diff --git a/advisories/unreviewed/2022/05/GHSA-29cc-vcq3-44cf/GHSA-29cc-vcq3-44cf.json b/advisories/unreviewed/2022/05/GHSA-29cc-vcq3-44cf/GHSA-29cc-vcq3-44cf.json index 17198ea36ea..9b437bb5aba 100644 --- a/advisories/unreviewed/2022/05/GHSA-29cc-vcq3-44cf/GHSA-29cc-vcq3-44cf.json +++ b/advisories/unreviewed/2022/05/GHSA-29cc-vcq3-44cf/GHSA-29cc-vcq3-44cf.json @@ -1,19 +1,28 @@ { "schema_version": "1.4.0", "id": "GHSA-29cc-vcq3-44cf", - "modified": "2022-05-24T19:07:43Z", + "modified": "2025-05-13T12:31:35Z", "published": "2022-05-24T19:07:43Z", "aliases": [ "CVE-2021-31895" ], "details": "A vulnerability has been identified in RUGGEDCOM ROS M2100 (All versions < V4.3.7), RUGGEDCOM ROS M2200 (All versions < V4.3.7), RUGGEDCOM ROS M969 (All versions < V4.3.7), RUGGEDCOM ROS RMC (All versions < V4.3.7), RUGGEDCOM ROS RMC20 (All versions < V4.3.7), RUGGEDCOM ROS RMC30 (All versions < V4.3.7), RUGGEDCOM ROS RMC40 (All versions < V4.3.7), RUGGEDCOM ROS RMC41 (All versions < V4.3.7), RUGGEDCOM ROS RMC8388 V4.X (All versions < V4.3.7), RUGGEDCOM ROS RMC8388 V5.X (All versions < V5.5.4), RUGGEDCOM ROS RP110 (All versions < V4.3.7), RUGGEDCOM ROS RS400 (All versions < V4.3.7), RUGGEDCOM ROS RS401 (All versions < V4.3.7), RUGGEDCOM ROS RS416 (All versions < V4.3.7), RUGGEDCOM ROS RS416v2 V4.X (All versions < V4.3.7), RUGGEDCOM ROS RS416v2 V5.X (All versions < 5.5.4), RUGGEDCOM ROS RS8000 (All versions < V4.3.7), RUGGEDCOM ROS RS8000A (All versions < V4.3.7), RUGGEDCOM ROS RS8000H (All versions < V4.3.7), RUGGEDCOM ROS RS8000T (All versions < V4.3.7), RUGGEDCOM ROS RS900 (32M) V4.X (All versions < V4.3.7), RUGGEDCOM ROS RS900 (32M) V5.X (All versions < V5.5.4), RUGGEDCOM ROS RS900G (All versions < V4.3.7), RUGGEDCOM ROS RS900G (32M) V4.X (All versions < V4.3.7), RUGGEDCOM ROS RS900G (32M) V5.X (All versions < V5.5.4), RUGGEDCOM ROS RS900GP (All versions < V4.3.7), RUGGEDCOM ROS RS900L (All versions < V4.3.7), RUGGEDCOM ROS RS900W (All versions < V4.3.7), RUGGEDCOM ROS RS910 (All versions < V4.3.7), RUGGEDCOM ROS RS910L (All versions < V4.3.7), RUGGEDCOM ROS RS910W (All versions < V4.3.7), RUGGEDCOM ROS RS920L (All versions < V4.3.7), RUGGEDCOM ROS RS920W (All versions < V4.3.7), RUGGEDCOM ROS RS930L (All versions < V4.3.7), RUGGEDCOM ROS RS930W (All versions < V4.3.7), RUGGEDCOM ROS RS940G (All versions < V4.3.7), RUGGEDCOM ROS RS969 (All versions < V4.3.7), RUGGEDCOM ROS RSG2100 (32M) V4.X (All versions < V4.3.7), RUGGEDCOM ROS RSG2100 (32M) V5.X (All versions < V5.5.4), RUGGEDCOM ROS RSG2100 V4.X (All versions < V4.3.7), RUGGEDCOM ROS RSG2100P (All versions < V4.3.7), RUGGEDCOM ROS RSG2100P (32M) V4.X (All versions < V4.3.7), RUGGEDCOM ROS RSG2100P (32M) V5.X (All versions < V5.5.4), RUGGEDCOM ROS RSG2200 (All versions < V4.3.7), RUGGEDCOM ROS RSG2288 V4.X (All versions < V4.3.7), RUGGEDCOM ROS RSG2288 V5.X (All versions < V5.5.4), RUGGEDCOM ROS RSG2300 V4.X (All versions < V4.3.7), RUGGEDCOM ROS RSG2300 V5.X (All versions < V5.5.4), RUGGEDCOM ROS RSG2300P V4.X (All versions < V4.3.7), RUGGEDCOM ROS RSG2300P V5.X (All versions < V5.5.4), RUGGEDCOM ROS RSG2488 V4.X (All versions < V4.3.7), RUGGEDCOM ROS RSG2488 V5.X (All versions < V5.5.4), RUGGEDCOM ROS RSG900 V4.X (All versions < V4.3.7), RUGGEDCOM ROS RSG900 V5.X (All versions < V5.5.4), RUGGEDCOM ROS RSG900C (All versions < V5.5.4), RUGGEDCOM ROS RSG900G V4.X (All versions < V4.3.7), RUGGEDCOM ROS RSG900G V5.X (All versions < V5.5.4), RUGGEDCOM ROS RSG900R (All versions < V5.5.4), RUGGEDCOM ROS RSG920P V4.X (All versions < V4.3.7), RUGGEDCOM ROS RSG920P V5.X (All versions < V5.5.4), RUGGEDCOM ROS RSL910 (All versions < V5.5.4), RUGGEDCOM ROS RST2228 (All versions < V5.5.4), RUGGEDCOM ROS RST916C (All versions < V5.5.4), RUGGEDCOM ROS RST916P (All versions < V5.5.4), RUGGEDCOM ROS i800 (All versions < V4.3.7), RUGGEDCOM ROS i801 (All versions < V4.3.7), RUGGEDCOM ROS i802 (All versions < V4.3.7), RUGGEDCOM ROS i803 (All versions < V4.3.7). The DHCP client in affected devices fails to properly sanitize incoming DHCP packets. This could allow an unauthenticated remote attacker to cause memory to be overwritten, potentially allowing remote code execution.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-31895" }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-373591.html" + }, { "type": "WEB", "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-373591.pdf" diff --git a/advisories/unreviewed/2025/01/GHSA-75jh-69xw-fw3p/GHSA-75jh-69xw-fw3p.json b/advisories/unreviewed/2025/01/GHSA-75jh-69xw-fw3p/GHSA-75jh-69xw-fw3p.json index 9251e92e64a..d4962e749f8 100644 --- a/advisories/unreviewed/2025/01/GHSA-75jh-69xw-fw3p/GHSA-75jh-69xw-fw3p.json +++ b/advisories/unreviewed/2025/01/GHSA-75jh-69xw-fw3p/GHSA-75jh-69xw-fw3p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-75jh-69xw-fw3p", - "modified": "2025-01-09T06:30:23Z", + "modified": "2025-05-13T12:31:35Z", "published": "2025-01-09T06:30:23Z", "aliases": [ "CVE-2024-56826" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://github.com/uclouvain/openjpeg/commit/e492644fbded4c820ca55b5e50e598d346e850e8" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7309" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-56826" diff --git a/advisories/unreviewed/2025/01/GHSA-9x68-7qq6-v523/GHSA-9x68-7qq6-v523.json b/advisories/unreviewed/2025/01/GHSA-9x68-7qq6-v523/GHSA-9x68-7qq6-v523.json index ce37cc38bf7..a46475f012c 100644 --- a/advisories/unreviewed/2025/01/GHSA-9x68-7qq6-v523/GHSA-9x68-7qq6-v523.json +++ b/advisories/unreviewed/2025/01/GHSA-9x68-7qq6-v523/GHSA-9x68-7qq6-v523.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9x68-7qq6-v523", - "modified": "2025-03-11T06:30:37Z", + "modified": "2025-05-13T12:31:35Z", "published": "2025-01-14T18:32:00Z", "aliases": [ "CVE-2024-12087" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2600" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7050" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-12087" diff --git a/advisories/unreviewed/2025/01/GHSA-ffph-g3pc-8r3g/GHSA-ffph-g3pc-8r3g.json b/advisories/unreviewed/2025/01/GHSA-ffph-g3pc-8r3g/GHSA-ffph-g3pc-8r3g.json index 6d7ef128e9e..2734a2829c9 100644 --- a/advisories/unreviewed/2025/01/GHSA-ffph-g3pc-8r3g/GHSA-ffph-g3pc-8r3g.json +++ b/advisories/unreviewed/2025/01/GHSA-ffph-g3pc-8r3g/GHSA-ffph-g3pc-8r3g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ffph-g3pc-8r3g", - "modified": "2025-03-11T06:30:38Z", + "modified": "2025-05-13T12:31:35Z", "published": "2025-01-14T18:32:00Z", "aliases": [ "CVE-2024-12088" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2600" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7050" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-12088" diff --git a/advisories/unreviewed/2025/01/GHSA-gp7r-m4cc-qhwq/GHSA-gp7r-m4cc-qhwq.json b/advisories/unreviewed/2025/01/GHSA-gp7r-m4cc-qhwq/GHSA-gp7r-m4cc-qhwq.json index 65df24aeb71..e1509387ed1 100644 --- a/advisories/unreviewed/2025/01/GHSA-gp7r-m4cc-qhwq/GHSA-gp7r-m4cc-qhwq.json +++ b/advisories/unreviewed/2025/01/GHSA-gp7r-m4cc-qhwq/GHSA-gp7r-m4cc-qhwq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gp7r-m4cc-qhwq", - "modified": "2025-03-11T06:30:37Z", + "modified": "2025-05-13T12:31:35Z", "published": "2025-01-14T18:32:00Z", "aliases": [ "CVE-2024-12747" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2600" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7050" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-12747" diff --git a/advisories/unreviewed/2025/01/GHSA-jq5v-29wx-7grq/GHSA-jq5v-29wx-7grq.json b/advisories/unreviewed/2025/01/GHSA-jq5v-29wx-7grq/GHSA-jq5v-29wx-7grq.json index f5fedddc909..eb71680a89b 100644 --- a/advisories/unreviewed/2025/01/GHSA-jq5v-29wx-7grq/GHSA-jq5v-29wx-7grq.json +++ b/advisories/unreviewed/2025/01/GHSA-jq5v-29wx-7grq/GHSA-jq5v-29wx-7grq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jq5v-29wx-7grq", - "modified": "2025-01-09T06:30:23Z", + "modified": "2025-05-13T12:31:35Z", "published": "2025-01-09T06:30:23Z", "aliases": [ "CVE-2024-56827" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://github.com/uclouvain/openjpeg/commit/e492644fbded4c820ca55b5e50e598d346e850e8" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7309" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-56827" diff --git a/advisories/unreviewed/2025/05/GHSA-455w-hjgq-78wr/GHSA-455w-hjgq-78wr.json b/advisories/unreviewed/2025/05/GHSA-455w-hjgq-78wr/GHSA-455w-hjgq-78wr.json new file mode 100644 index 00000000000..1e56da59a1e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-455w-hjgq-78wr/GHSA-455w-hjgq-78wr.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-455w-hjgq-78wr", + "modified": "2025-05-13T12:31:36Z", + "published": "2025-05-13T12:31:36Z", + "aliases": [ + "CVE-2025-40579" + ], + "details": "A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions). Affected devices are vulnerable to a stack-based buffer overflow.\nThis could allow a non-privileged local attacker to execute arbitrary code on the device or to cause a denial of service condition.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40579" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-327438.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T10:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5hmr-m4pw-7777/GHSA-5hmr-m4pw-7777.json b/advisories/unreviewed/2025/05/GHSA-5hmr-m4pw-7777/GHSA-5hmr-m4pw-7777.json new file mode 100644 index 00000000000..a772b4f914b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5hmr-m4pw-7777/GHSA-5hmr-m4pw-7777.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5hmr-m4pw-7777", + "modified": "2025-05-13T12:31:36Z", + "published": "2025-05-13T12:31:36Z", + "aliases": [ + "CVE-2025-40580" + ], + "details": "A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions). Affected devices are vulnerable to a stack-based buffer overflow.\nThis could allow a non-privileged local attacker to execute arbitrary code on the device or to cause a denial of service condition.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40580" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-327438.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T10:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-63xm-x5g2-5gr3/GHSA-63xm-x5g2-5gr3.json b/advisories/unreviewed/2025/05/GHSA-63xm-x5g2-5gr3/GHSA-63xm-x5g2-5gr3.json new file mode 100644 index 00000000000..fa9a7aff7ad --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-63xm-x5g2-5gr3/GHSA-63xm-x5g2-5gr3.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-63xm-x5g2-5gr3", + "modified": "2025-05-13T12:31:36Z", + "published": "2025-05-13T12:31:36Z", + "aliases": [ + "CVE-2025-40573" + ], + "details": "A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions). Affected devices are vulnerable to path traversal attacks.\nThis could allow a privileged local attacker to restore backups that are outside the backup folder.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40573" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-327438.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-35" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T10:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-66q5-cm35-phr2/GHSA-66q5-cm35-phr2.json b/advisories/unreviewed/2025/05/GHSA-66q5-cm35-phr2/GHSA-66q5-cm35-phr2.json new file mode 100644 index 00000000000..debb9937c5a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-66q5-cm35-phr2/GHSA-66q5-cm35-phr2.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-66q5-cm35-phr2", + "modified": "2025-05-13T12:31:35Z", + "published": "2025-05-13T12:31:35Z", + "aliases": [ + "CVE-2024-51445" + ], + "details": "A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.4). The affected application contains a XML External Entity Injection (XXE) vulnerability in the docx import feature. This could allow an authenticated remote attacker to read arbitrary data from the application server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51445" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-162255.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-611" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T10:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-752r-36f2-pch7/GHSA-752r-36f2-pch7.json b/advisories/unreviewed/2025/05/GHSA-752r-36f2-pch7/GHSA-752r-36f2-pch7.json new file mode 100644 index 00000000000..83b675c1b89 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-752r-36f2-pch7/GHSA-752r-36f2-pch7.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-752r-36f2-pch7", + "modified": "2025-05-13T12:31:36Z", + "published": "2025-05-13T12:31:36Z", + "aliases": [ + "CVE-2025-40572" + ], + "details": "A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions). Affected devices do not properly assign permissions to critical ressources.\nThis could allow a non-privileged local attacker to access sensitive information stored on the device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40572" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-327438.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T10:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8c82-4285-724r/GHSA-8c82-4285-724r.json b/advisories/unreviewed/2025/05/GHSA-8c82-4285-724r/GHSA-8c82-4285-724r.json new file mode 100644 index 00000000000..315f14779df --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8c82-4285-724r/GHSA-8c82-4285-724r.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8c82-4285-724r", + "modified": "2025-05-13T12:31:35Z", + "published": "2025-05-13T12:31:35Z", + "aliases": [ + "CVE-2025-24008" + ], + "details": "A vulnerability has been identified in SIRIUS 3RK3 Modular Safety System (MSS) (All versions), SIRIUS Safety Relays 3SK2 (All versions). The affected devices do not encrypt data in transit. An attacker with network access could eavesdrop the connection and retrieve sensitive information, including obfuscated safety passwords.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24008" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-222768.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-311" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T10:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8h7m-cr8f-h7x7/GHSA-8h7m-cr8f-h7x7.json b/advisories/unreviewed/2025/05/GHSA-8h7m-cr8f-h7x7/GHSA-8h7m-cr8f-h7x7.json new file mode 100644 index 00000000000..2482b38f89b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8h7m-cr8f-h7x7/GHSA-8h7m-cr8f-h7x7.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8h7m-cr8f-h7x7", + "modified": "2025-05-13T12:31:36Z", + "published": "2025-05-13T12:31:36Z", + "aliases": [ + "CVE-2025-40571" + ], + "details": "A vulnerability has been identified in Mendix OIDC SSO (Mendix 10 compatible) (All versions < V4.0.0), Mendix OIDC SSO (Mendix 9 compatible) (All versions). The Mendix OIDC SSO module grants read and write access to all tokens exclusively to the Administrator role and could result in privilege misuse by an adversary modifying the module during Mendix development.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40571" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-726617.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T10:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8m8v-2g6r-8jwq/GHSA-8m8v-2g6r-8jwq.json b/advisories/unreviewed/2025/05/GHSA-8m8v-2g6r-8jwq/GHSA-8m8v-2g6r-8jwq.json new file mode 100644 index 00000000000..0e77a7e5190 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8m8v-2g6r-8jwq/GHSA-8m8v-2g6r-8jwq.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8m8v-2g6r-8jwq", + "modified": "2025-05-13T12:31:36Z", + "published": "2025-05-13T12:31:36Z", + "aliases": [ + "CVE-2025-40576" + ], + "details": "A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions). Affected devices do not properly validate incoming Profinet packets.\nAn unauthenticated remote attacker can exploit this flaw by sending a specially crafted malicious packet, which leads to a crash of the dcpd process.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40576" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-327438.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T10:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c22p-h6j4-33wp/GHSA-c22p-h6j4-33wp.json b/advisories/unreviewed/2025/05/GHSA-c22p-h6j4-33wp/GHSA-c22p-h6j4-33wp.json new file mode 100644 index 00000000000..5157addf20c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c22p-h6j4-33wp/GHSA-c22p-h6j4-33wp.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c22p-h6j4-33wp", + "modified": "2025-05-13T12:31:36Z", + "published": "2025-05-13T12:31:35Z", + "aliases": [ + "CVE-2025-30174" + ], + "details": "A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC NMS (All versions), SINEMA Remote Connect (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All versions), Totally Integrated Automation Portal (TIA Portal) V19 (All versions), Totally Integrated Automation Portal (TIA Portal) V20 (All versions), User Management Component (UMC) (All versions < V2.15.1.1). Affected products contain a out of bound read buffer overflow vulnerability in the integrated UMC component. This could allow an unauthenticated remote attacker to cause a denial of service condition.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30174" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-614723.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T10:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c7rq-qv3j-63j3/GHSA-c7rq-qv3j-63j3.json b/advisories/unreviewed/2025/05/GHSA-c7rq-qv3j-63j3/GHSA-c7rq-qv3j-63j3.json new file mode 100644 index 00000000000..842f4967c89 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c7rq-qv3j-63j3/GHSA-c7rq-qv3j-63j3.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c7rq-qv3j-63j3", + "modified": "2025-05-13T12:31:36Z", + "published": "2025-05-13T12:31:36Z", + "aliases": [ + "CVE-2025-40556" + ], + "details": "A vulnerability has been identified in BACnet ATEC 550-440 (All versions), BACnet ATEC 550-441 (All versions), BACnet ATEC 550-445 (All versions), BACnet ATEC 550-446 (All versions). Affected devices improperly handle specific incoming BACnet MSTP messages. This could allow an attacker residing in the same BACnet network to send a specially crafted MSTP message that results in a denial of service condition of the targeted device. A power cycle is required to restore the device's normal operation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40556" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-828116.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T10:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-cf66-qpgq-6m7r/GHSA-cf66-qpgq-6m7r.json b/advisories/unreviewed/2025/05/GHSA-cf66-qpgq-6m7r/GHSA-cf66-qpgq-6m7r.json new file mode 100644 index 00000000000..c3a317ad73f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-cf66-qpgq-6m7r/GHSA-cf66-qpgq-6m7r.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cf66-qpgq-6m7r", + "modified": "2025-05-13T12:31:37Z", + "published": "2025-05-13T12:31:37Z", + "aliases": [ + "CVE-2025-4647" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon web allows Reflected XSS.\n\nA user with elevated privileges can bypass sanitization measures by replacing the content of an existing SVG.\n\nThis issue affects web: from 24.10.0 before 24.10.5, from 24.04.0 before 24.04.11, from 23.10.0 before 23.10.22, from 23.04.0 before 23.04.27, from 22.10.0 before 22.10.29.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4647" + }, + { + "type": "WEB", + "url": "https://github.com/centreon/centreon/releases" + }, + { + "type": "WEB", + "url": "https://thewatch.centreon.com/latest-security-bulletins-64/cve-2024-55574-centreon-web-high-severity-4435" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T10:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-cq6m-j4vh-qx8f/GHSA-cq6m-j4vh-qx8f.json b/advisories/unreviewed/2025/05/GHSA-cq6m-j4vh-qx8f/GHSA-cq6m-j4vh-qx8f.json new file mode 100644 index 00000000000..272ed03f06d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-cq6m-j4vh-qx8f/GHSA-cq6m-j4vh-qx8f.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cq6m-j4vh-qx8f", + "modified": "2025-05-13T12:31:36Z", + "published": "2025-05-13T12:31:36Z", + "aliases": [ + "CVE-2025-40577" + ], + "details": "A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions). Affected devices do not properly validate incoming Profinet packets.\nAn unauthenticated remote attacker can exploit this flaw by sending a specially crafted malicious packet, which leads to a crash of the dcpd process.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40577" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-327438.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T10:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-cx4x-4wcx-cq8q/GHSA-cx4x-4wcx-cq8q.json b/advisories/unreviewed/2025/05/GHSA-cx4x-4wcx-cq8q/GHSA-cx4x-4wcx-cq8q.json new file mode 100644 index 00000000000..468e298b058 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-cx4x-4wcx-cq8q/GHSA-cx4x-4wcx-cq8q.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cx4x-4wcx-cq8q", + "modified": "2025-05-13T12:31:35Z", + "published": "2025-05-13T12:31:35Z", + "aliases": [ + "CVE-2025-26390" + ], + "details": "A vulnerability has been identified in OZW672 (All versions < V6.0), OZW772 (All versions < V6.0). The web service of affected devices is vulnerable to SQL injection when checking authentication data. This could allow an unauthenticated remote attacker to bypass the check and authenticate as\nAdministrator user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26390" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-047424.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T10:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-f3qq-3q9x-c7ch/GHSA-f3qq-3q9x-c7ch.json b/advisories/unreviewed/2025/05/GHSA-f3qq-3q9x-c7ch/GHSA-f3qq-3q9x-c7ch.json new file mode 100644 index 00000000000..545d24b8400 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-f3qq-3q9x-c7ch/GHSA-f3qq-3q9x-c7ch.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f3qq-3q9x-c7ch", + "modified": "2025-05-13T12:31:36Z", + "published": "2025-05-13T12:31:36Z", + "aliases": [ + "CVE-2025-40574" + ], + "details": "A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions). Affected devices do not properly assign permissions to critical ressources.\nThis could allow a non-privileged local attacker to interact with the backupmanager service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40574" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-327438.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T10:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fjcf-72jr-936x/GHSA-fjcf-72jr-936x.json b/advisories/unreviewed/2025/05/GHSA-fjcf-72jr-936x/GHSA-fjcf-72jr-936x.json new file mode 100644 index 00000000000..9f6ff6d3129 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fjcf-72jr-936x/GHSA-fjcf-72jr-936x.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fjcf-72jr-936x", + "modified": "2025-05-13T12:31:35Z", + "published": "2025-05-13T12:31:35Z", + "aliases": [ + "CVE-2024-51444" + ], + "details": "A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.4). The application insufficiently validates user input for database read queries. This could allow an authenticated remote attacker to conduct an SQL injection attack that bypasses authorization controls and allows to download any data from the application's database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51444" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-162255.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T10:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g2fj-8g9p-p2rc/GHSA-g2fj-8g9p-p2rc.json b/advisories/unreviewed/2025/05/GHSA-g2fj-8g9p-p2rc/GHSA-g2fj-8g9p-p2rc.json new file mode 100644 index 00000000000..da052a07c6c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g2fj-8g9p-p2rc/GHSA-g2fj-8g9p-p2rc.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g2fj-8g9p-p2rc", + "modified": "2025-05-13T12:31:36Z", + "published": "2025-05-13T12:31:36Z", + "aliases": [ + "CVE-2025-40578" + ], + "details": "A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions). Affected devices do not properly handle multiple incoming Profinet packets received in rapid succession.\nAn unauthenticated remote attacker can exploit this flaw by sending multiple packets in a very short time frame, which leads to a crash of the dcpd process.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40578" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-327438.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T10:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g7c3-cgww-3fw7/GHSA-g7c3-cgww-3fw7.json b/advisories/unreviewed/2025/05/GHSA-g7c3-cgww-3fw7/GHSA-g7c3-cgww-3fw7.json new file mode 100644 index 00000000000..bb338194cd6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g7c3-cgww-3fw7/GHSA-g7c3-cgww-3fw7.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g7c3-cgww-3fw7", + "modified": "2025-05-13T12:31:36Z", + "published": "2025-05-13T12:31:36Z", + "aliases": [ + "CVE-2025-40583" + ], + "details": "A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions with SINEMA Remote Connect Edge Client installed). Affected devices do transmit sensitive information in cleartext.\nThis could allow a privileged local attacker to retrieve this sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40583" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-327438.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-319" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T10:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g96q-8ghc-48j6/GHSA-g96q-8ghc-48j6.json b/advisories/unreviewed/2025/05/GHSA-g96q-8ghc-48j6/GHSA-g96q-8ghc-48j6.json new file mode 100644 index 00000000000..a10cab8cbb1 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g96q-8ghc-48j6/GHSA-g96q-8ghc-48j6.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g96q-8ghc-48j6", + "modified": "2025-05-13T12:31:35Z", + "published": "2025-05-13T12:31:35Z", + "aliases": [ + "CVE-2024-51446" + ], + "details": "A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.4). The file upload feature of the affected application improperly sanitizes xml files. This could allow an authenticated remote attacker to conduct a stored cross-site scripting attack by uploading specially crafted xml files that are later downloaded and viewed by other users of the application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51446" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-162255.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T10:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gfrm-qw97-m8m8/GHSA-gfrm-qw97-m8m8.json b/advisories/unreviewed/2025/05/GHSA-gfrm-qw97-m8m8/GHSA-gfrm-qw97-m8m8.json new file mode 100644 index 00000000000..fc14f9de2f7 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gfrm-qw97-m8m8/GHSA-gfrm-qw97-m8m8.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gfrm-qw97-m8m8", + "modified": "2025-05-13T12:31:36Z", + "published": "2025-05-13T12:31:36Z", + "aliases": [ + "CVE-2025-31929" + ], + "details": "A vulnerability has been identified in IEC 1Ph 7.4kW Child socket (8EM1310-2EH04-0GA0) (All versions), IEC 1Ph 7.4kW Child socket/ shutter (8EM1310-2EN04-0GA0) (All versions), IEC 1Ph 7.4kW Parent cable 7m (8EM1310-2EJ04-3GA1) (All versions), IEC 1Ph 7.4kW Parent cable 7m incl. SIM (8EM1310-2EJ04-3GA2) (All versions), IEC 1Ph 7.4kW Parent socket (8EM1310-2EH04-3GA1) (All versions), IEC 1Ph 7.4kW Parent socket incl. SIM (8EM1310-2EH04-3GA2) (All versions), IEC 1Ph 7.4kW Parent socket/ shutter (8EM1310-2EN04-3GA1) (All versions), IEC 1Ph 7.4kW Parent socket/ shutter SIM (8EM1310-2EN04-3GA2) (All versions), IEC 3Ph 22kW Child cable 7m (8EM1310-3EJ04-0GA0) (All versions), IEC 3Ph 22kW Child socket (8EM1310-3EH04-0GA0) (All versions), IEC 3Ph 22kW Child socket/ shutter (8EM1310-3EN04-0GA0) (All versions), IEC 3Ph 22kW Parent cable 7m (8EM1310-3EJ04-3GA1) (All versions), IEC 3Ph 22kW Parent cable 7m incl. SIM (8EM1310-3EJ04-3GA2) (All versions), IEC 3Ph 22kW Parent socket (8EM1310-3EH04-3GA1) (All versions), IEC 3Ph 22kW Parent socket incl. SIM (8EM1310-3EH04-3GA2) (All versions), IEC 3Ph 22kW Parent socket/ shutter (8EM1310-3EN04-3GA1) (All versions), IEC 3Ph 22kW Parent socket/ shutter SIM (8EM1310-3EN04-3GA2) (All versions), IEC ERK 3Ph 22 kW Child cable 7m (8EM1310-3FJ04-0GA0) (All versions), IEC ERK 3Ph 22 kW Child cable 7m (8EM1310-3FJ04-0GA1) (All versions), IEC ERK 3Ph 22 kW Child cable 7m (8EM1310-3FJ04-0GA2) (All versions), IEC ERK 3Ph 22 kW Child socket (8EM1310-3FH04-0GA0) (All versions), IEC ERK 3Ph 22 kW Parent socket (8EM1310-3FH04-3GA1) (All versions), IEC ERK 3Ph 22 kW Parent socket incl. SI (8EM1310-3FH04-3GA2) (All versions), UL Commercial Cellular 48A NTEP (8EM1310-5HF14-1GA2) (All versions), UL Commercial Child 40A w/ 15118 HW (8EM1310-4CF14-0GA0) (All versions), UL Commercial Child 48A BA Compliant (8EM1315-5CG14-0GA0) (All versions), UL Commercial Child 48A w/ 15118 HW (8EM1310-5CF14-0GA0) (All versions), UL Commercial Parent 40A with Simcard (8EM1310-4CF14-1GA2) (All versions), UL Commercial Parent 48A (USPS) (8EM1317-5CG14-1GA2) (All versions), UL Commercial Parent 48A BA Compliant (8EM1315-5CG14-1GA2) (All versions), UL Commercial Parent 48A with Simcard BA (8EM1310-5CF14-1GA2) (All versions), UL Commercial Parent 48A, 15118, 25ft (8EM1310-5CG14-1GA1) (All versions), UL Commercial Parent 48A, 15118, 25ft (8EM1314-5CG14-2FA2) (All versions), UL Commercial Parent 48A, 15118, 25ft (8EM1315-5HG14-1GA2) (All versions), UL Commercial Parent 48A,15118 25ft Sim (8EM1310-5CG14-1GA2) (All versions), UL Resi High End 40A w/15118 Hw (8EM1312-4CF18-0FA3) (All versions), UL Resi High End 48A w/15118 Hw (8EM1312-5CF18-0FA3) (All versions), VersiCharge Blue™ 80A AC Cellular (8EM1315-7BG16-1FH2) (All versions). Affected devices do not contain an Immutable Root of Trust in M0 Hardware. An attacker with physical access to the device could use this to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31929" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-556937.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1326" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T10:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h46g-35r6-chx9/GHSA-h46g-35r6-chx9.json b/advisories/unreviewed/2025/05/GHSA-h46g-35r6-chx9/GHSA-h46g-35r6-chx9.json new file mode 100644 index 00000000000..b8ba75096ad --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h46g-35r6-chx9/GHSA-h46g-35r6-chx9.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h46g-35r6-chx9", + "modified": "2025-05-13T12:31:37Z", + "published": "2025-05-13T12:31:37Z", + "aliases": [ + "CVE-2025-4648" + ], + "details": "Download of Code Without Integrity Check vulnerability in Centreon web allows Reflected XSS.\nA user with elevated privileges can inject XSS by altering the content of a SVG media during the submit request.\nThis issue affects web: from 24.10.0 before 24.10.5, from 24.04.0 before 24.04.11, from 23.10.0 before 23.10.22, from 23.04.0 before 23.04.27, from 22.10.0 before 22.10.29.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4648" + }, + { + "type": "WEB", + "url": "https://github.com/centreon/centreon/releases" + }, + { + "type": "WEB", + "url": "https://thewatch.centreon.com/latest-security-bulletins-64/cve-2024-55575-centreon-web-high-severity-4434" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-494" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T10:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hww9-6wv5-mrp9/GHSA-hww9-6wv5-mrp9.json b/advisories/unreviewed/2025/05/GHSA-hww9-6wv5-mrp9/GHSA-hww9-6wv5-mrp9.json new file mode 100644 index 00000000000..17e648945a0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hww9-6wv5-mrp9/GHSA-hww9-6wv5-mrp9.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hww9-6wv5-mrp9", + "modified": "2025-05-13T12:31:36Z", + "published": "2025-05-13T12:31:36Z", + "aliases": [ + "CVE-2025-40582" + ], + "details": "A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions with SINEMA Remote Connect Edge Client installed). Affected devices do not properly sanitize configuration parameters.\nThis could allow a non-privileged local attacker to execute root commands on the device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40582" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-327438.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T10:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-j876-75h4-8xcg/GHSA-j876-75h4-8xcg.json b/advisories/unreviewed/2025/05/GHSA-j876-75h4-8xcg/GHSA-j876-75h4-8xcg.json new file mode 100644 index 00000000000..2d4671d9512 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-j876-75h4-8xcg/GHSA-j876-75h4-8xcg.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j876-75h4-8xcg", + "modified": "2025-05-13T12:31:37Z", + "published": "2025-05-13T12:31:37Z", + "aliases": [ + "CVE-2025-4649" + ], + "details": "Improper Privilege Management vulnerability in Centreon web allows Privilege Escalation.\nACL are not correctly taken into account in the display of the \"event logs\" page. This page requiring, high privileges, will display all available logs.\n\n\nThis issue affects web: from 24.10.3 before 24.10.4, from 24.04.09 before 24.04.10, from 23.10.19 before 23.10.21, from 23.04.24 before 23.04.26.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4649" + }, + { + "type": "WEB", + "url": "https://github.com/centreon/centreon/releases" + }, + { + "type": "WEB", + "url": "https://thewatch.centreon.com/latest-security-bulletins-64/centreon-web-medium-severity-4349" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T12:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jqfw-j9gv-q6cp/GHSA-jqfw-j9gv-q6cp.json b/advisories/unreviewed/2025/05/GHSA-jqfw-j9gv-q6cp/GHSA-jqfw-j9gv-q6cp.json new file mode 100644 index 00000000000..a551e5d89f3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jqfw-j9gv-q6cp/GHSA-jqfw-j9gv-q6cp.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jqfw-j9gv-q6cp", + "modified": "2025-05-13T12:31:36Z", + "published": "2025-05-13T12:31:36Z", + "aliases": [ + "CVE-2025-31930" + ], + "details": "A vulnerability has been identified in IEC 1Ph 7.4kW Child socket (8EM1310-2EH04-0GA0) (All versions < V2.135), IEC 1Ph 7.4kW Child socket/ shutter (8EM1310-2EN04-0GA0) (All versions < V2.135), IEC 1Ph 7.4kW Parent cable 7m (8EM1310-2EJ04-3GA1) (All versions < V2.135), IEC 1Ph 7.4kW Parent cable 7m incl. SIM (8EM1310-2EJ04-3GA2) (All versions < V2.135), IEC 1Ph 7.4kW Parent socket (8EM1310-2EH04-3GA1) (All versions < V2.135), IEC 1Ph 7.4kW Parent socket incl. SIM (8EM1310-2EH04-3GA2) (All versions < V2.135), IEC 1Ph 7.4kW Parent socket/ shutter (8EM1310-2EN04-3GA1) (All versions < V2.135), IEC 1Ph 7.4kW Parent socket/ shutter SIM (8EM1310-2EN04-3GA2) (All versions < V2.135), IEC 3Ph 22kW Child cable 7m (8EM1310-3EJ04-0GA0) (All versions < V2.135), IEC 3Ph 22kW Child socket (8EM1310-3EH04-0GA0) (All versions < V2.135), IEC 3Ph 22kW Child socket/ shutter (8EM1310-3EN04-0GA0) (All versions < V2.135), IEC 3Ph 22kW Parent cable 7m (8EM1310-3EJ04-3GA1) (All versions < V2.135), IEC 3Ph 22kW Parent cable 7m incl. SIM (8EM1310-3EJ04-3GA2) (All versions < V2.135), IEC 3Ph 22kW Parent socket (8EM1310-3EH04-3GA1) (All versions < V2.135), IEC 3Ph 22kW Parent socket incl. SIM (8EM1310-3EH04-3GA2) (All versions < V2.135), IEC 3Ph 22kW Parent socket/ shutter (8EM1310-3EN04-3GA1) (All versions < V2.135), IEC 3Ph 22kW Parent socket/ shutter SIM (8EM1310-3EN04-3GA2) (All versions < V2.135), IEC ERK 3Ph 22 kW Child cable 7m (8EM1310-3FJ04-0GA0) (All versions < V2.135), IEC ERK 3Ph 22 kW Child cable 7m (8EM1310-3FJ04-0GA1) (All versions < V2.135), IEC ERK 3Ph 22 kW Child cable 7m (8EM1310-3FJ04-0GA2) (All versions < V2.135), IEC ERK 3Ph 22 kW Child socket (8EM1310-3FH04-0GA0) (All versions < V2.135), IEC ERK 3Ph 22 kW Parent socket (8EM1310-3FH04-3GA1) (All versions < V2.135), IEC ERK 3Ph 22 kW Parent socket incl. SI (8EM1310-3FH04-3GA2) (All versions < V2.135), UL Commercial Cellular 48A NTEP (8EM1310-5HF14-1GA2) (All versions < V2.135), UL Commercial Child 40A w/ 15118 HW (8EM1310-4CF14-0GA0) (All versions < V2.135), UL Commercial Child 48A BA Compliant (8EM1315-5CG14-0GA0) (All versions < V2.135), UL Commercial Child 48A w/ 15118 HW (8EM1310-5CF14-0GA0) (All versions < V2.135), UL Commercial Parent 40A with Simcard (8EM1310-4CF14-1GA2) (All versions < V2.135), UL Commercial Parent 48A (USPS) (8EM1317-5CG14-1GA2) (All versions < V2.135), UL Commercial Parent 48A BA Compliant (8EM1315-5CG14-1GA2) (All versions < V2.135), UL Commercial Parent 48A with Simcard BA (8EM1310-5CF14-1GA2) (All versions < V2.135), UL Commercial Parent 48A, 15118, 25ft (8EM1310-5CG14-1GA1) (All versions < V2.135), UL Commercial Parent 48A, 15118, 25ft (8EM1314-5CG14-2FA2) (All versions < V2.135), UL Commercial Parent 48A, 15118, 25ft (8EM1315-5HG14-1GA2) (All versions < V2.135), UL Commercial Parent 48A,15118 25ft Sim (8EM1310-5CG14-1GA2) (All versions < V2.135), VersiCharge Blue™ 80A AC Cellular (8EM1315-7BG16-1FH2) (All versions < V2.135). Affected devices contain Modbus service enabled by default. This could allow an attacker connected to the same network to remotely control the EV charger.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31930" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-556937.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1188" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T10:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mhmm-4g6x-6p5g/GHSA-mhmm-4g6x-6p5g.json b/advisories/unreviewed/2025/05/GHSA-mhmm-4g6x-6p5g/GHSA-mhmm-4g6x-6p5g.json new file mode 100644 index 00000000000..ef61077af0f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mhmm-4g6x-6p5g/GHSA-mhmm-4g6x-6p5g.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mhmm-4g6x-6p5g", + "modified": "2025-05-13T12:31:35Z", + "published": "2025-05-13T12:31:35Z", + "aliases": [ + "CVE-2025-26389" + ], + "details": "A vulnerability has been identified in OZW672 (All versions < V8.0), OZW772 (All versions < V8.0). The web service in affected devices does not sanitize the input parameters required for the `exportDiagramPage` endpoint. This could allow an unauthenticated remote attacker to execute arbitrary code with root privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26389" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-047424.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T10:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p7rr-mpvr-c5pf/GHSA-p7rr-mpvr-c5pf.json b/advisories/unreviewed/2025/05/GHSA-p7rr-mpvr-c5pf/GHSA-p7rr-mpvr-c5pf.json new file mode 100644 index 00000000000..c2ae95cc853 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p7rr-mpvr-c5pf/GHSA-p7rr-mpvr-c5pf.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p7rr-mpvr-c5pf", + "modified": "2025-05-13T12:31:36Z", + "published": "2025-05-13T12:31:36Z", + "aliases": [ + "CVE-2025-30175" + ], + "details": "A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC NMS (All versions), SINEMA Remote Connect (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All versions), Totally Integrated Automation Portal (TIA Portal) V19 (All versions), Totally Integrated Automation Portal (TIA Portal) V20 (All versions), User Management Component (UMC) (All versions < V2.15.1.1). Affected products contain a out of bound write buffer overflow vulnerability in the integrated UMC component. This could allow an unauthenticated remote attacker to cause a denial of service condition.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30175" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-614723.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T10:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-pjf7-53hh-vgg4/GHSA-pjf7-53hh-vgg4.json b/advisories/unreviewed/2025/05/GHSA-pjf7-53hh-vgg4/GHSA-pjf7-53hh-vgg4.json new file mode 100644 index 00000000000..bc73633992a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pjf7-53hh-vgg4/GHSA-pjf7-53hh-vgg4.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pjf7-53hh-vgg4", + "modified": "2025-05-13T12:31:35Z", + "published": "2025-05-13T12:31:35Z", + "aliases": [ + "CVE-2025-24007" + ], + "details": "A vulnerability has been identified in SIRIUS 3RK3 Modular Safety System (MSS) (All versions), SIRIUS Safety Relays 3SK2 (All versions). Affected devices only provide weak password obfuscation. An attacker with network access could retrieve and de-obfuscate the safety password used for protection against inadvertent operating errors.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24007" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-222768.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-327" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T10:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q45j-65gq-r3p6/GHSA-q45j-65gq-r3p6.json b/advisories/unreviewed/2025/05/GHSA-q45j-65gq-r3p6/GHSA-q45j-65gq-r3p6.json new file mode 100644 index 00000000000..239ffe2afea --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q45j-65gq-r3p6/GHSA-q45j-65gq-r3p6.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q45j-65gq-r3p6", + "modified": "2025-05-13T12:31:37Z", + "published": "2025-05-13T12:31:36Z", + "aliases": [ + "CVE-2025-4646" + ], + "details": "Improper Privilege Management vulnerability in Centreon web (API Token creation form modules) allows Privilege Escalation.This issue affects web: from 24.04.0 before 24.04.10, from 24.10.0 before 24.10.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4646" + }, + { + "type": "WEB", + "url": "https://github.com/centreon/centreon/releases" + }, + { + "type": "WEB", + "url": "https://thewatch.centreon.com/latest-security-bulletins-64/cve-2024-55572-centreon-web-high-severity-4460" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T10:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q7j8-2mcw-6rrm/GHSA-q7j8-2mcw-6rrm.json b/advisories/unreviewed/2025/05/GHSA-q7j8-2mcw-6rrm/GHSA-q7j8-2mcw-6rrm.json new file mode 100644 index 00000000000..a0f01757215 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q7j8-2mcw-6rrm/GHSA-q7j8-2mcw-6rrm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q7j8-2mcw-6rrm", + "modified": "2025-05-13T12:31:37Z", + "published": "2025-05-13T12:31:37Z", + "aliases": [ + "CVE-2025-32917" + ], + "details": "Privilege escalation in jar_signature agent plugin in Checkmk versions <2.4.0b7 (beta), <2.3.0p32, <2.2.0p42, and 2.1.0p49 (EOL) allow user with write access to JAVA_HOME/bin directory to escalate privileges.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32917" + }, + { + "type": "WEB", + "url": "https://checkmk.com/werk/17985" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T11:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q7v7-jhxh-rv68/GHSA-q7v7-jhxh-rv68.json b/advisories/unreviewed/2025/05/GHSA-q7v7-jhxh-rv68/GHSA-q7v7-jhxh-rv68.json new file mode 100644 index 00000000000..c6aaaca1975 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q7v7-jhxh-rv68/GHSA-q7v7-jhxh-rv68.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q7v7-jhxh-rv68", + "modified": "2025-05-13T12:31:36Z", + "published": "2025-05-13T12:31:36Z", + "aliases": [ + "CVE-2025-32454" + ], + "details": "A vulnerability has been identified in Teamcenter Visualization V14.3 (All versions < V14.3.0.14), Teamcenter Visualization V2312 (All versions < V2312.0010), Teamcenter Visualization V2406 (All versions < V2406.0008), Teamcenter Visualization V2412 (All versions < V2412.0004). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted WRL files.\nThis could allow an attacker to execute code in the context of the current process.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32454" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-542540.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T10:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qchf-893f-x2hx/GHSA-qchf-893f-x2hx.json b/advisories/unreviewed/2025/05/GHSA-qchf-893f-x2hx/GHSA-qchf-893f-x2hx.json new file mode 100644 index 00000000000..bca3cb1ef88 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qchf-893f-x2hx/GHSA-qchf-893f-x2hx.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qchf-893f-x2hx", + "modified": "2025-05-13T12:31:36Z", + "published": "2025-05-13T12:31:36Z", + "aliases": [ + "CVE-2025-33025" + ], + "details": "A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versions < V2.16.5), RUGGEDCOM ROX RX1400 (All versions < V2.16.5), RUGGEDCOM ROX RX1500 (All versions < V2.16.5), RUGGEDCOM ROX RX1501 (All versions < V2.16.5), RUGGEDCOM ROX RX1510 (All versions < V2.16.5), RUGGEDCOM ROX RX1511 (All versions < V2.16.5), RUGGEDCOM ROX RX1512 (All versions < V2.16.5), RUGGEDCOM ROX RX1524 (All versions < V2.16.5), RUGGEDCOM ROX RX1536 (All versions < V2.16.5), RUGGEDCOM ROX RX5000 (All versions < V2.16.5). The 'traceroute' tool in the web interface of affected devices is vulnerable to command injection due to missing server side input sanitation. This could allow an authenticated remote attacker to execute arbitrary code with root privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33025" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-301229.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-602" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T10:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rq2h-x4xh-35w4/GHSA-rq2h-x4xh-35w4.json b/advisories/unreviewed/2025/05/GHSA-rq2h-x4xh-35w4/GHSA-rq2h-x4xh-35w4.json new file mode 100644 index 00000000000..64bf56953ca --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rq2h-x4xh-35w4/GHSA-rq2h-x4xh-35w4.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rq2h-x4xh-35w4", + "modified": "2025-05-13T12:31:36Z", + "published": "2025-05-13T12:31:36Z", + "aliases": [ + "CVE-2025-30176" + ], + "details": "A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC NMS (All versions), SINEMA Remote Connect (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All versions), Totally Integrated Automation Portal (TIA Portal) V19 (All versions), Totally Integrated Automation Portal (TIA Portal) V20 (All versions), User Management Component (UMC) (All versions < V2.15.1.1). Affected products contain a out of bound read buffer overflow vulnerability in the integrated UMC component. This could allow an unauthenticated remote attacker to cause a denial of service condition.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30176" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-614723.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T10:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v694-m53f-r3vf/GHSA-v694-m53f-r3vf.json b/advisories/unreviewed/2025/05/GHSA-v694-m53f-r3vf/GHSA-v694-m53f-r3vf.json new file mode 100644 index 00000000000..20afec554c4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v694-m53f-r3vf/GHSA-v694-m53f-r3vf.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v694-m53f-r3vf", + "modified": "2025-05-13T12:31:35Z", + "published": "2025-05-13T12:31:35Z", + "aliases": [ + "CVE-2025-24510" + ], + "details": "A vulnerability has been identified in MS/TP Point Pickup Module (All versions). Affected devices improperly handle specific incoming BACnet MSTP messages. This could allow an attacker residing in the same BACnet network to send a specially crafted MSTP message that results in a denial of service condition of the targeted device. A power cycle is required to restore the device's normal operation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24510" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-668154.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T10:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v8m4-8x6v-c5jw/GHSA-v8m4-8x6v-c5jw.json b/advisories/unreviewed/2025/05/GHSA-v8m4-8x6v-c5jw/GHSA-v8m4-8x6v-c5jw.json new file mode 100644 index 00000000000..ba39adb2950 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v8m4-8x6v-c5jw/GHSA-v8m4-8x6v-c5jw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v8m4-8x6v-c5jw", + "modified": "2025-05-13T12:31:36Z", + "published": "2025-05-13T12:31:36Z", + "aliases": [ + "CVE-2025-40628" + ], + "details": "SQL injection vulnerability in DomainsPRO 1.2. This vulnerability could allow an attacker to retrieve, create, update and delete databases via the “d” parameter in the “/article.php” endpoint.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40628" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/sql-injection-domainspro" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T10:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vj87-7w3c-ghmp/GHSA-vj87-7w3c-ghmp.json b/advisories/unreviewed/2025/05/GHSA-vj87-7w3c-ghmp/GHSA-vj87-7w3c-ghmp.json new file mode 100644 index 00000000000..b6fc1665121 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vj87-7w3c-ghmp/GHSA-vj87-7w3c-ghmp.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vj87-7w3c-ghmp", + "modified": "2025-05-13T12:31:36Z", + "published": "2025-05-13T12:31:36Z", + "aliases": [ + "CVE-2025-40555" + ], + "details": "A vulnerability has been identified in APOGEE PXC+TALON TC Series (BACnet) (All versions). Affected devices start sending unsolicited BACnet broadcast messages after processing a specific BACnet createObject request. This could allow an attacker residing in the same BACnet network to send a specially crafted message that results in a partial denial of service condition of the targeted device, and potentially reduce the availability of BACnet network. A power cycle is required to restore the device's normal operation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40555" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-718393.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-440" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T10:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vvww-6fqh-6jvq/GHSA-vvww-6fqh-6jvq.json b/advisories/unreviewed/2025/05/GHSA-vvww-6fqh-6jvq/GHSA-vvww-6fqh-6jvq.json new file mode 100644 index 00000000000..51eba69023a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vvww-6fqh-6jvq/GHSA-vvww-6fqh-6jvq.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vvww-6fqh-6jvq", + "modified": "2025-05-13T12:31:36Z", + "published": "2025-05-13T12:31:36Z", + "aliases": [ + "CVE-2025-40575" + ], + "details": "A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions). Affected devices do not properly validate incoming Profinet packets.\nAn unauthenticated remote attacker can exploit this flaw by sending a specially crafted malicious packet, which leads to a crash of the dcpd\nprocess.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40575" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-327438.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-457" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T10:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w4g2-c8px-8c79/GHSA-w4g2-c8px-8c79.json b/advisories/unreviewed/2025/05/GHSA-w4g2-c8px-8c79/GHSA-w4g2-c8px-8c79.json new file mode 100644 index 00000000000..15ed253c524 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w4g2-c8px-8c79/GHSA-w4g2-c8px-8c79.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w4g2-c8px-8c79", + "modified": "2025-05-13T12:31:36Z", + "published": "2025-05-13T12:31:36Z", + "aliases": [ + "CVE-2025-32469" + ], + "details": "A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versions < V2.16.5), RUGGEDCOM ROX RX1400 (All versions < V2.16.5), RUGGEDCOM ROX RX1500 (All versions < V2.16.5), RUGGEDCOM ROX RX1501 (All versions < V2.16.5), RUGGEDCOM ROX RX1510 (All versions < V2.16.5), RUGGEDCOM ROX RX1511 (All versions < V2.16.5), RUGGEDCOM ROX RX1512 (All versions < V2.16.5), RUGGEDCOM ROX RX1524 (All versions < V2.16.5), RUGGEDCOM ROX RX1536 (All versions < V2.16.5), RUGGEDCOM ROX RX5000 (All versions < V2.16.5). The 'ping' tool in the web interface of affected devices is vulnerable to command injection due to missing server side input sanitation. This could allow an authenticated remote attacker to execute arbitrary code with root privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32469" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-301229.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-602" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T10:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wmm5-59wm-x34p/GHSA-wmm5-59wm-x34p.json b/advisories/unreviewed/2025/05/GHSA-wmm5-59wm-x34p/GHSA-wmm5-59wm-x34p.json new file mode 100644 index 00000000000..2f47a58c5f5 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wmm5-59wm-x34p/GHSA-wmm5-59wm-x34p.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wmm5-59wm-x34p", + "modified": "2025-05-13T12:31:36Z", + "published": "2025-05-13T12:31:36Z", + "aliases": [ + "CVE-2025-40566" + ], + "details": "A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions < V4.1 Update 3), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1). Affected products do not correctly invalidate user sessions upon user logout. This could allow a remote unauthenticated attacker, who has obtained the session token by other means, to re-use a legitimate user's session even after logout.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40566" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-339086.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-613" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T10:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-x6hg-98ph-g733/GHSA-x6hg-98ph-g733.json b/advisories/unreviewed/2025/05/GHSA-x6hg-98ph-g733/GHSA-x6hg-98ph-g733.json new file mode 100644 index 00000000000..3e633c36654 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-x6hg-98ph-g733/GHSA-x6hg-98ph-g733.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x6hg-98ph-g733", + "modified": "2025-05-13T12:31:36Z", + "published": "2025-05-13T12:31:36Z", + "aliases": [ + "CVE-2025-33024" + ], + "details": "A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versions < V2.16.5), RUGGEDCOM ROX RX1400 (All versions < V2.16.5), RUGGEDCOM ROX RX1500 (All versions < V2.16.5), RUGGEDCOM ROX RX1501 (All versions < V2.16.5), RUGGEDCOM ROX RX1510 (All versions < V2.16.5), RUGGEDCOM ROX RX1511 (All versions < V2.16.5), RUGGEDCOM ROX RX1512 (All versions < V2.16.5), RUGGEDCOM ROX RX1524 (All versions < V2.16.5), RUGGEDCOM ROX RX1536 (All versions < V2.16.5), RUGGEDCOM ROX RX5000 (All versions < V2.16.5). The 'tcpdump' tool in the web interface of affected devices is vulnerable to command injection due to missing server side input sanitation. This could allow an authenticated remote attacker to execute arbitrary code with root privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33024" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-301229.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-602" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T10:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-x7gm-r2wp-mg4v/GHSA-x7gm-r2wp-mg4v.json b/advisories/unreviewed/2025/05/GHSA-x7gm-r2wp-mg4v/GHSA-x7gm-r2wp-mg4v.json new file mode 100644 index 00000000000..c275c512b1c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-x7gm-r2wp-mg4v/GHSA-x7gm-r2wp-mg4v.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x7gm-r2wp-mg4v", + "modified": "2025-05-13T12:31:35Z", + "published": "2025-05-13T12:31:35Z", + "aliases": [ + "CVE-2025-24009" + ], + "details": "A vulnerability has been identified in SIRIUS 3RK3 Modular Safety System (MSS) (All versions), SIRIUS Safety Relays 3SK2 (All versions). The affected devices do not require authentication to access critical resources. An attacker with network access could retrieve sensitive information from certain data records, including obfuscated safety passwords.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24009" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-222768.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T10:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xgrg-cw4v-4h6g/GHSA-xgrg-cw4v-4h6g.json b/advisories/unreviewed/2025/05/GHSA-xgrg-cw4v-4h6g/GHSA-xgrg-cw4v-4h6g.json new file mode 100644 index 00000000000..d007fd13e1b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xgrg-cw4v-4h6g/GHSA-xgrg-cw4v-4h6g.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xgrg-cw4v-4h6g", + "modified": "2025-05-13T12:31:35Z", + "published": "2025-05-13T12:31:35Z", + "aliases": [ + "CVE-2024-23815" + ], + "details": "A vulnerability has been identified in Desigo CC (All versions if access from Installed Clients to Desigo CC server is allowed from networks outside of a highly protected zone), Desigo CC (All versions if access from Installed Clients to Desigo CC server is only allowed within highly protected zones). The affected server application fails to authenticate specific client requests. Modification of the client binary could allow an unauthenticated remote attacker to execute arbitrary SQL queries on the server database via the event port (default: 4998/tcp)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23815" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-523418.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T10:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xw86-q236-p57v/GHSA-xw86-q236-p57v.json b/advisories/unreviewed/2025/05/GHSA-xw86-q236-p57v/GHSA-xw86-q236-p57v.json new file mode 100644 index 00000000000..f789919b773 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xw86-q236-p57v/GHSA-xw86-q236-p57v.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xw86-q236-p57v", + "modified": "2025-05-13T12:31:35Z", + "published": "2025-05-13T12:31:35Z", + "aliases": [ + "CVE-2024-51447" + ], + "details": "A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.2). The login implementation of the affected application contains an observable response discrepancy vulnerability when validating usernames. This could allow an unauthenticated remote attacker to distinguish between valid and invalid usernames.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51447" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-162255.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-204" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T10:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xww6-q5p3-h6pp/GHSA-xww6-q5p3-h6pp.json b/advisories/unreviewed/2025/05/GHSA-xww6-q5p3-h6pp/GHSA-xww6-q5p3-h6pp.json new file mode 100644 index 00000000000..bab5c93f739 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xww6-q5p3-h6pp/GHSA-xww6-q5p3-h6pp.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xww6-q5p3-h6pp", + "modified": "2025-05-13T12:31:36Z", + "published": "2025-05-13T12:31:36Z", + "aliases": [ + "CVE-2025-40581" + ], + "details": "A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions with SINEMA Remote Connect Edge Client installed). Affected devices are vulnerable to an authentication bypass.\nThis could allow a non-privileged local attacker to bypass the authentication of the SINEMA Remote Connect Edge Client, and to read and modify the configuration parameters.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40581" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/html/ssa-327438.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T10:15:28Z" + } +} \ No newline at end of file