diff --git a/advisories/github-reviewed/2025/01/GHSA-5vpc-35f4-r8w6/GHSA-5vpc-35f4-r8w6.json b/advisories/github-reviewed/2025/01/GHSA-5vpc-35f4-r8w6/GHSA-5vpc-35f4-r8w6.json index fb481a41041..ade558b735f 100644 --- a/advisories/github-reviewed/2025/01/GHSA-5vpc-35f4-r8w6/GHSA-5vpc-35f4-r8w6.json +++ b/advisories/github-reviewed/2025/01/GHSA-5vpc-35f4-r8w6/GHSA-5vpc-35f4-r8w6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5vpc-35f4-r8w6", - "modified": "2025-02-11T09:30:32Z", + "modified": "2025-02-11T12:30:54Z", "published": "2025-01-21T21:22:49Z", "aliases": [ "CVE-2024-11218" @@ -121,6 +121,14 @@ "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-11218" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:1296" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:1295" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:1275" diff --git a/advisories/github-reviewed/2025/01/GHSA-hp5j-2585-qx6g/GHSA-hp5j-2585-qx6g.json b/advisories/github-reviewed/2025/01/GHSA-hp5j-2585-qx6g/GHSA-hp5j-2585-qx6g.json index 69dd69dc453..43f2aadffc6 100644 --- a/advisories/github-reviewed/2025/01/GHSA-hp5j-2585-qx6g/GHSA-hp5j-2585-qx6g.json +++ b/advisories/github-reviewed/2025/01/GHSA-hp5j-2585-qx6g/GHSA-hp5j-2585-qx6g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hp5j-2585-qx6g", - "modified": "2025-01-28T19:15:28Z", + "modified": "2025-02-11T12:30:53Z", "published": "2025-01-28T12:31:07Z", "aliases": [ "CVE-2025-0750" @@ -40,6 +40,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0750" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:1122" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-0750" diff --git a/advisories/unreviewed/2022/10/GHSA-gh7w-58g5-rmwx/GHSA-gh7w-58g5-rmwx.json b/advisories/unreviewed/2022/10/GHSA-gh7w-58g5-rmwx/GHSA-gh7w-58g5-rmwx.json index 38db77564bd..081d47c85df 100644 --- a/advisories/unreviewed/2022/10/GHSA-gh7w-58g5-rmwx/GHSA-gh7w-58g5-rmwx.json +++ b/advisories/unreviewed/2022/10/GHSA-gh7w-58g5-rmwx/GHSA-gh7w-58g5-rmwx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gh7w-58g5-rmwx", - "modified": "2022-10-14T19:00:33Z", + "modified": "2025-02-11T12:30:52Z", "published": "2022-10-11T12:00:45Z", "aliases": [ "CVE-2022-31766" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-31766" }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-697140.html" + }, { "type": "WEB", "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-697140.pdf" diff --git a/advisories/unreviewed/2023/11/GHSA-282g-wxjw-75vj/GHSA-282g-wxjw-75vj.json b/advisories/unreviewed/2023/11/GHSA-282g-wxjw-75vj/GHSA-282g-wxjw-75vj.json index b8b1e8f209e..2d22703c8bf 100644 --- a/advisories/unreviewed/2023/11/GHSA-282g-wxjw-75vj/GHSA-282g-wxjw-75vj.json +++ b/advisories/unreviewed/2023/11/GHSA-282g-wxjw-75vj/GHSA-282g-wxjw-75vj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-282g-wxjw-75vj", - "modified": "2024-08-13T09:30:51Z", + "modified": "2025-02-11T12:30:52Z", "published": "2023-11-14T12:30:27Z", "aliases": [ "CVE-2023-44320" @@ -35,6 +35,10 @@ "type": "WEB", "url": "https://cert-portal.siemens.com/productcert/html/ssa-699386.html" }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-769027.html" + }, { "type": "WEB", "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-180704.pdf" diff --git a/advisories/unreviewed/2023/11/GHSA-mmpc-c8w6-wrm6/GHSA-mmpc-c8w6-wrm6.json b/advisories/unreviewed/2023/11/GHSA-mmpc-c8w6-wrm6/GHSA-mmpc-c8w6-wrm6.json index 5a5948d7e21..e274dac2ed3 100644 --- a/advisories/unreviewed/2023/11/GHSA-mmpc-c8w6-wrm6/GHSA-mmpc-c8w6-wrm6.json +++ b/advisories/unreviewed/2023/11/GHSA-mmpc-c8w6-wrm6/GHSA-mmpc-c8w6-wrm6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mmpc-c8w6-wrm6", - "modified": "2024-02-13T09:30:29Z", + "modified": "2025-02-11T12:30:53Z", "published": "2023-11-14T12:30:27Z", "aliases": [ "CVE-2023-44322" @@ -31,6 +31,10 @@ "type": "WEB", "url": "https://cert-portal.siemens.com/productcert/html/ssa-699386.html" }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-769027.html" + }, { "type": "WEB", "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-180704.pdf" diff --git a/advisories/unreviewed/2024/06/GHSA-qhx2-rhqq-2wmm/GHSA-qhx2-rhqq-2wmm.json b/advisories/unreviewed/2024/06/GHSA-qhx2-rhqq-2wmm/GHSA-qhx2-rhqq-2wmm.json index 81076f5bdbb..68930b95b74 100644 --- a/advisories/unreviewed/2024/06/GHSA-qhx2-rhqq-2wmm/GHSA-qhx2-rhqq-2wmm.json +++ b/advisories/unreviewed/2024/06/GHSA-qhx2-rhqq-2wmm/GHSA-qhx2-rhqq-2wmm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qhx2-rhqq-2wmm", - "modified": "2024-11-18T16:26:43Z", + "modified": "2025-02-11T12:30:53Z", "published": "2024-06-11T12:31:02Z", "aliases": [ "CVE-2024-35211" diff --git a/advisories/unreviewed/2024/11/GHSA-545p-76g5-36m8/GHSA-545p-76g5-36m8.json b/advisories/unreviewed/2024/11/GHSA-545p-76g5-36m8/GHSA-545p-76g5-36m8.json index c0742c17ce5..0f8fdc50998 100644 --- a/advisories/unreviewed/2024/11/GHSA-545p-76g5-36m8/GHSA-545p-76g5-36m8.json +++ b/advisories/unreviewed/2024/11/GHSA-545p-76g5-36m8/GHSA-545p-76g5-36m8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-545p-76g5-36m8", - "modified": "2024-11-12T15:30:43Z", + "modified": "2025-02-11T12:30:53Z", "published": "2024-11-12T15:30:43Z", "aliases": [ "CVE-2024-50560" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://cert-portal.siemens.com/productcert/html/ssa-354112.html" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-769027.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/11/GHSA-8fc3-6g2g-rgc3/GHSA-8fc3-6g2g-rgc3.json b/advisories/unreviewed/2024/11/GHSA-8fc3-6g2g-rgc3/GHSA-8fc3-6g2g-rgc3.json index 2fee40a1e4a..2e576e9936a 100644 --- a/advisories/unreviewed/2024/11/GHSA-8fc3-6g2g-rgc3/GHSA-8fc3-6g2g-rgc3.json +++ b/advisories/unreviewed/2024/11/GHSA-8fc3-6g2g-rgc3/GHSA-8fc3-6g2g-rgc3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8fc3-6g2g-rgc3", - "modified": "2024-11-12T15:30:43Z", + "modified": "2025-02-11T12:30:53Z", "published": "2024-11-12T15:30:43Z", "aliases": [ "CVE-2024-50572" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://cert-portal.siemens.com/productcert/html/ssa-354112.html" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-769027.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/11/GHSA-fc63-6853-v5m2/GHSA-fc63-6853-v5m2.json b/advisories/unreviewed/2024/11/GHSA-fc63-6853-v5m2/GHSA-fc63-6853-v5m2.json index 74ab13ef7e9..4ef787fa1c7 100644 --- a/advisories/unreviewed/2024/11/GHSA-fc63-6853-v5m2/GHSA-fc63-6853-v5m2.json +++ b/advisories/unreviewed/2024/11/GHSA-fc63-6853-v5m2/GHSA-fc63-6853-v5m2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fc63-6853-v5m2", - "modified": "2024-11-12T15:30:43Z", + "modified": "2025-02-11T12:30:53Z", "published": "2024-11-12T15:30:43Z", "aliases": [ "CVE-2024-50561" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://cert-portal.siemens.com/productcert/html/ssa-354112.html" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-769027.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-xh5q-pch5-g3xq/GHSA-xh5q-pch5-g3xq.json b/advisories/unreviewed/2025/01/GHSA-xh5q-pch5-g3xq/GHSA-xh5q-pch5-g3xq.json index 1f50a015ec0..a44d82d343d 100644 --- a/advisories/unreviewed/2025/01/GHSA-xh5q-pch5-g3xq/GHSA-xh5q-pch5-g3xq.json +++ b/advisories/unreviewed/2025/01/GHSA-xh5q-pch5-g3xq/GHSA-xh5q-pch5-g3xq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xh5q-pch5-g3xq", - "modified": "2025-02-03T21:31:48Z", + "modified": "2025-02-11T12:30:53Z", "published": "2025-01-14T18:32:00Z", "aliases": [ "CVE-2024-12085" @@ -63,6 +63,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:0885" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:1120" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-12085" diff --git a/advisories/unreviewed/2025/02/GHSA-357m-v762-qj4c/GHSA-357m-v762-qj4c.json b/advisories/unreviewed/2025/02/GHSA-357m-v762-qj4c/GHSA-357m-v762-qj4c.json new file mode 100644 index 00000000000..182341153a4 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-357m-v762-qj4c/GHSA-357m-v762-qj4c.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-357m-v762-qj4c", + "modified": "2025-02-11T12:30:55Z", + "published": "2025-02-11T12:30:54Z", + "aliases": [ + "CVE-2025-24956" + ], + "details": "A vulnerability has been identified in OpenV2G (All versions < V0.9.6). The OpenV2G EXI parsing feature is missing a length check when parsing X509 serial numbers. Thus, an attacker could introduce a buffer overflow that leads to memory corruption.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24956" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-647005.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T11:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-4688-8pmg-jw5w/GHSA-4688-8pmg-jw5w.json b/advisories/unreviewed/2025/02/GHSA-4688-8pmg-jw5w/GHSA-4688-8pmg-jw5w.json new file mode 100644 index 00000000000..d61259bb790 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-4688-8pmg-jw5w/GHSA-4688-8pmg-jw5w.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4688-8pmg-jw5w", + "modified": "2025-02-11T12:30:54Z", + "published": "2025-02-11T12:30:54Z", + "aliases": [ + "CVE-2024-45386" + ], + "details": "A vulnerability has been identified in SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Update 2), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1), SIMOCODE ES V19 (All versions < V19 Update 1), SIRIUS Safety ES V19 (TIA Portal) (All versions < V19 Update 1), SIRIUS Soft Starter ES V19 (TIA Portal) (All versions < V19 Update 1), TIA Administrator (All versions < V3.0.4). Affected products do not correctly invalidate user sessions upon user logout. This could allow a remote unauthenticated attacker, who has obtained the session token by other means, to re-use a legitimate user's session even after logout.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45386" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-342348.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-613" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T11:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-7hh3-mrx6-fgwq/GHSA-7hh3-mrx6-fgwq.json b/advisories/unreviewed/2025/02/GHSA-7hh3-mrx6-fgwq/GHSA-7hh3-mrx6-fgwq.json new file mode 100644 index 00000000000..79d92f6c8a1 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-7hh3-mrx6-fgwq/GHSA-7hh3-mrx6-fgwq.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7hh3-mrx6-fgwq", + "modified": "2025-02-11T12:30:55Z", + "published": "2025-02-11T12:30:55Z", + "aliases": [ + "CVE-2025-24532" + ], + "details": "A vulnerability has been identified in SCALANCE WAB762-1 (6GK5762-1AJ00-6AA0) (All versions < V3.0.0), SCALANCE WAM763-1 (6GK5763-1AL00-7DA0) (All versions < V3.0.0), SCALANCE WAM763-1 (ME) (6GK5763-1AL00-7DC0) (All versions < V3.0.0), SCALANCE WAM763-1 (US) (6GK5763-1AL00-7DB0) (All versions < V3.0.0), SCALANCE WAM766-1 (6GK5766-1GE00-7DA0) (All versions < V3.0.0), SCALANCE WAM766-1 (ME) (6GK5766-1GE00-7DC0) (All versions < V3.0.0), SCALANCE WAM766-1 (US) (6GK5766-1GE00-7DB0) (All versions < V3.0.0), SCALANCE WAM766-1 EEC (6GK5766-1GE00-7TA0) (All versions < V3.0.0), SCALANCE WAM766-1 EEC (ME) (6GK5766-1GE00-7TC0) (All versions < V3.0.0), SCALANCE WAM766-1 EEC (US) (6GK5766-1GE00-7TB0) (All versions < V3.0.0), SCALANCE WUB762-1 (6GK5762-1AJ00-1AA0) (All versions < V3.0.0), SCALANCE WUB762-1 iFeatures (6GK5762-1AJ00-2AA0) (All versions < V3.0.0), SCALANCE WUM763-1 (6GK5763-1AL00-3AA0) (All versions < V3.0.0), SCALANCE WUM763-1 (6GK5763-1AL00-3DA0) (All versions < V3.0.0), SCALANCE WUM763-1 (US) (6GK5763-1AL00-3AB0) (All versions < V3.0.0), SCALANCE WUM763-1 (US) (6GK5763-1AL00-3DB0) (All versions < V3.0.0), SCALANCE WUM766-1 (6GK5766-1GE00-3DA0) (All versions < V3.0.0), SCALANCE WUM766-1 (ME) (6GK5766-1GE00-3DC0) (All versions < V3.0.0), SCALANCE WUM766-1 (USA) (6GK5766-1GE00-3DB0) (All versions < V3.0.0). Affected devices with role `user` is affected by incorrect authorization in SNMPv3 View configuration. This could allow an attacker to change the View Type of SNMPv3 Views.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24532" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-769027.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T11:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-88wp-w57j-8x7m/GHSA-88wp-w57j-8x7m.json b/advisories/unreviewed/2025/02/GHSA-88wp-w57j-8x7m/GHSA-88wp-w57j-8x7m.json new file mode 100644 index 00000000000..4dc9edbc106 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-88wp-w57j-8x7m/GHSA-88wp-w57j-8x7m.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-88wp-w57j-8x7m", + "modified": "2025-02-11T12:30:54Z", + "published": "2025-02-11T12:30:54Z", + "aliases": [ + "CVE-2024-53648" + ], + "details": "A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.90), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP300) (All versions < V9.90), SIPROTEC 5 6MD86 (CP200) (All versions), SIPROTEC 5 6MD86 (CP300) (All versions < V9.90), SIPROTEC 5 6MD89 (CP300) (All versions < V9.90), SIPROTEC 5 6MU85 (CP300) (All versions < V9.90), SIPROTEC 5 7KE85 (CP200) (All versions), SIPROTEC 5 7KE85 (CP300) (All versions), SIPROTEC 5 7SA82 (CP100) (All versions), SIPROTEC 5 7SA82 (CP150) (All versions < V9.90), SIPROTEC 5 7SA86 (CP200) (All versions), SIPROTEC 5 7SA86 (CP300) (All versions < V9.90), SIPROTEC 5 7SA87 (CP200) (All versions), SIPROTEC 5 7SA87 (CP300) (All versions < V9.90), SIPROTEC 5 7SD82 (CP100) (All versions), SIPROTEC 5 7SD82 (CP150) (All versions < V9.90), SIPROTEC 5 7SD86 (CP200) (All versions), SIPROTEC 5 7SD86 (CP300) (All versions < V9.90), SIPROTEC 5 7SD87 (CP200) (All versions), SIPROTEC 5 7SD87 (CP300) (All versions < V9.90), SIPROTEC 5 7SJ81 (CP100) (All versions), SIPROTEC 5 7SJ81 (CP150) (All versions < V9.90), SIPROTEC 5 7SJ82 (CP100) (All versions), SIPROTEC 5 7SJ82 (CP150) (All versions < V9.90), SIPROTEC 5 7SJ85 (CP200) (All versions), SIPROTEC 5 7SJ85 (CP300) (All versions < V9.90), SIPROTEC 5 7SJ86 (CP200) (All versions), SIPROTEC 5 7SJ86 (CP300) (All versions < V9.90), SIPROTEC 5 7SK82 (CP100) (All versions), SIPROTEC 5 7SK82 (CP150) (All versions < V9.90), SIPROTEC 5 7SK85 (CP200) (All versions), SIPROTEC 5 7SK85 (CP300) (All versions < V9.90), SIPROTEC 5 7SL82 (CP100) (All versions), SIPROTEC 5 7SL82 (CP150) (All versions < V9.90), SIPROTEC 5 7SL86 (CP200) (All versions), SIPROTEC 5 7SL86 (CP300) (All versions < V9.90), SIPROTEC 5 7SL87 (CP200) (All versions), SIPROTEC 5 7SL87 (CP300) (All versions < V9.90), SIPROTEC 5 7SS85 (CP200) (All versions), SIPROTEC 5 7SS85 (CP300) (All versions < V9.90), SIPROTEC 5 7ST85 (CP200) (All versions), SIPROTEC 5 7ST85 (CP300) (All versions), SIPROTEC 5 7ST86 (CP300) (All versions), SIPROTEC 5 7SX82 (CP150) (All versions < V9.90), SIPROTEC 5 7SX85 (CP300) (All versions < V9.90), SIPROTEC 5 7SY82 (CP150) (All versions < V9.90), SIPROTEC 5 7UM85 (CP300) (All versions < V9.90), SIPROTEC 5 7UT82 (CP100) (All versions), SIPROTEC 5 7UT82 (CP150) (All versions < V9.90), SIPROTEC 5 7UT85 (CP200) (All versions), SIPROTEC 5 7UT85 (CP300) (All versions < V9.90), SIPROTEC 5 7UT86 (CP200) (All versions), SIPROTEC 5 7UT86 (CP300) (All versions < V9.90), SIPROTEC 5 7UT87 (CP200) (All versions), SIPROTEC 5 7UT87 (CP300) (All versions < V9.90), SIPROTEC 5 7VE85 (CP300) (All versions < V9.90), SIPROTEC 5 7VK87 (CP200) (All versions), SIPROTEC 5 7VK87 (CP300) (All versions < V9.90), SIPROTEC 5 7VU85 (CP300) (All versions < V9.90), SIPROTEC 5 Compact 7SX800 (CP050) (All versions < V9.90). Affected devices do not properly limit access to a development shell accessible over a physical interface. This could allow an unauthenticated attacker with physical access to the device to execute arbitrary commands on the device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53648" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-687955.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-489" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T11:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-8gh5-x56f-9qh9/GHSA-8gh5-x56f-9qh9.json b/advisories/unreviewed/2025/02/GHSA-8gh5-x56f-9qh9/GHSA-8gh5-x56f-9qh9.json new file mode 100644 index 00000000000..b511a983989 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-8gh5-x56f-9qh9/GHSA-8gh5-x56f-9qh9.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8gh5-x56f-9qh9", + "modified": "2025-02-11T12:30:54Z", + "published": "2025-02-11T12:30:54Z", + "aliases": [ + "CVE-2025-23363" + ], + "details": "A vulnerability has been identified in Teamcenter (All versions < V14.3.0.0). The SSO login service of affected applications accepts user-controlled input that could specify a link to an external site. This could allow an attacker to redirect the legitimate user to an attacker-chosen URL to steal valid session data. For a successful exploit, the legitimate user must actively click on an attacker-crafted link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23363" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-656895.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T11:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-8w92-pvrp-jcwv/GHSA-8w92-pvrp-jcwv.json b/advisories/unreviewed/2025/02/GHSA-8w92-pvrp-jcwv/GHSA-8w92-pvrp-jcwv.json new file mode 100644 index 00000000000..fdde74d8f1f --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-8w92-pvrp-jcwv/GHSA-8w92-pvrp-jcwv.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8w92-pvrp-jcwv", + "modified": "2025-02-11T12:30:55Z", + "published": "2025-02-11T12:30:55Z", + "aliases": [ + "CVE-2025-0588" + ], + "details": "In affected versions of Octopus Server it was possible for a user with sufficient access to set custom headers in all server responses. By submitting a specifically crafted referrer header the user could ensure that all subsequent server responses would return 500 errors rendering the site mostly unusable. The user would be able to subsequently set and unset the referrer header to control the denial of service state with a valid CSRF token whilst new CSRF tokens could not be generated.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0588" + }, + { + "type": "WEB", + "url": "https://advisories.octopus.com/post/2024/sa2025-05" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T12:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-9cmp-ppm3-hp8w/GHSA-9cmp-ppm3-hp8w.json b/advisories/unreviewed/2025/02/GHSA-9cmp-ppm3-hp8w/GHSA-9cmp-ppm3-hp8w.json new file mode 100644 index 00000000000..e85326464ac --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-9cmp-ppm3-hp8w/GHSA-9cmp-ppm3-hp8w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9cmp-ppm3-hp8w", + "modified": "2025-02-11T12:30:54Z", + "published": "2025-02-11T12:30:53Z", + "aliases": [ + "CVE-2025-26409" + ], + "details": "A serial interface can be accessed with physical access to the PCB of Wattsense Bridge devices. After connecting to the interface, access to the bootloader is possible, as well as a Linux login prompt. The bootloader access can be used to gain a root shell on the device. This issue is fixed in recent firmware versions BSP >= 6.4.1.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26409" + }, + { + "type": "WEB", + "url": "https://r.sec-consult.com/wattsense" + }, + { + "type": "WEB", + "url": "https://support.wattsense.com/hc/en-150/articles/13366066529437-Release-Notes" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1191" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T10:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-9hqf-2957-q2jh/GHSA-9hqf-2957-q2jh.json b/advisories/unreviewed/2025/02/GHSA-9hqf-2957-q2jh/GHSA-9hqf-2957-q2jh.json new file mode 100644 index 00000000000..bd0fd973407 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-9hqf-2957-q2jh/GHSA-9hqf-2957-q2jh.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9hqf-2957-q2jh", + "modified": "2025-02-11T12:30:54Z", + "published": "2025-02-11T12:30:54Z", + "aliases": [ + "CVE-2025-24499" + ], + "details": "A vulnerability has been identified in SCALANCE WAB762-1 (6GK5762-1AJ00-6AA0) (All versions < V3.0.0), SCALANCE WAM763-1 (6GK5763-1AL00-7DA0) (All versions < V3.0.0), SCALANCE WAM763-1 (ME) (6GK5763-1AL00-7DC0) (All versions < V3.0.0), SCALANCE WAM763-1 (US) (6GK5763-1AL00-7DB0) (All versions < V3.0.0), SCALANCE WAM766-1 (6GK5766-1GE00-7DA0) (All versions < V3.0.0), SCALANCE WAM766-1 (ME) (6GK5766-1GE00-7DC0) (All versions < V3.0.0), SCALANCE WAM766-1 (US) (6GK5766-1GE00-7DB0) (All versions < V3.0.0), SCALANCE WAM766-1 EEC (6GK5766-1GE00-7TA0) (All versions < V3.0.0), SCALANCE WAM766-1 EEC (ME) (6GK5766-1GE00-7TC0) (All versions < V3.0.0), SCALANCE WAM766-1 EEC (US) (6GK5766-1GE00-7TB0) (All versions < V3.0.0), SCALANCE WUB762-1 (6GK5762-1AJ00-1AA0) (All versions < V3.0.0), SCALANCE WUB762-1 iFeatures (6GK5762-1AJ00-2AA0) (All versions < V3.0.0), SCALANCE WUM763-1 (6GK5763-1AL00-3AA0) (All versions < V3.0.0), SCALANCE WUM763-1 (6GK5763-1AL00-3DA0) (All versions < V3.0.0), SCALANCE WUM763-1 (US) (6GK5763-1AL00-3AB0) (All versions < V3.0.0), SCALANCE WUM763-1 (US) (6GK5763-1AL00-3DB0) (All versions < V3.0.0), SCALANCE WUM766-1 (6GK5766-1GE00-3DA0) (All versions < V3.0.0), SCALANCE WUM766-1 (ME) (6GK5766-1GE00-3DC0) (All versions < V3.0.0), SCALANCE WUM766-1 (USA) (6GK5766-1GE00-3DB0) (All versions < V3.0.0). Affected devices do not properly validate input while loading the configuration files. This could allow an authenticated remote attacker to execute arbitrary shell commands on the device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24499" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-769027.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T11:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-c2p9-97ww-q2q5/GHSA-c2p9-97ww-q2q5.json b/advisories/unreviewed/2025/02/GHSA-c2p9-97ww-q2q5/GHSA-c2p9-97ww-q2q5.json new file mode 100644 index 00000000000..00227e29bb3 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-c2p9-97ww-q2q5/GHSA-c2p9-97ww-q2q5.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2p9-97ww-q2q5", + "modified": "2025-02-11T12:30:54Z", + "published": "2025-02-11T12:30:54Z", + "aliases": [ + "CVE-2024-13506" + ], + "details": "The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the display_name profile parameter in all versions up to, and including, 2.8.97 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13506" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/geodirectory/tags/2.8.97/includes/admin/class-geodir-admin-post-view.php#L317" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3225839" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d0d9ba14-c0c9-426e-927e-9139a0882f0d?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T11:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-chvr-56gh-gq34/GHSA-chvr-56gh-gq34.json b/advisories/unreviewed/2025/02/GHSA-chvr-56gh-gq34/GHSA-chvr-56gh-gq34.json new file mode 100644 index 00000000000..4542af1e93f --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-chvr-56gh-gq34/GHSA-chvr-56gh-gq34.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-chvr-56gh-gq34", + "modified": "2025-02-11T12:30:55Z", + "published": "2025-02-11T12:30:55Z", + "aliases": [ + "CVE-2025-26490" + ], + "details": "A vulnerability has been identified in Opcenter Intelligence (All versions < V2501). Personal access token disclosure vulnerability in Tableau Server. For details go to help.salesforce.com and search for knowledge article id 000390611.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26490" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-246355.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T11:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-gqcq-mrjf-wgc6/GHSA-gqcq-mrjf-wgc6.json b/advisories/unreviewed/2025/02/GHSA-gqcq-mrjf-wgc6/GHSA-gqcq-mrjf-wgc6.json new file mode 100644 index 00000000000..39e52b8c87c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-gqcq-mrjf-wgc6/GHSA-gqcq-mrjf-wgc6.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqcq-mrjf-wgc6", + "modified": "2025-02-11T12:30:54Z", + "published": "2025-02-11T12:30:54Z", + "aliases": [ + "CVE-2025-0862" + ], + "details": "The SuperSaaS – online appointment scheduling plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘after’ parameter in all versions up to, and including, 2.1.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is limited to Chromium-based browsers (e.g. Chrome, Edge, Brave).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0862" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/supersaas-appointment-scheduling/tags/2.1.12/includes/shortcode.php#L15" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/supersaas-appointment-scheduling/tags/2.1.12/includes/shortcode.php#L31" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3235242" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/8698255b-6c03-464b-8cb5-191d3e77009f?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T11:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-gvw4-x4h8-82qr/GHSA-gvw4-x4h8-82qr.json b/advisories/unreviewed/2025/02/GHSA-gvw4-x4h8-82qr/GHSA-gvw4-x4h8-82qr.json new file mode 100644 index 00000000000..21e5fb34315 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-gvw4-x4h8-82qr/GHSA-gvw4-x4h8-82qr.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gvw4-x4h8-82qr", + "modified": "2025-02-11T12:30:54Z", + "published": "2025-02-11T12:30:54Z", + "aliases": [ + "CVE-2024-54015" + ], + "details": "A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.90), SIPROTEC 5 6MD85 (CP300) (All versions >= V8.80 < V9.90), SIPROTEC 5 6MD86 (CP300) (All versions >= V8.80 < V9.90), SIPROTEC 5 6MD89 (CP300) (All versions >= V8.80 < V9.90), SIPROTEC 5 6MU85 (CP300) (All versions >= V8.80 < V9.90), SIPROTEC 5 7KE85 (CP300) (All versions >= V8.80), SIPROTEC 5 7SA82 (CP150) (All versions < V9.90), SIPROTEC 5 7SA86 (CP300) (All versions >= V8.80 < V9.90), SIPROTEC 5 7SA87 (CP300) (All versions >= V8.80 < V9.90), SIPROTEC 5 7SD82 (CP150) (All versions < V9.90), SIPROTEC 5 7SD86 (CP300) (All versions >= V8.80 < V9.90), SIPROTEC 5 7SD87 (CP300) (All versions >= V8.80 < V9.90), SIPROTEC 5 7SJ81 (CP150) (All versions < V9.90), SIPROTEC 5 7SJ82 (CP150) (All versions < V9.90), SIPROTEC 5 7SJ85 (CP300) (All versions >= V8.80 < V9.90), SIPROTEC 5 7SJ86 (CP300) (All versions >= V8.80 < V9.90), SIPROTEC 5 7SK82 (CP150) (All versions < V9.90), SIPROTEC 5 7SK85 (CP300) (All versions >= V8.80 < V9.90), SIPROTEC 5 7SL82 (CP150) (All versions < V9.90), SIPROTEC 5 7SL86 (CP300) (All versions >= V8.80 < V9.90), SIPROTEC 5 7SL87 (CP300) (All versions >= V8.80 < V9.90), SIPROTEC 5 7SS85 (CP300) (All versions >= V8.80 < V9.90), SIPROTEC 5 7ST85 (CP300) (All versions >= V8.80), SIPROTEC 5 7ST86 (CP300) (All versions), SIPROTEC 5 7SX82 (CP150) (All versions < V9.90), SIPROTEC 5 7SX85 (CP300) (All versions >= V8.80 < V9.90), SIPROTEC 5 7SY82 (CP150) (All versions < V9.90), SIPROTEC 5 7UM85 (CP300) (All versions >= V8.80 < V9.90), SIPROTEC 5 7UT82 (CP150) (All versions < V9.90), SIPROTEC 5 7UT85 (CP300) (All versions >= V8.80 < V9.90), SIPROTEC 5 7UT86 (CP300) (All versions >= V8.80 < V9.90), SIPROTEC 5 7UT87 (CP300) (All versions >= V8.80 < V9.90), SIPROTEC 5 7VE85 (CP300) (All versions >= V8.80 < V9.90), SIPROTEC 5 7VK87 (CP300) (All versions >= V8.80 < V9.90), SIPROTEC 5 7VU85 (CP300) (All versions < V9.90), SIPROTEC 5 Communication Module ETH-BA-2EL (Rev.2) (All versions < V9.90), SIPROTEC 5 Communication Module ETH-BB-2FO (Rev. 2) (All versions < V9.90), SIPROTEC 5 Communication Module ETH-BD-2FO (All versions >= V8.80 < V9.90), SIPROTEC 5 Compact 7SX800 (CP050) (All versions >= V9.50 < V9.90). Affected devices do not properly validate SNMP GET requests. This could allow an unauthenticated, remote attacker to retrieve sensitive information of the affected devices with SNMPv2 GET requests using default credentials.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54015" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-767615.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1392" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T11:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-gx9r-288j-7947/GHSA-gx9r-288j-7947.json b/advisories/unreviewed/2025/02/GHSA-gx9r-288j-7947/GHSA-gx9r-288j-7947.json new file mode 100644 index 00000000000..2bbbcc3db0f --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-gx9r-288j-7947/GHSA-gx9r-288j-7947.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gx9r-288j-7947", + "modified": "2025-02-11T12:30:54Z", + "published": "2025-02-11T12:30:54Z", + "aliases": [ + "CVE-2024-23814" + ], + "details": "A vulnerability has been identified in SCALANCE WAB762-1 (6GK5762-1AJ00-6AA0) (All versions < V3.0.0), SCALANCE WAM763-1 (6GK5763-1AL00-7DA0) (All versions < V3.0.0), SCALANCE WAM763-1 (ME) (6GK5763-1AL00-7DC0) (All versions < V3.0.0), SCALANCE WAM763-1 (US) (6GK5763-1AL00-7DB0) (All versions < V3.0.0), SCALANCE WAM766-1 (6GK5766-1GE00-7DA0) (All versions < V3.0.0), SCALANCE WAM766-1 (ME) (6GK5766-1GE00-7DC0) (All versions < V3.0.0), SCALANCE WAM766-1 (US) (6GK5766-1GE00-7DB0) (All versions < V3.0.0), SCALANCE WAM766-1 EEC (6GK5766-1GE00-7TA0) (All versions < V3.0.0), SCALANCE WAM766-1 EEC (ME) (6GK5766-1GE00-7TC0) (All versions < V3.0.0), SCALANCE WAM766-1 EEC (US) (6GK5766-1GE00-7TB0) (All versions < V3.0.0), SCALANCE WUB762-1 (6GK5762-1AJ00-1AA0) (All versions < V3.0.0), SCALANCE WUB762-1 iFeatures (6GK5762-1AJ00-2AA0) (All versions < V3.0.0), SCALANCE WUM763-1 (6GK5763-1AL00-3AA0) (All versions < V3.0.0), SCALANCE WUM763-1 (6GK5763-1AL00-3DA0) (All versions < V3.0.0), SCALANCE WUM763-1 (US) (6GK5763-1AL00-3AB0) (All versions < V3.0.0), SCALANCE WUM763-1 (US) (6GK5763-1AL00-3DB0) (All versions < V3.0.0), SCALANCE WUM766-1 (6GK5766-1GE00-3DA0) (All versions < V3.0.0), SCALANCE WUM766-1 (ME) (6GK5766-1GE00-3DC0) (All versions < V3.0.0), SCALANCE WUM766-1 (USA) (6GK5766-1GE00-3DB0) (All versions < V3.0.0). The integrated ICMP service of the network stack of affected devices can be forced to exhaust its available memory resources when receiving specially crafted messages targeting IP fragment re-assembly. This could allow an unauthenticated remote attacker to cause a temporary denial of service condition of the ICMP service, other communication services are not affected. Affected devices will resume normal operation after the attack terminates.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23814" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-769027.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T11:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-h9f9-r2j7-9685/GHSA-h9f9-r2j7-9685.json b/advisories/unreviewed/2025/02/GHSA-h9f9-r2j7-9685/GHSA-h9f9-r2j7-9685.json new file mode 100644 index 00000000000..2fd14f2e0ed --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-h9f9-r2j7-9685/GHSA-h9f9-r2j7-9685.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9f9-r2j7-9685", + "modified": "2025-02-11T12:30:54Z", + "published": "2025-02-11T12:30:54Z", + "aliases": [ + "CVE-2025-26411" + ], + "details": "An authenticated attacker is able to use the Plugin Manager of the web interface of the Wattsense Bridge devices to upload malicious Python files to the device. This enables an attacker to gain remote root access to the device. An attacker needs a valid user account on the Wattsense web interface to be able to conduct this attack. This issue is fixed in recent firmware versions BSP >= 6.1.0.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26411" + }, + { + "type": "WEB", + "url": "https://r.sec-consult.com/wattsense" + }, + { + "type": "WEB", + "url": "https://support.wattsense.com/hc/en-150/articles/13366066529437-Release-Notes" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T10:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-hrwq-g9x9-jmq2/GHSA-hrwq-g9x9-jmq2.json b/advisories/unreviewed/2025/02/GHSA-hrwq-g9x9-jmq2/GHSA-hrwq-g9x9-jmq2.json new file mode 100644 index 00000000000..f3029f14e80 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-hrwq-g9x9-jmq2/GHSA-hrwq-g9x9-jmq2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hrwq-g9x9-jmq2", + "modified": "2025-02-11T12:30:54Z", + "published": "2025-02-11T12:30:53Z", + "aliases": [ + "CVE-2025-26408" + ], + "details": "The JTAG interface of Wattsense Bridge devices can be accessed with physical access to the PCB. After connecting to the interface, full access to the device is possible. This enables an attacker to extract information, modify and debug the device's firmware. All known versions are affected.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26408" + }, + { + "type": "WEB", + "url": "https://r.sec-consult.com/wattsense" + }, + { + "type": "WEB", + "url": "https://support.wattsense.com/hc/en-150/articles/13366066529437-Release-Notes" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1191" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T10:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-jj4x-g447-hm4m/GHSA-jj4x-g447-hm4m.json b/advisories/unreviewed/2025/02/GHSA-jj4x-g447-hm4m/GHSA-jj4x-g447-hm4m.json new file mode 100644 index 00000000000..2b2d104af04 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-jj4x-g447-hm4m/GHSA-jj4x-g447-hm4m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jj4x-g447-hm4m", + "modified": "2025-02-11T12:30:54Z", + "published": "2025-02-11T12:30:54Z", + "aliases": [ + "CVE-2025-26410" + ], + "details": "The firmware of all Wattsense Bridge devices contain the same hard-coded user and root credentials. The user password can be easily recovered via password cracking attempts. The recovered credentials can be used to log into the device via the login shell that is exposed by the serial interface. The backdoor user has been removed in firmware BSP >= 6.4.1.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26410" + }, + { + "type": "WEB", + "url": "https://r.sec-consult.com/wattsense" + }, + { + "type": "WEB", + "url": "https://support.wattsense.com/hc/en-150/articles/13366066529437-Release-Notes" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-798" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T10:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-jpqx-54f3-2q5j/GHSA-jpqx-54f3-2q5j.json b/advisories/unreviewed/2025/02/GHSA-jpqx-54f3-2q5j/GHSA-jpqx-54f3-2q5j.json new file mode 100644 index 00000000000..fef4aa975c4 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-jpqx-54f3-2q5j/GHSA-jpqx-54f3-2q5j.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jpqx-54f3-2q5j", + "modified": "2025-02-11T12:30:54Z", + "published": "2025-02-11T12:30:54Z", + "aliases": [ + "CVE-2025-24811" + ], + "details": "A vulnerability has been identified in SIMATIC S7-1200 CPU 1211C AC/DC/Rly (6ES7211-1BE40-0XB0), SIMATIC S7-1200 CPU 1211C DC/DC/DC (6ES7211-1AE40-0XB0), SIMATIC S7-1200 CPU 1211C DC/DC/Rly (6ES7211-1HE40-0XB0), SIMATIC S7-1200 CPU 1212C AC/DC/Rly (6ES7212-1BE40-0XB0), SIMATIC S7-1200 CPU 1212C DC/DC/DC (6ES7212-1AE40-0XB0), SIMATIC S7-1200 CPU 1212C DC/DC/Rly (6ES7212-1HE40-0XB0), SIMATIC S7-1200 CPU 1212FC DC/DC/DC (6ES7212-1AF40-0XB0), SIMATIC S7-1200 CPU 1212FC DC/DC/Rly (6ES7212-1HF40-0XB0), SIMATIC S7-1200 CPU 1214C AC/DC/Rly (6ES7214-1BG40-0XB0), SIMATIC S7-1200 CPU 1214C DC/DC/DC (6ES7214-1AG40-0XB0), SIMATIC S7-1200 CPU 1214C DC/DC/Rly (6ES7214-1HG40-0XB0), SIMATIC S7-1200 CPU 1214FC DC/DC/DC (6ES7214-1AF40-0XB0), SIMATIC S7-1200 CPU 1214FC DC/DC/Rly (6ES7214-1HF40-0XB0), SIMATIC S7-1200 CPU 1215C AC/DC/Rly (6ES7215-1BG40-0XB0), SIMATIC S7-1200 CPU 1215C DC/DC/DC (6ES7215-1AG40-0XB0), SIMATIC S7-1200 CPU 1215C DC/DC/Rly (6ES7215-1HG40-0XB0), SIMATIC S7-1200 CPU 1215FC DC/DC/DC (6ES7215-1AF40-0XB0), SIMATIC S7-1200 CPU 1215FC DC/DC/Rly (6ES7215-1HF40-0XB0), SIMATIC S7-1200 CPU 1217C DC/DC/DC (6ES7217-1AG40-0XB0), SIPLUS S7-1200 CPU 1212 AC/DC/RLY (6AG1212-1BE40-2XB0), SIPLUS S7-1200 CPU 1212 AC/DC/RLY (6AG1212-1BE40-4XB0), SIPLUS S7-1200 CPU 1212 DC/DC/RLY (6AG1212-1HE40-2XB0), SIPLUS S7-1200 CPU 1212 DC/DC/RLY (6AG1212-1HE40-4XB0), SIPLUS S7-1200 CPU 1212C DC/DC/DC (6AG1212-1AE40-2XB0), SIPLUS S7-1200 CPU 1212C DC/DC/DC (6AG1212-1AE40-4XB0), SIPLUS S7-1200 CPU 1212C DC/DC/DC RAIL (6AG2212-1AE40-1XB0), SIPLUS S7-1200 CPU 1214 AC/DC/RLY (6AG1214-1BG40-2XB0), SIPLUS S7-1200 CPU 1214 AC/DC/RLY (6AG1214-1BG40-4XB0), SIPLUS S7-1200 CPU 1214 AC/DC/RLY (6AG1214-1BG40-5XB0), SIPLUS S7-1200 CPU 1214 DC/DC/DC (6AG1214-1AG40-2XB0), SIPLUS S7-1200 CPU 1214 DC/DC/DC (6AG1214-1AG40-4XB0), SIPLUS S7-1200 CPU 1214 DC/DC/DC (6AG1214-1AG40-5XB0), SIPLUS S7-1200 CPU 1214 DC/DC/RLY (6AG1214-1HG40-2XB0), SIPLUS S7-1200 CPU 1214 DC/DC/RLY (6AG1214-1HG40-4XB0), SIPLUS S7-1200 CPU 1214 DC/DC/RLY (6AG1214-1HG40-5XB0), SIPLUS S7-1200 CPU 1214C DC/DC/DC RAIL (6AG2214-1AG40-1XB0), SIPLUS S7-1200 CPU 1214FC DC/DC/DC (6AG1214-1AF40-5XB0), SIPLUS S7-1200 CPU 1214FC DC/DC/RLY (6AG1214-1HF40-5XB0), SIPLUS S7-1200 CPU 1215 AC/DC/RLY (6AG1215-1BG40-2XB0), SIPLUS S7-1200 CPU 1215 AC/DC/RLY (6AG1215-1BG40-4XB0), SIPLUS S7-1200 CPU 1215 AC/DC/RLY (6AG1215-1BG40-5XB0), SIPLUS S7-1200 CPU 1215 DC/DC/DC (6AG1215-1AG40-2XB0), SIPLUS S7-1200 CPU 1215 DC/DC/DC (6AG1215-1AG40-4XB0), SIPLUS S7-1200 CPU 1215 DC/DC/RLY (6AG1215-1HG40-2XB0), SIPLUS S7-1200 CPU 1215 DC/DC/RLY (6AG1215-1HG40-4XB0), SIPLUS S7-1200 CPU 1215 DC/DC/RLY (6AG1215-1HG40-5XB0), SIPLUS S7-1200 CPU 1215C DC/DC/DC (6AG1215-1AG40-5XB0), SIPLUS S7-1200 CPU 1215FC DC/DC/DC (6AG1215-1AF40-5XB0). Affected devices do not process correctly certain special crafted packets sent to port 80/tcp, which could allow an unauthenticated attacker to cause a denial of service in the device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24811" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-224824.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-404" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T11:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-m62f-jrrh-2q4v/GHSA-m62f-jrrh-2q4v.json b/advisories/unreviewed/2025/02/GHSA-m62f-jrrh-2q4v/GHSA-m62f-jrrh-2q4v.json new file mode 100644 index 00000000000..dcfcb3b23de --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-m62f-jrrh-2q4v/GHSA-m62f-jrrh-2q4v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m62f-jrrh-2q4v", + "modified": "2025-02-11T12:30:55Z", + "published": "2025-02-11T12:30:55Z", + "aliases": [ + "CVE-2025-26491" + ], + "details": "A vulnerability has been identified in Opcenter Intelligence (All versions < V2501). Server-side request forgery (SSRF) vulnerability in Tableau Server. For details go to help.salesforce.com and search for knowledge article id 001534936.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26491" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-246355.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T11:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-p2h9-63jc-gj67/GHSA-p2h9-63jc-gj67.json b/advisories/unreviewed/2025/02/GHSA-p2h9-63jc-gj67/GHSA-p2h9-63jc-gj67.json new file mode 100644 index 00000000000..602f0767947 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-p2h9-63jc-gj67/GHSA-p2h9-63jc-gj67.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p2h9-63jc-gj67", + "modified": "2025-02-11T12:30:54Z", + "published": "2025-02-11T12:30:54Z", + "aliases": [ + "CVE-2025-0526" + ], + "details": "In affected versions of Octopus Deploy it was possible to upload files to unexpected locations on the host using an API endpoint. The field lacked validation which could potentially result in ways to circumvent expected workflows.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0526" + }, + { + "type": "WEB", + "url": "https://advisories.octopus.com/post/2024/sa2025-03" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T11:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-p6r5-883m-2c48/GHSA-p6r5-883m-2c48.json b/advisories/unreviewed/2025/02/GHSA-p6r5-883m-2c48/GHSA-p6r5-883m-2c48.json new file mode 100644 index 00000000000..d5b1eeb4783 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-p6r5-883m-2c48/GHSA-p6r5-883m-2c48.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p6r5-883m-2c48", + "modified": "2025-02-11T12:30:54Z", + "published": "2025-02-11T12:30:54Z", + "aliases": [ + "CVE-2023-37482" + ], + "details": "The login functionality of the web server in affected devices does not normalize the response times of login attempts. An unauthenticated remote attacker could exploit this side-channel information to distinguish between valid and invalid usernames.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37482" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-195895.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-203" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T11:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-pggr-mph7-ch3v/GHSA-pggr-mph7-ch3v.json b/advisories/unreviewed/2025/02/GHSA-pggr-mph7-ch3v/GHSA-pggr-mph7-ch3v.json new file mode 100644 index 00000000000..edc3abd7b6f --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-pggr-mph7-ch3v/GHSA-pggr-mph7-ch3v.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pggr-mph7-ch3v", + "modified": "2025-02-11T12:30:54Z", + "published": "2025-02-11T12:30:54Z", + "aliases": [ + "CVE-2025-23403" + ], + "details": "A vulnerability has been identified in SIMATIC IPC DiagBase (All versions), SIMATIC IPC DiagMonitor (All versions). The affected device do not properly restrict the user permission for the registry key. This could allow an authenticated attacker to load vulnerable drivers into the system leading to privilege escalation or bypassing endpoint protection and other security measures.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23403" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-369369.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T11:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-pj3x-fjc7-82g7/GHSA-pj3x-fjc7-82g7.json b/advisories/unreviewed/2025/02/GHSA-pj3x-fjc7-82g7/GHSA-pj3x-fjc7-82g7.json new file mode 100644 index 00000000000..7654e199e57 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-pj3x-fjc7-82g7/GHSA-pj3x-fjc7-82g7.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pj3x-fjc7-82g7", + "modified": "2025-02-11T12:30:54Z", + "published": "2025-02-11T12:30:54Z", + "aliases": [ + "CVE-2024-53651" + ], + "details": "A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP300) (All versions), SIPROTEC 5 6MD86 (CP200) (All versions), SIPROTEC 5 6MD86 (CP300) (All versions), SIPROTEC 5 6MD89 (CP300) (All versions), SIPROTEC 5 6MU85 (CP300) (All versions), SIPROTEC 5 7KE85 (CP200) (All versions), SIPROTEC 5 7KE85 (CP300) (All versions), SIPROTEC 5 7SA82 (CP100) (All versions), SIPROTEC 5 7SA82 (CP150) (All versions), SIPROTEC 5 7SA86 (CP200) (All versions), SIPROTEC 5 7SA86 (CP300) (All versions), SIPROTEC 5 7SA87 (CP200) (All versions), SIPROTEC 5 7SA87 (CP300) (All versions), SIPROTEC 5 7SD82 (CP100) (All versions), SIPROTEC 5 7SD82 (CP150) (All versions), SIPROTEC 5 7SD86 (CP200) (All versions), SIPROTEC 5 7SD86 (CP300) (All versions), SIPROTEC 5 7SD87 (CP200) (All versions), SIPROTEC 5 7SD87 (CP300) (All versions), SIPROTEC 5 7SJ81 (CP100) (All versions), SIPROTEC 5 7SJ81 (CP150) (All versions), SIPROTEC 5 7SJ82 (CP100) (All versions), SIPROTEC 5 7SJ82 (CP150) (All versions), SIPROTEC 5 7SJ85 (CP200) (All versions), SIPROTEC 5 7SJ85 (CP300) (All versions), SIPROTEC 5 7SJ86 (CP200) (All versions), SIPROTEC 5 7SJ86 (CP300) (All versions), SIPROTEC 5 7SK82 (CP100) (All versions), SIPROTEC 5 7SK82 (CP150) (All versions), SIPROTEC 5 7SK85 (CP200) (All versions), SIPROTEC 5 7SK85 (CP300) (All versions), SIPROTEC 5 7SL82 (CP100) (All versions), SIPROTEC 5 7SL82 (CP150) (All versions), SIPROTEC 5 7SL86 (CP200) (All versions), SIPROTEC 5 7SL86 (CP300) (All versions), SIPROTEC 5 7SL87 (CP200) (All versions), SIPROTEC 5 7SL87 (CP300) (All versions), SIPROTEC 5 7SS85 (CP200) (All versions), SIPROTEC 5 7SS85 (CP300) (All versions), SIPROTEC 5 7ST85 (CP200) (All versions), SIPROTEC 5 7ST85 (CP300) (All versions), SIPROTEC 5 7ST86 (CP300) (All versions), SIPROTEC 5 7SX82 (CP150) (All versions), SIPROTEC 5 7SX85 (CP300) (All versions), SIPROTEC 5 7SY82 (CP150) (All versions), SIPROTEC 5 7UM85 (CP300) (All versions), SIPROTEC 5 7UT82 (CP100) (All versions), SIPROTEC 5 7UT82 (CP150) (All versions), SIPROTEC 5 7UT85 (CP200) (All versions), SIPROTEC 5 7UT85 (CP300) (All versions), SIPROTEC 5 7UT86 (CP200) (All versions), SIPROTEC 5 7UT86 (CP300) (All versions), SIPROTEC 5 7UT87 (CP200) (All versions), SIPROTEC 5 7UT87 (CP300) (All versions), SIPROTEC 5 7VE85 (CP300) (All versions), SIPROTEC 5 7VK87 (CP200) (All versions), SIPROTEC 5 7VK87 (CP300) (All versions), SIPROTEC 5 7VU85 (CP300) (All versions), SIPROTEC 5 Compact 7SX800 (CP050) (All versions). Affected devices do not encrypt certain data within the on-board flash storage on their PCB. This could allow an attacker with physical access to read the entire filesystem of the device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53651" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-111547.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-312" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T11:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-rxxw-q6vh-r7c8/GHSA-rxxw-q6vh-r7c8.json b/advisories/unreviewed/2025/02/GHSA-rxxw-q6vh-r7c8/GHSA-rxxw-q6vh-r7c8.json new file mode 100644 index 00000000000..2fb3bbd0606 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-rxxw-q6vh-r7c8/GHSA-rxxw-q6vh-r7c8.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rxxw-q6vh-r7c8", + "modified": "2025-02-11T12:30:54Z", + "published": "2025-02-11T12:30:54Z", + "aliases": [ + "CVE-2024-53977" + ], + "details": "A vulnerability has been identified in ModelSim (All versions < V2025.1), Questa (All versions < V2025.1). An example setup script contained in affected applications allows a specific executable file to be loaded from the current working directory. This could allow an authenticated local attacker to inject arbitrary code and escalate privileges in installations where administrators or processes with elevated privileges launch the script from a user-writable directory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53977" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-637914.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T11:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-v68j-53vw-j6rw/GHSA-v68j-53vw-j6rw.json b/advisories/unreviewed/2025/02/GHSA-v68j-53vw-j6rw/GHSA-v68j-53vw-j6rw.json new file mode 100644 index 00000000000..9718cf64095 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-v68j-53vw-j6rw/GHSA-v68j-53vw-j6rw.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v68j-53vw-j6rw", + "modified": "2025-02-11T12:30:54Z", + "published": "2025-02-11T12:30:54Z", + "aliases": [ + "CVE-2024-54089" + ], + "details": "A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All versions), TALON TC Series (BACnet) (All versions). Affected devices contain a weak encryption mechanism based on a hard-coded key.\nThis could allow an attacker to guess or decrypt the password from the cyphertext.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54089" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-615116.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-326" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T11:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-vf94-73hj-24cm/GHSA-vf94-73hj-24cm.json b/advisories/unreviewed/2025/02/GHSA-vf94-73hj-24cm/GHSA-vf94-73hj-24cm.json new file mode 100644 index 00000000000..2a00edcdc77 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-vf94-73hj-24cm/GHSA-vf94-73hj-24cm.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vf94-73hj-24cm", + "modified": "2025-02-11T12:30:54Z", + "published": "2025-02-11T12:30:54Z", + "aliases": [ + "CVE-2025-24812" + ], + "details": "A vulnerability has been identified in SIMATIC S7-1200 CPU 1211C AC/DC/Rly (6ES7211-1BE40-0XB0) (All versions < V4.7), SIMATIC S7-1200 CPU 1211C DC/DC/DC (6ES7211-1AE40-0XB0) (All versions < V4.7), SIMATIC S7-1200 CPU 1211C DC/DC/Rly (6ES7211-1HE40-0XB0) (All versions < V4.7), SIMATIC S7-1200 CPU 1212C AC/DC/Rly (6ES7212-1BE40-0XB0) (All versions < V4.7), SIMATIC S7-1200 CPU 1212C DC/DC/DC (6ES7212-1AE40-0XB0) (All versions < V4.7), SIMATIC S7-1200 CPU 1212C DC/DC/Rly (6ES7212-1HE40-0XB0) (All versions < V4.7), SIMATIC S7-1200 CPU 1212FC DC/DC/DC (6ES7212-1AF40-0XB0) (All versions < V4.7), SIMATIC S7-1200 CPU 1212FC DC/DC/Rly (6ES7212-1HF40-0XB0) (All versions < V4.7), SIMATIC S7-1200 CPU 1214C AC/DC/Rly (6ES7214-1BG40-0XB0) (All versions < V4.7), SIMATIC S7-1200 CPU 1214C DC/DC/DC (6ES7214-1AG40-0XB0) (All versions < V4.7), SIMATIC S7-1200 CPU 1214C DC/DC/Rly (6ES7214-1HG40-0XB0) (All versions < V4.7), SIMATIC S7-1200 CPU 1214FC DC/DC/DC (6ES7214-1AF40-0XB0) (All versions < V4.7), SIMATIC S7-1200 CPU 1214FC DC/DC/Rly (6ES7214-1HF40-0XB0) (All versions < V4.7), SIMATIC S7-1200 CPU 1215C AC/DC/Rly (6ES7215-1BG40-0XB0) (All versions < V4.7), SIMATIC S7-1200 CPU 1215C DC/DC/DC (6ES7215-1AG40-0XB0) (All versions < V4.7), SIMATIC S7-1200 CPU 1215C DC/DC/Rly (6ES7215-1HG40-0XB0) (All versions < V4.7), SIMATIC S7-1200 CPU 1215FC DC/DC/DC (6ES7215-1AF40-0XB0) (All versions < V4.7), SIMATIC S7-1200 CPU 1215FC DC/DC/Rly (6ES7215-1HF40-0XB0) (All versions < V4.7), SIMATIC S7-1200 CPU 1217C DC/DC/DC (6ES7217-1AG40-0XB0) (All versions < V4.7), SIPLUS S7-1200 CPU 1212 AC/DC/RLY (6AG1212-1BE40-2XB0) (All versions < V4.7), SIPLUS S7-1200 CPU 1212 AC/DC/RLY (6AG1212-1BE40-4XB0) (All versions < V4.7), SIPLUS S7-1200 CPU 1212 DC/DC/RLY (6AG1212-1HE40-2XB0) (All versions < V4.7), SIPLUS S7-1200 CPU 1212 DC/DC/RLY (6AG1212-1HE40-4XB0) (All versions < V4.7), SIPLUS S7-1200 CPU 1212C DC/DC/DC (6AG1212-1AE40-2XB0) (All versions < V4.7), SIPLUS S7-1200 CPU 1212C DC/DC/DC (6AG1212-1AE40-4XB0) (All versions < V4.7), SIPLUS S7-1200 CPU 1212C DC/DC/DC RAIL (6AG2212-1AE40-1XB0) (All versions < V4.7), SIPLUS S7-1200 CPU 1214 AC/DC/RLY (6AG1214-1BG40-2XB0) (All versions < V4.7), SIPLUS S7-1200 CPU 1214 AC/DC/RLY (6AG1214-1BG40-4XB0) (All versions < V4.7), SIPLUS S7-1200 CPU 1214 AC/DC/RLY (6AG1214-1BG40-5XB0) (All versions < V4.7), SIPLUS S7-1200 CPU 1214 DC/DC/DC (6AG1214-1AG40-2XB0) (All versions < V4.7), SIPLUS S7-1200 CPU 1214 DC/DC/DC (6AG1214-1AG40-4XB0) (All versions < V4.7), SIPLUS S7-1200 CPU 1214 DC/DC/DC (6AG1214-1AG40-5XB0) (All versions < V4.7), SIPLUS S7-1200 CPU 1214 DC/DC/RLY (6AG1214-1HG40-2XB0) (All versions < V4.7), SIPLUS S7-1200 CPU 1214 DC/DC/RLY (6AG1214-1HG40-4XB0) (All versions < V4.7), SIPLUS S7-1200 CPU 1214 DC/DC/RLY (6AG1214-1HG40-5XB0) (All versions < V4.7), SIPLUS S7-1200 CPU 1214C DC/DC/DC RAIL (6AG2214-1AG40-1XB0) (All versions < V4.7), SIPLUS S7-1200 CPU 1214FC DC/DC/DC (6AG1214-1AF40-5XB0) (All versions < V4.7), SIPLUS S7-1200 CPU 1214FC DC/DC/RLY (6AG1214-1HF40-5XB0) (All versions < V4.7), SIPLUS S7-1200 CPU 1215 AC/DC/RLY (6AG1215-1BG40-2XB0) (All versions < V4.7), SIPLUS S7-1200 CPU 1215 AC/DC/RLY (6AG1215-1BG40-4XB0) (All versions < V4.7), SIPLUS S7-1200 CPU 1215 AC/DC/RLY (6AG1215-1BG40-5XB0) (All versions < V4.7), SIPLUS S7-1200 CPU 1215 DC/DC/DC (6AG1215-1AG40-2XB0) (All versions < V4.7), SIPLUS S7-1200 CPU 1215 DC/DC/DC (6AG1215-1AG40-4XB0) (All versions < V4.7), SIPLUS S7-1200 CPU 1215 DC/DC/RLY (6AG1215-1HG40-2XB0) (All versions < V4.7), SIPLUS S7-1200 CPU 1215 DC/DC/RLY (6AG1215-1HG40-4XB0) (All versions < V4.7), SIPLUS S7-1200 CPU 1215 DC/DC/RLY (6AG1215-1HG40-5XB0) (All versions < V4.7), SIPLUS S7-1200 CPU 1215C DC/DC/DC (6AG1215-1AG40-5XB0) (All versions < V4.7), SIPLUS S7-1200 CPU 1215FC DC/DC/DC (6AG1215-1AF40-5XB0) (All versions < V4.7). Affected devices do not process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24812" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-224824.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1286" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T11:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-vwpq-f3cq-q82w/GHSA-vwpq-f3cq-q82w.json b/advisories/unreviewed/2025/02/GHSA-vwpq-f3cq-q82w/GHSA-vwpq-f3cq-q82w.json new file mode 100644 index 00000000000..3ed57bc0dd4 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-vwpq-f3cq-q82w/GHSA-vwpq-f3cq-q82w.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vwpq-f3cq-q82w", + "modified": "2025-02-11T12:30:54Z", + "published": "2025-02-11T12:30:54Z", + "aliases": [ + "CVE-2025-0525" + ], + "details": "In affected versions of Octopus Server the preview import feature could be leveraged to identify the existence of a target file. This could provide an adversary with information that may aid in further attacks against the server.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0525" + }, + { + "type": "WEB", + "url": "https://advisories.octopus.com/post/2024/sa2025-02" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T10:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-wh5p-642q-7g8m/GHSA-wh5p-642q-7g8m.json b/advisories/unreviewed/2025/02/GHSA-wh5p-642q-7g8m/GHSA-wh5p-642q-7g8m.json new file mode 100644 index 00000000000..1e38048f12f --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-wh5p-642q-7g8m/GHSA-wh5p-642q-7g8m.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wh5p-642q-7g8m", + "modified": "2025-02-11T12:30:54Z", + "published": "2025-02-11T12:30:54Z", + "aliases": [ + "CVE-2024-54090" + ], + "details": "A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All versions), TALON TC Series (BACnet) (All versions). Affected devices contain an out-of-bounds read in the memory dump function.\nThis could allow an attacker with Medium (MED) or higher privileges to cause the device to enter an insecure cold start state.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54090" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-615116.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T11:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-xm77-x3f8-rr93/GHSA-xm77-x3f8-rr93.json b/advisories/unreviewed/2025/02/GHSA-xm77-x3f8-rr93/GHSA-xm77-x3f8-rr93.json new file mode 100644 index 00000000000..c1ec23412bc --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-xm77-x3f8-rr93/GHSA-xm77-x3f8-rr93.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xm77-x3f8-rr93", + "modified": "2025-02-11T12:30:54Z", + "published": "2025-02-11T12:30:54Z", + "aliases": [ + "CVE-2025-0513" + ], + "details": "In affected versions of Octopus Server error messages were handled unsafely on the error page. If an adversary could control any part of the error message they could embed code which may impact the user viewing the error message.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0513" + }, + { + "type": "WEB", + "url": "https://advisories.octopus.com/post/2024/sa2025-04" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T11:15:15Z" + } +} \ No newline at end of file