supply Chain
  • csaf_redhat · RHSA-2023:5869Red Hat Security Advisory: nodejs:18 security update
  • csaf_redhat · RHSA-2023:5801Red Hat Security Advisory: Migration Toolkit for Runtimes security update
  • csaf_suse · SUSE-SU-2023:4129-1Security update for tomcat
  • csaf_redhat · RHSA-2023:6148Red Hat Security Advisory: Red Hat Advanced Cluster Management 2.7.9 security and bug fix updates
  • csaf_redhat · RHSA-2023:5541Red Hat Security Advisory: Logging Subsystem 5.6.12 - Red Hat OpenShift security update
  • csaf_redhat · RHSA-2023:7198Red Hat Security Advisory: OpenShift Container Platform 4.15.0 bug fix and security update
  • csaf_redhat · RHSA-2023:6787Red Hat Security Advisory: Network Observability security update
  • csaf_redhat · RHSA-2023:6021Red Hat Security Advisory: varnish:6 security update
  • csaf_redhat · RHSA-2023:5837Red Hat Security Advisory: nghttp2 security update
  • csaf_suse · SUSE-SU-2023:4150-1Security update for nodejs18
  • csaf_redhat · RHSA-2023:7610Red Hat Security Advisory: OpenShift Container Platform 4.12.45 packages and security update
  • csaf_redhat · RHSA-2023:6040Red Hat Security Advisory: Node Maintenance Operator 5.2.1 security update
  • csaf_redhat · RHSA-2023:6059Red Hat Security Advisory: Red Hat OpenShift Pipelines Client tkn for 1.12.1 release and security update
  • csaf_redhat · RHSA-2023:6118Red Hat Security Advisory: OpenShift API for Data Protection security update
  • csaf_redhat · RHSA-2023:7344Red Hat Security Advisory: openshift-gitops-kam security update
  • csaf_redhat · RHSA-2023:5973Red Hat Security Advisory: Red Hat AMQ Streams 2.5.1 release and security update
  • csaf_redhat · RHSA-2023:5979Red Hat Security Advisory: Satellite 6.12.5.2 Async Security Update
  • csaf_redhat · RHSA-2023:5989Red Hat Security Advisory: varnish security update
  • csaf_suse · SUSE-SU-2024:3097-1Security update for kubernetes1.28
  • csaf_redhat · RHSA-2023:7703Red Hat Security Advisory: Red Hat OpenShift Pipelines 1.10.6 release and security update
  • csaf_suse · SUSE-SU-2023:4374-1Security update for nodejs12
  • csaf_redhat · RHSA-2023:7482Red Hat Security Advisory: Red Hat Single Sign-On 7.6.6 security update on RHEL 7
  • csaf_redhat · RHSA-2023:6786Red Hat Security Advisory: Fence Agents Remediation Operator 0.2.1 security update
  • csaf_redhat · RHSA-2023:5866Red Hat Security Advisory: grafana security update
  • csaf_redhat · RHSA-2023:5922Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.4 security update
  • csaf_ncscnl · NCSC-2025-0028Kwetsbaarheden verholpen in Oracle Analytics
  • csaf_suse · SUSE-SU-2023:4373-1Security update for nodejs12
  • csaf_redhat · RHSA-2023:5864Red Hat Security Advisory: grafana security update
  • csaf_redhat · RHSA-2024:2633Red Hat Security Advisory: updated rhceph-6.1 container image
  • csaf_redhat · RHSA-2023:6161Red Hat Security Advisory: Migration Toolkit for Containers (MTC) 1.7.14 security and bug fix update
  • csaf_redhat · RHSA-2023:6137Red Hat Security Advisory: Migration Toolkit for Runtimes security update
  • csaf_redhat · RHSA-2023:6781Red Hat Security Advisory: openshift-pipelines-client security update
  • csaf_redhat · RHSA-2023:6832Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.14.0 security, enhancement & bug fix update
  • csaf_suse · SUSE-SU-2023:4199-1Security update for nghttp2
  • csaf_redhat · RHSA-2023:5767Red Hat Security Advisory: nghttp2 security update
  • csaf_redhat · RHSA-2023:6280Red Hat Security Advisory: Migration Toolkit for Applications security and bug fix update
  • csaf_ncscnl · NCSC-2025-0123Kwetsbaarheden verholpen in Oracle Database Producten
  • csaf_redhat · RHSA-2023:6085Red Hat Security Advisory: Red Hat OpenShift distributed tracing security update
  • csaf_redhat · RHSA-2023:6179Red Hat Security Advisory: Red Hat Product OCP Tools 4.13 OpenShift Jenkins security update
  • csaf_redhat · RHSA-2023:5710Red Hat Security Advisory: dotnet6.0 security update
  • csaf_ncscnl · NCSC-2024-0294Kwetsbaarheden verholpen in Oracle Communications
  • csaf_redhat · RHBA-2024:0599Red Hat Bug Fix Advisory: Migration Toolkit for Applications bug fix and enhancement update
  • csaf_redhat · RHSA-2023:5946Red Hat Security Advisory: Red Hat AMQ Broker 7.11.3 release and security update
  • csaf_redhat · RHSA-2023:5542Red Hat Security Advisory: Logging Subsystem 5.5.17 - Red Hat OpenShift security update
  • csaf_suse · SUSE-SU-2023:4133-1Security update for nodejs18
  • csaf_redhat · RHSA-2023:6239Red Hat Security Advisory: Kiali (Kiali 1.65.10) security update
  • csaf_ncscnl · NCSC-2024-0433Kwetsbaarheden verholpen in Siemens producten
  • csaf_redhat · RHSA-2023:5719Red Hat Security Advisory: go-toolset-1.19 and go-toolset-1.19-golang security update
  • csaf_redhat · RHSA-2023:5838Red Hat Security Advisory: nghttp2 security update
  • csaf_redhat · RHSA-2023:6061Red Hat Security Advisory: Red Hat OpenShift Pipelines 1.12.1 release and security update
  • csaf_redhat · RHSA-2024:0777Red Hat Security Advisory: jenkins and jenkins-2-plugins security update
  • csaf_redhat · RHSA-2023:7345Red Hat Security Advisory: Red Hat OpenShift GitOps v1.9.3 security update
  • csaf_redhat · RHSA-2023:5803Red Hat Security Advisory: nodejs:16 security update
  • csaf_redhat · RHSA-2023:5712Red Hat Security Advisory: nginx:1.20 security update
  • csaf_suse · SUSE-SU-2023:4624-1Security update for kubevirt, virt-api-container, virt-controller-container, virt-exportproxy-container, virt-exportserver-container, virt-handler-container, virt-launcher-container, virt-libguestfs-tools-container, virt-operator-container, virt-pr-helper-container
  • csaf_redhat · RHBA-2023:6078Red Hat Bug Fix Advisory: MTV 2.5.2 Images
  • csaf_redhat · RHSA-2023:6080Red Hat Security Advisory: Red Hat Integration Camel for Spring Boot 4.0.1 release security update
  • csaf_suse · SUSE-SU-2023:4207-1Security update for nodejs18
  • csaf_redhat · RHSA-2023:6117Red Hat Security Advisory: Red Hat Integration Camel K 1.10.4 release and security update
  • csaf_suse · SUSE-SU-2023:4163-1Security update for netty, netty-tcnative
  • csaf_redhat · RHSA-2023:7315Red Hat Security Advisory: OpenShift Container Platform 4.14.3 bug fix and security update
  • csaf_redhat · RHSA-2023:5749Red Hat Security Advisory: .NET 7.0 security update
  • csaf_redhat · RHSA-2023:5982Red Hat Security Advisory: Red Hat Satellite Client security and bug fix update
  • csaf_suse · SUSE-SU-2023:4295-1Security update for nodejs10
  • csaf_redhat · RHSA-2023:6106Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.57 SP1 security update
  • csaf_suse · SUSE-SU-2023:4069-1Security update for go1.21
  • csaf_redhat · RHSA-2023:6079Red Hat Security Advisory: Red Hat Integration Camel for Spring Boot 3.20.3 release and security update
  • csaf_redhat · RHSA-2023:5928Red Hat Security Advisory: tomcat security update
  • csaf_redhat · RHSA-2023:5738Red Hat Security Advisory: go-toolset and golang security and bug fix update
  • csaf_redhat · RHSA-2023:5974Red Hat Security Advisory: Network Observability security update
  • csaf_redhat · RHSA-2026:0722Red Hat Security Advisory: multicluster engine for Kubernetes v2.8.4 security update
  • csaf_redhat · RHSA-2023:5924Red Hat Security Advisory: varnish security update
  • csaf_redhat · RHSA-2023:5896Red Hat Security Advisory: OpenShift Container Platform 4.12.40 bug fix and security update
  • csaf_redhat · RHSA-2023:5956Red Hat Security Advisory: Red Hat Build of OptaPlanner 8.38.0 SP2 security update
  • csaf_cisa · ICSA-25-203-04Schneider Electric EcoStruxure Power Operation (Update A)
  • csaf_redhat · RHSA-2023:6119Red Hat Security Advisory: Multicluster Engine for Kubernetes 2.3.3 security updates and bug fixes
  • csaf_redhat · RHSA-2023:6782Red Hat Security Advisory: openshift-gitops-kam security update
  • csaf_redhat · RHSA-2023:7247Red Hat Security Advisory: Red Hat Fuse 7.12.1 release and security update
  • csaf_suse · SUSE-SU-2024:0573-1Security update for abseil-cpp, grpc, opencensus-proto, protobuf, python-abseil, python-grpcio, re2
  • csaf_redhat · RHSA-2023:5841Red Hat Security Advisory: httpd24-nghttp2 security update
  • csaf_suse · SUSE-SU-2023:4259-1Security update for nodejs12
  • csaf_redhat · RHSA-2023:6818Red Hat Security Advisory: Satellite 6.14 security and bug fix update
  • csaf_redhat · RHSA-2023:5945Red Hat Security Advisory: Red Hat AMQ Broker 7.10.4 release and security update
  • csaf_certbund · WID-SEC-W-2024-0597SAP Security Patch Day – März 2024
  • csaf_redhat · RHSA-2023:5849Red Hat Security Advisory: nodejs:18 security update
  • csaf_redhat · RHSA-2023:7521Red Hat Security Advisory: OpenShift Virtualization 4.13.6 RPMs security and bug fix update
  • csaf_redhat · RHSA-2023:6298Red Hat Security Advisory: Release of OpenShift Serverless Client kn 1.30.2 security update
  • csaf_redhat · RHSA-2023:5705Red Hat Security Advisory: rh-dotnet60-dotnet security, bug fix, and enhancement update
  • csaf_redhat · RHSA-2023:7653Red Hat Security Advisory: Service Registry (container images) release and security update [2.5.4 GA]
  • csaf_suse · SUSE-SU-2026:1058-1Security update for tomcat
  • csaf_redhat · RHSA-2023:7481Red Hat Security Advisory: OpenShift Container Platform 4.11.54 packages and security update
  • csaf_redhat · RHSA-2025:16668Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.1.12 on RHEL 7 security update
  • csaf_redhat · RHSA-2023:5769Red Hat Security Advisory: nghttp2 security update
  • csaf_redhat · RHSA-2023:6251Red Hat Security Advisory: OpenShift Virtualization 4.11.7 Images security and bug fix update
  • csaf_siemens · SSA-915275SSA-915275: Multiple Vulnerabilities in SINEC INS Before V1.0 SP2 Update 3
  • csaf_redhat · RHSA-2023:5530Red Hat Security Advisory: Logging Subsystem 5.7.7 - Red Hat OpenShift security update
  • csaf_suse · SUSE-SU-2024:3342-1Security update for kubernetes1.24
  • csaf_redhat · RHSA-2023:6233Red Hat Security Advisory: Red Hat OpenShift Enterprise security update
  • csaf_redhat · RHSA-2023:5947Red Hat Security Advisory: Run Once Duration Override Operator for Red Hat OpenShift 1.0.1 security update
  • csaf_redhat · RHSA-2023:5768Red Hat Security Advisory: nghttp2 security update
  • csaf_redhat · RHSA-2023:5976Red Hat Security Advisory: Service Telemetry Framework 1.5.2 security update
  • csaf_redhat · RHSA-2023:7638Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.4.14 on RHEL 8 security update
  • csaf_redhat · RHSA-2023:6779Red Hat Security Advisory: Red Hat OpenShift Pipelines Operator security update
  • csaf_redhat · RHSA-2023:5930Red Hat Security Advisory: varnish security update
  • csaf_redhat · RHSA-2023:5715Red Hat Security Advisory: nginx:1.20 security update
  • csaf_redhat · RHSA-2023:6030Red Hat Security Advisory: Red Hat AMQ Streams 2.2.2 release and security update
  • csaf_redhat · RHSA-2023:6784Red Hat Security Advisory: Node Health Check Operator 0.6.1 security update
  • csaf_redhat · RHBA-2023:6109Red Hat Bug Fix Advisory: MTV 2.4.3 Images
  • csaf_redhat · RHSA-2023:5765Red Hat Security Advisory: nodejs security update
  • csaf_redhat · RHSA-2023:5964Red Hat Security Advisory: Red Hat OpenStack Platform 16.2.5 (collectd-libpod-stats) security update
  • csaf_redhat · RHSA-2023:7687Red Hat Security Advisory: OpenShift Container Platform 4.13.26 bug fix and security update
  • csaf_suse · SUSE-SU-2023:4210-1Security update for jetty-minimal
  • csaf_redhat · RHBA-2023:6254Red Hat Bug Fix Advisory: OpenShift Container Platform Assisted Installer version 2.26.1 release
  • csaf_ncscnl · NCSC-2025-0187Kwetsbaarheden verholpen in Siemens producten
  • csaf_redhat · RHSA-2023:7741Red Hat Security Advisory: Red Hat Ceph Storage 6.1 security, enhancements, and bug fix update
  • csaf_redhat · RHSA-2023:7218Red Hat Security Advisory: Kernel Module Management security update
  • csaf_redhat · RHSA-2023:6042Red Hat Security Advisory: Self Node Remediation Operator 0.5.1 security update
  • csaf_redhat · RHEA-2023:7235Red Hat Enhancement Advisory: ACS 4.3 enhancement update
  • csaf_redhat · RHSA-2023:6746Red Hat Security Advisory: nghttp2 security update
  • csaf_redhat · RHSA-2023:5770Red Hat Security Advisory: nghttp2 security update
  • csaf_suse · SUSE-SU-2023:4492-1Security update for nghttp2
  • csaf_redhat · RHSA-2023:6114Red Hat Security Advisory: Red Hat support for Spring Boot 2.7.17 security update
  • csaf_redhat · RHSA-2023:6836Red Hat Security Advisory: OpenShift Container Platform 4.14.2 security and extras update
  • csaf_suse · SUSE-SU-2024:3094-1Security update for kubernetes1.26
  • csaf_redhat · RHBA-2023:6863Red Hat Bug Fix Advisory: LVMS 4.14.z Bug Fix and Enhancement update
  • csaf_redhat · RHSA-2023:6235Red Hat Security Advisory: OpenShift Virtualization 4.13.5 Images security update
  • csaf_suse · SUSE-SU-2023:4132-1Security update for nodejs18
  • csaf_redhat · RHSA-2023:6057Red Hat Security Advisory: toolbox security update
  • csaf_suse · SUSE-SU-2024:3343-1Security update for kubernetes1.24
  • csaf_redhat · RHSA-2023:7484Red Hat Security Advisory: Red Hat Single Sign-On 7.6.6 security update on RHEL 9
  • csaf_redhat · RHSA-2023:5805Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.4 Product Security and Bug Fix Update
  • csaf_redhat · RHSA-2023:7483Red Hat Security Advisory: Red Hat Single Sign-On 7.6.6 security update on RHEL 8
  • csaf_redhat · RHSA-2024:1444Red Hat Security Advisory: nodejs:16 security update
  • csaf_redhat · RHSA-2023:7335Red Hat Security Advisory: Updated Red Hat Process Automation Manager 7.13.4 SP2 Images
  • csaf_redhat · RHSA-2023:5708Red Hat Security Advisory: dotnet6.0 security update
  • csaf_redhat · RHSA-2023:7334Red Hat Security Advisory: rh-varnish6-varnish security update
  • csaf_redhat · RHSA-2023:5840Red Hat Security Advisory: rh-nodejs14 security update
  • csaf_redhat · RHSA-2023:6202Red Hat Security Advisory: Red Hat Advanced Cluster Management 2.6.8 security and bug fix updates
  • csaf_redhat · RHSA-2023:6785Red Hat Security Advisory: Machine Deletion Remediation Operator 0.2.1 security update
  • csaf_suse · SUSE-SU-2023:4068-1Security update for go1.20
  • csaf_redhat · RHSA-2023:5764Red Hat Security Advisory: nodejs security update
  • csaf_redhat · RHSA-2025:23529Red Hat Security Advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11.9 security update
  • csaf_redhat · RHSA-2023:5933Red Hat Security Advisory: Openshift Secondary Scheduler Operator 1.1.3 security update
  • csaf_ncscnl · NCSC-2024-0332Kwetsbaarheden verholpen in Siemens producten
  • csaf_redhat · RHSA-2023:7325Red Hat Security Advisory: OpenShift Container Platform 4.13.23 packages and security update
  • csaf_redhat · RHSA-2023:5720Red Hat Security Advisory: rh-nginx120-nginx security update
  • csaf_ncscnl · NCSC-2024-0293Kwetsbaarheden verholpen in Oracle Communications Applications
  • csaf_redhat · RHSA-2023:5902Red Hat Security Advisory: OpenShift Container Platform 4.13.18 security update
  • csaf_redhat · RHSA-2023:5867Red Hat Security Advisory: grafana security update
  • csaf_redhat · RHSA-2023:5717Red Hat Security Advisory: OpenShift Container Platform 4.11.52 packages and security update
  • csaf_redhat · RHSA-2023:5707Red Hat Security Advisory: dotnet6.0 security update
  • csaf_suse · SUSE-SU-2023:4155-1Security update for nodejs18
  • csaf_redhat · RHSA-2023:5802Red Hat Security Advisory: Migration Toolkit for Runtimes security update
  • csaf_redhat · RHSA-2023:5766Red Hat Security Advisory: nghttp2 security update
  • csaf_redhat · RHSA-2023:5711Red Hat Security Advisory: nginx security update
  • csaf_redhat · RHSA-2023:5851Red Hat Security Advisory: RHACS 4.1 enhancement and security update
  • csaf_redhat · RHSA-2023:6022Red Hat Security Advisory: varnish:6 security update
  • csaf_redhat · RHEA-2023:6562Red Hat Enhancement Advisory: nginx:1.22 bug fix and enhancement update
  • csaf_redhat · RHSA-2023:7682Red Hat Security Advisory: OpenShift Container Platform 4.14.6 bug fix and security update
  • csaf_redhat · RHSA-2023:7555Red Hat Security Advisory: OpenShift API for Data Protection (OADP) 1.3.0 security update
  • csaf_redhat · RHSA-2023:5971Red Hat Security Advisory: Red Hat OpenStack Platform 17.1.1 (director-operator) security update
  • csaf_redhat · RHSA-2023:5780Red Hat Security Advisory: Red Hat Integration Camel Extensions for Quarkus 2.13.3 security update
  • csaf_redhat · RHSA-2023:5835Red Hat Security Advisory: rhc-worker-script enhancement and security update
  • csaf_redhat · RHSA-2023:5931Red Hat Security Advisory: Satellite 6.13.5 Async Security Update
  • csaf_redhat · RHSA-2023:6840Red Hat Security Advisory: OpenShift Container Platform 4.14.2 packages and security update
  • csaf_redhat · RHSA-2023:5967Red Hat Security Advisory: Red Hat OpenStack Platform 16.1.9 (collectd-libpod-stats, etcd) security update
  • csaf_redhat · RHSA-2023:5006Red Hat Security Advisory: OpenShift Container Platform 4.14.0 bug fix and security update
  • csaf_redhat · RHSA-2023:5969Red Hat Security Advisory: Red Hat OpenStack Platform 17.1.1 security update
  • csaf_redhat · RHSA-2023:6048Red Hat Security Advisory: ACS 4.2 enhancement and security update
  • csaf_suse · SUSE-SU-2023:4200-1Security update for nghttp2
  • csaf_redhat · RHSA-2023:6145Red Hat Security Advisory: Multicluster Engine for Kubernetes 2.2.9 security updates and bug fixes
  • csaf_suse · SUSE-SU-2024:3098-1Security update for kubernetes1.27
  • csaf_redhat · RHSA-2023:6039Red Hat Security Advisory: Node Maintenance Operator 5.0.1 security update
  • csaf_redhat · RHSA-2024:0302Red Hat Security Advisory: Kube Descheduler Operator for Red Hat OpenShift 5.0.0 for RHEL 9:security update
  • csaf_redhat · RHSA-2023:5865Red Hat Security Advisory: grafana security update
  • csaf_redhat · RHSA-2023:6272Red Hat Security Advisory: OpenShift Container Platform 4.11.53 bug fix and security update
  • csaf_redhat · RHSA-2023:6105Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.57 SP1 security update
  • csaf_redhat · RHSA-2023:5863Red Hat Security Advisory: grafana security update
  • csaf_redhat · RHSA-2023:5970Red Hat Security Advisory: Red Hat OpenStack Platform 17.1.1 (collectd-libpod-stats) security update
Recommended actionPatch only the product branches with a verified fix

CISA confirms exploitation in the wild and lists 2023-10-31 as the remediation due date. Verified remediation exists for at least one product or source, but 17 structured product or package states remain unresolved. Apply remediation only to the exact product branch confirmed by its source.

Fix availability varies by product
01

What, why and how

HTTP/2 contains a rapid reset vulnerability that allows for a distributed denial-of-service attack (DDoS).

What

HTTP/2 contains a rapid reset vulnerability that allows for a distributed denial-of-service attack (DDoS).

Why

The product does not properly control the allocation and maintenance of a limited resource.

How

An attacker operating through a network path may attempt exploitation without authentication or user interaction. If successful, the issue may cause the confidentiality, integrity or availability impact described by the vendor.

What

HTTP/2 contains a rapid reset vulnerability that allows for a distributed denial-of-service attack (DDoS).

Why

The product does not properly control the allocation and maintenance of a limited resource.

How

An attacker operating through a network path may attempt exploitation without authentication or user interaction. If successful, the issue may cause the confidentiality, integrity or availability impact described by the vendor.

02

Exploit reality and attack path

CVSS severity, EPSS forecast probability, public exploit material and CISA-confirmed exploitation are separate signals.

Observed exploitation
?Confirmed exploitation and public exploit material are separate signals. Attacks can occur without public proof-of-concept or exploit code.
Confirmed in the wild

CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2023-10-10.

Public PoC / exploit material
?Confirmed exploitation and public exploit material are separate signals. Attacks can occur without public proof-of-concept or exploit code.
Reference recorded

A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.

Likely attack path
a network path → Uncontrolled Resource Consumption → cause the confidentiality, integrity or availability impact described by the vendor
Attack surface
Network
Privileges required
None: unauthenticated exploitation is possible
User interaction
None
Attack complexity
Low: no specialised conditions are recorded
Security boundary
Unchanged: impact remains within the vulnerable component's security authority
Weakness
?CWE means Common Weakness Enumeration: a standard category for the underlying weakness.
CWE-400 ↗

CWE-400: Uncontrolled Resource Consumption. The product does not properly control the allocation and maintenance of a limited resource.

CVSS vector
?CVSS means Common Vulnerability Scoring System. The vector records the metric values used to calculate technical severity.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Common Vulnerability Scoring System 3.1: the compact vector below is decoded into plain language.

AVNetworkAttack vector: The vulnerable component can be reached over a network.ACLowAttack complexity: No specialised conditions are required beyond attacker-controlled input.PRNonePrivileges required: The attacker does not need an account or existing privileges.UINoneUser interaction: No action by another user is required.SUnchangedScope: The security impact remains within the vulnerable component's authority.CNoneConfidentiality impact: No direct loss is represented by this metric.INoneIntegrity impact: No direct loss is represented by this metric.AHighAvailability impact: A successful attack can cause a major loss.
Post-exploitation / living off the land
No specific living-off-the-land technique is confirmed in the structured sources. Monitor normal administration tools for activity inconsistent with the affected service's baseline.
NetworkUnauthenticatedCWE-400CISA KEVPublic exploit reference
A

Official authority intelligence

Only matched European and national findings are included. Language selectors and unavailable sources are omitted.

ENISA EUVD · EUVD-2023-2795Known-exploited evidence recorded

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

Official EUVD record ↗
BSI · German · WID-SEC-2023-2655Node.js: Mehrere Schwachstellen

Ein entfernter, authentisierter oder anonymer Angreifer kann mehrere Schwachstellen in Node.js ausnutzen, um beliebigen Programmcode auszuführen, Informationen offenzulegen, einen Denial of Service Zustand herbeizuführen oder Sicherheitsvorkehrungen zu umgehen.

Official advisory ↗
BSI · German · WID-SEC-2023-2606Microsoft Windows und Microsoft Windows Server: Mehrere Schwachstellen

Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in verschiedenen Versionen von Microsoft Windows und Microsoft Windows Server ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand zu verursachen und Privilegien zu erweitern.

Official advisory ↗
BSI · German · WID-SEC-2024-3684IBM QRadar SIEM: Mehrere Schwachstellen

Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand zu erzeugen, vertrauliche Informationen offenzulegen oder einen Spoofing-Angriff durchzuführen.

Official advisory ↗
BSI · German · WID-SEC-2024-1642Oracle Communications: Mehrere Schwachstellen

Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Communications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.

Official advisory ↗
BSI · German · WID-SEC-2024-1652Oracle Supply Chain: Mehrere Schwachstellen

Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Supply Chain ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.

Official advisory ↗
BSI · German · WID-SEC-2024-1643Oracle Communications Applications: Mehrere Schwachstellen

Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Communications Applications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.

Official advisory ↗
BSI · German · WID-SEC-2024-1307Red Hat OpenShift Service Mesh Containers: Mehrere Schwachstellen

Ein Angreifer kann mehrere Schwachstellen in Red Hat OpenShift Service Mesh Containers ausnutzen, um Dateien zu manipulieren, einen 'Denial of Service'-Zustand erzuegen, beliebigen Code auszuführen, vertrauliche Informationen offenzulegen oder weitere nicht spezifizierte Angriffe durchzuführen.

Official advisory ↗
BSI · German · WID-SEC-2024-1248Xerox FreeFlow Print Server: Mehrere Schwachstellen

Ein Angreifer kann mehrere Schwachstellen in Xerox FreeFlow Print Server ausnutzen, um die Vertraulichkeit, Verfügbarkeit und Integrität des Systems zu gefährden

Official advisory ↗
BSI · German · WID-SEC-2024-1238HPE HP-UX: Mehrere Schwachstellen

Ein anonymer oder lokaler Angreifer kann mehrere Schwachstellen in HPE HP-UX Tomcat Servlet Engine ausnutzen, um Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand zu verursachen, vertrauliche Informationen offenzulegen oder Dateien zu manipulieren.

Official advisory ↗
BSI · German · WID-SEC-2024-0869Oracle Communications: Mehrere Schwachstellen

Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Oracle Communications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.

Official advisory ↗
BSI · German · WID-SEC-2024-0899Oracle Fusion Middleware: Mehrere Schwachstellen

Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Oracle Fusion Middleware ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.

Official advisory ↗
BSI · German · WID-SEC-2024-0870Oracle Communications Applications: Mehrere Schwachstellen

Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Oracle Communications Applications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.

Official advisory ↗
BSI · German · WID-SEC-2024-0874Oracle Enterprise Manager: Mehrere Schwachstellen

Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Enterprise Manager ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.

Official advisory ↗
BSI · German · WID-SEC-2024-0873Oracle Financial Services Applications: Mehrere Schwachstellen

Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Financial Services Applications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.

Official advisory ↗
BSI · German · WID-SEC-2024-0794Dell ECS: Mehrere Schwachstellen

Ein Angreifer kann mehrere Schwachstellen in Dell ECS ausnutzen, um seine Privilegien zu erweitern, beliebigen Programmcode mit Administratorrechten auszuführen, Informationen offenzulegen, Dateien zu manipulieren, einen Cross-Site-Scripting-Angriff durchzuführen, Sicherheitsvorkehrungen zu umgehen oder einen Denial of Service Zustand herbeizuführen.

Official advisory ↗
BSI · German · WID-SEC-2024-0597SAP Security Patch Day – März 2024

Ein Angreifer kann mehrere Schwachstellen in der SAP-Software ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen, vertrauliche Informationen offenzulegen oder Cross-Site-Scripting (XSS)-Angriffe durchzuführen.

Official advisory ↗
BSI · German · WID-SEC-2024-0521IBM MQ: Mehrere Schwachstellen

Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM MQ ausnutzen, um beliebigen Programmcode auszuführen, Informationen offenzulegen oder einen Denial of Service Zustand herbeizuführen.

Official advisory ↗
BSI · German · WID-SEC-2024-0123Oracle Fusion Middleware: Mehrere Schwachstellen

Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Fusion Middleware ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.

Official advisory ↗
BSI · German · WID-SEC-2024-0115Oracle Supply Chain: Mehrere Schwachstellen

Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Supply Chain ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.

Official advisory ↗
BSI · German · WID-SEC-2024-0117Oracle Retail Applications: Mehrere Schwachstellen

Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Retail Applications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.

Official advisory ↗
BSI · German · WID-SEC-2024-0107Oracle Communications Applications: Mehrere Schwachstellen

Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Oracle Communications Applications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.

Official advisory ↗
BSI · German · WID-SEC-2024-0106Oracle Communications: Mehrere Schwachstellen

Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Oracle Communications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.

Official advisory ↗
BSI · German · WID-SEC-2024-0025SAP Patchday Januar 2024

Ein entfernter Angreifer kann mehrere Schwachstellen in SAP-Software ausnutzen, um beliebigen Code auszuführen, einen Denial-of-Service-Zustand herbeizuführen, vertrauliche Informationen offenzulegen, Dateien zu manipulieren, seine Privilegien zu erweitern oder Phishing- und Cross-Site-Scripting (XSS)-Angriffe durchzuführen.

Official advisory ↗
BSI · German · WID-SEC-2023-2993Atlassian Bamboo, Atlassian Bitbucket, Atlassian Confluence and Atlassian Jira Software: Mehrere Schwachstellen

Ein Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Atlassian Bitbucket, Atlassian Confluence und Atlassian Jira Software ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen, vertrauliche Informationen offenzulegen oder einen Cross-Site-Scripting-Angriff durchzuführen.

Official advisory ↗
BSI · German · WID-SEC-2023-2788GitLab: Mehrere Schwachstellen

Ein Angreifer kann mehrere Schwachstellen in GitLab ausnutzen, um einen Denial of Service Angriff durchzuführen und Informationen offenzulegen.

Official advisory ↗
BSI · German · WID-SEC-2023-2723Red Hat Satellite: Mehrere Schwachstellen

Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Red Hat Satellite ausnutzen, um beliebigen Programmcode auszuführen oder einen Denial of Service Zustand herbeizuführen.

Official advisory ↗
BSI · German · WID-SEC-2023-2627Eclipse Jetty: Mehrere Schwachstellen ermöglichen Denial of Service

Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Eclipse Jetty ausnutzen, um einen Denial of Service Angriff durchzuführen.

Official advisory ↗
BSI · German · WID-SEC-2023-2611Microsoft Developer Tools: Mehrere Schwachstellen

Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Microsoft Developer Tools ausnutzen, um seine Privilegien zu erhöhen und einen Denial of Service Zustand zu verursachen.

Official advisory ↗
BSI · German · WID-SEC-2023-2618http/2 Implementierungen: Schwachstelle ermöglicht Denial of Service

Ein entfernter, anonymer Angreifer kann eine Schwachstelle in verschiedenen http/2 Implementierungen ausnutzen, um einen Denial of Service Angriff durchzuführen.

Official advisory ↗
BSI · German · WID-SEC-2026-3047IBM Planning Analytics: Mehrere Schwachstellen

Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM Planning Analytics ausnutzen, um einen Denial of Service Angriff durchzuführen oder Daten zu manipulieren.

Official advisory ↗
BSI · German · WID-SEC-2025-0225Dell PowerProtect Data Domain: Mehrere Schwachstellen

Ein Angreifer kann mehrere Schwachstellen in Dell PowerProtect Data Domain ausnutzen, um erhöhte Rechte zu erlangen, einen Denial-of-Service-Zustand herbeizuführen und einen nicht näher spezifizierten Angriff durchzuführen.

Official advisory ↗
BSI · German · WID-SEC-2024-1228Red Hat OpenStack: Mehrere Schwachstellen

Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat OpenStack ausnutzen, um Sicherheitsmaßnahmen zu umgehen, eine Denial-of-Service-Zustand zu erzeugen, um vertrauliche Informationen offenzulegen und Daten zu ändern.

Official advisory ↗
BSI · German · WID-SEC-2024-0894Oracle MySQL: Mehrere Schwachstellen

Ein Angreifer kann mehrere Schwachstellen in Oracle MySQL ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.

Official advisory ↗
BSI · German · WID-SEC-2024-0887Oracle Utilities Applications: Mehrere Schwachstellen

Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Oracle Utilities Applications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.

Official advisory ↗
BSI · German · WID-SEC-2024-0519IBM Maximo Asset Management: Mehrere Schwachstellen

Ein Angreifer kann mehrere Schwachstellen in IBM Maximo Asset Management ausnutzen, um beliebigen Programmcode auszuführen, Informationen offenzulegen, einen Denial of Service Zustand herbeizuführen oder einen Cross-Site-Scripting-Angriff durchzuführen.

Official advisory ↗
BSI · German · WID-SEC-2024-0121Oracle Java SE: Mehrere Schwachstellen

Ein entfernter, anonymer oder lokaler Angreifer kann mehrere Schwachstellen in Oracle Java SE ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.

Official advisory ↗
BSI · German · WID-SEC-2024-0118Oracle PeopleSoft: Mehrere Schwachstellen

Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle PeopleSoft ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.

Official advisory ↗
BSI · German · WID-SEC-2024-0116Oracle Siebel CRM: Mehrere Schwachstellen

Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Oracle Siebel CRM ausnutzen, um die Verfügbarkeit zu gefährden.

Official advisory ↗
BSI · German · WID-SEC-2024-0108Oracle Commerce: Mehrere Schwachstellen

Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Oracle Commerce ausnutzen, um die Integrität und Verfügbarkeit zu gefährden.

Official advisory ↗
BSI · German · WID-SEC-2023-3146IBM MQ Operator and Queue manager: Mehrere Schwachstellen

Ein Angreifer kann mehrere Schwachstellen in IBM MQ Operator and Queue manager ausnutzen, um einen Denial of Service Angriff durchzuführen, Informationen offenzulegen oder Sicherheitsmaßnahmen zu umgehen.

Official advisory ↗
BSI · German · WID-SEC-2023-2628Apache Tomcat: Mehrere Schwachstellen

Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Apache Tomcat ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen, Sicherheitsmaßnahmen zu umgehen oder vertrauliche Informationen offenzulegen.

Official advisory ↗
Canadian Centre for Cyber Security · English · AV24-701Microsoft security advisory – December 2024 monthly rollup (AV24–701)

On December 10, 2024, Microsoft published security advisories to address vulnerabilities in multiple products. Included were updates for the following products: Microsoft has indicated that CVE-2024-49138 and CVE-2023-44487* have been exploited.

Official advisory ↗
Canadian Centre for Cyber Security · English · AL23-015Vulnerability impacting HTTP/2 - Rapid Reset

An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.

Official advisory ↗
Canadian Centre for Cyber Security · English · AV23-615Microsoft security advisory – October 2023 monthly rollup (AV23-615)

On October 10, 2023, Microsoft published security updates to address vulnerabilities in multiple products. Included were critical updates for the following products: Microsoft has indicated that CVE-2023-44487, CVE-2023-36563 and CVE-2023-41763 have been exploited.

Official advisory ↗
Cyber Security Agency of Singapore · English · CSA-SB-20231011Security Bulletin 11 Oct 2023

The Cyber Security Agency of Singapore included this CVE in its official Security Bulletin 11 Oct 2023, published on 11 October 2023. Open the linked bulletin for the product, severity and reference information published in that issue.

Official advisory ↗
CERT-FR · French · CERTFR-2026-AVI-1206Multiples vulnérabilités dans les produits IBM

288092 du 17 septembre 2026 https://www.ibm.com/support/pages/node/7288092 Bulletin de sécurité IBM 7288365 du 17 septembre 2026 https://www.ibm.com/support/pages/node/7288365 Référence CVE CVE-2017-16026 https://www.cve.org/CVERecord?id=CVE-2017-16026 Référence CVE CVE-2021-23336 https://www.cve.org/CVERecord?id=CVE-2021-23336 Référence CVE CVE-2021-23337 https://www.cve.org/CVERecord?id=CVE-2021-23337 Référence CVE CVE-2022-42969 https://www.cve.org/CVERecord?id=CVE-2022-42969 Référence CVE CVE-2023-1370 https://www.cve.org/CVERecord?id=CVE-2023-1370 Référence CVE CVE-2023-28155 https://www.cve.org/CVERecord?id=CVE-2023-28155 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2024-47535 https://www.cve.org/CVERecord?id=CVE-2024-47535 Référence CVE CVE-2024-47764 https://www.cve.org/CVERecord?id=CVE-2024-47764 Référence CVE CVE-2024-56344 https://www.cve.org/CVERecord?id=CVE-2024-56344 Référence CVE CVE-2024-57699 https://www.cve.org/CVERecord?id=CVE-2024-57699 Référence CVE CVE-2025-12635 https://www.cve.org/CVERecord?id=CVE-2025-12635 Référence CVE CVE-2025-13465 https://www.cve.org/CVERecord?id=CVE-2025-13465 Référence CVE CVE-2025-13882 https://www.cve.org/CVERecord?id=CVE-2025-13882 Référence CVE CVE-2025-14009 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2026-AVI-1165Multiples vulnérabilités dans les produits IBM

ord?id=CVE-2023-34462 Référence CVE CVE-2023-34610 https://www.cve.org/CVERecord?id=CVE-2023-34610 Référence CVE CVE-2023-35701 https://www.cve.org/CVERecord?id=CVE-2023-35701 Référence CVE CVE-2023-3635 https://www.cve.org/CVERecord?id=CVE-2023-3635 Référence CVE CVE-2023-36478 https://www.cve.org/CVERecord?id=CVE-2023-36478 Référence CVE CVE-2023-36479 https://www.cve.org/CVERecord?id=CVE-2023-36479 Référence CVE CVE-2023-39410 https://www.cve.org/CVERecord?id=CVE-2023-39410 Référence CVE CVE-2023-40167 https://www.cve.org/CVERecord?id=CVE-2023-40167 Référence CVE CVE-2023-43642 https://www.cve.org/CVERecord?id=CVE-2023-43642 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-44981 https://www.cve.org/CVERecord?id=CVE-2023-44981 Référence CVE CVE-2023-45178 https://www.cve.org/CVERecord?id=CVE-2023-45178 Référence CVE CVE-2023-45288 https://www.cve.org/CVERecord?id=CVE-2023-45288 Référence CVE CVE-2023-45853 https://www.cve.org/CVERecord?id=CVE-2023-45853 Référence CVE CVE-2023-46120 https://www.cve.org/CVERecord?id=CVE-2023-46120 Référence CVE CVE-2023-50298 https://www.cve.org/CVERecord?id=CVE-2023-50298 Référence CVE CVE-2023-5072 https://www.cve.org/CVERecord?id=CVE-2023-5072 Référence CVE CVE-2023-5090 https://www.cve.org/CVERecord?id=CVE

Official advisory ↗
CERT-FR · French · CERTFR-2026-AVI-1067Multiples vulnérabilités dans les produits IBM

18 août 2026 https://www.ibm.com/support/pages/node/7284191 Bulletin de sécurité IBM 7284192 du 18 août 2026 https://www.ibm.com/support/pages/node/7284192 Bulletin de sécurité IBM 7284194 du 18 août 2026 https://www.ibm.com/support/pages/node/7284194 Bulletin de sécurité IBM 7284195 du 18 août 2026 https://www.ibm.com/support/pages/node/7284195 Bulletin de sécurité IBM 7284196 du 18 août 2026 https://www.ibm.com/support/pages/node/7284196 Bulletin de sécurité IBM 7284257 du 19 août 2026 https://www.ibm.com/support/pages/node/7284257 Bulletin de sécurité IBM 7284352 du 20 août 2026 https://www.ibm.com/support/pages/node/7284352 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2025-12817 https://www.cve.org/CVERecord?id=CVE-2025-12817 Référence CVE CVE-2025-12818 https://www.cve.org/CVERecord?id=CVE-2025-12818 Référence CVE CVE-2025-15649 https://www.cve.org/CVERecord?id=CVE-2025-15649 Référence CVE CVE-2026-10842 https://www.cve.org/CVERecord?id=CVE-2026-10842 Référence CVE CVE-2026-12087 https://www.cve.org/CVERecord?id=CVE-2026-12087 Référence CVE CVE-2026-14446 https://www.cve.org/CVERecord?id=CVE-2026-14446 Référence CVE CVE-2026-14512 https://www.cve.org/CVERecord?id=CVE-2026-14512 Référence CVE CVE-2026-14515 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2026-AVI-1032Multiples vulnérabilités dans les produits IBM

ité IBM 7282868 du 10 août 2026 https://www.ibm.com/support/pages/node/7282868 Bulletin de sécurité IBM 7283290 du 11 août 2026 https://www.ibm.com/support/pages/node/7283290 Bulletin de sécurité IBM 7277422 du 12 août 2026 https://www.ibm.com/support/pages/node/7277422 Bulletin de sécurité IBM 7283488 du 12 août 2026 https://www.ibm.com/support/pages/node/7283488 Bulletin de sécurité IBM 7283489 du 12 août 2026 https://www.ibm.com/support/pages/node/7283489 Bulletin de sécurité IBM 7283567 du 12 août 2026 https://www.ibm.com/support/pages/node/7283567 Référence CVE CVE-2021-23337 https://www.cve.org/CVERecord?id=CVE-2021-23337 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2024-3651 https://www.cve.org/CVERecord?id=CVE-2024-3651 Référence CVE CVE-2025-13465 https://www.cve.org/CVERecord?id=CVE-2025-13465 Référence CVE CVE-2025-14813 https://www.cve.org/CVERecord?id=CVE-2025-14813 Référence CVE CVE-2025-36372 https://www.cve.org/CVERecord?id=CVE-2025-36372 Référence CVE CVE-2025-66471 https://www.cve.org/CVERecord?id=CVE-2025-66471 Référence CVE CVE-2025-66614 https://www.cve.org/CVERecord?id=CVE-2025-66614 Référence CVE CVE-2025-68161 https://www.cve.org/CVERecord?id=CVE-2025-68161 Référence CVE CVE-2026-10109 https://www.cve.org/CVERecord?id=CV

Official advisory ↗
CERT-FR · French · CERTFR-2026-AVI-0627Multiples vulnérabilités dans les produits Splunk

ecord?id=CVE-2023-22946 Référence CVE CVE-2023-2976 https://www.cve.org/CVERecord?id=CVE-2023-2976 Référence CVE CVE-2023-34453 https://www.cve.org/CVERecord?id=CVE-2023-34453 Référence CVE CVE-2023-34454 https://www.cve.org/CVERecord?id=CVE-2023-34454 Référence CVE CVE-2023-34455 https://www.cve.org/CVERecord?id=CVE-2023-34455 Référence CVE CVE-2023-3635 https://www.cve.org/CVERecord?id=CVE-2023-3635 Référence CVE CVE-2023-37920 https://www.cve.org/CVERecord?id=CVE-2023-37920 Référence CVE CVE-2023-39410 https://www.cve.org/CVERecord?id=CVE-2023-39410 Référence CVE CVE-2023-43642 https://www.cve.org/CVERecord?id=CVE-2023-43642 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-47627 https://www.cve.org/CVERecord?id=CVE-2023-47627 Référence CVE CVE-2023-4807 https://www.cve.org/CVERecord?id=CVE-2023-4807 Référence CVE CVE-2023-49081 https://www.cve.org/CVERecord?id=CVE-2023-49081 Référence CVE CVE-2023-49082 https://www.cve.org/CVERecord?id=CVE-2023-49082 Référence CVE CVE-2023-49083 https://www.cve.org/CVERecord?id=CVE-2023-49083 Référence CVE CVE-2023-50782 https://www.cve.org/CVERecord?id=CVE-2023-50782 Référence CVE CVE-2023-5408 https://www.cve.org/CVERecord?id=CVE-2023-5408 Référence CVE CVE-2023-5590 https://www.cve.org/CVERecord?id=CVE-2

Official advisory ↗
CERT-FR · French · CERTFR-2026-AVI-0339Multiples vulnérabilités dans les produits VMware

d?id=CVE-2023-29403 Référence CVE CVE-2023-29404 https://www.cve.org/CVERecord?id=CVE-2023-29404 Référence CVE CVE-2023-29405 https://www.cve.org/CVERecord?id=CVE-2023-29405 Référence CVE CVE-2023-29406 https://www.cve.org/CVERecord?id=CVE-2023-29406 Référence CVE CVE-2023-29409 https://www.cve.org/CVERecord?id=CVE-2023-29409 Référence CVE CVE-2023-39318 https://www.cve.org/CVERecord?id=CVE-2023-39318 Référence CVE CVE-2023-39319 https://www.cve.org/CVERecord?id=CVE-2023-39319 Référence CVE CVE-2023-39323 https://www.cve.org/CVERecord?id=CVE-2023-39323 Référence CVE CVE-2023-39326 https://www.cve.org/CVERecord?id=CVE-2023-39326 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-45283 https://www.cve.org/CVERecord?id=CVE-2023-45283 Référence CVE CVE-2023-45284 https://www.cve.org/CVERecord?id=CVE-2023-45284 Référence CVE CVE-2023-45285 https://www.cve.org/CVERecord?id=CVE-2023-45285 Référence CVE CVE-2023-45287 https://www.cve.org/CVERecord?id=CVE-2023-45287 Référence CVE CVE-2023-45288 https://www.cve.org/CVERecord?id=CVE-2023-45288 Référence CVE CVE-2023-45289 https://www.cve.org/CVERecord?id=CVE-2023-45289 Référence CVE CVE-2023-45290 https://www.cve.org/CVERecord?id=CVE-2023-45290 Référence CVE CVE-2023-48795 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2026-AVI-0326Multiples vulnérabilités dans les produits VMware

VERecord?id=CVE-2023-3817 Référence CVE CVE-2023-38417 https://www.cve.org/CVERecord?id=CVE-2023-38417 Référence CVE CVE-2023-38552 https://www.cve.org/CVERecord?id=CVE-2023-38552 Référence CVE CVE-2023-39333 https://www.cve.org/CVERecord?id=CVE-2023-39333 Référence CVE CVE-2023-4010 https://www.cve.org/CVERecord?id=CVE-2023-4010 Référence CVE CVE-2023-4133 https://www.cve.org/CVERecord?id=CVE-2023-4133 Référence CVE CVE-2023-42366 https://www.cve.org/CVERecord?id=CVE-2023-42366 Référence CVE CVE-2023-43804 https://www.cve.org/CVERecord?id=CVE-2023-43804 Référence CVE CVE-2023-4408 https://www.cve.org/CVERecord?id=CVE-2023-4408 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-45803 https://www.cve.org/CVERecord?id=CVE-2023-45803 Référence CVE CVE-2023-45896 https://www.cve.org/CVERecord?id=CVE-2023-45896 Référence CVE CVE-2023-45927 https://www.cve.org/CVERecord?id=CVE-2023-45927 Référence CVE CVE-2023-45929 https://www.cve.org/CVERecord?id=CVE-2023-45929 Référence CVE CVE-2023-46316 https://www.cve.org/CVERecord?id=CVE-2023-46316 Référence CVE CVE-2023-46809 https://www.cve.org/CVERecord?id=CVE-2023-46809 Référence CVE CVE-2023-47210 https://www.cve.org/CVERecord?id=CVE-2023-47210 Référence CVE CVE-2023-49083 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2026-AVI-0316Multiples vulnérabilités dans les produits VMware

VERecord?id=CVE-2023-3817 Référence CVE CVE-2023-38417 https://www.cve.org/CVERecord?id=CVE-2023-38417 Référence CVE CVE-2023-38552 https://www.cve.org/CVERecord?id=CVE-2023-38552 Référence CVE CVE-2023-39333 https://www.cve.org/CVERecord?id=CVE-2023-39333 Référence CVE CVE-2023-4010 https://www.cve.org/CVERecord?id=CVE-2023-4010 Référence CVE CVE-2023-4133 https://www.cve.org/CVERecord?id=CVE-2023-4133 Référence CVE CVE-2023-42366 https://www.cve.org/CVERecord?id=CVE-2023-42366 Référence CVE CVE-2023-43804 https://www.cve.org/CVERecord?id=CVE-2023-43804 Référence CVE CVE-2023-4408 https://www.cve.org/CVERecord?id=CVE-2023-4408 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-45803 https://www.cve.org/CVERecord?id=CVE-2023-45803 Référence CVE CVE-2023-45896 https://www.cve.org/CVERecord?id=CVE-2023-45896 Référence CVE CVE-2023-45927 https://www.cve.org/CVERecord?id=CVE-2023-45927 Référence CVE CVE-2023-45929 https://www.cve.org/CVERecord?id=CVE-2023-45929 Référence CVE CVE-2023-46316 https://www.cve.org/CVERecord?id=CVE-2023-46316 Référence CVE CVE-2023-46809 https://www.cve.org/CVERecord?id=CVE-2023-46809 Référence CVE CVE-2023-47210 https://www.cve.org/CVERecord?id=CVE-2023-47210 Référence CVE CVE-2023-49083 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2026-AVI-0287Multiples vulnérabilités dans les produits NetApp

De multiples vulnérabilités ont été découvertes dans les produits NetApp. Elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.

Official advisory ↗
CERT-FR · French · CERTFR-2026-AVI-0281Multiples vulnérabilités dans les produits Splunk

ord?id=CVE-2022-31159 Référence CVE CVE-2022-3821 https://www.cve.org/CVERecord?id=CVE-2022-3821 Référence CVE CVE-2022-42003 https://www.cve.org/CVERecord?id=CVE-2022-42003 Référence CVE CVE-2022-42004 https://www.cve.org/CVERecord?id=CVE-2022-42004 Référence CVE CVE-2023-26118 https://www.cve.org/CVERecord?id=CVE-2023-26118 Référence CVE CVE-2023-26464 https://www.cve.org/CVERecord?id=CVE-2023-26464 Référence CVE CVE-2023-26604 https://www.cve.org/CVERecord?id=CVE-2023-26604 Référence CVE CVE-2023-33201 https://www.cve.org/CVERecord?id=CVE-2023-33201 Référence CVE CVE-2023-33202 https://www.cve.org/CVERecord?id=CVE-2023-33202 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-48795 https://www.cve.org/CVERecord?id=CVE-2023-48795 Référence CVE CVE-2023-49501 https://www.cve.org/CVERecord?id=CVE-2023-49501 Référence CVE CVE-2023-52428 https://www.cve.org/CVERecord?id=CVE-2023-52428 Référence CVE CVE-2023-6601 https://www.cve.org/CVERecord?id=CVE-2023-6601 Référence CVE CVE-2023-6602 https://www.cve.org/CVERecord?id=CVE-2023-6602 Référence CVE CVE-2023-6604 https://www.cve.org/CVERecord?id=CVE-2023-6604 Référence CVE CVE-2023-6605 https://www.cve.org/CVERecord?id=CVE-2023-6605 Référence CVE CVE-2024-12243 https://www.cve.org/CVERecord?id=CVE-2024

Official advisory ↗
CERT-FR · French · CERTFR-2026-AVI-0199Multiples vulnérabilités dans les produits VMware

ord?id=CVE-2023-39323 Référence CVE CVE-2023-39325 https://www.cve.org/CVERecord?id=CVE-2023-39325 Référence CVE CVE-2023-39326 https://www.cve.org/CVERecord?id=CVE-2023-39326 Référence CVE CVE-2023-39410 https://www.cve.org/CVERecord?id=CVE-2023-39410 Référence CVE CVE-2023-3978 https://www.cve.org/CVERecord?id=CVE-2023-3978 Référence CVE CVE-2023-42363 https://www.cve.org/CVERecord?id=CVE-2023-42363 Référence CVE CVE-2023-42364 https://www.cve.org/CVERecord?id=CVE-2023-42364 Référence CVE CVE-2023-42365 https://www.cve.org/CVERecord?id=CVE-2023-42365 Référence CVE CVE-2023-42366 https://www.cve.org/CVERecord?id=CVE-2023-42366 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-45283 https://www.cve.org/CVERecord?id=CVE-2023-45283 Référence CVE CVE-2023-45284 https://www.cve.org/CVERecord?id=CVE-2023-45284 Référence CVE CVE-2023-45285 https://www.cve.org/CVERecord?id=CVE-2023-45285 Référence CVE CVE-2023-45287 https://www.cve.org/CVERecord?id=CVE-2023-45287 Référence CVE CVE-2023-45288 https://www.cve.org/CVERecord?id=CVE-2023-45288 Référence CVE CVE-2023-45289 https://www.cve.org/CVERecord?id=CVE-2023-45289 Référence CVE CVE-2023-45290 https://www.cve.org/CVERecord?id=CVE-2023-45290 Référence CVE CVE-2023-46218 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0969Multiples vulnérabilités dans les produits VMware

Record?id=CVE-2023-4039 Référence CVE CVE-2023-40403 https://www.cve.org/CVERecord?id=CVE-2023-40403 Référence CVE CVE-2023-40745 https://www.cve.org/CVERecord?id=CVE-2023-40745 Référence CVE CVE-2023-4091 https://www.cve.org/CVERecord?id=CVE-2023-4091 Référence CVE CVE-2023-41175 https://www.cve.org/CVERecord?id=CVE-2023-41175 Référence CVE CVE-2023-4154 https://www.cve.org/CVERecord?id=CVE-2023-4154 Référence CVE CVE-2023-42669 https://www.cve.org/CVERecord?id=CVE-2023-42669 Référence CVE CVE-2023-42670 https://www.cve.org/CVERecord?id=CVE-2023-42670 Référence CVE CVE-2023-43887 https://www.cve.org/CVERecord?id=CVE-2023-43887 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-4527 https://www.cve.org/CVERecord?id=CVE-2023-4527 Référence CVE CVE-2023-45283 https://www.cve.org/CVERecord?id=CVE-2023-45283 Référence CVE CVE-2023-45284 https://www.cve.org/CVERecord?id=CVE-2023-45284 Référence CVE CVE-2023-45285 https://www.cve.org/CVERecord?id=CVE-2023-45285 Référence CVE CVE-2023-45287 https://www.cve.org/CVERecord?id=CVE-2023-45287 Référence CVE CVE-2023-45288 https://www.cve.org/CVERecord?id=CVE-2023-45288 Référence CVE CVE-2023-45289 https://www.cve.org/CVERecord?id=CVE-2023-45289 Référence CVE CVE-2023-45290 https://www.cve.org/CVERecord?id=CV

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0967Multiples vulnérabilités dans les produits VMware

rd?id=CVE-2023-2650 Référence CVE CVE-2023-27043 https://www.cve.org/CVERecord?id=CVE-2023-27043 Référence CVE CVE-2023-30584 https://www.cve.org/CVERecord?id=CVE-2023-30584 Référence CVE CVE-2023-36632 https://www.cve.org/CVERecord?id=CVE-2023-36632 Référence CVE CVE-2023-38552 https://www.cve.org/CVERecord?id=CVE-2023-38552 Référence CVE CVE-2023-39331 https://www.cve.org/CVERecord?id=CVE-2023-39331 Référence CVE CVE-2023-39332 https://www.cve.org/CVERecord?id=CVE-2023-39332 Référence CVE CVE-2023-39333 https://www.cve.org/CVERecord?id=CVE-2023-39333 Référence CVE CVE-2023-40217 https://www.cve.org/CVERecord?id=CVE-2023-40217 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-46809 https://www.cve.org/CVERecord?id=CVE-2023-46809 Référence CVE CVE-2023-4807 https://www.cve.org/CVERecord?id=CVE-2023-4807 Référence CVE CVE-2023-52969 https://www.cve.org/CVERecord?id=CVE-2023-52969 Référence CVE CVE-2023-52970 https://www.cve.org/CVERecord?id=CVE-2023-52970 Référence CVE CVE-2023-5752 https://www.cve.org/CVERecord?id=CVE-2023-5752 Référence CVE CVE-2023-6597 https://www.cve.org/CVERecord?id=CVE-2023-6597 Référence CVE CVE-2024-0397 https://www.cve.org/CVERecord?id=CVE-2024-0397 Référence CVE CVE-2024-0450 https://www.cve.org/CVERecord?id=CVE-2024-

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0960Multiples vulnérabilités dans VMware Tanzu

support-content-notification/-/external/content/SecurityAdvisories/0/36300 Bulletin de sécurité VMware 36301 du 04 novembre 2025 https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36301 Bulletin de sécurité VMware 36302 du 04 novembre 2025 https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36302 Référence CVE CVE-2022-29526 https://www.cve.org/CVERecord?id=CVE-2022-29526 Référence CVE CVE-2023-39325 https://www.cve.org/CVERecord?id=CVE-2023-39325 Référence CVE CVE-2023-3978 https://www.cve.org/CVERecord?id=CVE-2023-3978 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-45288 https://www.cve.org/CVERecord?id=CVE-2023-45288 Référence CVE CVE-2024-23337 https://www.cve.org/CVERecord?id=CVE-2024-23337 Référence CVE CVE-2024-24786 https://www.cve.org/CVERecord?id=CVE-2024-24786 Référence CVE CVE-2024-45336 https://www.cve.org/CVERecord?id=CVE-2024-45336 Référence CVE CVE-2024-45337 https://www.cve.org/CVERecord?id=CVE-2024-45337 Référence CVE CVE-2024-45341 https://www.cve.org/CVERecord?id=CVE-2024-45341 Référence CVE CVE-2024-53427 https://www.cve.org/CVERecord?id=CVE-2024-53427 Référence CVE CVE-2025-0913 https://www.cve.org/CVERecord?id=C

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0864Multiples vulnérabilités dans VMware Tanzu

Record?id=CVE-2023-3817 Référence CVE CVE-2023-38546 https://www.cve.org/CVERecord?id=CVE-2023-38546 Référence CVE CVE-2023-39323 https://www.cve.org/CVERecord?id=CVE-2023-39323 Référence CVE CVE-2023-39325 https://www.cve.org/CVERecord?id=CVE-2023-39325 Référence CVE CVE-2023-39326 https://www.cve.org/CVERecord?id=CVE-2023-39326 Référence CVE CVE-2023-39804 https://www.cve.org/CVERecord?id=CVE-2023-39804 Référence CVE CVE-2023-4016 https://www.cve.org/CVERecord?id=CVE-2023-4016 Référence CVE CVE-2023-40217 https://www.cve.org/CVERecord?id=CVE-2023-40217 Référence CVE CVE-2023-4039 https://www.cve.org/CVERecord?id=CVE-2023-4039 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-45285 https://www.cve.org/CVERecord?id=CVE-2023-45285 Référence CVE CVE-2023-45288 https://www.cve.org/CVERecord?id=CVE-2023-45288 Référence CVE CVE-2023-45289 https://www.cve.org/CVERecord?id=CVE-2023-45289 Référence CVE CVE-2023-45290 https://www.cve.org/CVERecord?id=CVE-2023-45290 Référence CVE CVE-2023-45918 https://www.cve.org/CVERecord?id=CVE-2023-45918 Référence CVE CVE-2023-46218 https://www.cve.org/CVERecord?id=CVE-2023-46218 Référence CVE CVE-2023-4641 https://www.cve.org/CVERecord?id=CVE-2023-4641 Référence CVE CVE-2023-47038 https://www.cve.org/CVERecord?id=CV

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0861Multiples vulnérabilités dans les produits IBM

port/pages/node/7247431 Référence CVE CVE-2019-11250 https://www.cve.org/CVERecord?id=CVE-2019-11250 Référence CVE CVE-2020-8565 https://www.cve.org/CVERecord?id=CVE-2020-8565 Référence CVE CVE-2022-1471 https://www.cve.org/CVERecord?id=CVE-2022-1471 Référence CVE CVE-2022-41723 https://www.cve.org/CVERecord?id=CVE-2022-41723 Référence CVE CVE-2022-41724 https://www.cve.org/CVERecord?id=CVE-2022-41724 Référence CVE CVE-2022-41725 https://www.cve.org/CVERecord?id=CVE-2022-41725 Référence CVE CVE-2022-46175 https://www.cve.org/CVERecord?id=CVE-2022-46175 Référence CVE CVE-2023-24532 https://www.cve.org/CVERecord?id=CVE-2023-24532 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2024-22243 https://www.cve.org/CVERecord?id=CVE-2024-22243 Référence CVE CVE-2024-22259 https://www.cve.org/CVERecord?id=CVE-2024-22259 Référence CVE CVE-2024-3651 https://www.cve.org/CVERecord?id=CVE-2024-3651 Référence CVE CVE-2024-45337 https://www.cve.org/CVERecord?id=CVE-2024-45337 Référence CVE CVE-2025-22868 https://www.cve.org/CVERecord?id=CVE-2025-22868 Référence CVE CVE-2025-22870 https://www.cve.org/CVERecord?id=CVE-2025-22870 Référence CVE CVE-2025-27789 https://www.cve.org/CVERecord?id=CVE-2025-27789 Référence CVE CVE-2025-41248 https://www.cve.org/CVERecord?id=CV

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0756Multiples vulnérabilités dans les produits VMware

ERecord?id=CVE-2023-40217 Référence CVE CVE-2023-4039 https://www.cve.org/CVERecord?id=CVE-2023-4039 Référence CVE CVE-2023-40403 https://www.cve.org/CVERecord?id=CVE-2023-40403 Référence CVE CVE-2023-4156 https://www.cve.org/CVERecord?id=CVE-2023-4156 Référence CVE CVE-2023-42366 https://www.cve.org/CVERecord?id=CVE-2023-42366 Référence CVE CVE-2023-4320 https://www.cve.org/CVERecord?id=CVE-2023-4320 Référence CVE CVE-2023-43785 https://www.cve.org/CVERecord?id=CVE-2023-43785 Référence CVE CVE-2023-43786 https://www.cve.org/CVERecord?id=CVE-2023-43786 Référence CVE CVE-2023-43787 https://www.cve.org/CVERecord?id=CVE-2023-43787 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-4527 https://www.cve.org/CVERecord?id=CVE-2023-4527 Référence CVE CVE-2023-45288 https://www.cve.org/CVERecord?id=CVE-2023-45288 Référence CVE CVE-2023-45322 https://www.cve.org/CVERecord?id=CVE-2023-45322 Référence CVE CVE-2023-45803 https://www.cve.org/CVERecord?id=CVE-2023-45803 Référence CVE CVE-2023-45853 https://www.cve.org/CVERecord?id=CVE-2023-45853 Référence CVE CVE-2023-46129 https://www.cve.org/CVERecord?id=CVE-2023-46129 Référence CVE CVE-2023-46218 https://www.cve.org/CVERecord?id=CVE-2023-46218 Référence CVE CVE-2023-46219 https://www.cve.org/CVERecord?id=CV

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0667Multiples vulnérabilités dans Juniper Secure Analytics

De multiples vulnérabilités ont été découvertes dans Juniper Secure Analytics. Elle permet à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0622Multiples vulnérabilités dans les produits VMware

cord?id=CVE-2023-3817 Référence CVE CVE-2023-39318 https://www.cve.org/CVERecord?id=CVE-2023-39318 Référence CVE CVE-2023-39319 https://www.cve.org/CVERecord?id=CVE-2023-39319 Référence CVE CVE-2023-39323 https://www.cve.org/CVERecord?id=CVE-2023-39323 Référence CVE CVE-2023-39325 https://www.cve.org/CVERecord?id=CVE-2023-39325 Référence CVE CVE-2023-39326 https://www.cve.org/CVERecord?id=CVE-2023-39326 Référence CVE CVE-2023-3978 https://www.cve.org/CVERecord?id=CVE-2023-3978 Référence CVE CVE-2023-40217 https://www.cve.org/CVERecord?id=CVE-2023-40217 Référence CVE CVE-2023-40403 https://www.cve.org/CVERecord?id=CVE-2023-40403 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-45283 https://www.cve.org/CVERecord?id=CVE-2023-45283 Référence CVE CVE-2023-45284 https://www.cve.org/CVERecord?id=CVE-2023-45284 Référence CVE CVE-2023-45285 https://www.cve.org/CVERecord?id=CVE-2023-45285 Référence CVE CVE-2023-45287 https://www.cve.org/CVERecord?id=CVE-2023-45287 Référence CVE CVE-2023-45288 https://www.cve.org/CVERecord?id=CVE-2023-45288 Référence CVE CVE-2023-45289 https://www.cve.org/CVERecord?id=CVE-2023-45289 Référence CVE CVE-2023-45290 https://www.cve.org/CVERecord?id=CVE-2023-45290 Référence CVE CVE-2023-46218 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0608Multiples vulnérabilités dans les produits IBM

d?id=CVE-2021-44533 Référence CVE CVE-2022-21803 https://www.cve.org/CVERecord?id=CVE-2022-21803 Référence CVE CVE-2022-21824 https://www.cve.org/CVERecord?id=CVE-2022-21824 Référence CVE CVE-2022-29078 https://www.cve.org/CVERecord?id=CVE-2022-29078 Référence CVE CVE-2022-30614 https://www.cve.org/CVERecord?id=CVE-2022-30614 Référence CVE CVE-2022-36773 https://www.cve.org/CVERecord?id=CVE-2022-36773 Référence CVE CVE-2022-49395 https://www.cve.org/CVERecord?id=CVE-2022-49395 Référence CVE CVE-2023-32732 https://www.cve.org/CVERecord?id=CVE-2023-32732 Référence CVE CVE-2023-33953 https://www.cve.org/CVERecord?id=CVE-2023-33953 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2024-52005 https://www.cve.org/CVERecord?id=CVE-2024-52005 Référence CVE CVE-2025-21587 https://www.cve.org/CVERecord?id=CVE-2025-21587 Référence CVE CVE-2025-22869 https://www.cve.org/CVERecord?id=CVE-2025-22869 Référence CVE CVE-2025-2900 https://www.cve.org/CVERecord?id=CVE-2025-2900 Référence CVE CVE-2025-30698 https://www.cve.org/CVERecord?id=CVE-2025-30698 Référence CVE CVE-2025-32414 https://www.cve.org/CVERecord?id=CVE-2025-32414 Référence CVE CVE-2025-36038 https://www.cve.org/CVERecord?id=CVE-2025-36038 Référence CVE CVE-2025-36097 https://www.cve.org/CVERecord?id=CV

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0565Multiples vulnérabilités dans les produits Schneider Electric

De multiples vulnérabilités ont été découvertes dans les produits Schneider Electric. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0532Multiples vulnérabilités dans les produits Splunk

De multiples vulnérabilités ont été découvertes dans les produits Splunk. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0524Multiples vulnérabilités dans VMware Tanzu

Record?id=CVE-2023-3817 Référence CVE CVE-2023-39318 https://www.cve.org/CVERecord?id=CVE-2023-39318 Référence CVE CVE-2023-39319 https://www.cve.org/CVERecord?id=CVE-2023-39319 Référence CVE CVE-2023-39323 https://www.cve.org/CVERecord?id=CVE-2023-39323 Référence CVE CVE-2023-39326 https://www.cve.org/CVERecord?id=CVE-2023-39326 Référence CVE CVE-2023-39328 https://www.cve.org/CVERecord?id=CVE-2023-39328 Référence CVE CVE-2023-39329 https://www.cve.org/CVERecord?id=CVE-2023-39329 Référence CVE CVE-2023-4016 https://www.cve.org/CVERecord?id=CVE-2023-4016 Référence CVE CVE-2023-4039 https://www.cve.org/CVERecord?id=CVE-2023-4039 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-45285 https://www.cve.org/CVERecord?id=CVE-2023-45285 Référence CVE CVE-2023-45287 https://www.cve.org/CVERecord?id=CVE-2023-45287 Référence CVE CVE-2023-45288 https://www.cve.org/CVERecord?id=CVE-2023-45288 Référence CVE CVE-2023-45289 https://www.cve.org/CVERecord?id=CVE-2023-45289 Référence CVE CVE-2023-45290 https://www.cve.org/CVERecord?id=CVE-2023-45290 Référence CVE CVE-2023-45853 https://www.cve.org/CVERecord?id=CVE-2023-45853 Référence CVE CVE-2023-4641 https://www.cve.org/CVERecord?id=CVE-2023-4641 Référence CVE CVE-2023-4752 https://www.cve.org/CVERecord?id=CVE

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0492Multiples vulnérabilités dans les produits Siemens

4AR3) versions antérieures à V3.2 SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3) versions antérieures à V3.1 SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3) versions antérieures à V3.2 SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3) versions antérieures à V3.1 SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3) versions antérieures à V3.2 SIMATIC S7-1500 versions supérieures ou égales àV3.1.5 pour les vulnérabilités CVE-2021-41617, CVE-2023-4527, CVE-2023-4806, CVE-2023-4911, CVE-2023-5363, CVE-2023-6246, CVE-2023-6779, CVE-2023-6780, CVE-2023-28531, CVE-2023-38545, CVE-2023-38546, CVE-2023-44487, CVE-2023-46218, CVE-2023-46219, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2023-52927, CVE-2024-2961, CVE-2024-6119, CVE-2024-6387, CVE-2024-12133, CVE-2024-12243, CVE-2024-24855, CVE-2024-26596, CVE-2024-28085, CVE-2024-33599, CVE-2024-33600, CVE-2024-33601, CVE-2024-33602, CVE-2024-34397, CVE-2024-37370, CVE-2024-37371, CVE-2024-45490, CVE-2024-45491, CVE-2024-45492, CVE-2024-50246, CVE-2024-53166, CVE-2024-57977, CVE-2024-57996, CVE-2024-58005, CVE-2025-4373, CVE-2025-4598, CVE-2025-21701, CVE-2025-21702, CVE-2025-21712, CVE-2025-21724, CVE-2025-21728, CVE-2025-21745, CVE-2025-21756, CVE-2025-21758, CVE-2025-21765, CVE-2025-2176

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0283Multiples vulnérabilités dans VMware Tanzu Greenplum

d?id=CVE-2023-37920 Référence CVE CVE-2023-39318 https://www.cve.org/CVERecord?id=CVE-2023-39318 Référence CVE CVE-2023-39319 https://www.cve.org/CVERecord?id=CVE-2023-39319 Référence CVE CVE-2023-39320 https://www.cve.org/CVERecord?id=CVE-2023-39320 Référence CVE CVE-2023-39321 https://www.cve.org/CVERecord?id=CVE-2023-39321 Référence CVE CVE-2023-39322 https://www.cve.org/CVERecord?id=CVE-2023-39322 Référence CVE CVE-2023-39323 https://www.cve.org/CVERecord?id=CVE-2023-39323 Référence CVE CVE-2023-39325 https://www.cve.org/CVERecord?id=CVE-2023-39325 Référence CVE CVE-2023-39326 https://www.cve.org/CVERecord?id=CVE-2023-39326 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-45283 https://www.cve.org/CVERecord?id=CVE-2023-45283 Référence CVE CVE-2023-45284 https://www.cve.org/CVERecord?id=CVE-2023-45284 Référence CVE CVE-2023-45285 https://www.cve.org/CVERecord?id=CVE-2023-45285 Référence CVE CVE-2023-45288 https://www.cve.org/CVERecord?id=CVE-2023-45288 Référence CVE CVE-2023-45289 https://www.cve.org/CVERecord?id=CVE-2023-45289 Référence CVE CVE-2023-45290 https://www.cve.org/CVERecord?id=CVE-2023-45290 Référence CVE CVE-2024-24783 https://www.cve.org/CVERecord?id=CVE-2024-24783 Référence CVE CVE-2024-24784 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0279Multiples vulnérabilités dans les produits IBM

ord?id=CVE-2021-23337 Référence CVE CVE-2021-4204 https://www.cve.org/CVERecord?id=CVE-2021-4204 Référence CVE CVE-2021-44906 https://www.cve.org/CVERecord?id=CVE-2021-44906 Référence CVE CVE-2021-47495 https://www.cve.org/CVERecord?id=CVE-2021-47495 Référence CVE CVE-2022-29153 https://www.cve.org/CVERecord?id=CVE-2022-29153 Référence CVE CVE-2022-48706 https://www.cve.org/CVERecord?id=CVE-2022-48706 Référence CVE CVE-2022-48890 https://www.cve.org/CVERecord?id=CVE-2022-48890 Référence CVE CVE-2022-48921 https://www.cve.org/CVERecord?id=CVE-2022-48921 Référence CVE CVE-2023-43804 https://www.cve.org/CVERecord?id=CVE-2023-43804 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-45142 https://www.cve.org/CVERecord?id=CVE-2023-45142 Référence CVE CVE-2023-45857 https://www.cve.org/CVERecord?id=CVE-2023-45857 Référence CVE CVE-2023-52455 https://www.cve.org/CVERecord?id=CVE-2023-52455 Référence CVE CVE-2023-52467 https://www.cve.org/CVERecord?id=CVE-2023-52467 Référence CVE CVE-2023-52605 https://www.cve.org/CVERecord?id=CVE-2023-52605 Référence CVE CVE-2023-52832 https://www.cve.org/CVERecord?id=CVE-2023-52832 Référence CVE CVE-2023-52885 https://www.cve.org/CVERecord?id=CVE-2023-52885 Référence CVE CVE-2023-52898 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0256Multiples vulnérabilités dans Broadcom VMware Tanzu Greenplum

d?id=CVE-2023-29403 Référence CVE CVE-2023-29404 https://www.cve.org/CVERecord?id=CVE-2023-29404 Référence CVE CVE-2023-29405 https://www.cve.org/CVERecord?id=CVE-2023-29405 Référence CVE CVE-2023-29406 https://www.cve.org/CVERecord?id=CVE-2023-29406 Référence CVE CVE-2023-29409 https://www.cve.org/CVERecord?id=CVE-2023-29409 Référence CVE CVE-2023-39318 https://www.cve.org/CVERecord?id=CVE-2023-39318 Référence CVE CVE-2023-39319 https://www.cve.org/CVERecord?id=CVE-2023-39319 Référence CVE CVE-2023-39323 https://www.cve.org/CVERecord?id=CVE-2023-39323 Référence CVE CVE-2023-39326 https://www.cve.org/CVERecord?id=CVE-2023-39326 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-45283 https://www.cve.org/CVERecord?id=CVE-2023-45283 Référence CVE CVE-2023-45284 https://www.cve.org/CVERecord?id=CVE-2023-45284 Référence CVE CVE-2023-45285 https://www.cve.org/CVERecord?id=CVE-2023-45285 Référence CVE CVE-2023-45287 https://www.cve.org/CVERecord?id=CVE-2023-45287 Référence CVE CVE-2023-45288 https://www.cve.org/CVERecord?id=CVE-2023-45288 Référence CVE CVE-2023-45289 https://www.cve.org/CVERecord?id=CVE-2023-45289 Référence CVE CVE-2023-45290 https://www.cve.org/CVERecord?id=CVE-2023-45290 Référence CVE CVE-2024-24783 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-1081Multiples vulnérabilités dans les produits IBM

d?id=CVE-2023-33546 Référence CVE CVE-2023-34453 https://www.cve.org/CVERecord?id=CVE-2023-34453 Référence CVE CVE-2023-34454 https://www.cve.org/CVERecord?id=CVE-2023-34454 Référence CVE CVE-2023-34455 https://www.cve.org/CVERecord?id=CVE-2023-34455 Référence CVE CVE-2023-34462 https://www.cve.org/CVERecord?id=CVE-2023-34462 Référence CVE CVE-2023-35116 https://www.cve.org/CVERecord?id=CVE-2023-35116 Référence CVE CVE-2023-36478 https://www.cve.org/CVERecord?id=CVE-2023-36478 Référence CVE CVE-2023-37920 https://www.cve.org/CVERecord?id=CVE-2023-37920 Référence CVE CVE-2023-43642 https://www.cve.org/CVERecord?id=CVE-2023-43642 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-48161 https://www.cve.org/CVERecord?id=CVE-2023-48161 Référence CVE CVE-2023-52425 https://www.cve.org/CVERecord?id=CVE-2023-52425 Référence CVE CVE-2023-52426 https://www.cve.org/CVERecord?id=CVE-2023-52426 Référence CVE CVE-2023-52428 https://www.cve.org/CVERecord?id=CVE-2023-52428 Référence CVE CVE-2024-0450 https://www.cve.org/CVERecord?id=CVE-2024-0450 Référence CVE CVE-2024-10041 https://www.cve.org/CVERecord?id=CVE-2024-10041 Référence CVE CVE-2024-10963 https://www.cve.org/CVERecord?id=CVE-2024-10963 Référence CVE CVE-2024-21208 https://www.cve.org/CVERecord?id=CV

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-1051Multiples vulnérabilités dans les produits IBM

ord?id=CVE-2023-24807 Référence CVE CVE-2023-24998 https://www.cve.org/CVERecord?id=CVE-2023-24998 Référence CVE CVE-2023-2597 https://www.cve.org/CVERecord?id=CVE-2023-2597 Référence CVE CVE-2023-26159 https://www.cve.org/CVERecord?id=CVE-2023-26159 Référence CVE CVE-2023-33850 https://www.cve.org/CVERecord?id=CVE-2023-33850 Référence CVE CVE-2023-38264 https://www.cve.org/CVERecord?id=CVE-2023-38264 Référence CVE CVE-2023-38737 https://www.cve.org/CVERecord?id=CVE-2023-38737 Référence CVE CVE-2023-39332 https://www.cve.org/CVERecord?id=CVE-2023-39332 Référence CVE CVE-2023-44483 https://www.cve.org/CVERecord?id=CVE-2023-44483 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-49735 https://www.cve.org/CVERecord?id=CVE-2023-49735 Référence CVE CVE-2023-50312 https://www.cve.org/CVERecord?id=CVE-2023-50312 Référence CVE CVE-2023-51775 https://www.cve.org/CVERecord?id=CVE-2023-51775 Référence CVE CVE-2023-5676 https://www.cve.org/CVERecord?id=CVE-2023-5676 Référence CVE CVE-2023-7104 https://www.cve.org/CVERecord?id=CVE-2023-7104 Référence CVE CVE-2024-20918 https://www.cve.org/CVERecord?id=CVE-2024-20918 Référence CVE CVE-2024-20919 https://www.cve.org/CVERecord?id=CVE-2024-20919 Référence CVE CVE-2024-20921 https://www.cve.org/CVERecord?id=CVE-

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0958Multiples vulnérabilités dans les produits IBM

ord?id=CVE-2023-31356 Référence CVE CVE-2023-3446 https://www.cve.org/CVERecord?id=CVE-2023-3446 Référence CVE CVE-2023-36328 https://www.cve.org/CVERecord?id=CVE-2023-36328 Référence CVE CVE-2023-36632 https://www.cve.org/CVERecord?id=CVE-2023-36632 Référence CVE CVE-2023-37920 https://www.cve.org/CVERecord?id=CVE-2023-37920 Référence CVE CVE-2023-38325 https://www.cve.org/CVERecord?id=CVE-2023-38325 Référence CVE CVE-2023-38546 https://www.cve.org/CVERecord?id=CVE-2023-38546 Référence CVE CVE-2023-39325 https://www.cve.org/CVERecord?id=CVE-2023-39325 Référence CVE CVE-2023-42465 https://www.cve.org/CVERecord?id=CVE-2023-42465 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-45284 https://www.cve.org/CVERecord?id=CVE-2023-45284 Référence CVE CVE-2023-45288 https://www.cve.org/CVERecord?id=CVE-2023-45288 Référence CVE CVE-2023-46218 https://www.cve.org/CVERecord?id=CVE-2023-46218 Référence CVE CVE-2023-4692 https://www.cve.org/CVERecord?id=CVE-2023-4692 Référence CVE CVE-2023-4693 https://www.cve.org/CVERecord?id=CVE-2023-4693 Référence CVE CVE-2023-4807 https://www.cve.org/CVERecord?id=CVE-2023-4807 Référence CVE CVE-2023-48161 https://www.cve.org/CVERecord?id=CVE-2023-48161 Référence CVE CVE-2023-48795 https://www.cve.org/CVERecord?id=CVE-20

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0940Multiples vulnérabilités dans les produits Moxa

De multiples vulnérabilités ont été découvertes dans les produits Moxa. Certaines d'entre elles permettent à un attaquant de provoquer une atteinte à l'intégrité des données, une injection de code indirecte à distance (XSS) et un contournement de la politique de sécurité.

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0923Multiples vulnérabilités dans les produits IBM

d?id=CVE-2023-29262 Référence CVE CVE-2023-36479 https://www.cve.org/CVERecord?id=CVE-2023-36479 Référence CVE CVE-2023-38009 https://www.cve.org/CVERecord?id=CVE-2023-38009 Référence CVE CVE-2023-38264 https://www.cve.org/CVERecord?id=CVE-2023-38264 Référence CVE CVE-2023-38737 https://www.cve.org/CVERecord?id=CVE-2023-38737 Référence CVE CVE-2023-40167 https://www.cve.org/CVERecord?id=CVE-2023-40167 Référence CVE CVE-2023-41900 https://www.cve.org/CVERecord?id=CVE-2023-41900 Référence CVE CVE-2023-42282 https://www.cve.org/CVERecord?id=CVE-2023-42282 Référence CVE CVE-2023-44483 https://www.cve.org/CVERecord?id=CVE-2023-44483 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-45133 https://www.cve.org/CVERecord?id=CVE-2023-45133 Référence CVE CVE-2023-45145 https://www.cve.org/CVERecord?id=CVE-2023-45145 Référence CVE CVE-2023-46234 https://www.cve.org/CVERecord?id=CVE-2023-46234 Référence CVE CVE-2023-46809 https://www.cve.org/CVERecord?id=CVE-2023-46809 Référence CVE CVE-2023-50312 https://www.cve.org/CVERecord?id=CVE-2023-50312 Référence CVE CVE-2023-51775 https://www.cve.org/CVERecord?id=CVE-2023-51775 Référence CVE CVE-2023-52428 https://www.cve.org/CVERecord?id=CVE-2023-52428 Référence CVE CVE-2024-21011 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0878Multiples vulnérabilités dans les produits Splunk

ord?id=CVE-2023-39319 Référence CVE CVE-2023-39320 https://www.cve.org/CVERecord?id=CVE-2023-39320 Référence CVE CVE-2023-39321 https://www.cve.org/CVERecord?id=CVE-2023-39321 Référence CVE CVE-2023-39322 https://www.cve.org/CVERecord?id=CVE-2023-39322 Référence CVE CVE-2023-39323 https://www.cve.org/CVERecord?id=CVE-2023-39323 Référence CVE CVE-2023-39325 https://www.cve.org/CVERecord?id=CVE-2023-39325 Référence CVE CVE-2023-39326 https://www.cve.org/CVERecord?id=CVE-2023-39326 Référence CVE CVE-2023-3978 https://www.cve.org/CVERecord?id=CVE-2023-3978 Référence CVE CVE-2023-43804 https://www.cve.org/CVERecord?id=CVE-2023-43804 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-45142 https://www.cve.org/CVERecord?id=CVE-2023-45142 Référence CVE CVE-2023-45283 https://www.cve.org/CVERecord?id=CVE-2023-45283 Référence CVE CVE-2023-45284 https://www.cve.org/CVERecord?id=CVE-2023-45284 Référence CVE CVE-2023-45285 https://www.cve.org/CVERecord?id=CVE-2023-45285 Référence CVE CVE-2023-45288 https://www.cve.org/CVERecord?id=CVE-2023-45288 Référence CVE CVE-2023-45803 https://www.cve.org/CVERecord?id=CVE-2023-45803 Référence CVE CVE-2023-47108 https://www.cve.org/CVERecord?id=CVE-2023-47108 Référence CVE CVE-2023-48795 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0866Multiples vulnérabilités dans les produits Juniper Networks

/CVERecord?id=CVE-2023-0567 Référence CVE CVE-2023-0568 https://www.cve.org/CVERecord?id=CVE-2023-0568 Référence CVE CVE-2023-0662 https://www.cve.org/CVERecord?id=CVE-2023-0662 Référence CVE CVE-2023-31124 https://www.cve.org/CVERecord?id=CVE-2023-31124 Référence CVE CVE-2023-31130 https://www.cve.org/CVERecord?id=CVE-2023-31130 Référence CVE CVE-2023-31147 https://www.cve.org/CVERecord?id=CVE-2023-31147 Référence CVE CVE-2023-32067 https://www.cve.org/CVERecord?id=CVE-2023-32067 Référence CVE CVE-2023-3823 https://www.cve.org/CVERecord?id=CVE-2023-3823 Référence CVE CVE-2023-3824 https://www.cve.org/CVERecord?id=CVE-2023-3824 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-51385 https://www.cve.org/CVERecord?id=CVE-2023-51385 Référence CVE CVE-2024-2511 https://www.cve.org/CVERecord?id=CVE-2024-2511 Référence CVE CVE-2024-39515 https://www.cve.org/CVERecord?id=CVE-2024-39515 Référence CVE CVE-2024-39516 https://www.cve.org/CVERecord?id=CVE-2024-39516 Référence CVE CVE-2024-39525 https://www.cve.org/CVERecord?id=CVE-2024-39525 Référence CVE CVE-2024-39526 https://www.cve.org/CVERecord?id=CVE-2024-39526 Référence CVE CVE-2024-39527 https://www.cve.org/CVERecord?id=CVE-2024-39527 Référence CVE CVE-2024-39534 https://www.cve.org/CVERecord?id=CV

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0741Multiples vulnérabilités dans Juniper Secure Analytics

d?id=CVE-2023-38264 Référence CVE CVE-2023-39318 https://www.cve.org/CVERecord?id=CVE-2023-39318 Référence CVE CVE-2023-39319 https://www.cve.org/CVERecord?id=CVE-2023-39319 Référence CVE CVE-2023-39321 https://www.cve.org/CVERecord?id=CVE-2023-39321 Référence CVE CVE-2023-39322 https://www.cve.org/CVERecord?id=CVE-2023-39322 Référence CVE CVE-2023-39326 https://www.cve.org/CVERecord?id=CVE-2023-39326 Référence CVE CVE-2023-43788 https://www.cve.org/CVERecord?id=CVE-2023-43788 Référence CVE CVE-2023-43789 https://www.cve.org/CVERecord?id=CVE-2023-43789 Référence CVE CVE-2023-43804 https://www.cve.org/CVERecord?id=CVE-2023-43804 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-45287 https://www.cve.org/CVERecord?id=CVE-2023-45287 Référence CVE CVE-2023-45802 https://www.cve.org/CVERecord?id=CVE-2023-45802 Référence CVE CVE-2023-45803 https://www.cve.org/CVERecord?id=CVE-2023-45803 Référence CVE CVE-2023-4692 https://www.cve.org/CVERecord?id=CVE-2023-4692 Référence CVE CVE-2023-4693 https://www.cve.org/CVERecord?id=CVE-2023-4693 Référence CVE CVE-2023-48795 https://www.cve.org/CVERecord?id=CVE-2023-48795 Référence CVE CVE-2023-5090 https://www.cve.org/CVERecord?id=CVE-2023-5090 Référence CVE CVE-2023-52425 https://www.cve.org/CVERecord?id=CVE-20

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0713Multiples vulnérabilités dans les produits VMware

ord?id=CVE-2022-37434 Référence CVE CVE-2022-40735 https://www.cve.org/CVERecord?id=CVE-2022-40735 Référence CVE CVE-2022-48622 https://www.cve.org/CVERecord?id=CVE-2022-48622 Référence CVE CVE-2023-22655 https://www.cve.org/CVERecord?id=CVE-2023-22655 Référence CVE CVE-2023-28746 https://www.cve.org/CVERecord?id=CVE-2023-28746 Référence CVE CVE-2023-3164 https://www.cve.org/CVERecord?id=CVE-2023-3164 Référence CVE CVE-2023-38575 https://www.cve.org/CVERecord?id=CVE-2023-38575 Référence CVE CVE-2023-39368 https://www.cve.org/CVERecord?id=CVE-2023-39368 Référence CVE CVE-2023-43490 https://www.cve.org/CVERecord?id=CVE-2023-43490 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-45733 https://www.cve.org/CVERecord?id=CVE-2023-45733 Référence CVE CVE-2023-45745 https://www.cve.org/CVERecord?id=CVE-2023-45745 Référence CVE CVE-2023-46103 https://www.cve.org/CVERecord?id=CVE-2023-46103 Référence CVE CVE-2023-47855 https://www.cve.org/CVERecord?id=CVE-2023-47855 Référence CVE CVE-2023-50387 https://www.cve.org/CVERecord?id=CVE-2023-50387 Référence CVE CVE-2023-50868 https://www.cve.org/CVERecord?id=CVE-2023-50868 Référence CVE CVE-2023-7104 https://www.cve.org/CVERecord?id=CVE-2023-7104 Référence CVE CVE-2024-1013 https://www.cve.org/CVERecord?id=CVE

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0672Multiples vulnérabilités dans les produits Siemens

d?id=CVE-2023-31122 Référence CVE CVE-2023-34050 https://www.cve.org/CVERecord?id=CVE-2023-34050 Référence CVE CVE-2023-39615 https://www.cve.org/CVERecord?id=CVE-2023-39615 Référence CVE CVE-2023-42794 https://www.cve.org/CVERecord?id=CVE-2023-42794 Référence CVE CVE-2023-42795 https://www.cve.org/CVERecord?id=CVE-2023-42795 Référence CVE CVE-2023-43622 https://www.cve.org/CVERecord?id=CVE-2023-43622 Référence CVE CVE-2023-44317 https://www.cve.org/CVERecord?id=CVE-2023-44317 Référence CVE CVE-2023-44320 https://www.cve.org/CVERecord?id=CVE-2023-44320 Référence CVE CVE-2023-44321 https://www.cve.org/CVERecord?id=CVE-2023-44321 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-45648 https://www.cve.org/CVERecord?id=CVE-2023-45648 Référence CVE CVE-2023-45802 https://www.cve.org/CVERecord?id=CVE-2023-45802 Référence CVE CVE-2023-4611 https://www.cve.org/CVERecord?id=CVE-2023-4611 Référence CVE CVE-2023-46120 https://www.cve.org/CVERecord?id=CVE-2023-46120 Référence CVE CVE-2023-46280 https://www.cve.org/CVERecord?id=CVE-2023-46280 Référence CVE CVE-2023-46589 https://www.cve.org/CVERecord?id=CVE-2023-46589 Référence CVE CVE-2023-49692 https://www.cve.org/CVERecord?id=CVE-2023-49692 Référence CVE CVE-2023-5180 https://www.cve.org/CVERecord?id=CVE

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0579Multiples vulnérabilités dans les produits IBM

ecord?id=CVE-2021-41072 Référence CVE CVE-2022-3287 https://www.cve.org/CVERecord?id=CVE-2022-3287 Référence CVE CVE-2023-25193 https://www.cve.org/CVERecord?id=CVE-2023-25193 Référence CVE CVE-2023-29483 https://www.cve.org/CVERecord?id=CVE-2023-29483 Référence CVE CVE-2023-31122 https://www.cve.org/CVERecord?id=CVE-2023-31122 Référence CVE CVE-2023-31484 https://www.cve.org/CVERecord?id=CVE-2023-31484 Référence CVE CVE-2023-3635 https://www.cve.org/CVERecord?id=CVE-2023-3635 Référence CVE CVE-2023-43804 https://www.cve.org/CVERecord?id=CVE-2023-43804 Référence CVE CVE-2023-44483 https://www.cve.org/CVERecord?id=CVE-2023-44483 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-45802 https://www.cve.org/CVERecord?id=CVE-2023-45802 Référence CVE CVE-2023-45803 https://www.cve.org/CVERecord?id=CVE-2023-45803 Référence CVE CVE-2023-46158 https://www.cve.org/CVERecord?id=CVE-2023-46158 Référence CVE CVE-2023-50312 https://www.cve.org/CVERecord?id=CVE-2023-50312 Référence CVE CVE-2023-51775 https://www.cve.org/CVERecord?id=CVE-2023-51775 Référence CVE CVE-2023-5752 https://www.cve.org/CVERecord?id=CVE-2023-5752 Référence CVE CVE-2023-6004 https://www.cve.org/CVERecord?id=CVE-2023-6004 Référence CVE CVE-2023-6597 https://www.cve.org/CVERecord?id=CVE-2

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0478Multiples vulnérabilités dans les produits Siemens

d?id=CVE-2023-38380 Référence CVE CVE-2023-38533 https://www.cve.org/CVERecord?id=CVE-2023-38533 Référence CVE CVE-2023-39615 https://www.cve.org/CVERecord?id=CVE-2023-39615 Référence CVE CVE-2023-41910 https://www.cve.org/CVERecord?id=CVE-2023-41910 Référence CVE CVE-2023-44317 https://www.cve.org/CVERecord?id=CVE-2023-44317 Référence CVE CVE-2023-44318 https://www.cve.org/CVERecord?id=CVE-2023-44318 Référence CVE CVE-2023-44319 https://www.cve.org/CVERecord?id=CVE-2023-44319 Référence CVE CVE-2023-44373 https://www.cve.org/CVERecord?id=CVE-2023-44373 Référence CVE CVE-2023-44374 https://www.cve.org/CVERecord?id=CVE-2023-44374 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-49691 https://www.cve.org/CVERecord?id=CVE-2023-49691 Référence CVE CVE-2023-50763 https://www.cve.org/CVERecord?id=CVE-2023-50763 Référence CVE CVE-2023-52474 https://www.cve.org/CVERecord?id=CVE-2023-52474 Référence CVE CVE-2023-5678 https://www.cve.org/CVERecord?id=CVE-2023-5678 Référence CVE CVE-2024-0775 https://www.cve.org/CVERecord?id=CVE-2024-0775 Référence CVE CVE-2024-26275 https://www.cve.org/CVERecord?id=CVE-2024-26275 Référence CVE CVE-2024-26276 https://www.cve.org/CVERecord?id=CVE-2024-26276 Référence CVE CVE-2024-26277 https://www.cve.org/CVERecord?id=CVE-

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0385Multiples vulnérabilités dans les produits IBM

org/CVERecord?id=CVE-2023-40283 Référence CVE CVE-2023-4128 https://www.cve.org/CVERecord?id=CVE-2023-4128 Référence CVE CVE-2023-4132 https://www.cve.org/CVERecord?id=CVE-2023-4132 Référence CVE CVE-2023-4155 https://www.cve.org/CVERecord?id=CVE-2023-4155 Référence CVE CVE-2023-4206 https://www.cve.org/CVERecord?id=CVE-2023-4206 Référence CVE CVE-2023-4207 https://www.cve.org/CVERecord?id=CVE-2023-4207 Référence CVE CVE-2023-4208 https://www.cve.org/CVERecord?id=CVE-2023-4208 Référence CVE CVE-2023-42753 https://www.cve.org/CVERecord?id=CVE-2023-42753 Référence CVE CVE-2023-43804 https://www.cve.org/CVERecord?id=CVE-2023-43804 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-44794 https://www.cve.org/CVERecord?id=CVE-2023-44794 Référence CVE CVE-2023-45803 https://www.cve.org/CVERecord?id=CVE-2023-45803 Référence CVE CVE-2023-45862 https://www.cve.org/CVERecord?id=CVE-2023-45862 Référence CVE CVE-2023-45871 https://www.cve.org/CVERecord?id=CVE-2023-45871 Référence CVE CVE-2023-46218 https://www.cve.org/CVERecord?id=CVE-2023-46218 Référence CVE CVE-2023-4622 https://www.cve.org/CVERecord?id=CVE-2023-4622 Référence CVE CVE-2023-4623 https://www.cve.org/CVERecord?id=CVE-2023-4623 Référence CVE CVE-2023-46813 https://www.cve.org/CVERecord?id=CVE-

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0366Multiples vulnérabilités dans les produits IBM

d?id=CVE-2023-28642 Référence CVE CVE-2023-28840 https://www.cve.org/CVERecord?id=CVE-2023-28840 Référence CVE CVE-2023-28841 https://www.cve.org/CVERecord?id=CVE-2023-28841 Référence CVE CVE-2023-28842 https://www.cve.org/CVERecord?id=CVE-2023-28842 Référence CVE CVE-2023-30861 https://www.cve.org/CVERecord?id=CVE-2023-30861 Référence CVE CVE-2023-31484 https://www.cve.org/CVERecord?id=CVE-2023-31484 Référence CVE CVE-2023-32681 https://www.cve.org/CVERecord?id=CVE-2023-32681 Référence CVE CVE-2023-34462 https://www.cve.org/CVERecord?id=CVE-2023-34462 Référence CVE CVE-2023-44270 https://www.cve.org/CVERecord?id=CVE-2023-44270 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-44981 https://www.cve.org/CVERecord?id=CVE-2023-44981 Référence CVE CVE-2023-45857 https://www.cve.org/CVERecord?id=CVE-2023-45857 Référence CVE CVE-2023-46136 https://www.cve.org/CVERecord?id=CVE-2023-46136 Référence CVE CVE-2023-5072 https://www.cve.org/CVERecord?id=CVE-2023-5072 Référence CVE CVE-2024-1135 https://www.cve.org/CVERecord?id=CVE-2024-1135 Référence CVE CVE-2024-21334 https://www.cve.org/CVERecord?id=CVE-2024-21334 Référence CVE CVE-2024-21501 https://www.cve.org/CVERecord?id=CVE-2024-21501 Référence CVE CVE-2024-21503 https://www.cve.org/CVERecord?id=CVE-

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0323Multiples vulnérabilités dans Oracle Weblogic

De multiples vulnérabilités ont été découvertes dans Oracle Weblogic. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à l'intégrité des données.

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0326Multiples vulnérabilités dans Oracle MySQL

niers correctifs de sécurité Résumé De multiples vulnérabilités ont été découvertes dans Oracle MySQL. Elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à l'intégrité des données et une atteinte à la confidentialité des données. Solution Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation). Documentation Bulletin de sécurité Oracle cpuapr2024 du 16 avril 2024 https://www.oracle.com/security-alerts/cpuapr2024.html Bulletin de sécurité Oracle cpuapr2024verbose du 16 avril 2024 https://www.oracle.com/security-alerts/cpuapr2024verbose.html Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-5678 https://www.cve.org/CVERecord?id=CVE-2023-5678 Référence CVE CVE-2023-6129 https://www.cve.org/CVERecord?id=CVE-2023-6129 Référence CVE CVE-2024-0727 https://www.cve.org/CVERecord?id=CVE-2024-0727 Référence CVE CVE-2024-0853 https://www.cve.org/CVERecord?id=CVE-2024-0853 Référence CVE CVE-2024-20993 https://www.cve.org/CVERecord?id=CVE-2024-20993 Référence CVE CVE-2024-20994 https://www.cve.org/CVERecord?id=CVE-2024-20994 Référence CVE CVE-2024-20998 https://www.cve.org/CVERecord?id=CVE-2024-20998 Référence CVE CVE-2024-21000 https://www.cve.org/CVERecord?id=CVE-2024

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0322Multiples vulnérabilités dans Oracle Database Server

2024verbose.html#DB Référence CVE CVE-2022-34169 https://www.cve.org/CVERecord?id=CVE-2022-34169 Référence CVE CVE-2022-34381 https://www.cve.org/CVERecord?id=CVE-2022-34381 Référence CVE CVE-2023-28823 https://www.cve.org/CVERecord?id=CVE-2023-28823 Référence CVE CVE-2023-36632 https://www.cve.org/CVERecord?id=CVE-2023-36632 Référence CVE CVE-2023-39975 https://www.cve.org/CVERecord?id=CVE-2023-39975 Référence CVE CVE-2023-40217 https://www.cve.org/CVERecord?id=CVE-2023-40217 Référence CVE CVE-2023-41105 https://www.cve.org/CVERecord?id=CVE-2023-41105 Référence CVE CVE-2023-42503 https://www.cve.org/CVERecord?id=CVE-2023-42503 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-47038 https://www.cve.org/CVERecord?id=CVE-2023-47038 Référence CVE CVE-2023-48795 https://www.cve.org/CVERecord?id=CVE-2023-48795 Référence CVE CVE-2023-49083 https://www.cve.org/CVERecord?id=CVE-2023-49083 Référence CVE CVE-2023-5072 https://www.cve.org/CVERecord?id=CVE-2023-5072 Référence CVE CVE-2024-20918 https://www.cve.org/CVERecord?id=CVE-2024-20918 Référence CVE CVE-2024-20919 https://www.cve.org/CVERecord?id=CVE-2024-20919 Référence CVE CVE-2024-20921 https://www.cve.org/CVERecord?id=CVE-2024-20921 Référence CVE CVE-2024-20922 https://www.cve.org/CVERecord?id=CV

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0297Multiples vulnérabilités dans Juniper

ord?id=CVE-2023-36054 Référence CVE CVE-2023-38408 https://www.cve.org/CVERecord?id=CVE-2023-38408 Référence CVE CVE-2023-38545 https://www.cve.org/CVERecord?id=CVE-2023-38545 Référence CVE CVE-2023-38546 https://www.cve.org/CVERecord?id=CVE-2023-38546 Référence CVE CVE-2023-3978 https://www.cve.org/CVERecord?id=CVE-2023-3978 Référence CVE CVE-2023-39975 https://www.cve.org/CVERecord?id=CVE-2023-39975 Référence CVE CVE-2023-40217 https://www.cve.org/CVERecord?id=CVE-2023-40217 Référence CVE CVE-2023-41913 https://www.cve.org/CVERecord?id=CVE-2023-41913 Référence CVE CVE-2023-43804 https://www.cve.org/CVERecord?id=CVE-2023-43804 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-46218 https://www.cve.org/CVERecord?id=CVE-2023-46218 Référence CVE CVE-2023-4785 https://www.cve.org/CVERecord?id=CVE-2023-4785 Référence CVE CVE-2023-4806 https://www.cve.org/CVERecord?id=CVE-2023-4806 Référence CVE CVE-2023-4807 https://www.cve.org/CVERecord?id=CVE-2023-4807 Référence CVE CVE-2023-48795 https://www.cve.org/CVERecord?id=CVE-2023-48795 Référence CVE CVE-2023-49083 https://www.cve.org/CVERecord?id=CVE-2023-49083 Référence CVE CVE-2023-5156 https://www.cve.org/CVERecord?id=CVE-2023-5156 Référence CVE CVE-2023-5981 https://www.cve.org/CVERecord?id=CVE-2023-

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0279Multiples vulnérabilités dans les produits IBM

De multiples vulnérabilités ont été découvertes dans les produits IBM . Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à l'intégrité des données et une atteinte à la confidentialité des données.

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0228Multiples vulnérabilités dans IBM

d?id=CVE-2023-34454 Référence CVE CVE-2023-34455 https://www.cve.org/CVERecord?id=CVE-2023-34455 Référence CVE CVE-2023-36478 https://www.cve.org/CVERecord?id=CVE-2023-36478 Référence CVE CVE-2023-36479 https://www.cve.org/CVERecord?id=CVE-2023-36479 Référence CVE CVE-2023-38039 https://www.cve.org/CVERecord?id=CVE-2023-38039 Référence CVE CVE-2023-39685 https://www.cve.org/CVERecord?id=CVE-2023-39685 Référence CVE CVE-2023-40167 https://www.cve.org/CVERecord?id=CVE-2023-40167 Référence CVE CVE-2023-41900 https://www.cve.org/CVERecord?id=CVE-2023-41900 Référence CVE CVE-2023-43642 https://www.cve.org/CVERecord?id=CVE-2023-43642 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-44981 https://www.cve.org/CVERecord?id=CVE-2023-44981 Référence CVE CVE-2023-45177 https://www.cve.org/CVERecord?id=CVE-2023-45177 Référence CVE CVE-2023-46179 https://www.cve.org/CVERecord?id=CVE-2023-46179 Référence CVE CVE-2023-46181 https://www.cve.org/CVERecord?id=CVE-2023-46181 Référence CVE CVE-2023-46182 https://www.cve.org/CVERecord?id=CVE-2023-46182 Référence CVE CVE-2023-46604 https://www.cve.org/CVERecord?id=CVE-2023-46604 Référence CVE CVE-2023-47147 https://www.cve.org/CVERecord?id=CVE-2023-47147 Référence CVE CVE-2023-47162 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0209Multiples vulnérabilités dans les produits SAP

De multiples vulnérabilités ont été découvertes dans les produits SAP . Certaines d'entre elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données et une exécution de code arbitraire à distance et un déni de service à distance.

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0203Multiples vulnérabilités dans les produits Siemens

d?id=CVE-2023-36639 Référence CVE CVE-2023-36641 https://www.cve.org/CVERecord?id=CVE-2023-36641 Référence CVE CVE-2023-37935 https://www.cve.org/CVERecord?id=CVE-2023-37935 Référence CVE CVE-2023-38545 https://www.cve.org/CVERecord?id=CVE-2023-38545 Référence CVE CVE-2023-38546 https://www.cve.org/CVERecord?id=CVE-2023-38546 Référence CVE CVE-2023-40718 https://www.cve.org/CVERecord?id=CVE-2023-40718 Référence CVE CVE-2023-41675 https://www.cve.org/CVERecord?id=CVE-2023-41675 Référence CVE CVE-2023-41841 https://www.cve.org/CVERecord?id=CVE-2023-41841 Référence CVE CVE-2023-44250 https://www.cve.org/CVERecord?id=CVE-2023-44250 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-45793 https://www.cve.org/CVERecord?id=CVE-2023-45793 Référence CVE CVE-2023-47537 https://www.cve.org/CVERecord?id=CVE-2023-47537 Référence CVE CVE-2023-49125 https://www.cve.org/CVERecord?id=CVE-2023-49125 Référence CVE CVE-2024-21483 https://www.cve.org/CVERecord?id=CVE-2024-21483 Référence CVE CVE-2024-21762 https://www.cve.org/CVERecord?id=CVE-2024-21762 Référence CVE CVE-2024-22039 https://www.cve.org/CVERecord?id=CVE-2024-22039 Référence CVE CVE-2024-22040 https://www.cve.org/CVERecord?id=CVE-2024-22040 Référence CVE CVE-2024-22041 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0199Multiples vulnérabilités dans IBM

d?id=CVE-2023-33850 Référence CVE CVE-2023-34478 https://www.cve.org/CVERecord?id=CVE-2023-34478 Référence CVE CVE-2023-36478 https://www.cve.org/CVERecord?id=CVE-2023-36478 Référence CVE CVE-2023-36479 https://www.cve.org/CVERecord?id=CVE-2023-36479 Référence CVE CVE-2023-39325 https://www.cve.org/CVERecord?id=CVE-2023-39325 Référence CVE CVE-2023-40167 https://www.cve.org/CVERecord?id=CVE-2023-40167 Référence CVE CVE-2023-40743 https://www.cve.org/CVERecord?id=CVE-2023-40743 Référence CVE CVE-2023-41900 https://www.cve.org/CVERecord?id=CVE-2023-41900 Référence CVE CVE-2023-42282 https://www.cve.org/CVERecord?id=CVE-2023-42282 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-45857 https://www.cve.org/CVERecord?id=CVE-2023-45857 Référence CVE CVE-2023-47248 https://www.cve.org/CVERecord?id=CVE-2023-47248 Référence CVE CVE-2023-5676 https://www.cve.org/CVERecord?id=CVE-2023-5676 Référence CVE CVE-2024-20918 https://www.cve.org/CVERecord?id=CVE-2024-20918 Référence CVE CVE-2024-20921 https://www.cve.org/CVERecord?id=CVE-2024-20921 Référence CVE CVE-2024-20945 https://www.cve.org/CVERecord?id=CVE-2024-20945 Référence CVE CVE-2024-20952 https://www.cve.org/CVERecord?id=CVE-2024-20952 Référence CVE CVE-2024-23334 https://www.cve.org/CVERecord?id=CV

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0180Multiples vulnérabilités dans les produits IBM

ecord?id=CVE-2023-30589 Référence CVE CVE-2023-30996 https://www.cve.org/CVERecord?id=CVE-2023-30996 Référence CVE CVE-2023-32344 https://www.cve.org/CVERecord?id=CVE-2023-32344 Référence CVE CVE-2023-3446 https://www.cve.org/CVERecord?id=CVE-2023-3446 Référence CVE CVE-2023-36478 https://www.cve.org/CVERecord?id=CVE-2023-36478 Référence CVE CVE-2023-3817 https://www.cve.org/CVERecord?id=CVE-2023-3817 Référence CVE CVE-2023-38359 https://www.cve.org/CVERecord?id=CVE-2023-38359 Référence CVE CVE-2023-39410 https://www.cve.org/CVERecord?id=CVE-2023-39410 Référence CVE CVE-2023-43051 https://www.cve.org/CVERecord?id=CVE-2023-43051 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-45133 https://www.cve.org/CVERecord?id=CVE-2023-45133 Référence CVE CVE-2023-45857 https://www.cve.org/CVERecord?id=CVE-2023-45857 Référence CVE CVE-2023-46158 https://www.cve.org/CVERecord?id=CVE-2023-46158 Référence CVE CVE-2023-46234 https://www.cve.org/CVERecord?id=CVE-2023-46234 Référence CVE CVE-2023-46604 https://www.cve.org/CVERecord?id=CVE-2023-46604 Référence CVE CVE-2023-48795 https://www.cve.org/CVERecord?id=CVE-2023-48795 Référence CVE CVE-2023-50324 https://www.cve.org/CVERecord?id=CVE-2023-50324 Référence CVE CVE-2023-51384 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0156Multiples vulnérabilités dans les produits Tenable

d?id=CVE-2023-31124 Référence CVE CVE-2023-31130 https://www.cve.org/CVERecord?id=CVE-2023-31130 Référence CVE CVE-2023-31147 https://www.cve.org/CVERecord?id=CVE-2023-31147 Référence CVE CVE-2023-32067 https://www.cve.org/CVERecord?id=CVE-2023-32067 Référence CVE CVE-2023-35941 https://www.cve.org/CVERecord?id=CVE-2023-35941 Référence CVE CVE-2023-35942 https://www.cve.org/CVERecord?id=CVE-2023-35942 Référence CVE CVE-2023-35943 https://www.cve.org/CVERecord?id=CVE-2023-35943 Référence CVE CVE-2023-35944 https://www.cve.org/CVERecord?id=CVE-2023-35944 Référence CVE CVE-2023-35945 https://www.cve.org/CVERecord?id=CVE-2023-35945 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2024-0057 https://www.cve.org/CVERecord?id=CVE-2024-0057 Référence CVE CVE-2024-1683 https://www.cve.org/CVERecord?id=CVE-2024-1683 Référence CVE CVE-2024-20672 https://www.cve.org/CVERecord?id=CVE-2024-20672 Référence CVE CVE-2024-23322 https://www.cve.org/CVERecord?id=CVE-2024-23322 Référence CVE CVE-2024-23323 https://www.cve.org/CVERecord?id=CVE-2024-23323 Référence CVE CVE-2024-23324 https://www.cve.org/CVERecord?id=CVE-2024-23324 Référence CVE CVE-2024-23325 https://www.cve.org/CVERecord?id=CVE-2024-23325 Référence CVE CVE-2024-23327 https://www.cve.org/CVERecord?id=CVE-

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0145Multiples vulnérabilités dans les produits IBM

CVERecord?id=CVE-2023-40692 Référence CVE CVE-2023-4128 https://www.cve.org/CVERecord?id=CVE-2023-4128 Référence CVE CVE-2023-4206 https://www.cve.org/CVERecord?id=CVE-2023-4206 Référence CVE CVE-2023-4207 https://www.cve.org/CVERecord?id=CVE-2023-4207 Référence CVE CVE-2023-4208 https://www.cve.org/CVERecord?id=CVE-2023-4208 Référence CVE CVE-2023-42795 https://www.cve.org/CVERecord?id=CVE-2023-42795 Référence CVE CVE-2023-43020 https://www.cve.org/CVERecord?id=CVE-2023-43020 Référence CVE CVE-2023-43642 https://www.cve.org/CVERecord?id=CVE-2023-43642 Référence CVE CVE-2023-44270 https://www.cve.org/CVERecord?id=CVE-2023-44270 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-44981 https://www.cve.org/CVERecord?id=CVE-2023-44981 Référence CVE CVE-2023-45133 https://www.cve.org/CVERecord?id=CVE-2023-45133 Référence CVE CVE-2023-45142 https://www.cve.org/CVERecord?id=CVE-2023-45142 Référence CVE CVE-2023-45178 https://www.cve.org/CVERecord?id=CVE-2023-45178 Référence CVE CVE-2023-45193 https://www.cve.org/CVERecord?id=CVE-2023-45193 Référence CVE CVE-2023-45648 https://www.cve.org/CVERecord?id=CVE-2023-45648 Référence CVE CVE-2023-45803 https://www.cve.org/CVERecord?id=CVE-2023-45803 Référence CVE CVE-2023-45857 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0113Multiples vulnérabilités dans les produits IBM

d?id=CVE-2023-34396 Référence CVE CVE-2023-34453 https://www.cve.org/CVERecord?id=CVE-2023-34453 Référence CVE CVE-2023-34454 https://www.cve.org/CVERecord?id=CVE-2023-34454 Référence CVE CVE-2023-34455 https://www.cve.org/CVERecord?id=CVE-2023-34455 Référence CVE CVE-2023-34462 https://www.cve.org/CVERecord?id=CVE-2023-34462 Référence CVE CVE-2023-36478 https://www.cve.org/CVERecord?id=CVE-2023-36478 Référence CVE CVE-2023-36479 https://www.cve.org/CVERecord?id=CVE-2023-36479 Référence CVE CVE-2023-40167 https://www.cve.org/CVERecord?id=CVE-2023-40167 Référence CVE CVE-2023-41900 https://www.cve.org/CVERecord?id=CVE-2023-41900 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-46308 https://www.cve.org/CVERecord?id=CVE-2023-46308 Référence CVE CVE-2023-46849 https://www.cve.org/CVERecord?id=CVE-2023-46849 Référence CVE CVE-2023-46850 https://www.cve.org/CVERecord?id=CVE-2023-46850 Référence CVE CVE-2023-4807 https://www.cve.org/CVERecord?id=CVE-2023-4807 Référence CVE CVE-2023-5363 https://www.cve.org/CVERecord?id=CVE-2023-5363 Référence CVE CVE-2023-5676 https://www.cve.org/CVERecord?id=CVE-2023-5676 Gestion détaillée du document le 09 février 2024 Version initiale Alertes Avis Bulletins d’actualités Mentions légales Conditions générales À pro

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0108Multiples vulnérabilités dans les produits Fortinet

De multiples vulnérabilités ont été découvertes dans les produits Fortinet . Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et un contournement de la politique de sécurité.

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0074Multiples vulnérabilités dans les produits IBM

De multiples vulnérabilités ont été découvertes dans les produits IBM . Certaines d'entre elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur, une exécution de code arbitraire à distance et un déni de service à distance.

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0057Multiples vulnérabilités dans les produits IBM

De multiples vulnérabilités ont été découvertes dans les produits IBM . Certaines d'entre elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur, une exécution de code arbitraire à distance et un déni de service à distance.

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0047Multiples vulnérabilités dans Oracle PeopleSoft

De multiples vulnérabilités ont été découvertes dans Oracle PeopleSoft. Elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à l'intégrité des données et une atteinte à la confidentialité des données.

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0046Multiples vulnérabilités dans Oracle Java SE

De multiples vulnérabilités ont été découvertes dans Oracle Java SE. Elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à l'intégrité des données et une atteinte à la confidentialité des données.

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0031Multiples vulnérabilités dans les produits IBM

d?id=CVE-2021-37137 Référence CVE CVE-2021-38153 https://www.cve.org/CVERecord?id=CVE-2021-38153 Référence CVE CVE-2021-43797 https://www.cve.org/CVERecord?id=CVE-2021-43797 Référence CVE CVE-2023-22036 https://www.cve.org/CVERecord?id=CVE-2023-22036 Référence CVE CVE-2023-22049 https://www.cve.org/CVERecord?id=CVE-2023-22049 Référence CVE CVE-2023-36478 https://www.cve.org/CVERecord?id=CVE-2023-36478 Référence CVE CVE-2023-36479 https://www.cve.org/CVERecord?id=CVE-2023-36479 Référence CVE CVE-2023-40167 https://www.cve.org/CVERecord?id=CVE-2023-40167 Référence CVE CVE-2023-41900 https://www.cve.org/CVERecord?id=CVE-2023-41900 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-47145 https://www.cve.org/CVERecord?id=CVE-2023-47145 Gestion détaillée du document le 12 janvier 2024 Version initiale Alertes Avis Bulletins d’actualités Mentions légales Conditions générales À propos Contact cyber.gouv.fr service-public.fr legifrance.gouv.fr info.gouv.fr france.fr info.gouv.fr/risques Premier Ministre / Secrétariat Général de la Défense et de la Sécurité Nationale / Agence nationale de la sécurité des systèmes d'information

Official advisory ↗
CERT-FR · French · CERTFR-2024-AVI-0018Multiples vulnérabilités dans les produits SAP

De multiples vulnérabilités ont été découvertes dans les produits SAP. Certaines d'entre elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur, une exécution de code arbitraire à distance et un déni de service à distance.

Official advisory ↗
CERT-FR · French · CERTFR-2023-AVI-1062Multiples vulnérabilités dans Juniper Secure Analytics

De multiples vulnérabilités ont été découvertes dans Juniper Secure Analytics. Certaines d'entre elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur, une exécution de code arbitraire à distance et un déni de service à distance.

Official advisory ↗
CERT-FR · French · CERTFR-2023-AVI-1055Multiples vulnérabilités dans les produits IBM

d?id=CVE-2023-36478 Référence CVE CVE-2023-36479 https://www.cve.org/CVERecord?id=CVE-2023-36479 Référence CVE CVE-2023-37920 https://www.cve.org/CVERecord?id=CVE-2023-37920 Référence CVE CVE-2023-40167 https://www.cve.org/CVERecord?id=CVE-2023-40167 Référence CVE CVE-2023-40787 https://www.cve.org/CVERecord?id=CVE-2023-40787 Référence CVE CVE-2023-41080 https://www.cve.org/CVERecord?id=CVE-2023-41080 Référence CVE CVE-2023-41835 https://www.cve.org/CVERecord?id=CVE-2023-41835 Référence CVE CVE-2023-42795 https://www.cve.org/CVERecord?id=CVE-2023-42795 Référence CVE CVE-2023-43804 https://www.cve.org/CVERecord?id=CVE-2023-43804 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-45648 https://www.cve.org/CVERecord?id=CVE-2023-45648 Référence CVE CVE-2023-46589 https://www.cve.org/CVERecord?id=CVE-2023-46589 Référence CVE CVE-2023-46604 https://www.cve.org/CVERecord?id=CVE-2023-46604 Référence CVE CVE-2023-47146 https://www.cve.org/CVERecord?id=CVE-2023-47146 Gestion détaillée du document le 22 décembre 2023 Version initiale Alertes Avis Bulletins d’actualités Mentions légales Conditions générales À propos Contact cyber.gouv.fr service-public.fr legifrance.gouv.fr info.gouv.fr france.fr info.gouv.fr/risques Premier Ministre / Secrétariat Général d

Official advisory ↗
CERT-FR · French · CERTFR-2023-AVI-1015Multiples vulnérabilités dans les produits Siemens

d?id=CVE-2023-42755 Référence CVE CVE-2023-44317 https://www.cve.org/CVERecord?id=CVE-2023-44317 Référence CVE CVE-2023-44318 https://www.cve.org/CVERecord?id=CVE-2023-44318 Référence CVE CVE-2023-44319 https://www.cve.org/CVERecord?id=CVE-2023-44319 Référence CVE CVE-2023-44320 https://www.cve.org/CVERecord?id=CVE-2023-44320 Référence CVE CVE-2023-44321 https://www.cve.org/CVERecord?id=CVE-2023-44321 Référence CVE CVE-2023-44322 https://www.cve.org/CVERecord?id=CVE-2023-44322 Référence CVE CVE-2023-44373 https://www.cve.org/CVERecord?id=CVE-2023-44373 Référence CVE CVE-2023-44374 https://www.cve.org/CVERecord?id=CVE-2023-44374 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-4527 https://www.cve.org/CVERecord?id=CVE-2023-4527 Référence CVE CVE-2023-45322 https://www.cve.org/CVERecord?id=CVE-2023-45322 Référence CVE CVE-2023-45853 https://www.cve.org/CVERecord?id=CVE-2023-45853 Référence CVE CVE-2023-45871 https://www.cve.org/CVERecord?id=CVE-2023-45871 Référence CVE CVE-2023-46156 https://www.cve.org/CVERecord?id=CVE-2023-46156 Référence CVE CVE-2023-4623 https://www.cve.org/CVERecord?id=CVE-2023-4623 Référence CVE CVE-2023-46281 https://www.cve.org/CVERecord?id=CVE-2023-46281 Référence CVE CVE-2023-46282 https://www.cve.org/CVERecord?id=CVE-

Official advisory ↗
CERT-FR · French · CERTFR-2023-AVI-0976Multiples vulnérabilités dans les produits IBM

ord?id=CVE-2022-48303 Référence CVE CVE-2023-1255 https://www.cve.org/CVERecord?id=CVE-2023-1255 Référence CVE CVE-2023-24998 https://www.cve.org/CVERecord?id=CVE-2023-24998 Référence CVE CVE-2023-26279 https://www.cve.org/CVERecord?id=CVE-2023-26279 Référence CVE CVE-2023-32001 https://www.cve.org/CVERecord?id=CVE-2023-32001 Référence CVE CVE-2023-34104 https://www.cve.org/CVERecord?id=CVE-2023-34104 Référence CVE CVE-2023-36478 https://www.cve.org/CVERecord?id=CVE-2023-36478 Référence CVE CVE-2023-38039 https://www.cve.org/CVERecord?id=CVE-2023-38039 Référence CVE CVE-2023-41080 https://www.cve.org/CVERecord?id=CVE-2023-41080 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Gestion détaillée du document le 23 novembre 2023 Version initiale Alertes Avis Bulletins d’actualités Mentions légales Conditions générales À propos Contact cyber.gouv.fr service-public.fr legifrance.gouv.fr info.gouv.fr france.fr info.gouv.fr/risques Premier Ministre / Secrétariat Général de la Défense et de la Sécurité Nationale / Agence nationale de la sécurité des systèmes d'information

Official advisory ↗
CERT-FR · French · CERTFR-2023-AVI-0963Vulnérabilité dans les produits Cisco

Une vulnérabilité a été découverte dans les produits Cisco . Elle permet à un attaquant de provoquer un déni de service à distance.

Official advisory ↗
CERT-FR · French · CERTFR-2023-AVI-0958Multiples vulnérabilités dans IBM

De multiples vulnérabilités ont été découvertes dans les produits IBM . Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité des données et une exécution de code arbitraire à distance.

Official advisory ↗
CERT-FR · French · CERTFR-2023-AVI-0957Multiples vulnérabilités dans le noyau Linux de RedHat

.org/CVERecord?id=CVE-2023-3776 Référence CVE CVE-2023-38545 https://www.cve.org/CVERecord?id=CVE-2023-38545 Référence CVE CVE-2023-38546 https://www.cve.org/CVERecord?id=CVE-2023-38546 Référence CVE CVE-2023-4128 https://www.cve.org/CVERecord?id=CVE-2023-4128 Référence CVE CVE-2023-4132 https://www.cve.org/CVERecord?id=CVE-2023-4132 Référence CVE CVE-2023-4155 https://www.cve.org/CVERecord?id=CVE-2023-4155 Référence CVE CVE-2023-4206 https://www.cve.org/CVERecord?id=CVE-2023-4206 Référence CVE CVE-2023-4207 https://www.cve.org/CVERecord?id=CVE-2023-4207 Référence CVE CVE-2023-4208 https://www.cve.org/CVERecord?id=CVE-2023-4208 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-4527 https://www.cve.org/CVERecord?id=CVE-2023-4527 Référence CVE CVE-2023-4732 https://www.cve.org/CVERecord?id=CVE-2023-4732 Référence CVE CVE-2023-4806 https://www.cve.org/CVERecord?id=CVE-2023-4806 Référence CVE CVE-2023-4813 https://www.cve.org/CVERecord?id=CVE-2023-4813 Référence CVE CVE-2023-4911 https://www.cve.org/CVERecord?id=CVE-2023-4911 Gestion détaillée du document le 17 novembre 2023 Version initiale Alertes Avis Bulletins d’actualités Mentions légales Conditions générales À propos Contact cyber.gouv.fr service-public.fr legifrance.gouv.fr info.gouv.fr fran

Official advisory ↗
CERT-FR · French · CERTFR-2023-AVI-0905Multiples vulnérabilités dans GitLab

De multiples vulnérabilités ont été découvertes dans GitLab. Elles permettent à un attaquant de provoquer un déni de service à distance, un contournement de la politique de sécurité et une atteinte à la confidentialité des données.

Official advisory ↗
CERT-FR · French · CERTFR-2023-AVI-0886Multiples vulnérabilités dans Tenable Identity Exposure

De multiples vulnérabilités ont été découvertes dans Tenable Identity Exposure. Certaines d'entre elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur, une exécution de code arbitraire à distance et un déni de service à distance.

Official advisory ↗
CERT-FR · French · CERTFR-2023-AVI-0843Vulnérabilité dans les produits Symantec

Une vulnérabilité a été découverte dans les produits Symantec . Elle permet à un attaquant de provoquer un déni de service à distance.

Official advisory ↗
CERT-FR · French · CERTFR-2023-AVI-0837Multiples vulnérabilités dans les produits F5

De multiples vulnérabilités ont été découvertes dans les produits F5. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et un contournement de la politique de sécurité.

Official advisory ↗
CERT-FR · French · CERTFR-2023-AVI-0832Multiples vulnérabilités dans Apache Tomcat

De multiples vulnérabilités ont été découvertes dans les produits Apache Tomcat . Elles permettent à un attaquant de provoquer un contournement de la politique de sécurité, une atteinte à la confidentialité des données et un déni de service à distance.

Official advisory ↗
CERT-FR · French · CERTFR-2023-AVI-0830Multiples vulnérabilités dans les produits Microsoft

De multiples vulnérabilités ont été corrigées dans les produits Microsoft . Elles permettent à un attaquant de provoquer une élévation de privilèges, une usurpation d'identité, une exécution de code à distance, un déni de service et une atteinte à la confidentialité des données.

Official advisory ↗
CERT-FR · French · CERTFR-2023-AVI-0828Multiples vulnérabilités dans Microsoft .Net

De multiples vulnérabilités ont été corrigées dans Microsoft .Net . Elles permettent à un attaquant de provoquer un déni de service.

Official advisory ↗
CERT-FR · French · CERTFR-2023-AVI-0827Multiples vulnérabilités dans Microsoft Windows

octobre 2023 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-41770 Bulletin de sécurité Microsoft CVE-2023-41771 du 10 octobre 2023 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-41771 Bulletin de sécurité Microsoft CVE-2023-41772 du 10 octobre 2023 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-41772 Bulletin de sécurité Microsoft CVE-2023-41773 du 10 octobre 2023 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-41773 Bulletin de sécurité Microsoft CVE-2023-41774 du 10 octobre 2023 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-41774 Bulletin de sécurité Microsoft CVE-2023-44487 du 10 octobre 2023 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-44487 Référence CVE CVE-2023-29348 https://www.cve.org/CVERecord?id=CVE-2023-29348 Référence CVE CVE-2023-35349 https://www.cve.org/CVERecord?id=CVE-2023-35349 Référence CVE CVE-2023-36420 https://www.cve.org/CVERecord?id=CVE-2023-36420 Référence CVE CVE-2023-36431 https://www.cve.org/CVERecord?id=CVE-2023-36431 Référence CVE CVE-2023-36434 https://www.cve.org/CVERecord?id=CVE-2023-36434 Référence CVE CVE-2023-36435 https://www.cve.org/CVERecord?id=CVE-2023-36435 Référence CVE CVE-2023-36436 https://www.cve.org/CVERecord?id=CVE-2023-36436 Référence CVE CVE-2023

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2026-022982The Go Project等の複数ベンダの製品における複数の脆弱性

Traefikのバージョン2.10.5以前および3.0.0-beta4は、Go標準ライブラリのHTTP/2実装に起因するHTTP/2リクエスト処理におけるサービス拒否(DoS)脆弱性(CVE-2023-44487 / CVE-2023-39325、いわゆる「Rapid Reset」手法)の影響を受けます。リモートの攻撃者はHTTP/2ストリームを高速に作成およびキャンセルすることで、サーバーのリソースを枯渇させてサービスを利用不能にする可能性があります。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2023-015462インターネット技術タスクフォース (IETF) の http 等複数ベンダの製品におけるリソースの枯渇に関する脆弱性

インターネット技術タスクフォース (IETF) の http 等複数ベンダの製品には、リソースの枯渇に関する脆弱性が存在します。

Official advisory ↗
KISA KrCERT/CC · Korean · KNVD-6482MS 5월 보안 위협에 따른 정기 보안 업데이트 권고

M | CVE-2025-24054 | NTLM 해시 공개 스푸핑 취약성 | | Azure Virtual Desktop | CVE-2025-21416 | Azure Virtual Desktop 권한 상승 취약성 | | Visual Studio Code | CVE-2025-21264 | Visual Studio Code 보안 기능 바이패스 취약성 | | Windows Update Stack | CVE-2025-21204 | Windows Process Activation 권한 상승 취약성 | | Azure Agent Installer | CVE-2025-21199 | 백업 및 사이트 복구용 Azure Agent Installer 권한 상승 취약성 | | Windows Standards-Based Storage Management Service | CVE-2025-21174 | Windows 표준 스토리지 관리 서비스 서비스 거부 취약성 | | Windows Remote Desktop Services | CVE-2024-49128 | Windows 원격 데스크톱 서비스 원격 코드 실행 취약성 | | Windows Secure Kernel Mode | CVE-2024-21302 | Windows 보안 커널 모드 권한 상승 취약성 | | HTTP/2 | CVE-2023-44487 | MITRE: CVE-2023-44487 HTTP/2 고속 초기화 공격 | | Windows DVD Maker | CVE-2017-0045 | Windows DVD 제작자 XML 외부 엔터티 정보 공개 취약성 | ##### □ 작성 : 위협분석단 취약점분석팀

Official advisory ↗
KISA KrCERT/CC · Korean · KNVD-6354MS 12월 보안 위협에 따른 정기 보안 업데이트 권고

1116 | Chromium: CVE-2024-11116 그림판에서 부적절한 구현 | | Microsoft Edge (Chromium-based) | CVE-2024-11115 | Chromium: CVE-2024-11115 탐색에서 불충분한 정책 적용 | | Microsoft Edge (Chromium-based) | CVE-2024-11114 | Chromium: CVE-2024-11114 보기에서 부적절한 구현 | | Microsoft Edge (Chromium-based) | CVE-2024-11113 | Chromium: CVE-2024-11113 접근성에서 UaF(Use after free) | | Microsoft Edge (Chromium-based) | CVE-2024-11112 | Chromium: CVE-2024-11112 미디어에서 UaF(Use after free) | | Microsoft Edge (Chromium-based) | CVE-2024-11111 | Chromium: CVE-2024-11111 자동 채우기에서 부적절한 구현 | | Microsoft Edge (Chromium-based) | CVE-2024-11110 | Chromium: CVE-2024-11110 깜박임의 부적절한 구현 | | HTTP/2 | CVE-2023-44487 | MITRE: CVE-2023-44487 HTTP/2 고속 초기화 공격 | | Microsoft QUIC | CVE-2023-38171 | Microsoft QUIC 서비스 거부 취약성 | | Microsoft QUIC | CVE-2023-36435 | Microsoft QUIC 서비스 거부 취약성 | | Microsoft Windows | CVE-2016-3352 | Windows 정보 유출 취약성 | ##### □ 작성 : 위협분석단 취약점분석팀

Official advisory ↗
KISA KrCERT/CC · Korean · KNVD-6041MS 11월 보안 위협에 따른 정기 보안 업데이트 권고

3-5475 DevTools에서 부적절한 구현 | | Microsoft Edge (Chromium-based) | CVE-2023-5474 | Chromium: CVE-2023-5474 PDF에서 힙 버퍼 오버플로 | | Microsoft Edge (Chromium-based) | CVE-2023-5473 | Chromium: CVE-2023-5473 캐스팅에서 UaF(Use after free) | | Microsoft Edge (Chromium-based) | CVE-2023-5472 | Chromium: CVE-2023-5472: 프로필에서 UaF(Use after free) | | Microsoft Edge (Chromium-based) | CVE-2023-5218 | Chromium: CVE-2023-5218 사이트 격리에서 UaF(Use after free) | | Microsoft Edge (Chromium-based) | CVE-2023-5217 | Chromium: CVE-2023-5217 libvpx의 vp8 인코딩에서 힙 버퍼 오버플로 | | Microsoft Edge (Chromium-based) | CVE-2023-4863 | Chromium: CVE-2023-4863 WebP에서 힙 버퍼 오버플로 | | HTTP/2 | CVE-2023-44487 | MITRE: CVE-2023-44487 HTTP/2 고속 초기화 공격 | | Adobe | CVE-2023-44323 | Adobe: CVE-2023-44323 Adobe PDF 원격 코드 실행 취약성 | | Windows Layer 2 Tunneling Protocol | CVE-2023-41765 | L2TP(Layer 2 Tunneling Protocol) 원격 코드 실행 취약성 | | Windows cURL Implementation | CVE-2023-38545 | Hackerone: CVE-2023-38545 SOCKS5 힙 버퍼 오버플로 | | Windows Mobile Device Management | CVE-2023-38186 | Windows 모바일 장치 관리 권한 상승 취약성 | | Microsoft Office SharePoint | CVE-2023-38177 | Microsoft SharePoint Server 원격 코드 실행 취약성 | | Microsoft QUIC | CVE-2023-38171 | Microsoft QUIC 서비스 거부 취약성 | | Microsoft Dynamics | CVE-2023-38164 | Microsoft Dynamics 365(온-프레미스) 교차-사이트 스크립팅 취약성 | | Azu

Official advisory ↗
KISA KrCERT/CC · Korean · KNVD-6013MS 10월 보안 위협에 따른 정기 보안 업데이트 권고

| CVE-2023-4905 | Chromium: CVE-2023-4905 Prompts에서 부적절한 구현 | | Microsoft Edge (Chromium-based) | CVE-2023-4904 | Chromium: CVE-2023-4904 다운로드에서 불충분한 정책 적용 | | Microsoft Edge (Chromium-based) | CVE-2023-4903 | Chromium: CVE-2023-4903 사용자 지정 모바일 탭에서 부적절한 구현 | | Microsoft Edge (Chromium-based) | CVE-2023-4902 | Chromium: CVE-2023-4902 입력에서 부적절한 구현 | | Microsoft Edge (Chromium-based) | CVE-2023-4901 | Chromium: CVE-2023-4901 Prompts에서 부적절한 구현 | | Microsoft Edge (Chromium-based) | CVE-2023-4900 | Chromium: CVE-2023-4900 사용자 지정 탭에서 부적절한 구현 | | Microsoft Edge (Chromium-based) | CVE-2023-4863 | Chromium: CVE-2023-4863 WebP에서 힙 버퍼 오버플로 | | HTTP/2 | CVE-2023-44487 | MITRE: CVE-2023-44487 HTTP/2 고속 초기화 공격 | | Windows Layer 2 Tunneling Protocol | CVE-2023-41774 | L2TP(Layer 2 Tunneling Protocol) 원격 코드 실행 취약성 | | Windows Layer 2 Tunneling Protocol | CVE-2023-41773 | L2TP(Layer 2 Tunneling Protocol) 원격 코드 실행 취약성 | | Windows Win32K | CVE-2023-41772 | Win32k 권한 상승 취약성 | | Windows Layer 2 Tunneling Protocol | CVE-2023-41771 | L2TP(Layer 2 Tunneling Protocol) 원격 코드 실행 취약성 | | Windows Layer 2 Tunneling Protocol | CVE-2023-41770 | L2TP(Layer 2 Tunneling Protocol) 원격 코드 실행 취약성 | | Windows Layer 2 Tunneling Protocol | CVE-2023-41769 | L2TP(Layer 2 Tunneling Protocol) 원격 코드 실행 취약성 | | Windows Layer 2 Tunneling Pro

Official advisory ↗
KISA KrCERT/CC · Korean · KNVD-6012현재 악용되고 있는 Exploit(Update. 2023-10-10)

HTTP/2 contains a rapid reset vulnerability that allows for a distributed denial-of-service attack (DDoS).

Official advisory ↗
NCSC-NL · Dutch · NCSC-2024-0332Kwetsbaarheden verholpen in Siemens producten

De kwetsbaarheden stellen een kwaadwillende mogelijk in staat aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade: - Denial-of-Service (DoS) - Manipulatie van gegevens - Omzeilen van een beveiligingsmaatregel - (Remote) code execution (Administrator/Root rechten) - (Remote) code execution (Gebruikersrechten) - Toegang tot systeemgegevens - Spoofing - Verhoogde gebruikersrechten De kwaadwillende heeft hiervoor toegang nodig tot de productieomgeving. Het is goed gebruik een dergelijke omgeving niet publiek toegankelijk te hebben.

Official advisory ↗
NCSC-NL · Dutch · NCSC-2024-0306Kwetsbaarheden verholpen in Oracle Supply Chain

Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade: * Denial-of-Service (DoS) * Toegang tot gevoelige gegevens * Toegang tot systeemgegevens * Manipulatie van gegevens * (Remote) code execution (Gebruikersrechten)

Official advisory ↗
NCSC-NL · Dutch · NCSC-2024-0294Kwetsbaarheden verholpen in Oracle Communications

Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade: * Denial-of-Service (DoS) * Toegang tot gevoelige gegevens * Toegang tot systeemgegevens * Manipulatie van gegevens * (Remote) code execution (Gebruikersrechten)

Official advisory ↗
NCSC-NL · Dutch · NCSC-2024-0293Kwetsbaarheden verholpen in Oracle Communications Applications

Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade: * Denial-of-Service (DoS) * Toegang tot gevoelige gegevens * Toegang tot systeemgegevens * Manipulatie van gegevens * Omzeilen van beveiligingsmaatregel * (Remote) code execution (Gebruikersrechten)

Official advisory ↗
NCSC-NL · Dutch · NCSC-2024-0246Kwetsbaarheden verholpen in Siemens producten

De kwetsbaarheden stellen een kwaadwillende mogelijk in staat aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade: - Denial-of-Service (DoS) - Manipulatie van gegevens - Omzeilen van beveiligingsmaatregel - (Remote) code execution (Administrator/Root rechten) - (Remote) code execution (Gebruikersrechten) - Toegang tot systeemgegevens - Verhoogde gebruikersrechten De kwaadwillende heeft hiervoor toegang nodig tot de productieomgeving. Het is goed gebruik een dergelijke omgeving niet publiek toegankelijk te hebben.

Official advisory ↗
NCSC-NL · Dutch · NCSC-2025-0187Kwetsbaarheden verholpen in Siemens producten

De kwetsbaarheden stellen een kwaadwillende mogelijk in staat aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade: - Denial-of-Service (DoS) - Manipulatie van gegevens - Omzeilen van een beveiligingsmaatregel - Omzeilen van authenticatie - (Remote) code execution (root/admin rechten) - (Remote) code execution (Gebruikersrechten) - Toegang tot systeemgegevens - Toegang tot gevoelige gegevens - Spoofing De kwaadwillende heeft hiervoor toegang nodig tot de productieomgeving. Het is goed gebruik een dergelijke omgeving niet publiek toegankelijk te hebben.

Official advisory ↗
NCSC-NL · Dutch · NCSC-2025-0123Kwetsbaarheden verholpen in Oracle Database Producten

De kwetsbaarheden stellen ongeauthenticeerde kwaadwillenden in staat om een Denial-of-Service te veroorzaken of om ongeautoriseerde toegang te verkrijgen tot gevoelige gegevens en gegevens te manipuleren. Subcomponenten als de RDBMS Listener, Java VM, en andere componenten zijn specifiek kwetsbaar, met CVSS-scores variërend van 5.3 tot 7.5, wat duidt op een gematigd tot hoog risico.

Official advisory ↗
NCSC-NL · Dutch · NCSC-2025-0028Kwetsbaarheden verholpen in Oracle Analytics

Een kwaadwillende kan de kwetsbaarheden misbruiken om een Denial-of-Service te veroorzaken, of zich toegang te verschaffen tot gevoelige gegevens.

Official advisory ↗
NCSC-NL · Dutch · NCSC-2024-0433Kwetsbaarheden verholpen in Siemens producten

De kwetsbaarheden stellen een kwaadwillende mogelijk in staat aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade: - Denial-of-Service (DoS) - Cross-Site-Scripting (XSS) - Manipulatie van gegevens - Omzeilen van een beveiligingsmaatregel - Omzeilen van authenticatie - (Remote) code execution (Administrator/Root rechten) - (Remote) code execution (Gebruikersrechten) - Toegang tot systeemgegevens - Verhoogde gebruikersrechten De kwaadwillende heeft hiervoor toegang nodig tot de productieomgeving. Het is goed gebruik een dergelijke omgeving niet publiek toegankelijk te hebben.

Official advisory ↗
NCSC-NL · Dutch · NCSC-2024-0411Kwetsbaarheden verholpen in Oracle Database producten

Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade: - Denial-of-Service (DoS) - Manipuleren van data - Toegang tot gevoelige gegevens

Official advisory ↗
03

Patch and workaround

Operational remediation based on structured source evidence.

Status
?Patch availability is based on structured fixed-version fields and authoritative update references. If no fix is verified, check the vendor advisory before making a change.
Fix availability varies by product
Affected
Fixed
An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
Action
Use the product-specific evidence above. Patch only products with a verified fixed release, and keep every affected or under-investigation state without a matching fix in the remediation queue.
Workaround
Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.
Official vendor articles2 stored documents

Linked articles are downloaded and versioned as source evidence. A CVE mention or approved update relationship does not, by itself, verify a fix for every product branch.

  • [security] Go 1.21.3 and Go 1.20.10 are released →Original publisher ↗Searchable text snapshot · Captured 29 Sep 2026Groups Groups Conversations All groups and messages Send feedback to Google Help Training Sign in Groups Groups Conversations About     [security] Go 1.21.3 and Go 1.20.10 are released 17,080 views Skip to first unread message  anno...@golang.org unread, Oct 10, 2023, 7:03:53 PM 10/10/23    Reply to
  • CVE-2023-44487 | Ubuntu →Original publisher ↗Searchable text snapshot · Captured 29 Sep 2026CVE-2023-44487 Publication date 10 October 2023 Last updated 26 November 2025 Ubuntu priority High Why this priority? Cvss 3 Severity Score 7.5 &middot; High Score breakdown Toggle side navigation Description The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellatio
04

Evidence and provenance

Published 10 Oct 2023 · Last source change 14 Jul 2026, 12:03 UTC · CWE-400 · Uncontrolled Resource Consumption

CVE recordCVE.org · 5.2
CVSS sourceNIST NVD
EPSS source
?The date BlackTree first stored a score for this CVE from the daily FIRST EPSS feed.
FIRST · tracked since 2026-08-14
European sourceENISA EUVD · EUVD-2023-2795
Product sourceVendor CSAF · Siemens ProductCERT
Remediation sourceVendor CSAF · Siemens ProductCERT
CWE sourceCISA ADP
NVD statusNVD enriched

Core structured fields are present and their contributing authorities are shown above.

Material change intelligence

What changed after publication

View recent updates ↗
  1. Vendor guidanceAuthoritative vendor guidance changed: added remediation: github.com/30055; removed remediation: download.schneider-electric.com/files?p_Doc_Ref=SEVD-2025-189-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2025-189-03.pdf.
    Before
    mitigation: github.com/277 · mitigation: nginx.com/http-2-rapid-reset-attack-impacting-f5-nginx-products · patch: cgit.freebsd.org/commit?id=c64c329c2c1752f46b73e3e6ce9f4329be6629f9 · 49 more references
    After
    mitigation: github.com/277 · mitigation: nginx.com/http-2-rapid-reset-attack-impacting-f5-nginx-products · patch: cgit.freebsd.org/commit?id=c64c329c2c1752f46b73e3e6ce9f4329be6629f9 · 49 more references
    github.com ↗
  2. Affected versionsThe structured affected or fixed version information changed.
    Before
    http: 2.0 · Fixed: The CVE’s listed above affect the PostgresSQL pgadmin tool. If you have installed this tool, not required by EcoStruxure™ Power Operation 2024, we recommend you uninstall it from your EPO server and client machines.We strongly recommend customers take the following actions:• If waveform analysis and ETAP simulation features are not used, uninstall PostgreSQLOR• For those customers using waveform analysis and ETAP simulation features, we recommend all deployments of EPO only accept connections from localhost in PostgresSQL. Contact customer care for information on how to modify PostgreSQL. Further, we recommend you manually uninstall PostgreSQL 14.10 and update to PostgreSQL 14.17 or higher. EcoStruxure™ Power Operation 2024 CU2 includes an updated version of PostgreSQL and is available for download here: https://community.se.com/t5/EcoStruxure-Power-Operation/v2024-Release-amp-Updates-Install-Procedure/m-p/478928/thread-id/6997#M6997
    After
    http: 2.0 · Fixed: An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
    CISA KEV ↗
  3. Affected versionsThe structured affected or fixed version information changed.
    Before
    n/a: n/a · Fixed: An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
    After
    http: 2.0 · Fixed: An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
    CISA KEV ↗
  4. Affected versionsThe structured affected or fixed version information changed.
    Before
    n/a · Fixed: An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
    After
    n/a: n/a · Fixed: An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
    CNA ↗
  5. Affected versionsThe structured affected or fixed version information changed.
    Before
    http: 2.0 · Fixed: An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
    After
    http: 2.0 · Fixed: The CVE’s listed above affect the PostgresSQL pgadmin tool. If you have installed this tool, not required by EcoStruxure™ Power Operation 2024, we recommend you uninstall it from your EPO server and client machines.We strongly recommend customers take the following actions:• If waveform analysis and ETAP simulation features are not used, uninstall PostgreSQLOR• For those customers using waveform analysis and ETAP simulation features, we recommend all deployments of EPO only accept connections from localhost in PostgresSQL. Contact customer care for information on how to modify PostgreSQL. Further, we recommend you manually uninstall PostgreSQL 14.10 and update to PostgreSQL 14.17 or higher. EcoStruxure™ Power Operation 2024 CU2 includes an updated version of PostgreSQL and is available for download here: https://community.se.com/t5/EcoStruxure-Power-Operation/v2024-Release-amp-Updates-Install-Procedure/m-p/478928/thread-id/6997#M6997
    Schneider Electric CPCERT ↗
  6. Vendor guidanceAuthoritative vendor guidance changed: added remediation: sick.com/sca-2025-0011.json; removed remediation: endress.com.
    Before
    remediation: endress.com
    After
    remediation: sick.com/sca-2025-0011.json
    SICK PSIRT ↗
  7. Vendor guidanceAuthoritative vendor guidance changed: added remediation: sick.com/special_information_sick_operating_guidelines_cybersecurity_by_sick_en_im0106719.pdf; removed remediation: sick.com/psirt.
    Before
    remediation: sick.com/psirt
    After
    remediation: sick.com/special_information_sick_operating_guidelines_cybersecurity_by_sick_en_im0106719.pdf
    SICK PSIRT ↗
Material fields only · duplicate refreshes suppressed · history retained for the configured operational retention period
Technical terms and abbreviations used in this report
CVE
Common Vulnerabilities and Exposures: the public identifier for one disclosed vulnerability.
CVSS
Common Vulnerability Scoring System: a technical severity framework; it is not patching priority by itself.
EPSS
Exploit Prediction Scoring System: FIRST's estimate of the probability that exploitation activity will be observed in the next 30 days; it is a forecast, not confirmation.
CWE
Common Weakness Enumeration: the standard category describing the underlying software or hardware weakness.
CNA
CVE Numbering Authority: an organisation authorised to assign and publish CVE records.
CISA ADP
Cybersecurity and Infrastructure Security Agency Authorized Data Publisher: structured enrichment added to a CVE record.
NVD
National Vulnerability Database: NIST's enrichment service for CVE records.
CERT / CSIRT
A computer security incident response team that publishes warnings or coordinates incident response.
PoC
Proof of concept: public material that demonstrates or helps reproduce exploitation.
CSAF
Common Security Advisory Framework: a machine-readable format for security advisories.
LoTL
Living off the land: abuse of legitimate tools or system functions during an attack.
Free version - for non-commercial use only.CVE-2023-44487 · cve.blacktree.nl